Policies & agreements

Privacy Policy

What we collect about a student and a staff member, where it is held, exactly what the AI is sent, and how a school has any of it corrected or removed. Written to be read by a principal, a privacy officer and a parent — not only by a lawyer.

Version 1.0 Issued 18 August 2026 Next review 18 August 2027 Privacy Officer Jake Gatto
Contact the Privacy Officer

Free to read. No account, no login.

The short version

A summary, not a substitute — the sections below are the policy.

The school decides, we process

Student information belongs to the school. We hold it on the school's instructions and use it for nothing else.

Stored in Melbourne

All storage and application processing runs in Azure's Australia Southeast region. Staff email stays in Sydney.

The AI never sees a name

One answer at a time, with a year-level band — never a name, a student number or any identifier. Named work is blocked before it is sent.

No trackers, no ads, no training

No analytics, no advertising networks, no third-party content on any page a child sees, and no model is trained on your data.

Free access and deletion

Acknowledged in 5 business days, completed within 30 days, at no charge, with a written deletion certificate.

Every view of a child's work is logged

Who opened it and when. Two-step verification is required for administrators and principals.

Parents and carers: please contact your child's school first — the school decides what happens to its students' records, and we act on its instruction. See section 10.

On this page

What this policy covers, and who is responsible for what

Reason Education is a maths assessment tool for primary schools. A child answers questions and does their working out on a canvas in the student app. The system marks the answer. A teacher reads the working and decides what it means.

The core of it

The school is the entity that decides what student information exists and why. We hold and process it on the school's instructions, under a written agreement, to deliver the service to that school. We do not use school or student data for our own purposes.

Two consequences follow, and both are deliberate:

  • We do not promise deletion of a child's records to a parent. Retention and deletion of student records are matters between a school and the families it serves, under the school's own obligations. We give the school the mechanism (section 10) and we act on the school's instruction.
  • We do not advise a school on whether it needs parental consent. That is the school's determination under its own policy and its department's guidance.

This policy covers all personal information handled by entity name — to be confirmed (ACN acn — to be confirmed, ABN abn — to be confirmed), trading as Reason Education, in operating the Reason Education staff portal and student app.

How you see this policy before you use the service

This policy is published free of charge on this page, and is attached to every school agreement before it is signed.

  • A school sees this policy and the collection notice before signing. No account is created for any user until the agreement is executed.
  • A staff member must tick to confirm they have read this policy on the account-setup screen, before their password is set and before the account can be used. The confirmation is recorded with the policy version and a timestamp.
  • Students do not create accounts and are not asked to agree to anything. Accounts are created by the school. The student app shows a short, plain child-facing explanation of what the app records.

Keeping this policy accurate

This policy is version-controlled and dated. It is reviewed:

  • at least annually, on the next review date shown at the top of this page; and
  • whenever what we collect, why we hold it, who we disclose it to, or where it is processed changes — including any change of sub-processor, hosting region, or of the AI model in use.

Each review records the version, the date, who reviewed it and what changed. A review that finds no change still gets a dated entry, because “we looked and it was still true” is the part an assessor cannot otherwise verify.

  • v1.0 First issue.

What we collect and hold

About students

Supplied by the school, or generated by the child's own work:

  • First name and last name
  • Year level
  • A student number that we generate — it is ours, not the school's, and not a government number
  • A chosen emoji, so a young child can recognise their own name on a list
  • Answers to assessment questions
  • Images of handwritten working out, stored as PNG
  • Curriculum judgements against Victorian Curriculum 2.0 (derived from AC V9.0)
  • Growth history — the record of those judgements over time

About school staff

Name, email address, school, a password hash, and a TOTP secret if they have enrolled a second factor. We hold email delivery logs and sign-in attempt records for security and deliverability.

About the school

School name, and contact details of the staff who administer the account.

What we do not collect, at all

  • Date of birth, age or gender
  • Parent or guardian details, or a home address
  • Health information or financial information
  • Any racial, ethnic, or Aboriginal and Torres Strait Islander status field
  • Any government identifier
  • Location, of any kind
  • Analytics, trackers, advertising networks, remote fonts, or any third-party content on a page a child sees

We call these assessment records and growth history. Nothing beyond the list above is compiled about a child, and the product has no feature that would.

How we collect and hold it

Collection

Student information is entered or uploaded by school staff, or created by the child using the app — their answers and their working out. Staff information is entered by the staff member or by their school administrator. None of it is collected from third parties, purchased, or inferred from anywhere else.

Holding

Production runs on Microsoft Azure App Service and Azure Database for MySQL Flexible Server in Australia Southeast (Melbourne), with working-out images in blob storage in the same region. Data is encrypted in transit and at rest. Access is per-school: every query touching a child's information is scoped to the school that owns it.

Test environments

Our non-production hosting is a labelled test environment only. It carries synthetic data. No school or student data is ever placed on it.

