Wu & Bishop Consultancy · Last updated 21 September 2026
1. The short version
This page explains what happens to your information when you use Wu & Bishop Consultancy. We tried to write it so you can actually read it.
- To use the courses you make an account. That means we store your email, a name you pick, your progress, and your practice portfolio. If you sign up for the weekly tip email, we store that email address too.
- We run no ads, no analytics and no tracking pixels. We do not sell or rent your data.
- Your card details never reach us. Stripe handles payments.
- Your account data sits in a database run by Supabase, on servers in the United States — not in Australia.
- Loading this page tells a few other companies your IP address, including Google. The full list is below.
- You need to be at least 13 to have an account. If you are under 18, talk to a parent or guardian before you pay for anything.
- You can ask us to show you your data, fix it, or delete it. Email wu.bishconsultancy@gmail.com.
We have tried to write this to line up with the Australian Privacy Principles and, for visitors in Europe and the UK, the GDPR. We are not lawyers, this page is not legal advice, and we are not claiming we have got every rule right — it is a plain description of what actually happens. If you spot something wrong, tell us and we will fix it.
2. Who runs this site
Wu & Bishop Consultancy is run by two high-school students in Victoria, Australia. We are not a company with a legal department. We are two people who built a website to teach other students how investing works.
The two of us are the people responsible for what happens to your data — the "data controller", if you have run into that phrase. You can reach us at wu.bishconsultancy@gmail.com. We do not have a data protection officer, and we do not have a representative in the EU or the UK.
Being small matters for two reasons. First, we deliberately collect as little as we can — every extra field is one more thing to lose. Second, we are not professionals, so read the security section below and judge for yourself.
This site is not a bank, a broker, or a financial adviser. The practice market uses fake money. We never hold your real money, we never see your bank or share trading accounts, and we will never ask you for them.
3. What we collect, and why
When you make an account, we store:
- Your email address — so you can log in, and so we can reach you about your account.
- The name you type into "what should we call you?" — used to greet you in the app. It does not have to be your real name, and we would rather it was not.
- A referral code that we generate for you.
- The date and time your account was created.
- Your password, which goes to Supabase and is kept by Supabase as a hash. There is a section on this below.
As you use the site, we store one block of data attached to your account. It holds:
- Which course you chose, and how far through each lesson you are — so you can pick up where you left off.
- Your daily streak, including the list of dates you visited the site — that is how the streak counter works.
- Whether you dismissed the upgrade message — so we stop showing it to you.
- Your practice portfolio: the weekly deposit amount you picked, your pretend cash balance, what you "hold", and a log of your practice trades. All of it is fake money.
- A star rating and written review, if you choose to leave one.
If you sign up for the weekly tip email in the box at the bottom of the homepage, or the one on the coming-soon page, we store the address you typed and the time you typed it, in the same database as everything else. That is all it holds. Nothing else about you is attached to it, and you do not need an account.
If you subscribe, we store a record of the subscription — which plan, when it started, and what it costs. Stripe handles the payments themselves, including each monthly charge, and keeps its own records.
If you leave a review, it stays attached to your account. We will not publish it on the site, or anywhere else, unless we ask you first and you say yes.
That is everything we put in our database. It is not the same as everything anyone can see: the companies that host and serve this site keep their own server logs, which include your IP address. Those are listed in their own section below.
We do not ask for your real name, address, phone number, date of birth, school or photo. We do not connect to any real bank, broker or trading account, and we never see your real balances or real trades. The only money-shaped number we hold is the weekly deposit figure you type into the practice market — a made-up number for a made-up portfolio, though if you set it to what you actually save, treat it as something you have told us.
4. What we do not do
- No analytics. We do not use Google Analytics, or Plausible, or anything like it, and there is no tracking script on the page. To be straight about it, that does not make us blind: we can see the things listed above — your lesson progress, the dates your streak counter recorded, your practice trades — and our providers keep their own server logs. What we do not have is an analytics product watching how you move around.
