1. Who we are
Aris is operated by Verdax Software Ltd, a company registered in England and Wales. When we refer to “Aris”, “we”, “us” or “our”, we mean Verdax Software Ltd.
We are the data controller for the personal data we process through the Aris mobile application and website. If you have any questions about how we handle your data, contact us at privacy@verdax.co.uk.
2. What data we collect
Account information
When you create an account, we collect:
- Name and email address
- Profile image (if provided via Google or Apple sign-in)
- Authentication data managed by our authentication provider (Clerk)
Profile and career data
During onboarding and as you use the app, you may provide:
- Current role and career goal
- Industry and interest areas
- Experience level and learning preferences
- Gender and date of birth (optional)
Learning content
- PDF documents and handbooks you upload for course generation
- Conversation history from lessons, Study Buddy sessions, and career coaching
- Quiz answers, scores, and performance data
- Flashcard review history and spaced repetition data
- Study notes and exported content
Simulation and interview data
- Transcripts of voice-based simulation and interview sessions
- Performance scores and AI-generated feedback reports
- Email follow-up responses composed during simulations
Audio recordings are not stored. Voice input is transcribed in real-time and only the text transcript is retained.
Usage and engagement data
- Lesson completion, streaks, and badges earned
- Points and gamification progress
- Course enrolment and progress tracking
Subscription and payment data
- Subscription tier and status (Free, Standard, or Pro+)
- Purchase history managed by Apple App Store or Google Play Store
We do not process or store your payment card details. All payment processing is handled by Apple or Google through their respective app stores.
Device and technical data
- Push notification tokens for delivering study reminders
3. How we use your data
We use your personal data to:
- Provide and personalise AI-powered lessons, adapting content to your background and learning pace
- Generate structured courses from uploaded handbooks or qualification searches
- Deliver voice-based simulations and interview practice with AI-scored feedback
- Provide AI career coaching informed by your progress and goals
- Track your learning progress, streaks, and achievements
- Generate flashcards and manage spaced repetition schedules
- Send push notifications for study reminders and due flashcard reviews
- Process subscriptions and manage access to features based on your tier
- Improve the quality and accuracy of our AI tutoring
4. Third parties who receive your data
We share data with the following service providers who help us deliver Aris:
AI and content processing
- Anthropic (Claude API) — Conversation content is sent to generate AI tutoring responses, career coaching, and course structures
- OpenAI — Used for course generation from uploaded documents and real-time audio transcription during simulations
- ElevenLabs — Generated response text is sent for text-to-speech conversion during voice features
Infrastructure and storage
- MongoDB Atlas — Cloud database hosting for all application data
- Cloudinary — Secure storage for uploaded PDF documents and profile images
Authentication and payments
- Clerk — Authentication and user account management
- RevenueCat — Subscription and in-app purchase management
- Apple App Store / Google Play Store — Payment processing for subscriptions
Communications
- Expo — Push notification delivery
- YouTube Data API — Search queries for educational video recommendations (no personal data shared)
We do not sell your personal data to any third party. We only share data with service providers who need it to deliver specific functionality within Aris.
5. Legal basis for processing
Under UK GDPR, we process your personal data on the following legal bases:
- Contract performance — Processing necessary to provide the Aris service you signed up for, including AI tutoring, course generation, and progress tracking
- Legitimate interests — Improving our AI models and service quality, preventing abuse, and ensuring platform security
- Consent — Push notifications and optional profile data (you can withdraw consent at any time)
6. Data retention
We retain your personal data for as long as your account is active. This includes your conversation history, progress data, and uploaded content, as these are necessary to provide a continuous and personalised learning experience.
When you delete your account, we delete your personal data from our systems. Some data may be retained in encrypted backups for a limited period as required for legal or operational purposes.
Career coaching threads that have been inactive for an extended period may be automatically archived and eventually purged.
7. Your rights
Under UK GDPR, you have the right to:
- Access — Request a copy of the personal data we hold about you
- Rectification — Request correction of inaccurate personal data
- Erasure — Request deletion of your personal data (“right to be forgotten”)
- Data portability — Request your data in a machine-readable format
- Objection — Object to processing based on legitimate interests
- Restriction — Request that we limit processing in certain circumstances
- Withdraw consent — Where processing is based on consent, you can withdraw it at any time
To exercise any of these rights, contact us at privacy@verdax.co.uk. We will respond within one month as required by UK GDPR.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
8. Data security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption of data in transit (TLS/HTTPS)
- Encryption of data at rest in our database
- Input sanitisation and AI output scanning to prevent injection attacks
- Rate limiting to prevent abuse
- Secure authentication via Clerk with support for social sign-in
- Regular security reviews of our infrastructure
9. Children
Aris is designed for working professionals aged 18 and over. We do not knowingly collect personal data from anyone under the age of 18. If we become aware that we have collected data from a minor, we will take steps to delete it promptly.
10. International data transfers
Some of our service providers (including Anthropic, OpenAI, ElevenLabs, MongoDB Atlas, and Cloudinary) process data in the United States or other countries outside the UK. Where this occurs, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or equivalent mechanisms approved under UK data protection law.
11. Cookies
Our website uses minimal, essential cookies required for the site to function. We do not use tracking cookies, advertising cookies, or third-party analytics on our website. The Aris mobile application does not use cookies.
12. Changes to this policy
We may update this Privacy Policy from time to time. If we make significant changes, we will notify you through the app or by email. The “Last updated” date at the top of this page indicates when the policy was most recently revised.
13. Contact us
If you have any questions about this Privacy Policy or how we handle your data, contact us at:
Verdax Software Ltd
Email: privacy@verdax.co.uk