Trust & Security
Last reviewed: June 2026. This page is maintained by the Make Me Revise team to answer common security and privacy questions about the platform. It describes the controls we have enabled today and is editable project content — not an independent certification or audit attestation.
Authentication & access
Accounts are protected by email and password sign-in and Google OAuth. Sessions are managed via secure, HTTP-only auth tokens issued by our backend provider. Admin-only areas require server-side role checks; client-side flags alone never grant elevated access.
Hosting & platform
Make Me Revise runs on the Lovable platform with a managed Supabase Postgres backend and edge functions. The platform provides TLS in transit, encryption at rest for the database, and isolated per-project credentials. Lovable and Supabase secure the underlying infrastructure; Make Me Revise is responsible for application logic, access policies, and how student data is used.
Data we collect
We collect the data needed to personalise revision: name, email, exam board and subjects, exam dates, study progress, answers submitted while practising, and AI-generated notes you save. We do not collect payment card details directly — payments are handled by Dodo Payments.
Row-level access controls
Student data is protected by row-level security policies in the database. By default, a signed-in user can only read and write their own rows. Admin tooling is gated by a separate role table and server-validated checks.
Subprocessors & integrations
We share data only with the providers required to operate the service: Lovable Cloud / Supabase (database, auth, edge functions, storage), Dodo Payments (subscription billing), Resend (transactional email), Google Analytics (aggregated, anonymised usage analytics), and AI model providers (used server-side to generate notes, questions and tutor responses).
Retention & deletion
Account data is retained while your account is active. You can request a data export or full account deletion at any time by emailing support@makemerevise.com. Deletion requests are actioned within 30 days.
Security & incident contact
If you believe you have found a security issue, email support@makemerevise.com with the subject line "Security Report" and we will respond as quickly as we can. Please do not publicly disclose issues until we have had a reasonable opportunity to investigate and remediate.
Compliance
Make Me Revise is a young platform and does not currently hold formal certifications such as SOC 2 or ISO 27001. We aim to align our practices with widely accepted security and privacy norms, and we will update this page as our compliance posture evolves.