- No advertising. No ad networks, no tracking pixels, no fingerprinting scripts.
- We do not sell, rent or trade your personal information, and we do not "share" it for cross-context behavioural advertising, which is the phrase some US state laws use. We never have, and nobody has ever offered. If that ever changed we would tell you first and it would be opt-in.
- No marketing partners. We do not hand your data to other businesses for their own purposes. The companies listed further down — Supabase, Stripe, Netlify and the rest — are service providers: they handle data on our behalf so the site works. That is a different thing, and it is the only kind of sharing that happens in normal operation. The narrow situations where anyone else could get your data have their own section below.
- No marketing emails you did not ask for. The only mailing list is the weekly tip email, and the only way onto it is typing your address into the box yourself. It is opt-in, every email will carry an unsubscribe link, and emailing us also gets you off the list. It has not started sending yet; it begins after the courses launch.
The only emails you should get from us are account emails — confirming your email address, and a password-reset link if you have asked us for one — which are sent through Supabase's email service. The only other reason we would email you is something important about your account, a security problem, or a big change to this policy.
5. Passwords and payments
Passwords. Supabase Auth handles logins. When you sign up or log in, your password travels over an encrypted connection to Supabase, which stores it as a hash — scrambled in a way that cannot practically be turned back into your password. It is never stored in readable form, and we cannot see it or look it up. If you forget it, email us from the address on your account and we will help you get back in — there is no self-service reset yet.
Payments. If you subscribe to a course, Stripe runs the checkout and the recurring billing. Your card number, expiry date and security code go straight to Stripe. They never touch this site or our database, and we never see them — including on renewals, which Stripe charges without us ever handling the card.
Because a subscription carries on over time, what we hold is a little more than a one-off sale would be: which plan you are on, when it started, whether it is currently active, when the next payment is due, and if and when you cancelled. We use it for exactly one thing — deciding whether to unlock your lessons. We do not hold a payment history; that lives with Stripe, and you can ask them or us for a receipt at any time.
Stripe keeps its own record of the payment under its own privacy policy. Stripe also collects information about your device and how you interact with its checkout in order to detect fraud — that is Stripe's collection rather than ours, and it is described in Stripe's policy.
If you are under 18, read the under-18 section before you pay for anything.
6. Where your data is stored, including outside Australia
Your account data lives in a database hosted by Supabase. Our project sits in a United States region. It is not in Australia.
So your email address, display name, streak, progress, sale record and practice portfolio leave Australia and are stored overseas. Data on US servers is subject to US law, which is different from Australian law, and in some situations US authorities can require access to data held there. We are telling you this plainly so you can decide.
The other companies below are outside Australia too. Stripe and Netlify are US companies. Google, our market-data provider and jsDelivr also operate overseas, and content delivery networks in particular serve files from whichever of their servers is nearest you, which could be almost anywhere.
Australian privacy law asks us to take reasonable steps to make sure an overseas recipient handles your information properly. Here is what that actually amounts to for us: we use established providers rather than obscure ones, we accept their published data processing terms, we turn on the security settings they offer, and we keep the amount of data we send them small. We are not in a position to audit any of them, and we are not going to imply otherwise.
If we ever move the database to a different region, we will update this page. If storing your data overseas is not acceptable to you, please do not create an account — you can read the whole site without one.
7. Every other company your browser talks to
When you open this site, your browser has to fetch files from other companies. Any company your browser asks for a file can see your IP address (a rough indicator of where you are), the time, and basic information about your browser. That happens automatically, whether or not you have an account. Here is the complete list and what each one gets.
- Netlify — hosts the site. It serves the pages to you, so it sees your IP address and which pages you asked for, and it keeps its own server logs.
- Supabase — handles accounts, the database, some server-side functions, and account emails. It receives your email address, your password (which it stores as a hash), everything listed in "What we collect", and your IP address whenever your browser talks to it.
- Stripe — handles payments. It receives your card and payment details, plus information about your device for fraud checks, but only if you actually start a checkout. If you never buy anything, Stripe never gets your details. The checkout is closed at the moment, so this cannot happen at all.
