Privacy Policy

What data this site collects, who else can see it, and how to make us delete it.

The short version

You can read this entire site without giving us anything. We have no accounts, no newsletter, no comment system and no tracking pixels of our own. Search runs in your browser and nothing you type is sent to us. The only personal data we hold is the email you send us, if you send one. Third-party advertising, when it is enabled, will set its own cookies and is described in section 5.

This policy explains how ScholarBrief (“we”, “us”) handles personal data when you visit thankyounotes.store. It applies to this website only, and not to any external site we link to. Where this policy uses the terms controller, processor, personal data and processing, they carry the meanings given in the EU General Data Protection Regulation (GDPR) and the UK GDPR.

ScholarBrief is the controller for the data described here. Contact: editor@thankyounotes.store, subject line PRIVACY.

1. What we collect directly

Email correspondence

If you email us or use the contact form, we receive your email address, your name if you include it, and whatever you write. The contact form does not transmit anything to us on its own — it composes a message in your own email application, and nothing leaves your device until you press send there.

Purpose: to answer you and, for corrections, to keep a record of what was reported and what we changed.
Legal basis: legitimate interests (GDPR Art. 6(1)(f)) in responding to enquiries and maintaining an auditable corrections record; for legal notices, compliance with a legal obligation (Art. 6(1)(c)).
Retention: general correspondence is deleted after 24 months. Correction reports are kept as long as the affected page is published, because the corrections log is part of our editorial record. Legal notices are kept for 6 years.

Nothing else

We do not operate user accounts, logins, profiles, newsletters, mailing lists, comment sections, forums, surveys, quizzes, downloads behind a form, or “scholarship matching” services. We never ask for your date of birth, nationality, passport details, immigration status, grades, financial information or banking details, and you should be extremely suspicious of any education website that does.

2. What is collected automatically

Server logs

Our hosting provider records standard web server logs for every request: IP address, timestamp, requested URL, HTTP status, referring URL and user-agent string. These are used for security, abuse prevention and diagnosing faults. We do not use them to build profiles of individuals and we do not combine them with any other data.

Legal basis: legitimate interests (Art. 6(1)(f)) in operating and securing the site.
Retention: logs are retained by the host for a short rolling period, typically no more than 30 days, and then discarded.

Local storage in your browser

If you use the dark/light mode switch, your choice is stored in your browser’s localStorage under the key sb-theme. This never leaves your device, is not readable by us, and is not a cookie. Clearing your browser’s site data removes it.

Search

The site search downloads a single index file and runs entirely in your browser. Your search terms are not transmitted anywhere, not logged, and not visible to us.

3. What we do not do

  • We do not sell, rent or trade personal data. Ever, to anyone, for any price.
  • We do not share your email address with universities, scholarship providers, education agents, recruiters or lead-generation companies.
  • We do not run our own tracking pixels, session recorders, heatmaps or fingerprinting scripts.
  • We do not knowingly build advertising profiles ourselves.
  • We do not require an email address to read anything on this site.

4. Cookies

ScholarBrief sets no first-party cookies. The site functions completely without them. Cookies that may be set by third-party advertising are covered in the next section and in the separate cookie policy, which lists categories, purposes and how to control them.

5. Advertising

Current status

Third-party advertising is not yet enabled on this site. This section describes what will apply when it is, and this policy will be updated with the activation date at that point. Until then, no advertising cookies are set and no ad network receives data from your visit.

When advertising is enabled, ScholarBrief intends to use Google AdSense. In that arrangement:

  • Google and its partners act as independent controllers for the data they collect through advertising, not as our processors. We do not receive that data, and we cannot access, correct or delete it on your behalf.
  • Third-party vendors, including Google, use cookies and similar technologies to serve ads based on your prior visits to this and other websites.
  • Google’s use of advertising cookies enables it and its partners to serve ads to you based on your visit to this site and/or other sites on the internet.
  • You can opt out of personalised advertising by Google at Google Ads Settings (opens in a new tab). You can opt out of personalised advertising by many other vendors at aboutads.info/choices, the NAI opt-out and, in Europe, Your Online Choices.
  • Google’s own handling of data is described in the Google Privacy & Terms page for partner sites.
  • For visitors in the EEA, UK and Switzerland, a consent management platform will request consent for advertising cookies and for personalised advertising before any such cookie is set, and will record your choice. You will be able to withdraw or change that choice at any time from the link in our footer.

Advertising is bought as inventory. No advertiser receives editorial influence, prior sight of unpublished work, or the ability to commission or suppress a page. See our editorial policy.

6. Analytics

We currently run no third-party analytics. If we add analytics in future, we will use a configuration that does not set cookies and does not collect personal data, or one gated behind consent, and we will update this policy and the cookie policy before it goes live.

7. Hosting and international transfers

This site is served as static files from a commercial hosting and content delivery provider, which processes server log data on our behalf as a processor under a data processing agreement. Content is distributed from edge locations worldwide, so a request from you may be served and logged in a country other than your own.

Where personal data is transferred out of the EEA or the UK, the transfer relies on the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable) or an adequacy decision, together with the supplementary technical measures our provider applies.

8. Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you and receive a copy.
  • Rectify inaccurate data.
  • Erase data (“right to be forgotten”), subject to our need to retain records of legal notices.
  • Restrict or object to processing based on legitimate interests.
  • Portability — receive your data in a structured, machine-readable format.
  • Withdraw consent at any time, where processing is based on consent.
  • Not be discriminated against for exercising privacy rights (California).
  • Opt out of “sale” or “sharing” of personal information for cross-context behavioural advertising (California and several other US states). ScholarBrief does not sell personal information as those laws define it. When third-party advertising is enabled, the setting of advertising cookies may constitute “sharing” under the CPRA, and an opt-out control will be provided in the footer at that time.

To exercise any right, email editor@thankyounotes.store with the subject PRIVACY. We respond within 30 days. We may need to ask a question to confirm you are the person the data relates to, but we will not demand identity documents to answer a routine request.

If you are in the EEA or UK and are unhappy with our response, you may complain to your national data protection authority — in the UK, the Information Commissioner’s Office. We would rather you came to us first.

9. Children

This site is written for people applying to or attending higher education and is not directed at children under 13 (or under 16 in jurisdictions that set that threshold for consent to information society services). We do not knowingly collect personal data from children. If you believe a child has sent us personal data, email us and we will delete it.

10. Security

The site is served over HTTPS with HTTP Strict Transport Security. It is a static site with no database, no user accounts and no login, which removes most categories of data breach by design — there is no store of personal records to compromise. Email correspondence is held in a mailbox protected by multi-factor authentication.

11. External links

We link to government departments, scholarship commissions, universities and other official sources. Once you follow a link, you are on someone else’s site under their privacy policy, which we do not control and have not audited. We link directly, without redirect or tracking wrappers, so that you can always see where a link goes before you click it.

12. Changes to this policy

When we change this policy we update the date at the top of the page. For material changes — particularly enabling advertising or analytics — we will state what changed and when, in this section, rather than silently republishing.

Change log: 11 September 2026 — first published.