Privacy
Without an account, your practice stays on your device and is gone when you close the browser. With one, it is synced so a second device can pick it up. An account is optional and changes only what is named below. This page says exactly what that means, and where the exceptions are.
Last updated 12 August 2026
The short version
- An account is optional. Signed out — which is the default, and how the app ships today — nothing identifies you and nothing is held about you.
- Signed out, your progress lives only in the tab you have open and is gone when you close it. Signed in, it is kept on your account so it follows you between devices.
- No cookies, no analytics, no advertising and no third-party trackers.
- Your writing and speaking transcript are sent for marking when you ask. Signed out, they disappear with the tab; signed in, completed feedback can be stored in your private history so you can revisit it.
- BandUp keeps technical AI-cost records — the feature, model, token counts, calculated cost, request ID and time — but never the words sent or received, your name, email or account ID.
- BandUp never uploads audio from your microphone and never saves it as a file.
- On the web you can choose to have your speech transcribed on your own device, so the audio never leaves it at all. The recogniser built into your browser or phone is still the default.
What is stored, and where
Signed out, everything BandUp remembers about you lives in the tab you are using and nowhere else. Close the tab or the browser and it is gone; open BandUp again and you start fresh. Nothing is left behind on the machine, which matters most on a shared or borrowed one. Signed in, the five learner entries are kept on your account instead, so they follow you between devices. A sixth, clearly marked below, is only an admin dashboard layout and always stays in that administrator’s browser. This is the whole of it:
ielts-prep-v1
Your placement result, target band, study plan and test scores.
bandup.drills.v1
Which grammar and vocabulary drills you have finished, and how you did.
bandup.lookups.v1
Words you have tapped to look up, so you can revise them later.
bandup.theme
Whether you chose the warm, light or dark theme.
bandup.speech.v1
Which speech recogniser you chose for the speaking test, and which model size.
bandup.admin.overview.v1
For a site administrator only: which two charts they chose for the admin overview. It contains no learner, account or financial data and stays in that browser.
Two standard model files can also be stored on your device. If you turn on on-device transcription in the speaking test, its speech model (about 75 or 145 MB, depending on which you pick) is downloaded once and kept in your browser’s cache. On the web, the natural British examiner voice uses a separate model of about 92 MB, downloaded when you first start an interview. Both run on your device, hold no data about you and are the same files every learner downloads.
Because this lives on the device and nowhere else, your progress does not follow you to a new phone or a different browser, and we cannot recover it for you if it is lost.
What leaves your device
Five features need a model to think about your English, and those are the only times anything you write is sent anywhere. Each one goes to BandUp’s server, which passes it to Anthropic’s API for the answer and sends that answer back to you. The marking request itself is not written to a server log. If you are signed in and save your completed practice, its feedback record can include the essay or speaking transcript so your history can be reopened later.
To measure what the AI actually costs, BandUp keeps a separate technical receipt for each completed request: the feature used, Claude model, provider request ID, input, output and cache token counts, calculated cost and time. It contains no prompt, answer, transcript, name, email or account ID and cannot recreate what anybody wrote or said.
Writing marking /api/grade/writing
The essay you wrote and the task prompt it answers.
Speaking marking /api/grade/speaking
The written transcript of your interview — the text, never the audio.
New practice tests /api/generate
The topic and difficulty you picked. Nothing about you.
Word lookup /api/define
The word you selected and the sentence it appeared in.
Ask a tutor /api/chat
The question you typed, and the recent messages of that conversation so the answer follows on. The conversation lives in the tab you are reading it in and is gone when you close it.
Your placement result, your study plan and your test scores are never among them. Anthropic handles what it receives under its own terms; BandUp sends no name, no email and no identifier alongside it, because it holds none.
Model downloads also leave your device, and carry none of your work: if you turn on on-device transcription, its speech model is downloaded once from Hugging Face; when you first start a web speaking interview, the natural examiner model and British voice are downloaded there too. The words spoken by the examiner are generated locally and are not sent to a voice service.
Placement, the study plan, the bundled practice tests, the grammar and vocabulary drills and the marking of reading and listening answers all run entirely on your device, and work with no connection at all.
