What this policy covers, and who is responsible for what
Reason Education is a maths assessment tool for primary schools. A child answers questions and does their working out on a canvas in the student app. The system marks the answer. A teacher reads the working and decides what it means.
The core of it
The school is the entity that decides what student information exists and why. We hold and process it on the school's instructions, under a written agreement, to deliver the service to that school. We do not use school or student data for our own purposes.
Two consequences follow, and both are deliberate:
- We do not promise deletion of a child's records to a parent. Retention and deletion of student records are matters between a school and the families it serves, under the school's own obligations. We give the school the mechanism (section 10) and we act on the school's instruction.
- We do not advise a school on whether it needs parental consent. That is the school's determination under its own policy and its department's guidance.
This policy covers all personal information handled by entity name — to be confirmed (ACN acn — to be confirmed, ABN abn — to be confirmed), trading as Reason Education, in operating the Reason Education staff portal and student app.
How you see this policy before you use the service
This policy is published free of charge on this page, and is attached to every school agreement before it is signed.
- A school sees this policy and the collection notice before signing. No account is created for any user until the agreement is executed.
- A staff member must tick to confirm they have read this policy on the account-setup screen, before their password is set and before the account can be used. The confirmation is recorded with the policy version and a timestamp.
- Students do not create accounts and are not asked to agree to anything. Accounts are created by the school. The student app shows a short, plain child-facing explanation of what the app records.
Keeping this policy accurate
This policy is version-controlled and dated. It is reviewed:
- at least annually, on the next review date shown at the top of this page; and
- whenever what we collect, why we hold it, who we disclose it to, or where it is processed changes — including any change of sub-processor, hosting region, or of the AI model in use.
Each review records the version, the date, who reviewed it and what changed. A review that finds no change still gets a dated entry, because “we looked and it was still true” is the part an assessor cannot otherwise verify.
- v1.0 First issue.
What we collect and hold
About students
Supplied by the school, or generated by the child's own work:
- First name and last name
- Year level
- A student number that we generate — it is ours, not the school's, and not a government number
- A chosen emoji, so a young child can recognise their own name on a list
- Answers to assessment questions
- Images of handwritten working out, stored as PNG
- Curriculum judgements against Victorian Curriculum 2.0 (derived from AC V9.0)
- Growth history — the record of those judgements over time
About school staff
Name, email address, school, a password hash, and a TOTP secret if they have enrolled a second factor. We hold email delivery logs and sign-in attempt records for security and deliverability.
About the school
School name, and contact details of the staff who administer the account.
What we do not collect, at all
- Date of birth, age or gender
- Parent or guardian details, or a home address
- Health information or financial information
- Any racial, ethnic, or Aboriginal and Torres Strait Islander status field
- Any government identifier
- Location, of any kind
- Analytics, trackers, advertising networks, remote fonts, or any third-party content on a page a child sees
We call these assessment records and growth history. Nothing beyond the list above is compiled about a child, and the product has no feature that would.
How we collect and hold it
Collection
Student information is entered or uploaded by school staff, or created by the child using the app — their answers and their working out. Staff information is entered by the staff member or by their school administrator. None of it is collected from third parties, purchased, or inferred from anywhere else.
Holding
Production runs on Microsoft Azure App Service and Azure Database for MySQL Flexible Server in Australia Southeast (Melbourne), with working-out images in blob storage in the same region. Data is encrypted in transit and at rest. Access is per-school: every query touching a child's information is scoped to the school that owns it.
Test environments
Our non-production hosting is a labelled test environment only. It carries synthetic data. No school or student data is ever placed on it.
Why we hold it, and what happens if it is not provided
We hold this information for one purpose: to deliver maths assessment to the school that asked for it. Specifically, to mark answers, to show a teacher a child's working, to record curriculum judgements the teacher makes, to show growth over time, to run staff accounts securely, and to support the school when it asks.
What we never do with it
We do not use it for marketing, market research, product analytics, advertising, building a picture of a person for any other purpose, or to train or improve any AI model.
If information is not provided
A student's first name and year level are needed to create an account and to give a child the right assessment — without them the child cannot use the service. A staff email address is needed to issue an account and to send a password reset — without it there is no account. The emoji is optional. Nothing else about a student is mandatory.
The AI, stated plainly
Stated up front
The AI is designed to receive and process personal information. We say so because it is true, and because a service that says otherwise is inviting an assessor to find out for themselves.
The boundary, exactly
- A model is sent one answer at a time: the question, the answer given, whether our own code marked it correct, a year-level band (“middle primary” — never “Year 3”), and the image of the working out.
