Privacy Policy

Version 2.9 · Last updated 8 October 2026

Our AI reads your emails only to extract events, dates, tasks and details — and according to AWS's Bedrock documentation, the service does not store or log prompts, use them to train models, or give model providers access to them. The email text is saved with your account so events show their full details and can be re-checked, visible only to your household and never shared or used for anything else. Uploaded documents are deleted as soon as processing finishes. We don't sell your data, we don't use advertising or analytics cookies. When we use AI, we send the text itself (the email, message or document) together with your children's first names, year groups and internal record numbers, so events land on the right child. We do not add your account ID, your contact details or any payment information. If the message you forward contains someone's phone number or address, that text is sent as part of the message.

1. Who We Are

SchoolSphere is operated by SchoolSphere Ltd, a company registered in England and Wales. We are the data controller of your personal data under UK GDPR and the Data Protection Act 2018.

Questions or requests? Email privacy@schoolsphere.app. We respond within 30 days.

You also have the right to contact the Information Commissioner's Office (ICO) at ico.org.uk or 0303 123 1113.

2. Who This Policy Applies To

SchoolSphere is designed for parents and carers aged 18 and over, based primarily in the United Kingdom. This policy is governed by UK law (UK GDPR and the Data Protection Act 2018).

If you are located in the European Union or EEA, you have additional rights under EU GDPR, including the right to lodge a complaint with your local supervisory authority. If you are located in California, USA, you may have additional rights under the CCPA/CPRA, including the right to know, delete, and opt out of the sale of personal information — we do not sell personal information. If you are located elsewhere, local data protection laws may also apply. In all cases, we apply the same high standard of protection described in this policy.

SchoolSphere is not directed at children under 13. We do not knowingly collect personal data from children under 13 without verifiable parental consent. If you believe a child under 13 has provided us with personal data, please contact privacy@schoolsphere.app and we will delete it promptly.

3. What Data We Collect

Account information

When you sign in — via Clerk, our authentication provider, using Apple, Google, Microsoft, an email address and password, or a one-time email code — we store your name, email address, unique user ID, and account creation date. Any password you set is handled and stored securely by Clerk, not by SchoolSphere — we never receive or store it. By completing sign-in, you confirm that you are 18 or over.

Children's profile information

When you add a child, we store their first name or nickname, year group, avatar emoji, and colour. We do not collect children's dates of birth, addresses, photographs, or government identifiers. Children cannot create accounts or access the app directly.

Events and calendar data

We store events you add manually or import via text, email, PDF extraction, or school letter scanning — including titles, dates, requirements, and the child they are associated with.

Trusted senders — whose email we read

Email sync reads only emails from the senders you mark as trusted; it never reads the rest of your inbox. A trusted sender can be an exact email address (for example office@stmarys.co.uk) or a whole school domain, which also covers its subdomains (for example @stmarys.co.uk, matching office@stmarys.co.uk and admin@mail.stmarys.co.uk). A public email provider — Gmail, Outlook, iCloud and the like — cannot be trusted as a whole domain, because that would mean trusting every one of its users; you can still add an individual address there. This rule is applied on every provider below. If a provider's search returns an email that does not exactly match a trusted sender (for example a similar-looking address), we look only at its sender, discard it without downloading its content, and keep nothing about it except a note not to check that message again.

Gmail integration (optional, consent-based)

If you connect Gmail, we use the Gmail API with read-only scope, and we ask Google only for emails from your trusted senders — so Google's servers return only those emails and we never receive a listing of your whole inbox. Our AI reads that email content only to extract events, dates, tasks and details, and the AI provider does not retain it or use it to train its models. The email text is saved with your account so events show their full details and can be re-checked — visible only to your household and never shared or used for anything else. Disconnecting Gmail deletes the stored access from our systems and revokes SchoolSphere's access with Google; you can do this at any time in Settings.

Outlook / Microsoft 365 integration (optional, consent-based)

If you connect Outlook, we use the Microsoft Graph API with read-only scope. To decide what to read, SchoolSphere first sees only the sender and date of new messages; it then fetches the subject, content and attachments only for messages from a trusted sender. Nothing is stored about any other email, and the mailbox is strictly read-only — nothing is ever marked as read, moved or deleted. Our AI reads that email content only to extract events, dates, tasks and details, and the AI provider does not retain it or use it to train its models. The email text is saved with your account so events show their full details and can be re-checked — visible only to your household and never shared or used for anything else. Disconnecting Outlook deletes the stored access from our systems; Microsoft does not offer a way to revoke a single app's token, so the token is simply deleted on our side. You can disconnect at any time in Settings.

iCloud Mail integration (optional, consent-based)

If you connect iCloud Mail, we access your inbox over IMAP using an app-specific password you generate at account.apple.com. We ask Apple's server only for emails from your trusted senders, so it returns only those emails. The mailbox is read-only — we never send, move or delete anything. Our AI reads that email content only to extract events, dates, tasks and details, and the AI provider does not retain it or use it to train its models. The email text is saved with your account so events show their full details and can be re-checked — visible only to your household and never shared or used for anything else. The app-specific password is stored encrypted. Disconnecting iCloud Mail deletes that stored password from our systems; you can also revoke the app-specific password yourself at any time at account.apple.com. You can disconnect at any time in Settings.

Uploaded documents

PDFs and photos you upload are processed by AI to extract event information. The original files are deleted as soon as processing finishes — we do not retain uploaded documents. Extracted events are saved to your account.

Pasted text

Text you paste (email text, WhatsApp messages) is sent to our AI to extract events, dates, tasks and details; the AI provider does not retain it. The text is saved with your account alongside the events it produced, so those events keep their full context and can be re-checked — visible only to your household and never shared or used for anything else.

Subscription and billing data

If you subscribe, payment is processed by Stripe. We do not store your card details. We receive from Stripe: your customer ID, subscription status, plan type, and billing dates.

Push notification tokens

If you enable push notifications, we store a device push token to deliver reminders to your device.

Technical data

We collect standard server logs (IP addresses, request timestamps, error reports) for security monitoring only. These are retained for a maximum of 90 days and are not used for any other purpose. We do not use any third-party analytics services (such as Google Analytics, Firebase, or Mixpanel). No analytics cookies or tracking scripts are loaded.

4. How We Use Your Data

We use your data only to provide the SchoolSphere service. Specifically: to run your account and calendar (lawful basis: contract); to process Gmail, Outlook, iCloud Mail and uploaded documents, and to write events to any Google, Outlook or iCloud calendar you connect, with your consent (lawful basis: consent — revocable at any time in Settings); to process subscription payments (lawful basis: contract); and for security monitoring (lawful basis: legitimate interests).

We do not use your data for advertising, profiling, or any purpose not listed here.

5. Data Minimisation and Purpose Limitation

We collect only the minimum personal data necessary to provide the service. Each piece of data we hold has a specific, documented purpose, and we do not use it for anything beyond that purpose. We conduct periodic internal reviews of what data we hold to ensure we are not retaining anything unnecessary. If a feature is removed or changed, we delete any data that was collected solely for that feature.

For children's profiles in particular, we deliberately limit collection to first name and year group — the minimum needed to organise events by child. We do not collect, and actively avoid requesting, any additional information about children.

6. AI Processing — How It Works

SchoolSphere uses AI to extract event information from emails, documents, and natural language input. This processing is performed by Amazon Web Services, using Amazon Bedrock in London, with Anthropic's Claude models accessed through Bedrock. We never send your data to Anthropic directly. According to AWS's Bedrock documentation, Bedrock does not store or log prompts and completions, does not use them to train models, does not share them with third parties, and model providers such as Anthropic have no access to them (see AWS Bedrock data protection).

When we use AI, we send the text itself (the email, message or document) together with your children's first names, year groups and internal record numbers, so events land on the right child. We do not add your account ID, your contact details or any payment information. If the message you forward contains someone's phone number or address, that text is sent as part of the message. The service returns structured event data, which SchoolSphere keeps with your account as described in the Email and Pasted Text sections above.

AI processing is performed server-side (not on your device). All communication between our servers and AWS Bedrock is encrypted in transit. This AI processing is used solely for event extraction and calendar assistant features — it is not used for profiling, advertising, or any decision-making about you.

7. Children's Data — Special Protections

SchoolSphere is for parents and carers aged 18 and over. Children do not have accounts and cannot use the app directly. We apply the following protections in line with the ICO's Children's Code (Age Appropriate Design Code):

Age verification is carried out at sign-in: users sign in via Clerk (using Apple, Google, Microsoft, an email address and password, or a one-time email code) and by completing registration they self-declare they are 18 or over. We do not knowingly allow users under 18 to create accounts. Before enabling Gmail, Outlook or iCloud Mail integration or AI features that process family content, users are shown a clear consent screen explaining what data is accessed and how it is used.

Children's data is stored only as entered by the parent or carer. Children cannot access or modify their own records. We do not use children's information for advertising or profiling. Household members only see children's data for children the account holder has explicitly shared. When an account is deleted, all children's data is permanently and immediately deleted. We collect only the minimum information necessary (first name or nickname and year group).

We do not knowingly process personal data relating to children under 13 without verifiable parental consent. If you believe this has occurred, please contact privacy@schoolsphere.app immediately.

