1. Introduction
Ratemymodule.ie is committed to protecting your privacy and handling your personal data in a fair, transparent and secure manner.
This Privacy Policy explains how personal data is collected and used when you access or use Ratemymodule.ie (the "Platform"), an Irish-based student platform that allows verified UCD students to anonymously rate and review university modules.
This policy is intended to comply with Regulation (EU) 2016/679 (General Data Protection Regulation, "GDPR") and the Irish Data Protection Act 2018.
2. Who We Are (Data Controller)
The data controller for personal data processed through the Platform is:
Ratemymodule.ie, operated in Ireland
Platform operator: Raffael Richter
The Platform is an independent student project and is not affiliated with, endorsed by, or operated by University College Dublin (UCD).
3. What Data We Collect
Account Data
When you create and use an account, we process:
- your @ucdconnect.ie email address;
- authentication and account identifiers (for example user ID);
- email verification status and session/authentication records;
- password credentials managed through Supabase authentication (hashed using bcrypt and not stored in plain text by us).
Review Content
When you submit a review, we process:
- module code;
- overall star rating;
- ratings for how worthwhile and how interesting you found the module, and whether you would recommend it;
- a difficulty rating, an approximate band of hours per week the module took you, and optionally how fast it moved;
- the trimester and academic year in which you took the module;
- the name of the lecturer who taught it (or your indication that you do not remember), a rating of how well the module was taught, optional descriptive tags about the teaching, and an optional comment about the lecturer — see "Reviews that name lecturers" below;
- optional tags describing how the module ran in practice (for example whether lectures were recorded), and whether course materials were needed;
- optionally, the grade band you received (for example "A" or "B", or "rather not say"). Grades are only ever displayed as part of a group and are suppressed entirely where too few students have reported one — see section 6;
- written feedback in response to specific prompts: what the module was like in practice, advice for future students, and optionally assessment and content;
- review timestamps (such as created and updated dates).
Reviews written before August 2026 may instead contain the earlier rating categories (Workload, Difficulty, Teaching Quality, Assessment Fairness and Interest) and a single free-text comment. That content is retained as its author submitted it. Assessment Fairness ratings are no longer collected or displayed.
Unfinished Reviews (Drafts)
While you are filling in the review form, what you have entered is saved automatically so you can finish later. A draft is stored against your account and the module it relates to.
Drafts are private to you. They are not published, not shown to other users, not included in any module rating or statistic, and are deleted when you submit the review. You can see and discard your drafts at any time under "My reviews", and drafts are removed if you delete your account.
Your Module Lists
Two parts of the Platform let you keep a private list of modules. Your watchlist is modules you are considering. My Semester is modules you have told us you are actually taking in a particular trimester. They are separate lists and they say different things about you.
For a module on either list we store:
- the module code, and which of the two lists it is on;
- for My Semester, the trimester and academic year you are taking it in. The term is part of the record: a module you sat in last autumn is a different fact about you from one you are sitting in now;
- how it got onto the list — for example whether you pasted the code, picked it from your course, or moved it across from your watchlist — which we use to see which way of building a list people actually use;
- an optional short note you can write on it;
- when it was added and when it was last changed.
Both lists are private to you. A list is never shown to another user, never published, never counted in any module rating or statistic, and never used to build any public figure — not even an anonymous or grouped one. We hold your semester list to a tighter standard than a review: saying you are enrolled in five particular modules is close to a timetable, and a timetable can identify a person in a small school. Nothing in the Platform can read another person's list, and moderators have no access to either list.
You can take a module off either list at any time, on the page it appears on. Doing so deletes that entry outright — it is not hidden, archived or kept out of sight. Both lists are deleted if you delete your account.
We keep your semester list for as long as it is useful to you for reviewing those modules: the term you are in now, and recent past terms you may still want to write about. Older terms are cleared. Anything you turned into a published review is your own review from that point on, and is governed by the rest of this policy rather than by the list it came from.
