Skip to content

For institutions

Procurement, privacy and data

bǎi nián shù rén — “A hundred years to raise a person”

What we store about your students, where it lives, and the answers your DPO will ask for.

8 min read

Not what you were looking for?

What a school’s procurement or data-protection review usually asks, answered from what the system actually does. Where the honest answer is "that needs a conversation", it says so rather than guessing.

What we hold about a student

  • IdentityName and email address. Nothing more is required to create an account.
  • The learning recordAnswers, completed checkpoints, and the mastery, retention and error patterns derived from them. This is the service — it schedules review and produces progress.
  • Activity timingWhen study happened. Per-checkpoint active time is separate and is only collected with analytics consent.
  • Circle membershipWhich classes they are in and which assignments they were set.

What staff can and cannot see

Teachers and admins see outcomes: completion, results, timing, skill balance. They do not see text a student wrote — not AI-tutor conversations, not free-text answers, not messages. No teacher-facing endpoint returns it.

A teacher’s view of a learner is also built from the learner’s own panels, so there is nothing on a staff screen a student cannot see about themselves. Group medians are withheld below five learners, because an average plus one known score identifies the rest.

Subject access and erasure

Both are self-service and both are driven by the same manifest of every user-linked table. A table added to the system appears in the export and in the erasure at the same time, which is what stops a new feature quietly storing data neither operation knows about.

Export returns everything held, reports any part it cannot produce rather than silently omitting it, and strips live security tokens. Erasure blocks sign-in immediately, holds the data for 30 days so a mistaken deletion is recoverable, then hard-deletes.

Under-age students

A child account created by a guardian requires an explicit consent affirmation, and who consented and when is recorded against the account as an audit trail rather than merely asked for.

Guardian-managed accounts are kept off public surfaces entirely — they do not appear in the tutor directory or any other public listing. Messaging is restricted server-side to people who share a circle, so there is no route by which a stranger can contact a student.

Payments

Handled by Stripe. Card details go directly to them and are never stored on our servers — we hold a customer reference, not a card number. Invoices and receipts are managed through the billing area.

What this article cannot answer

Data residency, a signed data-processing agreement, retention schedules beyond the above, sub-processor lists, security questionnaires, and anything requiring a contractual commitment.

Those are real questions and the honest answer is that they are a conversation rather than a help article. Write to us with your questionnaire — a specific list is far easier to answer properly than a general enquiry.

The formal documents

Privacy PolicyIncluding the retention sectionTerms of ServiceThe agreement itselfCookie PolicyWhat each consent category coversData & PrivacyExport and erasure

Common questions

No. No teacher-facing or admin-facing endpoint returns text a student wrote. Staff see outcomes — completion, results, timing, skill balance.

Continue learning

What we measure, and what we do notPlainly: the data behind your progress, the three consent tiers, and the things we will never do.Seats, tiers and limitsHow seats are counted, what each tier includes, and what happens when you reach a limit.Exporting or deleting your dataDownload everything we hold, or close the account for good — what each does and what it cannot undo.