- Our market-data provider — supplies the ASX share prices and the price charts in the practice market. Your browser never talks to it: it asks a server of ours, and that server asks the provider. So the provider sees our server and the ASX codes requested, and it does not see your IP address, your name, your email or your account.
- Google Fonts — supplies the typeface the site uses (Inter). Your browser downloads it from fonts.googleapis.com and fonts.gstatic.com, which means Google sees your IP address and the fact that you loaded a page on this site. This happens on every page load, whether or not you have a Google account and whether or not you are logged in to one. We can stop it by hosting the font file ourselves, and we are going to.
- jsDelivr — a free code delivery network. Your browser downloads the Supabase JavaScript library from it, so jsDelivr sees your IP address too.
- YouTube (Google) — hosts our introduction video. Nothing is sent to YouTube unless you press play. The picture you see before that is an image file served from our own site, so simply loading the homepage tells Google nothing. If you do press play, the video player loads from youtube-nocookie.com and from that moment YouTube can see your IP address, that you watched this video, and — if you happen to be signed in to a Google account in the same browser — it can connect the view to that account. We use the no-cookie version of the player, which avoids tracking cookies for advertising, but it does not make the connection private. If you would rather Google knew nothing at all, don't press play.
Each of these companies has its own privacy policy and its own server logs, which we cannot see or control. We do not send them anything beyond what is described here. Things do come back to us, but only what the site needs to work: your own account data from Supabase, confirmation from Stripe that you paid and for what, and share prices from our market-data provider. None of them tell us anything about you from anywhere else, and none of them build us a picture of you.
8. Cookies and localStorage
The long version of this section, including how to clear everything and what breaks if you do, is our Cookies Policy. The short version: we do not show a cookie banner because we do not use advertising or analytics cookies. The only browser storage on this site is what is needed to keep you logged in and to remember your settings. Here is all of it.
- Login session. Supabase Auth stores a session token in your browser so you stay logged in between pages. Without it you would have to log in constantly. Logging out clears it.
- localStorage: theme. We save whether you picked light or dark mode.
- localStorage: price cache. We save the day's share prices, the price charts and a note of which codes had no data that day, so the site does not have to re-ask our market-data provider every time you open a page.
- localStorage: lesson tools. The figures you type into the budget, "find the money", emergency-fund, super-option, portfolio-split and ten-year-plan tools inside the lessons are saved on your own device so they are still there next time. They never leave your browser and we do not see them.
- sessionStorage: a friend’s referral code. If you arrive on an invite link we hold the code until you close the tab, so it can be filled in for you at the checkout. Nothing is sent anywhere until you apply it.
The theme, the price cache and the lesson-tool figures sit on your own device and we do not send any of them to our database or to anyone else. If you go through a Stripe checkout, Stripe sets its own storage on its own pages for fraud prevention — that one is covered by Stripe's policy, not this page. Clearing your browser's site data removes everything on our side; the theme, the prices and the lesson-tool figures just reset.
9. How long we keep your data
Straight answer: we keep your account data for as long as your account exists. We do not currently delete inactive accounts automatically, which means data can sit there long after someone has stopped using the site. If you are done with us, ask and we will delete it.
If you ask us to delete your account, we will delete your database record and your login. We aim to do that within 30 days of your request. Supabase takes routine backups of the database, so a copy of your data may remain inside a backup for a while afterwards before it is overwritten — we cannot reach into a backup and pull out one person's record. Backups are not used for anything except restoring the site after a failure.
Two things survive deletion:
- Stripe keeps its own record of any payment you made. That is Stripe's record, not ours, and we cannot delete it.
- We keep a plain record that a purchase happened — what was bought, when, and for how much — because Australian tax rules generally require business records to be kept for around five years. That record does not need your progress, streak or practice portfolio, so all of that still goes.
Anything stored in your own browser (theme, cached prices, login session) is yours to clear whenever you want.
