Last updated: 9 November 2025
Your privacy matters. Here's what you need to know:
Read the full policy below for complete details on how we handle your personal information.
Welcome to Essy ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our essay planning application.
Legal Entity and Data Controller: Essy is operated by David Hailes, based in the United Kingdom. For the purposes of UK and EU data protection law, David Hailes (trading as Essy) is the data controller responsible for your personal data.
Contact Information:
Email: privacy@essy.app
For data protection queries, rights requests, or privacy concerns, please contact us at the email above.
By using Essy, you agree to the collection and use of information in accordance with this policy.
We collect personal information that you voluntarily provide to us when you:
We store the content you create in Essy, including:
Important: Your essay content is private and belongs to you. We do not share, sell, or use your essay content for any purpose other than providing our service to you.
When you use AI-powered features (Pro plan only), we process:
AI processing is performed by Anthropic (Claude AI). We send only the necessary context to generate helpful guidance. Your full essay content is never sent to AI services.
We automatically collect certain information when you use Essy:
For transparency, here's a quick overview of what data we collect and how we handle it:
| Data Type | Purpose | Shared With | Retention |
|---|---|---|---|
| Email, Name | Account setup & authentication | Clerk (auth), Resend (emails) | Until account deleted |
| Essay content | Provide planning service | Supabase (storage only) | Until account deleted |
| Payment data | Billing & subscriptions | Stripe (PCI DSS compliant) | 7 years (legal requirement) |
| AI context (Pro) | Generate AI guidance | Anthropic (Claude AI) | Not stored by Essy or Anthropic |
| Usage logs | Security & troubleshooting | None | 90 days |
| Support emails | Customer support & quality | None | 12 months |
We work with trusted third-party service providers who process personal data on our behalf as data processors (also called "subprocessors" under GDPR). Each provider processes data strictly under our instructions and in accordance with this Privacy Policy and data protection law.
Our current data processors include:
We maintain a current list of subprocessors and will notify users of any changes to this list. You can request an up-to-date list at any time by contacting privacy@essy.app.
We use your information to:
Under UK and EU data protection law, we process your personal data under the following legal bases:
AI Processing Clarification: Processing for AI-powered features (available on Pro plan) is necessary for the performance of our contract with you when you choose to use these tools. This isnot based on consent, but on contractual necessity. You can control this processing by choosing whether or not to use AI features—AI processing only occurs when you actively request it (e.g., clicking "Analyse with AI" or "Generate AI Questions").
For transparency and audit purposes, here's a quick reference table showing how we process your data:
| Processing Purpose | Legal Basis | Example |
|---|---|---|
| Account creation & access | Contractual necessity | Providing access to your account |
| Essay storage & management | Contractual necessity | Storing and retrieving your essay content |
| Payment processing | Contractual necessity & legal obligation | Processing Pro subscription payments |
| AI feature use (Pro) | Contractual necessity | Generating AI suggestions when you click "Analyse with AI" |
| Security & fraud prevention | Legitimate interests | Protecting against unauthorized access and abuse |
| Financial record-keeping | Legal obligation | Retaining transaction records for 7 years (HMRC requirement) |
| Optional analytics/cookies | Consent | Non-essential cookies for performance tracking |
You have the right to object to processing based on legitimate interests. Contact us at privacy@essy.app to exercise this right.
Your data is stored securely using:
We implement industry-standard security measures:
However, no method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
In the unlikely event of a data breach affecting your personal data, we are committed to transparency and compliance with UK GDPR requirements:
If you suspect unauthorized access to your account or have security concerns, please contact us immediately at privacy@essy.app.
We share limited data with trusted third parties who help us provide our service:
These providers are contractually obligated to protect your data and use it only for the purposes we specify. They act as data processors on our behalf under GDPR.
We may disclose your information if required by law, court order, or to protect our rights, property, or safety, or that of others.
The Service or our transactional emails may contain links to third-party websites or services (such as Stripe checkout pages, support documentation, or educational resources). We are not responsible for the privacy practices or content of those external sites. These third parties have their own privacy policies, and we recommend reviewing their policies before providing any personal information. Links to third-party sites do not imply endorsement or responsibility for their content or practices.
Under UK and EU data protection law (UK GDPR / EU GDPR), you have the following rights:
How to Exercise Your Rights: Contact us at privacy@essy.app to exercise any of these rights. We will respond within 30 days (or as required by applicable law).
Right to Lodge a Complaint: If you believe we have not handled your personal data properly, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk or your local data protection authority if you are in the EU.
You can permanently delete your account at any time. To delete your account:
What gets deleted:
What is preserved (anonymous data only):
Important notes:
To exercise other data rights, please contact us at the email address below. We will respond within 30 days.
We retain your information for as long as necessary to provide our service:
Inactive Accounts: If your account remains inactive (no login or use) for 24 months, we may contact you to confirm whether you wish to keep your account. If we receive no response within 30 days, we reserve the right to delete inactive accounts and their associated data.
When you delete your account (Avatar → Security → Delete Account), we follow this deletion schedule:
If you only cancel your Pro subscription (Avatar → Manage Subscription → Cancel), your account and all essays remain intact. You simply revert to the Free plan.
We are required by UK law to retain certain financial records for accounting and tax purposes. After account deletion, these records are fully anonymized and stored separately from any identifiable information. This ensures compliance with GDPR right to deletion while meeting our legal obligations.
We use cookies and similar technologies to:
Cookie Consent: Essential cookies are strictly necessary for the Service to function and do not require consent. Non-essential cookies (such as analytics and performance cookies) are used only with your consent. If you decline non-essential cookies, essential cookies will still function to operate your account securely.
Third-party services we use (such as Clerk for authentication and Stripe for payments) may also set their own cookies. These are covered by their respective privacy policies.
You can control or disable cookies through your browser settings. However, disabling essential cookies will prevent you from using Essy. For more information about managing cookies, visit your browser's help documentation.
Essy is intended for students aged 16 and older. Users under 16 must have parental or guardian consent to use the Service. We do not knowingly collect personal information from children under 16 without appropriate parental consent.
If you believe we have collected information from a child under 16 without proper consent, please contact us immediately at support@essy.app and we will take steps to delete such information promptly. Parents or guardians may request access to, correction of, or deletion of their child's personal information by contacting us.
Some of our service providers may process or store data outside the UK or EU (for example, Anthropic's AI services operate in the United States). When your personal data is transferred internationally, we ensure appropriate safeguards are in place to protect your information.
These safeguards include:
We only transfer data internationally where necessary to provide our Service and ensure your data is protected in accordance with this Privacy Policy and applicable data protection laws (UK GDPR, EU GDPR).
We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through a prominent notice on our service. Your continued use of Essy after changes constitutes acceptance of the updated policy.
This Privacy Policy and our data processing practices are governed by the laws of England and Wales. We comply with UK GDPR and, where applicable, EU GDPR requirements.
Your Right to Complain: If you have concerns about how we handle your personal data, we encourage you to contact us first at privacy@essy.app so we can work to resolve the issue.
However, you have the right to lodge a complaint directly with the relevant supervisory authority:
These authorities will investigate your complaint and work with us to resolve any issues with our data processing practices.
If you have questions about this Privacy Policy or how we handle your data, please contact us:
Email: privacy@essy.app
For transparency, we maintain a log of significant updates to this Privacy Policy:
Future updates will be logged here for transparency. Significant changes will be communicated via email.
Summary: We respect your privacy. Your essays are yours—we don't sell your data, share your content, or use your work to train AI models. We only use your information to provide and improve our service to you.