ArchitectEdu

Legal

Privacy

This page is about adults — parents and teachers. Children are covered separately and more strictly, because the protection for a child is that we hold nothing at all.

In plain language — true today

  • No ads, no trackers, no third-party scripts, no pixels.
  • Before any text reaches an AI model it is scrubbed on our own servers for anything personal; if the scrubbing fails, the request is refused rather than sent.
  • Every AI call is logged — what was removed, counted by kind, never the words — and deletion on request is verified and itself logged.

Privacy policy — written by counsel, not designed

Below: the same facts at length — a description of what the system does, written from the architecture. It is not the notice.

01

Children are covered elsewhere

If you are here about a child, the child privacy notice is the page you want. It is not a summary of this one; the rules are different and stricter.

02

What we hold about you

If you are a teacher, an email address, which organisation you belong to, and your role. The email address is encrypted where it is stored. It is a professional identifier for an adult, which is a different thing from a child’s personal information, and we say so rather than pretending we hold nothing.

If you are a parent, an email address, so a setup link and a consent record have somewhere to go.

Teachers sign in through the Google account their school gave them. We never see a password and there is none for us to lose.

03

Your email is scrubbed too

The scrubber described in the child privacy notice does not distinguish between an adult’s personal information and a child’s. If you type a colleague’s name into a note, it is replaced before any of it reaches a model, exactly as a pupil’s name would be.

04

What this site does not do

There is no analytics on this site. Not anonymised analytics, not cookieless analytics — none. We do not know how many people read this page.

There are no advertising trackers, no session recording, no chat widget, and no fonts, scripts or images loaded from anybody else’s servers. This is checked automatically against the built site before it can be published, so it is a property rather than an intention.

The consequence is worth being straightforward about: we are giving up the ability to see which pages work. That is a real cost and we think it is the right trade on a property a child can reach.

05

Cookies

This site sets none. There is no consent banner because there is nothing to consent to, which is the only version of a cookie banner anyone has ever enjoyed.

Signed-in surfaces use a session token rather than a tracking cookie. It identifies the session and nothing else, and it is discarded when the session ends.

06

Deletion

Ask and we remove it. Deletion is removal of rows, not a flag that hides them.

The audit records described in the child privacy notice are exempt, because they contain no personal information and deleting them would destroy the evidence that the rules were followed.

How deletion works: a learner is erased from every table that references them in one operation, and the erasure itself is logged with a count and no identifier. The test suite enumerates those tables from the database catalogue, so a new table cannot be forgotten. There is no public sign-up: a school opens a child’s account by handing them a card.