10. When we would hand your data over, and what happens if we stop
Beyond the service providers listed above, there are only a few situations where anyone else would get your information. We would rather set them out than leave you guessing.
- If the law requires it. A court order, a warrant, or a lawful demand from a regulator. We would comply, and unless we were forbidden from telling you, we would tell you.
- If someone were in serious danger. If we genuinely believed someone was at risk of serious harm, we would pass on what was needed to the right people. We do not expect this to ever come up on a site about compound interest, but we are not going to write a rule we would break.
- If the site changes hands. If we ever handed this site to someone else, accounts would go with it. We would email everyone with an account before that happened, so you could delete yours first if you wanted to.
We are high-school students, and at some point we will finish school. If we decide to shut the site down, we will give notice by email and on the site, give you a chance to download your data, and then delete the database — rather than leave it sitting on a server nobody is watching.
11. If you are under 18
Most people using this site are high-school students, and plenty are under 18. So are we.
You need to be at least 13 to create an account. If you are under 13, please do not sign up. In the United States a law called COPPA says sites cannot collect information from under-13s without a parent's verified consent, and we have not built a way to do that — so the answer is simply 13 and over. If you are under 13 and want to learn from the site, ask a parent or guardian to email wu.bishconsultancy@gmail.com. If we find out an account belongs to someone under 13, we will delete the account and the data attached to it, at no cost and without arguing about it.
If you are in the EU, the UK, or somewhere with its own rule, the minimum age for agreeing to have your data handled online can be higher — depending on the country it is 13, 14, 15 or 16. If you are under that age where you live, get a parent or guardian's permission before making an account and ask them to email us so we have it on record. If we learn that an account belongs to someone under that age with no parent's permission behind it, we will delete it. This is a description of how we handle it, not legal advice about your country's rules.
Being honest about the limits: we do not ask for your date of birth and we cannot verify anyone's age. We are relying on you telling the truth, and on parents and guardians contacting us if something is wrong. That is a large part of why we keep so little — there is not much here to get wrong.
Parents and guardians: email wu.bishconsultancy@gmail.com and you can ask what we hold about your child, have it corrected, get a copy of it, or have the account and its data deleted. We will ask a couple of questions to check the account really is your child's — that is to stop a stranger doing the same thing — and then do it. You do not have to give a reason, and there is no charge.
Before you pay for anything, talk to a parent or guardian. If you are under 18 you should not be putting a card into a checkout page without them knowing. If someone under 18 has bought a course without a parent knowing, email us and we will refund it.
One deliberate design choice: we do not ask for your real name, school, address, photo, phone number, or anything about your real money. The "what should we call you?" box does not need your real name — a nickname is completely fine, and honestly we would prefer it.
12. Your rights, and how to use them
Wherever you live, you can ask us to:
- Show you everything we hold about you.
- Correct anything that is wrong — including your display name or email.
- Take you off the weekly tip email, and delete the address we hold for it.
- Delete your account and the data attached to it. The sale record described above is the one exception, and it stays on its own without the rest.
- Send you a copy of your data in a file you can keep.
You can also use the site without telling us your real name — the display name is yours to choose. We do need a working email address, because that is how logging in works.
How to do it: email wu.bishconsultancy@gmail.com from the address on your account and tell us what you want. If you email from a different address, we will have to ask you some questions first — otherwise anyone could write in and ask for your data.
We aim to reply within 7 days and to finish within 30 days. There is no charge. If something is going to take longer than 30 days, we will tell you why before the 30 days is up.
If you are in Australia, the Privacy Act 1988 and the Australian Privacy Principles apply, and the Office of the Australian Information Commissioner (OAIC) is the regulator; we treat everyone the same way wherever they live.
If you think we have mishandled your information, tell us first and give us a chance to fix it. If you are in Australia and you are not satisfied with how we deal with it, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
13. Extra rights if you are in the EU or the UK
If you are in the EU or the UK, the GDPR gives you rights on top of the ones above: access, correction, erasure, restricting how we use your data, portability (a copy in a usable format), objecting to processing, and withdrawing consent at any time.
