Privacy Notice
Last updated: 27 September 2026.
This notice explains what personal data we collect when you use this site, why we collect it, and the rights you have over it. It covers every part of totorex.ai: Toto-Rex's Study Corner, the UK & EU, US & Canada, Asia and Global editions, the Glossary, the Classroom and the app preview. We have tried to write it the way Toto-Rex writes everything: plainly, and without forty pages of throat-clearing.
1. Who we are
Toto-Rex's Study Corner is published by Maqutt Studio Ltd ("we", "us", "our"), the data controller for the personal data described here.
Maqutt Studio Ltd (company no. 17154771)
71–75 Shelton Street, Covent Garden, London WC2H 9JQ
Email: hello@maqutt.studio
ICO registration reference: ZC189558
Because this site is read across the UK and the EU/EEA, this notice is written to meet both the UK GDPR and the EU GDPR. We are not required to appoint a Data Protection Officer and have not appointed one: the address above reaches the person accountable for data protection. If we become required to appoint a representative in the EU under Article 27 of the EU GDPR, their details will be published here.
2. The data we collect, and why
Newsletter sign-up
When you subscribe, we collect your email address. We use it only to send you the newsletter and, occasionally, a message about the newsletter itself (for example, a change to how often it goes out). The newsletter is written for adult learners and is not marketed to children. We know the learning tools, games and Classroom are likely to be used by younger readers, so the site is built the way the ICO's Age Appropriate Design Code expects: no accounts, no profiling, no advertising, no analytics, nothing published from what you type, and learning records kept on your own device rather than on our servers. If you believe a child has sent us personal information, contact us and we will delete it.
The book-notification and app-waitlist forms work the same way: we collect your email address and the list you joined, use them only to tell you when that book or app is available, and keep them in a private Google Sheet until then (sections 4 and 7).
Messages you send us
If you write to Toto-Rex by email (the contact form is not yet open), we collect the name, email address and message you provide, so we can read it and reply.
Browsing the site
We do not use analytics, advertising or cross-site tracking. The site stores functional data in your own browser, including display and language preferences, the optional learner name you enter, lesson completion, quiz grades, XP, study-card progress, notebook entries, personal notes and game progress. This lets the learning tools remember where you stopped. It stays on that device, is not submitted to us, and can be erased through your browser's site-data controls. See our cookies & storage policy for the full list.
The site's display assets, including its typefaces, are self-hosted. Language dictionaries and any baked translations are static site files applied in your browser. The production site does not send page text, or anything you type, to a translation service. If a translation is not available, the English text remains visible and is marked as such, rather than triggering an external translation request.
Serving the pages
The site is published as static files on a content-delivery network (Cloudflare). To send you a page, and to keep the site available, our host necessarily processes the technical data in your request, including your IP address, the page requested, the time, and your browser's user-agent string. It may also set a short-lived, first-party security cookie to tell human traffic from automated traffic. We do not receive visitor-level reports from it, do not use it to identify or profile you, and do not combine it with anything else.
3. Our lawful bases (UK GDPR and EU GDPR)
- Consent — for sending you the newsletter. You can withdraw it at any time, which won't affect messages already sent.
- Legitimate interests — for reading and replying to messages you choose to send us, and for keeping the site secure and working. We have weighed this against your interests and consider it proportionate.
4. Who we share it with
We don't sell your data. We share it only with the service providers ("processors") that help us run the site, and only so they can do that job:
- Cloudflare, Inc. (United States, with a global network): hosting, content delivery, DNS and security for the site, and routing for our email domain. It processes the request data described in section 2.
- Google LLC (United States): holds the sign-up lists in a private Google Sheet once the forms are connected. Nothing from Google is loaded into the pages you read.
- Our mailbox provider, which carries and stores messages you send us and our replies.
- A newsletter delivery platform, to send the newsletter once it launches. We will name it here before the first issue goes out.
We may also disclose data where the law requires it. Each processor is bound by a contract to protect your data and use it only on our instructions.
5. International transfers
We do not need to move your data abroad for any purpose of our own, and we never do so for marketing. Two things nevertheless involve processing outside the United Kingdom, and it would be wrong to tell you otherwise.
- Serving pages. A content-delivery network answers your request from the data centre nearest to you, so a request from outside the UK is handled, and logged, outside the UK.
- Email and sign-up lists. Our mailbox provider, the Google Sheet that will hold the sign-up lists and any future newsletter platform may store data on servers outside the UK, including in the United States.
For transfers from the UK we rely on UK adequacy regulations where they cover the country in question; for the United States, on the UK Extension to the EU–US Data Privacy Framework (the UK–US data bridge) where the provider is certified under it; and otherwise on the ICO's International Data Transfer Agreement or the EU standard contractual clauses with the UK Addendum, together with a transfer risk assessment. If you are in the EU/EEA, your data reaches us in the United Kingdom under the European Commission's adequacy decision for the UK, renewed on 19 December 2025 and valid until 27 December 2031. You can ask us which safeguard applies to a particular provider.
6. Keeping your data secure
The site is served only over HTTPS. There is no login, no database of learners and no server-side copy of your learning records, which removes most of what could be lost. Access to the mailbox and, when it launches, the subscriber list is limited to the people who need it, protected by two-factor authentication, and covered by confidentiality obligations. If a breach ever affects your rights, we will tell the ICO within 72 hours where the law requires it, and tell you where the risk to you is high.
7. How long we keep it
- Newsletter: until you unsubscribe, after which we remove your address from the active list within 30 days, keeping only a minimal suppression record so we do not email you again by mistake.
- Book-notification and app-waitlist lists: until we have sent you the message you signed up for, or until you ask to be removed. If the book or app has not launched within 12 months of your sign-up, we delete the list.
- Messages: for as long as needed to deal with your enquiry, and normally no more than 24 months afterwards.
- Server logs held by our host: short-lived, and kept by the provider under its own retention schedule rather than copied into our systems.
- Learning and preference data in your browser: until you clear this site's data. We do not receive or retain a server-side copy.
8. Your rights
Under the UK GDPR, and under the EU GDPR where it applies to you, you have the right to access your data; to have it corrected or erased; to object to or restrict its use; to data portability; and to withdraw consent at any time. To exercise any of these, email hello@maqutt.studio. You can also object at any time to any use of your data for direct marketing. There is no charge, and we will respond within the statutory time limit (one month, extendable by two further months for complex requests).
9. Automated decisions, profiling and AI
We do not make any decision about you by automated means, and we do not profile you. Quiz marking, XP and flashcard scheduling run in your own browser, affect nothing outside the site, and are not reported to us. This site is about AI; it does not use AI on you.
We do use AI tools in producing the site's writing and its translations, which is a separate question from your personal data. How that works is set out in section 3 of our terms of use.
10. Complaints
We would rather hear from you first so we can put things right. Under section 164A of the Data Protection Act 2018 you can complain to us directly, by email to hello@maqutt.studio or by any other means that suits you. We will acknowledge your complaint within 30 days, look into it, and tell you the outcome without undue delay. You also have the right to complain to a data protection regulator. In the UK that is the Information Commissioner's Office, at ico.org.uk/make-a-complaint (Wycliffe House, Water Lane, Wilmslow SK9 5AF; helpline 0303 123 1113). If you are in the EU/EEA, you may instead complain to the supervisory authority where you live, work, or where the issue arose; you can find yours via the European Data Protection Board.
11. Changes to this notice
If we change how we handle your data, we will update this page and the "last updated" date above. Material changes affecting the newsletter will be flagged in the newsletter itself.