Emails and Email Permissions
Some email is part of running your account and is sent whether or not you have asked for anything: confirming your address, resetting your password, replying about a report you made, and telling you when this policy changes. There is no opt-out for those — they are how the account works and how we tell you things we are obliged to tell you.
Everything else needs your permission first, and we ask separately for two separate things:
- Updates about the site — offered when you create your account, as "Send me occasional updates about the site". A few emails a year about what has changed here.
- Semester emails — offered at the end of setting up My Semester, and only ever about the modules on that list: a note when registration closes to check you are still taking them, a heads-up before your busiest week, and one at the end of term asking how they went so that you can review them.
These are two permissions, not one. Ticking either does not tick the other, and stopping either does not stop the other. Both start off unticked, and both are optional: using My Semester, or any other feature, is never treated as agreement to be emailed about it, and every feature works the same whether you say yes or no.
When you give either permission we record what you agreed to, when you agreed, and which version of the wording you were shown — so that we can always say what was asked and what was answered. When you withdraw it we record that too, as its own act, rather than quietly dropping the permission. We also keep a record of the emails we have actually sent you: which message, to which address, and whether it was delivered, so that the same message is not sent twice and so that we can look into a delivery problem.
Every email that depends on your permission carries an unsubscribe link, and that link works without signing in. It opens a page showing both permissions, so you can stop one and keep the other. You can also write to support@ratemymodule.ie and ask us to stop either or both.
Reports About Content
Anyone can report a review using the flag icon on it. You do not need an account, and you do not have to tell us who you are. When a review is reported we store:
- the review being reported and the category chosen (for example that the reporter is named in it, or that it is abusive);
- the explanation written in the form;
- an email address, but only if one is given. Signed-out reporters can leave the field blank and report anonymously; signed-in reporters are asked to tick a box before their account address is attached, and can replace it with a different one;
- the account identifier of the reporter where they were signed in, used to moderate and to detect abuse of the report function. Nothing identifies a signed-out reporter;
- the reference number shown when the report is submitted, and the decision made on it.
An address given here is used to reply about that report and for nothing else. It is never published, never shown to the author of the reported review, and never added to any mailing list.
Usage Data
To run and improve the Platform, we may process:
- module interaction data (including searches and page/module views);
- upvote activity (for example marking reviews as helpful);
- moderation activity, including the reports described above and the decisions taken on them;
- review form analytics: when the review form is opened, submitted or abandoned, the module it related to, whether it was a new review or an edit, whether the user was signed in, and how many of the required fields had been completed. These records are tied to a random identifier that lasts only for your current browser session. They do not contain your account identifier, your email address, or anything you typed. The same records note when an account sign-up is submitted or refused, with a short reason category (for example "too many requests") rather than any detail of the attempt;
- visit source: when you first arrive, a short label for how you reached the site (for example "instagram", "linktree" or "google", or the campaign name written on a link we or a partner published), the kind of page you landed on (for example "a module page"), whether your screen is phone-sized, and whether you were already signed in. These labels are worked out in your browser: the address of the page that sent you, your IP address and your browser's identifying details are not stored with them. They use the same random identifier as the review form analytics, which lasts only for your current browser session;
- service diagnostics and feature usage patterns.
Technical Data
We may also process technical and log data such as:
- IP address and request metadata;
- browser and device information;
- date/time logs and referring URLs;
- cookie or similar identifier data needed for service operation and analytics.