The legal bases we rely on:
- Performing a contract — your email, display name, course choice, lesson progress and practice portfolio. We need these to give you the account and the course you asked for.
- Legitimate interests — keeping the site working and secure, preventing abuse, and keeping an accurate record of sales. Our tax obligations are Australian rather than European, so for people in Europe we point at this basis for the sale record rather than at "legal obligation".
- Consent — the optional star rating and written review. You can withdraw that at any time and we will delete it.
Giving us an email address is a requirement of having an account; without it we cannot create one. Everything else is either optional or generated as you use the site.
Transfers out of Europe. Your data goes to servers in the United States through Supabase, and Stripe, Netlify, Google, our market-data provider and jsDelivr all operate outside Europe. We rely on the standard contractual clauses in those companies' published data processing terms. We have not carried out our own transfer risk assessment on top of that, and we would rather say so than imply a level of diligence we have not done.
We do not make automated decisions about you that produce legal or similarly significant effects, and we do not build advertising or behavioural profiles.
We are based in Australia and we do not have a representative in the EU or the UK. You can complain to the data protection authority in your country. In the UK that is the Information Commissioner's Office at ico.org.uk.
14. If you are in the United States
Several US states — California among them, and a growing list of others — give residents their own privacy rights. Rather than work out which state you are in, we offer the same things to everyone: email us and we will show you what we hold, correct it, give you a copy, or delete it. There is no charge, and we will not treat you any differently for asking.
In the language those laws use, for the record: we do not sell personal information, we do not share it for cross-context behavioural advertising, we do not use it for targeted advertising, and we do not profile in a way that produces legal or similarly significant effects. We do not knowingly collect anything from a child under 13 — see the under-18 section.
15. Security, honestly
What we actually do:
- The site is served over an encrypted connection (https).
- Passwords are hashed by Supabase Auth. We never see them.
- Card details never reach us — they go straight to Stripe.
- The two of us are the only people with a login to the database, and we deliberately keep the amount of data we collect small. Supabase runs the servers, so Supabase's own systems and staff can reach the infrastructure the database sits on — that is true of any hosted database, and it is worth you knowing.
What we are not going to pretend:
- We are high-school students, not security engineers. We have had no security audit and we hold no certification. If you ever see "bank-level security" written about this site, it did not come from us.
- No system is perfectly secure. A bug in our code, a mistake by us, or a breach at Supabase, Stripe, Netlify, jsDelivr or our market-data provider could expose data. We cannot promise that will never happen.
- One weakness we used to list here has been fixed: our market-data key used to be visible in the page's code. It now lives only on a server of ours and never reaches your browser. The old key was public for a while, so we are treating it as compromised and replacing it. It only ever fetched public share prices — it could not reach your account, your data, your password or any money.
Two things you can do: use a password you do not use anywhere else, and do not type anything into this site that you would be upset to see leaked.
If there is a data breach that affects you, we will email the address on your account and put a notice on the site as soon as we understand what happened. Where the rules require it, we will report it to the Office of the Australian Information Commissioner, and for anyone affected in the EU or the UK, to the relevant data protection authority within the time limits those rules set.
16. Changes to this policy
If what the site does with data changes, this page changes. The "last updated" date at the top tells you when it last did.
For small things — clearer wording, a corrected detail, a typo — we just update the page and the date.
For anything that actually changes what happens to your data — a new company receiving your information, a new type of data collected, a new use for data we already have — we will put a visible notice on the site and email people with accounts, before the change takes effect or as soon as it does. We are not going to rewrite this page quietly.
17. Contact us
Email wu.bishconsultancy@gmail.com. It reaches the two of us and nobody else — though like any email, it lands in an inbox held by an email provider, which is one more company that ends up holding whatever you send us.
Use it to: see your data, correct it, delete your account, ask a question as a parent or guardian, report a security problem you have spotted, or tell us that something on this page is wrong, unclear or out of date.
If we have got something wrong, tell us. We will fix it and update this page.