- No identifier crosses. Not a name, not our student number, not a database id, not a pseudonymous token. The payload is built from an allow-list, so a field added to our database next year is not sent by default.
- The AI never decides a mark. Correct or incorrect is decided by our own code against an answer key. The model is told the verdict; it is never asked for one.
- The AI never talks to a child. There is no chatbot, tutor or hint of any kind, for anyone under 18 or over it.
- The model returns four fields: a description of the method, where it broke down, a tag from a fixed list a human wrote, and a confidence band. Anything else is discarded whole.
- The provider is contractually barred from training on our data, and the request is made with retention disabled on the provider's side.
The image is personal information the moment it reaches the model
A child writes their name on their work because that is what children are taught to do. Four controls address this:
- The canvas has no name field, no header and no title area — nothing invites a name.
- A child-readable instruction on the canvas, and a matching note in the teacher's run instructions.
- A blocking scan of all textual content against the roster of that actual class run. A hit means the page is not sent — it goes to teacher-only review and is logged.
- A scan of the model's own response. A model echoing a classmate's name means it read one off the image, and the response is quarantined.
What we will not claim
We will never say “the AI can never see a name.” Control 4 fires after the call has been made — it is detection, not prevention. The honest position is: these four controls, the no-training term, and the fact that a child may still write identifying details on their page, which we detect and quarantine where we can.
Who we disclose it to
We use a small number of sub-processors. They are named in full, with data types, purpose, lawful basis and country, in the Sub-Processor Register (publishing soon).
| Sub-processor | What they receive | Where |
|---|---|---|
| Anthropic | Working-out images and the inference payload described in section 7. No name, no identifier. | United States |
| Microsoft Azure | Everything held — all storage and application processing. | Australia Southeast (Melbourne) |
| Amazon Web Services | Staff email, through Amazon SES. No student data. | Australia (Sydney), ap-southeast-2 |
| Have I Been Pwned | The first five characters of a hash, when a staff password is checked against known breaches. Never a password, never a user's details. | — |
We disclose personal information to nobody else, in any circumstance, other than: where the individual has consented; where required or authorised by Australian law or a court or tribunal order; where permitted under privacy legislation; or where we reasonably believe disclosure is reasonably necessary for an enforcement body's enforcement-related activities.
Including the usual exception
We do not sell data. We do not share it with advertisers, data brokers, analytics providers or researchers. We do not share aggregated or pseudonymised data either — the exception people usually leave themselves. There is none here.
Overseas disclosure
Yes — one disclosure leaves Australia, and only one.
| Where | What goes there | Why |
|---|---|---|
| United States — Anthropic | The AI payload in section 7: the working-out image, the question, the answer, the mark, a year-level band. No name, no identifier. | Model inference. There is no comparable Australian-hosted model that meets the no-training and zero-retention terms. |
| Australia (Melbourne) — Microsoft Azure | All storage and all application processing. | Production hosting. |
| Australia (Sydney) — Amazon SES | Staff name, school email address, and the account and service email itself, including single-use account-recovery links. No student data. | Transactional email. The provider was chosen on residency: it is the only candidate with an Australian region, so this information stays onshore. |
Said precisely
We do not claim “nothing leaves Australian jurisdiction” — that would be false. What is true is that stored student data is held in Melbourne, and the only information that leaves is the pseudonymised inference payload described in section 7.
We take reasonable steps to ensure the overseas recipient handles the information consistently with the Australian Privacy Principles: a written agreement, the no-training term confirmed in writing, zero data retention on the provider's side, and a documented check that all three are in force.
Access, correction and deletion
Any individual, or a school on behalf of a student, may ask us for access to the personal information we hold about them, to correct it, or to delete it.
| How | Email privacy email — to be confirmed, or write to registered address — to be confirmed. |
|---|---|
| Cost | Free. Always. We do not charge for access, correction or deletion. |
| Timeframe | We acknowledge within 5 business days and complete the request within 30 days. In no case will a request take longer than 3 months; if something would push it past 30 days we will tell you why and when it will be done. |
Parents and carers
Please contact your child's school. The school holds the relationship with the family and decides what happens to its students' records; we act on the school's instruction. We will always tell a school exactly what we hold and how to have it changed or removed — that is the mechanism, and it is theirs to use.
Most correction is faster done directly: a teacher or school administrator can correct a student's name, year level or class in the portal at any time.