4. How We Use Your Data
We use personal data to:
- create, verify and manage user accounts;
- restrict participation features to verified @ucdconnect.ie users;
- provide core platform functionality, including posting reviews, viewing ratings, upvoting, and editing/deleting your own content;
- receive and act on reports about reviews, and reply to whoever made one where they asked us to;
- save your unfinished reviews so that you can come back and complete them;
- keep the private module lists you build — your watchlist and your semester — and show you your own term, its weeks and its deadlines on the pages that use them;
- send you the emails you have specifically asked for, and only those: occasional updates about the site, or messages about the modules in your semester;
- record and act on your email permissions, including keeping proof of what you agreed to and when, and acting on a withdrawal;
- calculate and display module statistics, such as average ratings, the share of students who would recommend a module, and grouped figures for reported hours and grades;
- measure how the review form performs — for example how often it is started, completed or abandoned — so that we can make it quicker and clearer to use;
- monitor service reliability, performance and security;
- prevent, detect and investigate misuse, spam, fraud or abuse;
- moderate content and process reports;
- respond to support requests, including deletion requests;
- comply with legal obligations and protect legal rights.
We use privacy-conscious analytics for service improvement. We do not use your data for advertising, and we do not sell personal data.
We do not carry out solely automated decision-making (including profiling) that produces legal effects or similarly significant effects for users within the meaning of Article 22 GDPR.
5. Lawful Bases for Processing
Under Article 6 GDPR, we rely on the following lawful bases:
- Contract (Article 6(1)(b)): where processing is necessary to provide the Platform and account features you request.
- Legitimate Interests (Article 6(1)(f)): for security, moderation, abuse prevention, service analytics, and platform improvement. We apply safeguards including data minimisation, limited access controls, and pseudonymous display of reviews.
- Legal Obligation (Article 6(1)(c)): where processing is required by applicable law.
- Consent (Article 6(1)(a)): for any email you have asked to receive — updates about the site, and semester emails — and where required for non-essential cookies/analytics technologies. Each of these is a separate permission, given separately and withdrawable on its own without affecting the others or your account. You may withdraw consent at any time, including through the unsubscribe link in any email we send you, which works without signing in.
6. Anonymity, Public Content & Named Lecturers
Reviews are displayed anonymously to other users. Your public review does not include your email address or direct account identity.
However, review records are internally linked to your account identifier for moderation, abuse prevention, and handling legal/data protection requests.
Every review you submit is published. All of the review content listed in section 3 appears on the module's public page, which is visible to visitors who are not signed in and may be indexed by search engines. The only exceptions are your grade band and your unfinished drafts, described below. If you include personal details in the written sections, those details become visible to others — please avoid including personal data about yourself or other people unless it is genuinely necessary to the review.
Grades are never shown individually. A grade band you report is combined with other students' before anything is displayed, is withheld entirely on modules where fewer than five students have reported one, and is never shown on your review, in a tooltip, or anywhere else that could connect it to you. It is not made available to visitors who are not signed in.
Reviews that name lecturers
Reviews identify the lecturer who taught the module, which means the Platform processes personal data about members of UCD staff. Teaching ratings, teaching tags and lecturer comments are published on the relevant module page, attributed to the named person and dated to the terms they were reported for.
This processing is limited on purpose. Ratings and tags describe how a module was taught — clarity, structure, organisation — and are shown only for the module they were given about. We do not combine a lecturer's ratings across modules, publish any ranking of staff, or offer a profile page for an individual member of staff. Content about a person rather than about their teaching is out of scope and is removed under our moderation process.
If you are named on the Platform and wish to exercise your data protection rights, including access, correction, objection or erasure, you can do it from the review itself: the flag icon on any review opens a form that does not require an account. Choose “I’m named in this review”, tell us what you want done, and leave an email address if you would like to be told the outcome. You will be shown a reference number for the request.
You can also write to support@ratemymodule.ie if you would rather not use the form. Either way, the same rights and timelines described in section 11 apply.
7. Cookies & Analytics
We use cookies and similar technologies for essential platform functions (for example login and session security) and privacy-compliant analytics.
We do not use advertising cookies, behavioural advertising trackers, or third-party ad-tech profiling systems.
Where required by law, non-essential cookies/analytics are only set with consent. You can also manage cookies through your browser settings.
8. Data Sharing & Third Parties
We share personal data only where necessary and on a lawful basis, including with:
- Supabase (authentication and managed database infrastructure);
- Resend (email delivery). Your email address and the content of the message are shared with them so that it can be sent. They send on our instructions only and do not use your address for anything of their own;
- infrastructure providers used by Supabase, including AWS eu-west-1 (Ireland);
- analytics or technical service providers acting on our instructions;
- professional advisers where necessary; and
- public authorities where legally required.
We do not sell personal data and we do not share personal data for advertising purposes.
9. Data Retention
We keep personal data only for as long as necessary for the purposes in this policy.
- Account data is retained while your account is active.
- Review, upvote and moderation records are retained for as long as needed to operate, secure and moderate the Platform.
- A contact address given with a report is kept while that report and any correspondence about it are open, and afterwards only for as long as needed to show what was decided and why.
- Unfinished review drafts are kept until you submit the review they belong to, at which point they are deleted, or until you delete your account.
- Your watchlist is kept until you remove a module from it or delete your account. Your semester list is kept while it is useful to you for reviewing those modules — the current term and recent past terms — and older terms are cleared. Removing a module from either list deletes that entry rather than hiding it.
- Your email permissions, and the record of when you gave or withdrew them, are kept while your account exists and for as long as we may need to show that a message was sent with permission. The record of emails sent to you is kept for the same reason.
- Technical logs and analytics data, including the review form analytics described in section 3, are retained for limited periods proportionate to security and service improvement needs.
You can request deletion of your account and associated reviews by contacting us. We will action valid requests without undue delay, unless retention is required by law or for the establishment, exercise or defence of legal claims.
10. Data Security
We implement appropriate technical and organisational security measures designed to protect personal data, including:
- encrypted transmission using HTTPS/TLS;
- managed secure infrastructure and role-based access controls;
- password hashing via Supabase authentication using bcrypt;
- measures to detect and respond to unauthorised access and misuse.
Data is stored in a secure Supabase-managed environment hosted in AWS eu-west-1 (Ireland). No method of transmission or storage is completely risk-free, but we take reasonable steps to protect your data.
11. Your GDPR Rights
Subject to applicable law, you have the right to:
- request access to your personal data;
- request rectification of inaccurate personal data;
- request erasure of personal data;
- request restriction of processing;
- request data portability;
- object to processing based on legitimate interests;
- withdraw consent where processing is based on consent; and
- lodge a complaint with a supervisory authority.
To exercise your rights, contact us at support@ratemymodule.ie. We may need to verify your identity and will respond in line with GDPR timelines.
If your request is about a specific review — for example one that names you — the fastest route is the flag icon on that review, which works without an account and is described in section 6. Requests made that way are answered within one month, and we can only reply if you leave an email address.
If your request is to stop receiving email from us, you do not need to write to us or sign in: the unsubscribe link in any email we have sent you identifies you on its own and opens a page with a control for each of the two permissions described in section 3.
If you ask us for a copy of your data, it includes everything described in section 3 that is held against your account — your reviews and drafts, your watchlist and your semester list, your email permissions and the emails we have sent you. There is no self-service download; ask us at the address above and we will put it together for you.
You may also lodge a complaint with the Irish Data Protection Commission (DPC): https://www.dataprotection.ie
12. International Transfers (if applicable)
The Platform is operated in Ireland and data is primarily stored within the EEA, including AWS eu-west-1.
If personal data is transferred outside the EEA/UK in limited circumstances, we will ensure appropriate safeguards are in place, such as an adequacy decision or Standard Contractual Clauses (SCCs), together with supplementary measures where required.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect legal, operational or technical changes.
When updates are made, the "Last updated" date above will be revised. Where changes are material, we will provide a clear notice through the Platform.
14. Contact Us
If you have questions about this Privacy Policy or how your data is handled, please contact:
Ratemymodule.ie, operated in Ireland
Email: support@ratemymodule.ie
To request deletion of your account and associated reviews, contact us at the same email address.