Legal
Privacy Policy
Last updated: 19 April 2026 · Pilot release · Draft pending counsel review · Read the DPIA (also draft)
If you’re a child reading this
- We remember your name, your year at school, and what you’ve been learning so we can help you better.
- We don’t show your work to anyone except your grown-up. Your teacher only sees what your grown-up says they can.
- We never give your information to people who want to sell you things.
- If you ever feel uncomfortable, tell your grown-up. They can ask us to delete everything.
The plain-English version (for parents)
- We only collect what we need to personalise learning and keep your child safe.
- We don’t sell your data, we don’t serve ads, and we don’t use your child’s work to train general AI models.
- You can download everything we hold about you, or delete your account, from Settings → Data & Privacy.
- If we get it wrong, you have the right to complain to the UK Information Commissioner’s Office (ICO registration: TBC by founder).
1. Who we are
EverywhereX is a learning platform run by a UK-based organisation, founded as an initiative of the 1 in 10 Dyslexia charity (see 1in10.co.uk). Under UK GDPR we are the data controller for personal data processed through the service. If you have a question about how your data is handled, or you want to exercise any of your rights, email privacy@evx.logicmesh.dev.
2. What we collect
We collect three categories of personal data:
About the account holder (usually a parent)
- Your name and email address.
- Authentication data (password hash managed by Supabase, or your Google sign-in identifier — we never see your Google password).
- Account role (parent, teacher, admin) and any school or organisation affiliation if you were invited by one.
- Notification preferences, accessibility preferences, last-seen timestamp, and records of which transactional emails we’ve sent you.
About your child (or pupil, if you are a teacher)
- First name, year group, date of birth, and the responses to the intake questionnaire (learning style, interests, goals, SEND types, current levels).
- The AI-generated learning persona built from those responses.
- Every lesson started, completed, quiz score, time spent, and chat message exchanged with the AI tutor.
- Per-child accessibility settings (dyslexia font, text-to-speech, extended time, reduced density, high contrast).
We deliberately do not collect:your child’s surname, home address, phone number, photograph, medical diagnosis letters, school attendance records, or any EHCP documentation. If any of that ends up in a free-text field by accident, tell us and we’ll erase it.
Operational data (everyone)
- AI-usage metering: which endpoint was called, how many tokens were used, the model, and the pence cost. Used for abuse prevention and capacity planning.
- Moderation flags: when a message is refused by the safety filter, we log the event so admins can review patterns.
- Rate-limit counters and session metadata for security.
- Error telemetry via Sentry (EU region) when something breaks. Sentry receives stack traces and route names, never chat content or intake answers.
- Email delivery events (accepted, bounced, complained) to help us debug deliverability.
3. Why we use it (our lawful bases)
Under UK GDPR we must identify a lawful basis for every use of personal data. Ours are:
- Performance of a contract (Article 6(1)(b)) — to provide the learning service you signed up for: account management, lesson delivery, AI tutoring, progress tracking, transactional confirmation emails.
- Legitimate interests (Article 6(1)(f)) — for service integrity, fraud and abuse prevention, moderation of AI outputs, and service analytics. We have balanced our interest against your rights and concluded that a platform serving children cannot run without these.
- Consent (Article 6(1)(a)) — for optional marketing-style emails such as the weekly progress digest, re-engagement nudges, and product updates. You can withdraw at any time from Settings.
- Legal obligation (Article 6(1)(c)) — where a safeguarding concern or a law-enforcement request requires disclosure.
Where we process data about a child, we rely on parental consent provided by the account holder (UK GDPR Article 8 and the AADC). We do not create accounts directly for children under 13.