The microphone, in full
The speaking test asks for microphone access so it can hear your answers. This is the part worth reading carefully, because the speaking test now offers two ways of turning speech into text and they differ in exactly this respect. You choose on the screen before the interview starts.
Your device’s recogniser — the default
- Your speech is turned into text by the recogniser built into the device or browser you are using — Apple’s speech recognition in the iOS app, the browser’s own Web Speech API on the web. BandUp receives only the words it returns.
- Those recognisers are not ours, and some of them send audio to their own servers to transcribe it — Chrome’s uploads to Google. Apple and the makers of Chrome, Safari and Edge each decide whether recognition happens on the device or in their cloud, and that is governed by their privacy policies, not this one. We would rather tell you this plainly than claim your voice never leaves the phone when we cannot guarantee it.
On-device transcription — if you turn it on
- With this on, your audio never leaves your device. A speech model called Whisper runs inside your own browser and does the transcription there. Nothing is sent to BandUp, to us, or to anyone else, and no recogniser outside your device hears it.
- Your answer is held in memory while you speak, because this model needs the whole answer before it can transcribe it. It is never written to a file and it is discarded as soon as the text comes back.
- There is one exception worth being exact about, and it is not audio. The model itself has to be downloaded before it can run, and it comes from Hugging Face, who host it. That request happens once, then the file is cached and used offline. Hugging Face therefore sees that some device asked for the file, along with the IP address any download reveals. It carries no audio, no transcript, no identifier, and nothing about you or your practice.
- This option is available on the web. The iOS app does not offer it yet: the on-device model there is written but not yet built into a released version, so in the app the speaking test still uses Apple’s recogniser. When that changes, this page changes with it.
Both ways share the rest: BandUp never uploads your audio and never saves it as a file. Only the finished transcript — text — is sent for marking, and only when you ask for feedback. The microphone is used during the speaking test and at no other time. You can also skip the microphone entirely and type your answers.
The speaking examiner also reads its questions aloud using the voice built into your device. That is playback only; nothing is captured.
If you sign in
BandUp can be used entirely signed out, and is by default. The placement test, your study plan, every practice test and both sets of drills work without an account and always will. An account exists to carry that work between your phone and your laptop, and to raise the daily limit on AI feedback.
You can sign in with Google, with Apple, or with an email address and a password. With Google or Apple, BandUp never sees a password at all — the provider confirms it is you and passes on your email address and nothing else. If you set a password instead, it is held by Supabase, our database provider, as a one-way hash: a value that can check a password is right and cannot be turned back into it. Nobody here can read your password, including us.
If you do sign in, we hold:
- Your email address, so the account can be recovered if you lose access to Google or Apple.
- A count of AI requests over the last thirty days, so each feature's allowance can be applied. It records that a request happened and to which feature — never what you wrote, said or were told.
- A one-way hash of the internet address the request came from, so that one address cannot spend an unlimited amount of AI by making accounts. It is salted and cannot be turned back into an address, and it is used for nothing else — not location, not advertising, not analytics.
- A copy of your study progress, if you choose to sync it, so a new device can pick up where the last one left off.
- For completed writing and speaking practice, the saved history can include your essay or transcript and the feedback, so you can revisit the original sitting.
- Anything you choose to put on your account page: a display name, a profile picture, and optionally your date of birth. All of it is optional, all of it can be cleared, and the account works exactly the same if you leave it empty.
Your date of birth is used for exactly one thing: confirming you are 13 or over. This app is not intended for younger children, and a date of birth is the only way that can be checked rather than assumed. Nothing else reads it — it does not affect your plan, your band or anything you see.
We previously asked for your gender. It has been removed, because nothing in BandUp ever used it and holding personal information with no purpose is not something we want to do. Any gender already stored has been deleted along with the field.
Your profile picture is stored privately and is never public. BandUp has no profile pages, no leaderboards and no way for other learners to find you, so the only person who ever sees it is you. It is served through a link that expires after an hour rather than from a permanent address.
Account data is stored with Supabase, who host the database on our behalf. Their servers may be in a different country from yours, which is true of almost any hosted service and is worth saying rather than leaving you to assume otherwise.
