Privacy Policy
Draft — not legal advice. Review with a solicitor before relying on this, particularly for compliance with the Australian Privacy Principles and any state education-department data policies. See LAUNCH_PLAN.md Stage 10.
What we store
This portal (hosted on Vercel, data in Supabase) stores only billing and licensing metadata:
- Email address and school/organisation name
- Subscription status, plan, and Stripe customer/subscription IDs
- A one-way hash of your licence key (the key itself is never stored in reversible form)
- A one-way hash of a random per-installation device identifier (not your hardware serial number)
- Reported class counts (a number only, used for billing and plan limits)
- Bug reports you choose to submit via the desktop app's "Report a Bug" button
What we never store
Student names, MIS/EQ IDs, class rosters, behaviour notes, attendance data, OneSchool or Outlook credentials, and downloaded reports all stay on your device and are never sent to this portal.
Payment data
Card details are handled entirely by Stripe; we never see or store your card number. See Stripe's Privacy Policy.
Third parties
We use Stripe (payments), Supabase (database), Vercel (hosting), and, once configured, Resend (transactional email) and Cloudflare Turnstile (bot protection).
Contact
[TBD: support/privacy contact — placeholder, see README.md.]