Legal
Privacy notice
Last updated: 25 September 2026. We'll change this if how we handle your data changes, and we'll tell you before we do.
The short version
- We collect your sign-in details, the cards you've seen, and how you did. Nothing else.
- We use that data to run the service. We don't sell it.
- You can delete your account and all your data from the Profile page at any time.
- If you're under 13 and joining with a class code from your teacher, your school authorises your account. If you're signing up on your own, you need a parent or guardian's permission.
Who we are
Educator is a daily-practice study tool for GCSE and KS3 subjects, currently thirteen: Food Preparation and Nutrition, History, Geography, Combined Science, Design & Technology, Religious Studies, Computer Science, Business Studies, PE Theory, Drama, Sociology, Psychology and Music. It's operated by Ben Willis, a sole trader based in England. The data controller is Ben Willis. Reach us at support@educator-labs.com or via the contact page.
If you're unhappy with how we're handling your data, you can complain to the Information Commissioner's Office at ico.org.uk.
What we collect
- Account: your name, email, and a unique account ID (provided by our authentication partner Clerk). If you sign up with Google or Microsoft, we also receive your profile picture.
- Date of birth: asked for when you sign yourself up, whether on your own or with a class code from your teacher. We use it to check whether you're under 13 (if you're signing up on your own and are under 13, we need a parent or guardian's permission, see below), then store the date so we don't have to ask again. We don't ask for it if your teacher created your account for you.
- Practice activity: which cards you saw, your answers, your score, your streak, your XP.
- Push notifications (only if you turn on practice reminders): the push address your browser gives us, the two security keys that go with it, and your device's browser description (user agent). We delete it when you turn reminders off, when your browser tells us the subscription has expired, or when your account is deleted.
- Subscription information (paying users only): we keep a Stripe customer ID and your current plan + renewal date on your account. We never see or store your card details; those are held by Stripe.
- Technical: standard server logs (IP address, time of request) kept for 30 days for security and debugging only. Crash and error reports captured by Sentry.
- Usage analytics: we use Vercel Web Analytics and Speed Insights to count page views and measure performance. These are cookieless: nothing is stored on your device, visits are aggregated and anonymised, and there is no cross-site tracking.
- Attribution: when you first arrive from a link carrying a marketing tag (such as a utm_source or a referral parameter), we store one first-party cookie (edu_src) for up to 90 days recording only which channel sent you: an anonymous label like “newsletter” or a referring site. It holds no name, email, or other identifier, is never shared, and is never used for advertising.
We don't use cookies for advertising, and we don't allow third-party trackers. We don't collect anything we don't need to run the service.
What we use it for
- To show you cards, score you, and keep your streak going.
- To put you on the leaderboard against people in your class or school (when those features land).
- To answer your support questions if you email us.
- To keep the service secure and debug problems.
Who we share it with
We use these companies to run Educator. They're our processors:
- Clerk: handles your sign-in. Stores your name, email, and password hash (or your Google / Microsoft OAuth identity if you sign in with one of those).
- Neon: our database. Stores your practice activity.
- Vercel: hosts the website. Sees server logs and request metadata, and provides our cookieless web analytics (aggregate page views and performance timings).
- Stripe: handles all card payments and subscription billing for paying individual users. We send Stripe your name, email, and customer ID. Stripe stores your card details; we never see them. UK-regulated payment processor.
- Resend: sends transactional emails (welcome notes, weekly digests for teachers). Sees your email address and the content of the message sent.
- Sentry: captures error reports so we can fix bugs. May include your user ID and the page you were on when the error happened.
We don't share your data with anyone else. We don't sell it. We don't use it for advertising.
Where we store it
Practice data is stored in the United States, specifically AWS US East (Northern Virginia). Some processors (Clerk, Vercel) also handle data in the US. These transfers are covered by the UK International Data Transfer Agreement (IDTA) under the UK's adequacy regulations. Server logs are deleted after 30 days. Your account data stays as long as your account exists.
Your rights
- Access: see what we hold about you. Use the “Download my data” button on your profile.
- Delete: remove your account and all your data using “Delete my account” on your profile.
- Correct: if anything we hold is wrong, get in touch via the contact page.
- Object or restrict: stop us using your data for things you don't want. Email us.
- Complain: the ICO is the regulator, at ico.org.uk.
If you're under 13
It depends how you joined, because the two routes have different people responsible for the account.
Joining with a class code from your teacher. Your school sets Educator up for your class and decides which pupils use it, so your school is responsible for your data and Educator handles it on your school's behalf. That means we don't ask you for a parent's permission ourselves - your school arranges anything like that under its own policies. You just need the join code your teacher gave you; without a working code we can't set the account up.
Signing up on your own. Here no school stands behind the account, so we need a parent or guardian's permission. Give us their email address and we'll send them a link to confirm. The account stays locked until they do, and is deleted automatically if it isn't confirmed within seven days.
If you're a parent and want an account removed, reach out via the contact page, or speak to the school if the account was set up for a class.
For schools
Our standing Data Processing Agreement forms part of every school subscription. The school is the data controller for student accounts; Educator is the processor. Data Protection Officers can request a countersigned copy, our DPIA, or our Record of Processing Activities via the contact page.
Changes to this notice
If we change how we handle your data, we'll update this page and tell you the next time you sign in. Major changes will require fresh consent.