Privacy policy

Privacy Policy — SENBridge (England)

Last updated: 10 June 2026
Status: Pre-trial draft — accounts, session chat, Favourites and My letters (when enabled); subscription/billing wording for future Stripe checkout. Solicitor review required before trial launch of stored user content or paid plans.

Website: https://senbridge.uk (private beta may use a temporary host URL until the domain is connected).


1. Who we are (data controller)

SENBridge (England) (“the Service”, “we”, “us”) is an unofficial information tool that helps users understand SEND-related legislation and official guidance for England. It is operated as a private beta.

| | | |---|---| | Service | SENBridge (England) | | Website | https://senbridge.uk | | Contact (privacy & account requests) | noreply@senbridge.co.uk | | Operator | Sam Connor (sole trader) |

For UK GDPR, the data controller is the operator named above. If we appoint a limited company later, we will update this section.


2. What this Service is not

  • Not formal legal advice — use a solicitor or SENDIASS for your situation.
  • Not medical or clinical advice.
  • We are not a local authority, school, SENDIASS, regulator, or tribunal service.
  • We do not provide crisis or safeguarding intervention; see §12.

3. Information we collect and use

3.1 Account information (if you register or sign in)

When you create an account, we store:

  • Email address (used to sign in and for account emails)
  • Password (stored as a one-way hash, not plain text)
  • Account tier / subscription status (active trial, active subscription, or lapsed) — used to enforce access and limits
  • Subscription status (when billing is enabled): plan name, trial end date, renewal date, cancellation status — stored to operate access; payment card details are handled by the payment provider (e.g. Stripe), not stored by us as full card numbers
  • Session data needed to keep you signed in (see cookies below)

We may also store password-reset tokens and email-change tokens (hashed) until they expire or are used. If you request an email change, we temporarily store your new email address (encrypted at rest) until you confirm or the token expires (up to 24 hours).

Lawful basis (UK GDPR): Contract — necessary to provide your account and the Service you asked for.

3.2 Chat and questions

On our servers

  • We do not store full chat conversations in our database.
  • Your messages are processed to generate a reply, then discarded on the server for that request (unless you choose to save content under §3.3 or §3.4).
  • Conversation context for follow-up questions may be sent again within the same session (up to 6 prior messages, 600 characters each, 2500 characters total).

In your browser (same tab)

  • The chat UI may keep messages in sessionStorage (key sen-chat-session-v1, up to 80 messages, draft input up to 2000 characters) so your conversation can continue if you refresh the page or move to another page in the same tab (e.g. Favourites) and return to chat.
  • This stays on your device until you close the tab, use Clear chat, sign out, or clear site data.
  • We also record per-tab processing consent in sessionStorage and (when enforced) a signed HttpOnly cookie so the server can verify you accepted before sending messages to AI.

Please do not type more personal data than you need (e.g. full names, addresses, NHS numbers, or detailed medical records). The Service works best with general SEND questions.

Lawful basis (ordinary personal data in chat): Contract (Art. 6(1)(b)) — necessary to answer your request.

Lawful basis (special category data — e.g. disability, health, or child details you choose to include): Explicit consent (Art. 9(2)(a)) — before your first message in each browser tab, you must click “I understand and agree to continue” on the chat consent panel. Only share sensitive information if necessary.

Automated decisions: The Service does not make automated decisions with legal or similarly significant effects on you (UK GDPR Art. 22). AI output is informational only.

3.3 Favourites (starred messages) — when enabled

When the Favourites feature is enabled, you may choose to save individual chat messages to your account by starring them.

What we store:

  • The message text you saved (your message or an assistant reply)
  • An optional title you give the save
  • Whether it was you or the assistant
  • For assistant replies: an optional snapshot of cited sources and the model name
  • Optional Top saves shortlist marker (ordering only — not a separate copy)
  • When you saved it

What we do not store: your full chat history — only messages you explicitly save. We do not use saved favourites to train AI models.

Retention: until you delete the save or delete your account.

Lawful basis: Contract (Art. 6(1)(b)); Art. 9(2)(a) where saved text is special category — user-initiated save after in-app notice.

Limits (when enabled): active subscribers may save up to 75 favourites (see Terms §7.8). Without an active subscription or trial, saving is not available.

3.4 My letters (editable letter drafts) — when enabled

When My letters is enabled, you may choose to save letter or email drafts to your account and edit them on the My letters page.

What we store:

  • Draft title (optional)
  • Draft body text (including your edits)
  • Created and last updated timestamps
  • Optional reference if the draft was first saved from a chat message (message id only — not a full chat log)

Email: If you tap Email on a draft or use Share → Email on a chat reply, your device opens your own email app (e.g. via mailto:). We do not send email on your behalf and do not receive a copy of what you send.

Retention: until you delete the draft or delete your account.

Lawful basis: same as §3.3 — Contract; Art. 9(2)(a) where draft text is special category.

Limits: active subscribers may save up to 25 letter drafts (see Terms §7.8). Without an active subscription or trial, saving is not available.

3.5 Account export (data portability)

Signed-in users may download a copy of account-held personal data (account details, favourites, letter drafts) in a machine-readable JSON file from Account settings → Download my data. This supports your right to data portability (UK GDPR Art. 20) where it applies.