Why we hold it, and what happens if it is not provided

We hold this information for one purpose: to deliver maths assessment to the school that asked for it. Specifically, to mark answers, to show a teacher a child's working, to record curriculum judgements the teacher makes, to show growth over time, to run staff accounts securely, and to support the school when it asks.

What we never do with it

We do not use it for marketing, market research, product analytics, advertising, building a picture of a person for any other purpose, or to train or improve any AI model.

If information is not provided

A student's first name and year level are needed to create an account and to give a child the right assessment — without them the child cannot use the service. A staff email address is needed to issue an account and to send a password reset — without it there is no account. The emoji is optional. Nothing else about a student is mandatory.

The AI, stated plainly

Stated up front

The AI is designed to receive and process personal information. We say so because it is true, and because a service that says otherwise is inviting an assessor to find out for themselves.

The boundary, exactly

  • A model is sent one answer at a time: the question, the answer given, whether our own code marked it correct, a year-level band (“middle primary” — never “Year 3”), and the image of the working out.
  • No identifier crosses. Not a name, not our student number, not a database id, not a pseudonymous token. The payload is built from an allow-list, so a field added to our database next year is not sent by default.
  • The AI never decides a mark. Correct or incorrect is decided by our own code against an answer key. The model is told the verdict; it is never asked for one.
  • The AI never talks to a child. There is no chatbot, tutor or hint of any kind, for anyone under 18 or over it.
  • The model returns four fields: a description of the method, where it broke down, a tag from a fixed list a human wrote, and a confidence band. Anything else is discarded whole.
  • The provider is contractually barred from training on our data, and the request is made with retention disabled on the provider's side.

The image is personal information the moment it reaches the model

A child writes their name on their work because that is what children are taught to do. Four controls address this:

  1. The canvas has no name field, no header and no title area — nothing invites a name.
  2. A child-readable instruction on the canvas, and a matching note in the teacher's run instructions.
  3. A blocking scan of all textual content against the roster of that actual class run. A hit means the page is not sent — it goes to teacher-only review and is logged.
  4. A scan of the model's own response. A model echoing a classmate's name means it read one off the image, and the response is quarantined.

What we will not claim

We will never say “the AI can never see a name.” Control 4 fires after the call has been made — it is detection, not prevention. The honest position is: these four controls, the no-training term, and the fact that a child may still write identifying details on their page, which we detect and quarantine where we can.

Who we disclose it to

We use a small number of sub-processors. They are named in full, with data types, purpose, lawful basis and country, in the Sub-Processor Register (publishing soon).

Summary of who receives what.
Sub-processorWhat they receiveWhere
AnthropicWorking-out images and the inference payload described in section 7. No name, no identifier.United States
Microsoft AzureEverything held — all storage and application processing.Australia Southeast (Melbourne)
Amazon Web ServicesStaff email, through Amazon SES. No student data.Australia (Sydney), ap-southeast-2
Have I Been PwnedThe first five characters of a hash, when a staff password is checked against known breaches. Never a password, never a user's details.

We disclose personal information to nobody else, in any circumstance, other than: where the individual has consented; where required or authorised by Australian law or a court or tribunal order; where permitted under privacy legislation; or where we reasonably believe disclosure is reasonably necessary for an enforcement body's enforcement-related activities.

Including the usual exception

We do not sell data. We do not share it with advertisers, data brokers, analytics providers or researchers. We do not share aggregated or pseudonymised data either — the exception people usually leave themselves. There is none here.

Overseas disclosure

Yes — one disclosure leaves Australia, and only one.

WhereWhat goes thereWhy
United States — Anthropic The AI payload in section 7: the working-out image, the question, the answer, the mark, a year-level band. No name, no identifier. Model inference. There is no comparable Australian-hosted model that meets the no-training and zero-retention terms.
Australia (Melbourne) — Microsoft Azure All storage and all application processing. Production hosting.
Australia (Sydney) — Amazon SES Staff name, school email address, and the account and service email itself, including single-use account-recovery links. No student data. Transactional email. The provider was chosen on residency: it is the only candidate with an Australian region, so this information stays onshore.

Said precisely

We do not claim “nothing leaves Australian jurisdiction” — that would be false. What is true is that stored student data is held in Melbourne, and the only information that leaves is the pseudonymised inference payload described in section 7.

We take reasonable steps to ensure the overseas recipient handles the information consistently with the Australian Privacy Principles: a written agreement, the no-training term confirmed in writing, zero data retention on the provider's side, and a documented check that all three are in force.

Access, correction and deletion

Any individual, or a school on behalf of a student, may ask us for access to the personal information we hold about them, to correct it, or to delete it.

HowEmail privacy email — to be confirmed, or write to registered address — to be confirmed.
CostFree. Always. We do not charge for access, correction or deletion.
TimeframeWe acknowledge within 5 business days and complete the request within 30 days. In no case will a request take longer than 3 months; if something would push it past 30 days we will tell you why and when it will be done.