Questions about any of this, or a request about your data, go to hello@bandup.life.
Signing out ends the session on that device and deletes nothing. To close the account altogether, use Delete your account on your account page: it removes your email address, your details, your picture and any synced practice, immediately and permanently. The copy in your own browser stays, because it was never ours to delete — clear that from your browser’s settings whenever you like.
Sessions are kept in your device’s own storage rather than in a cookie, which is why signing in still sets none.
Organizations, teachers and shared progress
If you join a school or other organization in BandUp, that workspace stores your membership, role, teacher assignment and requests to join, leave or change access. Work completed after joining is shared with that organization. Sharing work from before joining is a separate choice and, while you remain a student member, changing it uses an approval request.
Assigned teachers can see only their assigned students. Organization managers can see members and student history in their own organization. That history can include scores, answers, feedback, essays and speaking transcripts. BandUp administrators can access organization records when needed to approve, secure or support the service. Other learners cannot see them.
An active, suspended or leaving student member cannot clear their history. Teachers may archive an assigned student’s organization view; managers may permanently remove an attempt from that organization only, with a recorded reason. Neither action deletes the learner’s original account record. Joining, decisions, assignments and removals create an audit record so permissions and data changes can be investigated.
After an approved departure, the former student can change consent without organization approval. Closing the BandUp account deletes the learner-owned source records; minimal security audit and organization-removal records can remain where required to establish what an administrator did, without keeping the essay or transcript in those records.
Cookies and tracking
There are none. BandUp sets no cookies, includes no analytics or advertising scripts, and loads nothing from a third party that could watch you across sites. There is no consent banner here because there is nothing to consent to. Signing in does not change this: the session is held in your device’s own storage, not in a cookie.
One honest edge: if you subscribe, the payment page is Stripe’s own, on Stripe’s domain, and it sets its own cookies under its own policy — as any payment page does. You are on their site for those two minutes, and back here after.
The web version is served by a hosting provider that, like any web host, records ordinary server request logs. BandUp does not use those logs to build any picture of you.
If you subscribe
Your card details never reach BandUp. Paying takes you to Stripe, the payment company, and the card is typed on their page and stored by them. Nothing here ever sees a card number, an expiry date or a security code, which means there is no version of this app being breached that exposes your card.
Stripe tells us only what is needed to know what you have bought: that a subscription started, renewed or ended, which plan it is, and an identifier that links it to your account. That is what the app stores — the plan, the dates, and the identifier.
Stripe is a separate company and handles your payment information under its own privacy policy. It needs your name, email and card to process a payment, and it uses that information to detect fraud, which is the reason payment works at all.
If you never subscribe, none of this applies to you and no payment company is involved in your account at all.
Deleting your data
Without an account everything is on your device, so deleting it is entirely in your hands and takes effect immediately:
- In the app: delete BandUp from your device. Its storage goes with it.
- On the web: clear site data for this site in your browser’s settings.
Signed out there is no request to send us and no account to close, because nothing is held on our side to delete. That deletion is final — your progress cannot be restored afterwards. If you have an account, see below for what it holds and how to close it.
Children
BandUp is a study tool for people preparing for an English exam and is not aimed at children under 13. Without an account it collects nothing that identifies anybody. With one it holds an email address, and whatever else you choose to add, which is why the age limit exists at all. If you are in the EU or the UK and under 16, the law may require a parent’s permission before an account is made in your name — please ask them first.
Who is responsible for your data
BandUp is run by Adam Yiu, as an individual rather than through a company. That is the person responsible for the data described on this page — what the GDPR calls the controller — and the person any request or complaint reaches.
Adam Yiu11B, Chai Kung Mansion
Taikoo Shing
Hong Kong
Write to hello@bandup.life to ask what is held about you, to have it corrected, or to have it deleted. If you are in the EU or the UK you also have the right to complain to your national data protection authority; in Hong Kong that is the Privacy Commissioner for Personal Data.
Changes to this policy
If what BandUp stores or sends ever changes, this page changes with it and the date at the top is updated. The version you are reading ships inside the app you have installed, so it always describes that version.
That is the whole policy. Back to the practice: