For schools
Data & privacy, in plain English
Schools trust us with student data, so here's exactly how we handle it, what we store, where it lives, and the rights you keep. No jargon.
We never sell or share student data
Student data is used only to run the platform for your school. We never sell it, and we never share it with advertisers or third parties for marketing.
Student work never trains AI
We do not use student work to train AI models, and our AI provider does not train on anything sent through its API. Answers are processed only to give the student feedback.
You own your school's data
The school remains the data controller. You can ask us to export or delete your data at any time, and we action deletion requests within 30 days.
Minimal collection
We collect only what the platform needs: name, email, the work a student completes, marks and progress. No home address, no phone number, no unnecessary personal data.
No ads, no ad-tracking
We show no advertising and use no third-party advertising or social-media trackers. Optional product analytics (PostHog, Microsoft Clarity) load only for visitors who accept cookies, never identify a student, and are never used for advertising.
Secure by default
Encrypted in transit (HTTPS) and at rest, access-controlled by role, with two-factor authentication available on every account.
Questions heads & IT ask
Exactly what do you store about a student?
Their name and email, the school and classes they join, the work they're set and complete, their marks, grades and progress, and any answers or questions they submit for AI marking or the tutor. Nothing more, no home address, no phone number, and no student payment details on a school plan.
Do you use student data to train AI?
No. When a student submits an answer for marking or asks the tutor a question, it is sent to our AI provider (Anthropic) purely to generate that response. It is not used to train their models or ours, and it is never used for advertising or sold on.
What happens to answers submitted for AI marking?
They are processed to produce feedback and stored with the student's own record so they can see their history and progress. They are not shared, sold, or used to train models.
Is it suitable for under-18s?
Yes. There is no advertising, no behavioural profiling and no data selling. Parents/guardians get read-only access, and a student only needs a name and email to take part.
Where is the data hosted?
Our database and application are currently hosted in the United States (AWS, US-East) via our infrastructure providers Neon and Vercel. Where data is transferred outside the UK/EEA, we rely on the European Commission's Standard Contractual Clauses to protect it. We're happy to discuss EU-region hosting for a school that requires it.
Who can see a student's work?
The student, their teacher(s) for the classes they're in, a linked parent/guardian (read-only summary), and the school's head admin. SuperExams staff access data only for support and only when needed.
What about sub-processors?
We use a small set of providers to run the service: Neon (database), Vercel (hosting), Cloudflare (file storage), Stripe (payments), Google Workspace (email), Anthropic (AI marking and tutoring), Sentry (error monitoring), and — only for visitors who accept optional cookies — PostHog (EU) and Microsoft Clarity for privacy-friendly product analytics. Each is bound by its own data-protection terms, and the full list is in our Data Processing Agreement.
What happens if there is a data breach?
We notify the affected school promptly and, where legally required, the relevant supervisory authority within 72 hours of becoming aware, in line with GDPR.
Can we control what students can access?
Yes. Through your branded school portal you can limit which subjects appear and manage who is a member, so students only see what you want them to.
Can we get a data-processing agreement?
Yes. We can provide a short data-processing agreement covering what's stored, where, retention and your rights, for your head or DPO to sign before a pilot.
How long is data kept?
While the account is active. When a student leaves, their account unlinks from the school. On a deletion request we remove personal data within 30 days. If you don't continue after a pilot, we delete the school's student data on request, nothing is kept or repurposed.
Want the data-processing agreement, or EU-region hosting for a pilot?
We'll sort it before you start. Founder-led, reply within one working day.
Send your detailsSee also our privacy policy and terms.