4. Who we share it with
We use a small number of vetted sub-processors to run the service. None of them are permitted to use your data for their own purposes.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage | EU (Ireland) |
| OpenAI (Chat) | AI tutor (text), persona generation, learning plans, EHCP-shaped SEND profile generation | USA (API tier — no training; UK SCCs) |
| OpenAI (Realtime) | Voice tutor — live voice conversation with the AI tutor via WebRTC. Audio not retained by OpenAI to train models; audio not stored by us by default (transcript persistence is opt-in per child). | USA (UK SCCs) |
| Microsoft Azure | Immersive Reader (text-to-speech, picture dictionary, syllable splitting). Lesson text only; no personal data about your child is sent. | EU (West / North Europe) |
| Mailcow (self-hosted) | Transactional email delivery | UK |
| Sentry | Error and performance telemetry | EU (Germany) |
| Oak National Academy | Curriculum content source (one-way, no personal data sent) | UK |
Chat messages are sent to OpenAI’s API for inference only. Under our API-tier agreement, OpenAI does not use inputs or outputs to train its models.
We do not transfer personal data outside the UK/EEA to countries without an adequacy decision except the OpenAI API call described above, which relies on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses.
5. How long we keep it
- Account and child profiles: for the life of the account. Delete from Settings at any time.
- Progress and chat history: same as the account, unless you delete an individual child sooner.
- Email delivery events: 12 months, then automatically purged.
- Operational logs (AI spend, moderation flags): retained after account deletion with the personal link severed, so service-integrity metrics continue to work.
- GDPR request audit log: retained indefinitely for ICO compliance proof. Contains email and request type only.
- Backups: 30 days rolling. A deleted account may persist in a backup snapshot for up to 30 days before it rolls off.
6. Your rights
Under UK GDPR you have the right to:
- Access and portability — download a machine-readable copy of everything we hold about you from Settings → Data & Privacy.
- Erasure— delete your account from the same page. Deletion is scheduled 14 days ahead so you have a chance to change your mind; after that we can’t restore it.
- Rectification— edit your profile and your child’s learning profile from Settings.
- Restriction and objection — contact us at privacy@evx.logicmesh.dev if you want us to pause processing or object on legitimate-interest grounds.
- Withdraw consent — turn off any optional email from Settings at any time.
- Complain to the ICO— if you are unhappy with how we’ve handled your data, you can complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint. We’d rather you talked to us first, but this right is yours regardless.
7. Children and the Age-Appropriate Design Code
This service is designed with the ICO’s Age-Appropriate Design Code (AADC) in mind. In particular:
- Best interests of the child — the service puts learning outcomes and safety above engagement metrics. We deliberately do not use dark patterns such as anxiety-inducing daily streaks or public leaderboards.
- Default to high privacy — a new account comes with optional marketing and nudge emails off by default at the product level, and all settings are held at the most privacy-protective option until the adult actively changes them.
- Transparency — this notice is written for the adult; a child-facing version will be added alongside the student-login flow in a future release.
- Profiling — we build an AI persona from the intake answers so lessons can be personalised. This persona is never used for advertising, never shared, and can be reviewed and edited by the parent from the child detail page.
- Data minimisation — we only ask for what we need to teach the child and keep them safe.
8. Security
Data is encrypted in transit (TLS 1.2+) and at rest. Access to production systems is restricted to named engineers with two-factor authentication. Chat content is moderated through the OpenAI moderation API both before the model sees the request and before the response reaches the child. We keep a running audit of moderation events for admin review.
9. Safeguarding
If the AI tutor detects content that suggests a child is at risk of harm, the conversation is flagged and stored for review. In a genuine safeguarding concern we will follow the procedures set out in Keeping Children Safe in Education 2025and, where appropriate, share information with the child’s school DSL or relevant authorities. This is a narrow legal-obligation carve-out on the non-disclosure rule and does not affect day-to-day privacy.
10. Changes to this policy
If we make a material change we’ll email registered account holders and update the date at the top of this page. Routine editorial changes are logged in the Help Centre.
This notice is a pilot version. It will be reviewed by a qualified UK data-protection practitioner before public launch and may be amended to reflect the finalised DPIA and any school-specific DPAs.