3.6 What we do not store

We do not store on our servers:

  • Full chat conversations (unless you explicitly save individual messages or letter drafts)
  • File attachments or uploaded documents
  • A persistent child profile or multi-child case file
  • Data for advertising or AI model training from your content

We will update this policy before any new category of stored data goes live.

3.8 Subscription and payment data (when billing is enabled)

If you subscribe or start a free trial that converts to paid access:

  • We store subscription identifiers, plan, status, and billing period dates returned by our payment provider.
  • Payment card details are collected and processed by the provider (e.g. Stripe); we receive only tokens/identifiers needed to manage your subscription, not your full card number.
  • We may receive billing email, last four digits of card, and payment failure notices for account support.

Lawful basis: Contract (Art. 6(1)(b)) — necessary to provide paid access and comply with tax/accounting obligations where applicable.

We will update this section with the live provider name and data regions before checkout goes live.

3.9 Technical and security data

We may process:

  • IP address and request metadata (rate limiting, abuse prevention, short-lived logs)
  • Browser/device type (standard web server logs)
  • Authentication audit events (e.g. sign-in, password reset)
  • Error logs (we aim not to log full chat message text)
  • Operator security alerts (aggregated signals)

Lawful basis: Legitimate interests (security, abuse prevention, reliability) and, where applicable, legal obligation.

3.10 Cookies and similar technologies

We use essential cookies and browser storage for sign-in, security, in-tab chat, and dismissed in-app notices. We do not use advertising or cross-site tracking cookies.

Full details: Cookie Policy.


4. How we use information

We use the above to provide and secure the Service, send transactional account emails, enforce rate limits, and improve reliability. We do not sell your personal data or use your content to train AI models.


5. AI processing (Google Gemini)

Your questions and retrieved excerpts from official sources are sent to Google’s Gemini API to generate responses. Google acts as a processor under its own terms. Processing is in real time for each request.

Saved favourites and letter drafts are stored on our database and are not sent to Google unless you paste them into a new chat message.

Data may be processed in the UK, EEA, United States, or other countries where Google or our host operates, with appropriate safeguards where UK GDPR requires them.


6. Processors and hosting

| Processor | Purpose | |-----------|---------| | Hosting provider (e.g. Railway) | App and database hosting | | PostgreSQL (via host) | Account, favourites, and letter drafts | | Resend (or similar) | Transactional email (password reset, email change) | | Google (Gemini) | AI-generated replies | | Upstash Redis (if enabled) | Rate limiting only | | Stripe (or similar, when enabled) | Subscription checkout and recurring billing |


7. Retention

| Data | Retention | |------|-----------| | Account data | While your account exists | | Password-reset / email-change tokens | Short TTL, then deleted | | Server / security logs | Limited period (e.g. up to 90 days) | | Chat (live requests) | Not retained in our database after each reply | | In-tab chat (browser) | Until tab closed, Clear chat, sign out, or site data cleared | | Favourites | Until you delete the save or delete your account | | Letter drafts | Until you delete the draft or delete your account | | Subscription records | While required for billing, tax, and dispute resolution, then deleted or anonymised per provider rules |

Backups may retain deleted data for a short period before overwrite.


8. Your rights (UK)

You may have rights to access, rectify, erase, restrict, object, data portability, and to withdraw consent where we rely on consent.

  • Contact: noreply@senbridge.co.uk — we respond within one month where required.
  • Delete account: Account settings → Delete account, or email from your registered address.
  • Export: when available, via account settings or contact us.
  • Complaint: ico.org.uk.

9. Security

We use HTTPS, hashed passwords, access controls, and cascade deletion when you delete your account. Report suspected breaches to noreply@senbridge.co.uk.


10. Lawful bases summary (UK GDPR)

| Processing | Basis | |------------|--------| | Account & sign-in | Contract (Art. 6(1)(b)) | | Answering chat | Contract (Art. 6(1)(b)) | | Favourites / My letters | Contract; Art. 9(2)(a) where content is special category | | Subscription & billing | Contract (Art. 6(1)(b)) | | Security & rate limits | Legitimate interests (Art. 6(1)(f)) | | Special category in chat | Explicit consent (Art. 9(2)(a)) — per-tab consent |


11. Children, safeguarding, and sensitive information

  • The Service is for adults aged 18+. Do not allow children under 18 to create accounts.
  • Content may involve special category data — only share what is necessary.
  • Safeguarding: if a child is at risk, contact 999 or local safeguarding services. This Service is not monitored 24/7.

12. Changes

We may update this policy. The Last updated date will change. Material changes to stored-data features will be reflected here before they go live where practicable.


13. Feature status (pre-trial)

| Feature | Status | |---------|--------| | Session chat + in-tab browser storage | Live | | Favourites | Built — solicitor review before trial launch | | My letters (editable drafts) | Built/planned — solicitor review before launch | | Account export | Available from Account settings | | Paid subscription (Stripe) | Planned — not live in private beta; solicitor review before checkout |

This policy is not legal advice — obtain UK solicitor review before inviting trial users to stored-data features or enabling billing.