Retention
Retention and deletion are set out in full in our Data Retention and Deletion Policy and in clause 7 of the school agreement. In summary, we commit to:
- deleting a student's record, a cohort, or all of a school's data from live systems within 30 days of the school asking in writing, free of charge, with a written deletion certificate issued automatically;
- deleting a school's data within 30 days of the agreement ending, after the export window;
- retaining encrypted backups for 100 days and then expiring them;
- retaining audit logs for 24 months, because a security log deleted early is a security control removed.
What that means for backups
Deleted data persists in encrypted backups for up to a further 100 days and is destroyed as those backups age out. We say this rather than claim an instant deletion no backup regime can deliver.
Government identifiers
We do not adopt, use or disclose any government-related identifier as our own identifier of a person. There is no field for a Victorian Student Number, a USI, a Medicare number, a driver licence or a tax file number, and there is nowhere to put one. The student number in the product is generated by us and means nothing outside the product.
No cross-school discovery
There is no search, directory, or discovery feature that lets a user in one school find, view or discover a user or any personal information from another school. Every query that touches a child's information is scoped to the school that owns it, and this is enforced in the query itself rather than in the page that calls it. There is no data sharing between customers, no cross-school analytics and no transfer feature.
Security
The controls are set out in full in our Security Policy. In short:
- Staff passwords are hashed with bcrypt and must be at least 15 characters — or 12 with a second factor.
- TOTP two-step verification is required for school administrators and principals, available to every other staff account, and can be required school-wide.
- Sessions lock after 15 minutes idle and expire absolutely at 12 hours.
- Every state change and every view of a child's work is logged with who did it.
- Reset and invite links are stored hashed, single-use and time-limited.
- Access to production is held by the smallest number of people that can run the service.
- Eleven automated test suites cover the AI boundary, the release gate, the name detection, the second factor and the provenance rules.
If a breach occurs
If a data breach occurs that is likely to cause serious harm, we notify the affected school without waiting for the investigation to finish, and we meet our obligations under the Notifiable Data Breaches scheme.
Marketing, and dealing with us anonymously
We do not add anyone to a marketing list. Any commercial or promotional email is opt-in only — you receive it because you asked to. Service messages (an outage, a security notice, a renewal, a policy update) are not marketing and are sent to account holders regardless.
You can deal with us anonymously or under a pseudonym when making a general enquiry, giving feedback, or reporting a security issue. We only need to know who you are when the request concerns a specific account or a specific person's information — because we cannot safely act on those without knowing who is asking.
Complaints
If you think we have breached your privacy, tell us: privacy email — to be confirmed, or registered address — to be confirmed, marked to the Privacy Officer.
What happens then:
- We acknowledge in writing within 5 business days, and tell you who is handling it.
- The Privacy Officer investigates. This is Jake Gatto, who is not the founder who writes the code — a complaint about the product is not investigated by the person who built it.
- We respond in writing within 30 days with what we found, what we are doing about it, and what you can do if you disagree. If it will take longer we tell you why and give you a date, and it will not exceed 3 months.
- The finding produces either a change with a test behind it, or a written record of why no change is warranted. A complaint that produces neither has not been closed.
If you are not satisfied
You can complain to the Office of the Australian Information Commissioner (oaic.gov.au, 1300 363 992). If your complaint concerns a Victorian government school, the Office of the Victorian Information Commissioner (ovic.vic.gov.au) may also be able to help. Nothing in this policy limits your right to go to either of them at any time.
Contact us
| Entity | entity name — to be confirmed (ACN acn — to be confirmed, ABN abn — to be confirmed), trading as Reason Education |
|---|---|
| Privacy Officer | Jake Gatto, Founder and CEO |
| Privacy enquiries, access, correction, complaints | privacy email — to be confirmed |
| General support | support email — to be confirmed |
| Child safety concerns | child safety email — to be confirmed |
| Phone | phone number — to be confirmed |
| Post | registered address — to be confirmed |
When this policy changes
When we change this policy or our terms:
- We notify every account holder by email at least 14 days before the change takes effect, with a plain summary of what changed and why. Schools are told at the same time as their staff.
- On the first sign-in after the change takes effect, each user is shown the new version and must review and accept it before continuing. Continuing to use the service without accepting is not an option we offer — implied consent is not consent to a document nobody opened.
- A material change to what we collect, who we disclose it to, or where it is processed is notified to the school as a change to the agreement, not merely as a policy update.
- Every version stays available at
/privacy-policy/versions, so a school can see what it agreed to and when.
Issued
Version 1.0, 18 August 2026 — Jake Gatto, Founder and CEO, Privacy Officer. Next scheduled review 18 August 2027, or sooner on any change to what we collect, who we disclose it to, or where it is processed.