Last updated: 15 July 2026
Because this app is designed to be used by children, we collect the minimum data needed to run it, we do not sell or share children's data with third parties for marketing, and every optional data use (like receiving product emails) is switched off unless a parent actively turns it on.
| Who | What | Why |
|---|---|---|
| Parent | Email address, password (stored as a secure hash, never in plain text), display name | To create and secure the family account, and to contact you about the account (e.g. verification, password resets, trial status) |
| Parent (optional) | Town/city and postcode AREA only (e.g. "Manchester, M14") — never a full street address | To power the optional "Local League", which compares your child with similarly-aged children in the same rough area. Skipping this has no effect on any other part of the app. |
| Child | First name/username, a 4-digit PIN (hashed), year group, learning progress (scores, streaks, badges) | To let your child log in with a simple family code + PIN (no email needed for children), and to show you their progress in Parent HQ |
| Child (optional) | School name | Only used to show a "same school as you" badge to your child in the Local League — a child's school name is never shown to any other family, only whether it matches |
| Both | Usage data (quiz results, study minutes, generated practice questions attempted) | To power the learning journey, mastery tracking, and Parent HQ reports |
We do not require or request a child's email address, exact date of birth, home address, or photo for the app to function. Optional profile fields (like an avatar photo, area, or school name) are only ever set by a parent choice, never required. The Local League never reveals a full address, a full name (other than your own child's, to you), a school name (other than your own child's, to you), or any way to contact another family — there is no messaging feature between families anywhere in the app.
A family account can only be created by someone who confirms, at signup, that they are the parent or legal guardian of the children who will use it. We rely on this parental confirmation, together with the parent's acceptance of these terms, as the basis for a child's data being processed under UK GDPR Article 8.
Data is stored on a persistent, access-controlled disk on our hosting provider (Render, UK/EU region where available). Nightly backups are kept for 7 days to protect against accidental loss.
We do not sell personal data. We use the following processors strictly to run the app:
| Service | Purpose |
|---|---|
| Render | Application hosting and database storage |
| Anthropic (Claude API) | Generates NEW practice questions from curriculum topics; every AI-generated question is reviewed by us before it is ever shown to a child — no child data is sent to this service |
| Resend (email) | Sends account emails (verification, password reset, co-parent invites) to the parent's email address only |
We will never email a child. Occasional product update emails to the parent's address are opt-in only and off by default — you can turn them on or off at any time in Parent HQ.
We keep account and progress data for as long as the family account is active. If an account is deleted, personal data is removed within a reasonable period, except where we're required to keep minimal records for legal or accounting reasons.
As the account holder, you can ask to see, correct, export, or delete the data we hold about your family at any time by contacting us through Parent HQ. You can also complain to the UK Information Commissioner's Office (ico.org.uk) if you believe we have not handled your data correctly.
If this policy changes in a way that affects how your data is used, we will email the account holder before the change takes effect.