Parents and carers

Please contact your child's school. The school holds the relationship with the family and decides what happens to its students' records; we act on the school's instruction. We will always tell a school exactly what we hold and how to have it changed or removed — that is the mechanism, and it is theirs to use.

Most correction is faster done directly: a teacher or school administrator can correct a student's name, year level or class in the portal at any time.

Retention

Retention and deletion are set out in full in our Data Retention and Deletion Policy and in clause 7 of the school agreement. In summary, we commit to:

  • deleting a student's record, a cohort, or all of a school's data from live systems within 30 days of the school asking in writing, free of charge, with a written deletion certificate issued automatically;
  • deleting a school's data within 30 days of the agreement ending, after the export window;
  • retaining encrypted backups for 100 days and then expiring them;
  • retaining audit logs for 24 months, because a security log deleted early is a security control removed.

What that means for backups

Deleted data persists in encrypted backups for up to a further 100 days and is destroyed as those backups age out. We say this rather than claim an instant deletion no backup regime can deliver.

Government identifiers

We do not adopt, use or disclose any government-related identifier as our own identifier of a person. There is no field for a Victorian Student Number, a USI, a Medicare number, a driver licence or a tax file number, and there is nowhere to put one. The student number in the product is generated by us and means nothing outside the product.

No cross-school discovery

There is no search, directory, or discovery feature that lets a user in one school find, view or discover a user or any personal information from another school. Every query that touches a child's information is scoped to the school that owns it, and this is enforced in the query itself rather than in the page that calls it. There is no data sharing between customers, no cross-school analytics and no transfer feature.

Security

The controls are set out in full in our Security Policy. In short:

  • Staff passwords are hashed with bcrypt and must be at least 15 characters — or 12 with a second factor.
  • TOTP two-step verification is required for school administrators and principals, available to every other staff account, and can be required school-wide.
  • Sessions lock after 15 minutes idle and expire absolutely at 12 hours.
  • Every state change and every view of a child's work is logged with who did it.
  • Reset and invite links are stored hashed, single-use and time-limited.
  • Access to production is held by the smallest number of people that can run the service.
  • Eleven automated test suites cover the AI boundary, the release gate, the name detection, the second factor and the provenance rules.

If a breach occurs

If a data breach occurs that is likely to cause serious harm, we notify the affected school without waiting for the investigation to finish, and we meet our obligations under the Notifiable Data Breaches scheme.

Marketing, and dealing with us anonymously

We do not add anyone to a marketing list. Any commercial or promotional email is opt-in only — you receive it because you asked to. Service messages (an outage, a security notice, a renewal, a policy update) are not marketing and are sent to account holders regardless.

You can deal with us anonymously or under a pseudonym when making a general enquiry, giving feedback, or reporting a security issue. We only need to know who you are when the request concerns a specific account or a specific person's information — because we cannot safely act on those without knowing who is asking.

Complaints

If you think we have breached your privacy, tell us: privacy email — to be confirmed, or registered address — to be confirmed, marked to the Privacy Officer.

What happens then:

  1. We acknowledge in writing within 5 business days, and tell you who is handling it.
  2. The Privacy Officer investigates. This is Jake Gatto, who is not the founder who writes the code — a complaint about the product is not investigated by the person who built it.
  3. We respond in writing within 30 days with what we found, what we are doing about it, and what you can do if you disagree. If it will take longer we tell you why and give you a date, and it will not exceed 3 months.
  4. The finding produces either a change with a test behind it, or a written record of why no change is warranted. A complaint that produces neither has not been closed.

If you are not satisfied

You can complain to the Office of the Australian Information Commissioner (oaic.gov.au, 1300 363 992). If your complaint concerns a Victorian government school, the Office of the Victorian Information Commissioner (ovic.vic.gov.au) may also be able to help. Nothing in this policy limits your right to go to either of them at any time.

Contact us

Entityentity name — to be confirmed (ACN acn — to be confirmed, ABN abn — to be confirmed), trading as Reason Education
Privacy OfficerJake Gatto, Founder and CEO
Privacy enquiries, access, correction, complaintsprivacy email — to be confirmed
General supportsupport email — to be confirmed
Child safety concernschild safety email — to be confirmed
Phonephone number — to be confirmed
Postregistered address — to be confirmed

When this policy changes

When we change this policy or our terms:

  • We notify every account holder by email at least 14 days before the change takes effect, with a plain summary of what changed and why. Schools are told at the same time as their staff.
  • On the first sign-in after the change takes effect, each user is shown the new version and must review and accept it before continuing. Continuing to use the service without accepting is not an option we offer — implied consent is not consent to a document nobody opened.
  • A material change to what we collect, who we disclose it to, or where it is processed is notified to the school as a change to the agreement, not merely as a policy update.
  • Every version stays available at /privacy-policy/versions, so a school can see what it agreed to and when.

Issued

Version 1.0, 18 August 2026 — Jake Gatto, Founder and CEO, Privacy Officer. Next scheduled review 18 August 2027, or sooner on any change to what we collect, who we disclose it to, or where it is processed.