ThinkLikeLaw
Terms of Service Support

Privacy Policy

Effective Date: 17 February 2026  |  Last Updated: 17 February 2026  |  Version: 1.0

ThinkLikeLaw ("we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our website and use our services (collectively, the "Service"), in accordance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA 2018), and the Privacy and Electronic Communications Regulations 2003 (PECR).

Please read this Privacy Policy carefully. By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.

1. Data Controller

The data controller responsible for your personal data is:

  • Name: ThinkLikeLaw
  • Email: privacy@thinklikelaw.com
  • Jurisdiction: England and Wales, United Kingdom

For the purposes of the UK GDPR, we are the data controller in respect of the personal data we process about you.

2. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person ('data subject'), as defined under Article 4(1) UK GDPR.
  • "Processing" means any operation performed on personal data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction.
  • "Special Category Data" means personal data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation.

3. Personal Data We Collect

We collect and process the following categories of personal data:

3.1 Data You Provide Directly

Category Data Elements Purpose
Account Registration First name, last name, email address, password (hashed), university Account creation, personalisation, communication
Profile Information Target qualification year, current academic status, study preferences Personalised learning experience
User Content Uploaded lecture notes, essays, notes created within the Service Providing AI-powered analysis and feedback
Payment Information Billing name, email, payment method details (processed by Stripe) Subscription billing and invoicing
Support Requests Name, email, message content Responding to enquiries and providing support

3.2 Data Collected Automatically

Category Data Elements Purpose
Usage Data Pages visited, features used, time spent, click patterns Service improvement and analytics
Device Data Browser type, operating system, screen resolution, device identifiers Compatibility and debugging
Network Data IP address, approximate geolocation (country/region level) Security, fraud prevention, legal compliance
Cookies & Similar Technologies Session tokens, preference cookies, analytics identifiers Authentication, personalisation, analytics

3.3 Data from Third Parties

If you sign in using Google OAuth, we receive your name, email address, and profile picture from Google. We do not receive or store your Google password.

4. Lawful Bases for Processing

We process your personal data under the following lawful bases as defined in Article 6(1) UK GDPR:

Lawful Basis Processing Activity
Contract (Art. 6(1)(b)) Account registration, providing the Service, processing subscriptions and payments, delivering AI-generated content
Legitimate Interests (Art. 6(1)(f)) Service improvement, analytics, fraud prevention, security monitoring, customer support. Our legitimate interest is to operate and improve the Service. We have assessed that this processing does not override your rights and freedoms.
Consent (Art. 6(1)(a)) Marketing emails (where applicable), non-essential cookies. You may withdraw consent at any time.
Legal Obligation (Art. 6(1)(c)) Tax records, regulatory compliance, responding to lawful requests from authorities

5. How We Use Your Data

We use your personal data for the following purposes:

  1. Account Management: Creating and maintaining your account, authenticating your identity, and managing your subscription.
  2. Service Delivery: Providing AI-powered legal education tools including case summaries, issue spotting, essay marking, flashcards, and podcasts.
  3. Personalisation: Tailoring content and features to your university, academic level, and study preferences.
  4. Communication: Sending essential service notifications (account confirmations, password resets, subscription updates). We will not send marketing communications without your explicit consent.
  5. Payment Processing: Processing subscription payments through our payment processor, Stripe. We do not store your full credit card details on our servers.
  6. Improvement and Analytics: Analysing usage patterns to improve functionality, fix bugs, and develop new features.
  7. Security: Detecting and preventing fraud, abuse, and security threats.
  8. Legal Compliance: Complying with applicable laws, regulations, and legal processes.

6. Data Sharing and Disclosure

We do not sell, rent, or trade your personal data. We may share your data with the following categories of recipients:

Recipient Purpose Safeguards
Supabase Inc. (Database & Auth) Hosting, authentication, database storage Data Processing Agreement (DPA), Standard Contractual Clauses (SCCs) for US transfers, SOC 2 Type II compliant
Stripe Inc. (Payments) Payment processing, subscription management PCI DSS Level 1 certified, DPA, SCCs
Google LLC (OAuth) Social login authentication OAuth 2.0, limited data scope (email, name, profile picture), DPA
Cloudflare Inc. (Hosting) CDN, DDoS protection, edge computing DPA, EU-US Data Privacy Framework
OpenAI / AI Providers AI-powered content generation DPA, data not used for model training, API-only access

We may also disclose your data where required by law, regulation, court order, or other governmental request, or where we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

7. International Transfers

Some of our third-party service providers are located outside the United Kingdom. Where personal data is transferred outside the UK, we ensure that appropriate safeguards are in place in accordance with Article 46 UK GDPR, including:

  • Standard Contractual Clauses (SCCs) approved by the Information Commissioner's Office (ICO)
  • UK Adequacy Decisions where the destination country ensures an adequate level of protection
  • Binding Corporate Rules (BCRs) where applicable

You may request a copy of the relevant safeguards by contacting us at the address above.

8. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:

Data Type Retention Period Justification
Account data Duration of account + 30 days after deletion request Contract performance, account recovery
User-generated content Duration of account Service delivery
Payment records 7 years from transaction date UK tax and accounting obligations (Taxes Management Act 1970)
Support tickets 2 years from resolution Legitimate interest in quality assurance
Analytics data 26 months (anonymised after) Service improvement
Cookie consent records 2 years PECR compliance, proof of consent

Upon expiry of the retention period, personal data will be securely deleted or irreversibly anonymised.

9. Cookies and Similar Technologies

We use cookies in accordance with the Privacy and Electronic Communications Regulations 2003 (PECR) and ICO guidance.

9.1 Strictly Necessary Cookies

These cookies are essential for the Service to function and cannot be switched off. They include session authentication tokens and CSRF protection tokens.

9.2 Functional Cookies

These cookies remember your preferences such as theme selection (dark/light mode), sidebar state, and language preferences.

9.3 Analytics Cookies

With your consent, we may use analytics cookies to understand how visitors interact with the Service. No analytics cookies are set without your prior consent.

You can manage cookie preferences through your browser settings. Disabling strictly necessary cookies may affect the functionality of the Service.

10. Your Rights Under UK GDPR

Under the UK GDPR and DPA 2018, you have the following rights in relation to your personal data:

  1. Right of Access (Article 15): You have the right to request a copy of the personal data we hold about you. We will respond within one month of receiving your request.
  2. Right to Rectification (Article 16): You have the right to request correction of inaccurate or incomplete personal data.
  3. Right to Erasure (Article 17): You have the right to request deletion of your personal data where there is no compelling reason for its continued processing. This right is not absolute and may be limited by legal obligations.
  4. Right to Restriction of Processing (Article 18): You have the right to request that we restrict the processing of your personal data in certain circumstances.
  5. Right to Data Portability (Article 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
  6. Right to Object (Article 21): You have the right to object to processing based on legitimate interests or direct marketing.
  7. Rights Related to Automated Decision-Making (Article 22): You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Our AI tools provide educational assistance only and do not make decisions with legal or similarly significant effects on you.
  8. Right to Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at privacy@thinklikelaw.com. We will respond to all legitimate requests within one calendar month. In exceptional circumstances, we may extend this by two further months, but we will inform you of the reason for the extension.

There is no fee for exercising your rights, unless your request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse the request.

11. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage, in accordance with Article 32 UK GDPR. These measures include:

  • Encryption at rest and in transit (TLS 1.2 or higher)
  • Secure password hashing (bcrypt)
  • Role-based access controls
  • Regular security audits and vulnerability assessments
  • Data minimisation principles
  • Secure backup procedures

12. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  1. Notify the Information Commissioner's Office (ICO) within 72 hours of becoming aware of the breach (Article 33 UK GDPR)
  2. Notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms (Article 34 UK GDPR)
  3. Document all breaches, including the facts, effects, and remedial action taken

13. Children's Privacy

The Service is intended for users aged 16 years and older, in line with the UK GDPR age of digital consent. We do not knowingly collect personal data from individuals under the age of 16. If we become aware that we have collected personal data from a child under 16 without appropriate parental consent, we will take steps to delete such data promptly.

14. Third-Party Links

The Service may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices of such third parties. We encourage you to read the privacy policies of any third-party sites you visit.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the updated policy on this page with a revised "Last Updated" date
  • Sending an email notification to registered users where the changes are material

Your continued use of the Service after any modifications constitutes your acceptance of the updated Privacy Policy.

16. Complaints

If you are dissatisfied with how we handle your personal data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

  • Website: ico.org.uk/make-a-complaint
  • Telephone: 0303 123 1113
  • Address: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

We would appreciate the opportunity to resolve your concern before you contact the ICO.

17. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

  • Email: privacy@thinklikelaw.com
  • Support: thinklikelaw.com/support

© 2026 ThinkLikeLaw. All rights reserved.

Privacy Terms Support