8. Who We Share Data With

We do not sell your data. We share data only with the third parties below, each acting as a data processor.

Railway — hosting and database

Our backend and database run on Railway, which stores your account data, children's profiles, events, and calendar entries in a managed MySQL database. Railway hosts our database and backend in EU West (Amsterdam, Netherlands).

Cloudflare — email routing and network proxy

Cloudflare handles two things for us. First, inbound email: school emails you forward to your SchoolSphere address are received first by Cloudflare Email Routing, which passes the message to SchoolSphere for processing. Second, network proxy: schoolsphere.app is served through Cloudflare, so traffic between the app and our backend passes through Cloudflare's network.

Netlify — website hosting

Our public website (schoolsphere.co.uk) is hosted by Netlify, which, like any web host, processes visitors' IP addresses in order to serve the pages.

Clerk — sign-in and authentication

Sign-in is handled by Clerk (using Apple, Google, Microsoft, an email address and password, or a one-time email code). Clerk receives your name, email address, unique user ID, sign-in method, and — if you set one — your password, which Clerk stores securely; SchoolSphere never receives or stores it. Clerk is based in the USA and is certified under the EU-US Data Privacy Framework, including the UK Extension.

Amazon Web Services (Amazon Bedrock) — AI event extraction and calendar assistant

Text content (email bodies, pasted text, document text) is processed by Amazon Web Services using Amazon Bedrock, in London, with Anthropic's Claude models, for event extraction and natural language processing — together with your children's first names, year groups and internal record numbers, so that events are assigned to the right child. We do not add your account ID, your contact details or any payment information; if a message you forward contains someone's phone number or address, that text is sent as part of the message. According to AWS's Bedrock documentation, Bedrock does not store or log prompts and completions, does not use them to train models, does not share them with third parties, and model providers such as Anthropic have no access to them (see AWS Bedrock data protection).

Amazon Web Services (S3) — temporary file storage

Uploaded files (PDFs, photos) are temporarily stored in AWS S3 (eu-west-2, London) for the duration of AI processing only, then immediately deleted.

Google LLC — Gmail and Google Calendar

If you connect Gmail, we use the Gmail API (read-only) to fetch school emails from your trusted senders only. If you connect Google Calendar, we write the event's title, description and time to your calendar. We do not add your child's name or any child label to the event, but the title and description are copied as they are, so they may mention your child if the original message did. You can revoke access at any time in your Google account or in SchoolSphere Settings; disconnecting either deletes the stored tokens from our systems and revokes SchoolSphere's access with Google.

Microsoft Corporation — Outlook and Outlook Calendar

If you connect Outlook, we use the Microsoft Graph API (read-only) to fetch school emails, seeing only the sender and date of other messages and fetching the content only for your trusted senders. If you connect Outlook Calendar, we write the event's title, description and time to your calendar. We do not add your child's name or any child label to the event, but the title and description are copied as they are, so they may mention your child if the original message did. You can revoke access at any time in your Microsoft account or in SchoolSphere Settings; disconnecting deletes the stored tokens from our systems. Microsoft does not offer a way to revoke a single app's token, so the token is simply deleted on our side.

Apple — iCloud Mail and iCloud Calendar

If you connect iCloud Mail, we read it over IMAP (read-only) using an app-specific password you generate at account.apple.com, fetching only emails from your trusted senders. If you connect iCloud Calendar, we write the event's title, description, location and time to your calendar over CalDAV. We do not add your child's name or any child label to the event, but the title and description are copied as they are, so they may mention your child if the original message did. App-specific passwords are stored encrypted. Disconnecting deletes the stored password from our systems; you can also revoke the app-specific password yourself at any time at account.apple.com.

360dialog and Meta Platforms — WhatsApp

If you use SchoolSphere on WhatsApp, your messages, voice notes, and any images or PDFs you send — and the replies and digests we send you — pass through the WhatsApp Business API, provided by 360dialog and operated by Meta Platforms. 360dialog GmbH is based in Germany.

Resend — outbound email

Emails we send you (digests, notifications, and feedback replies) are delivered through Resend, which receives the recipient email address and the message content. Resend processes this under its Data Processing Addendum, with the EU Standard Contractual Clauses as amended by the UK Addendum.

OpenAI OpCo, LLC (USA) — voice transcription

If you use the voice assistant, or send a voice note to SchoolSphere on WhatsApp, the audio is sent to OpenAI's Whisper API (in the USA) to transcribe it into text. The resulting text is then processed in the same way as pasted text. We do not send audio to OpenAI for any other purpose. OpenAI processes this under OpenAI's Data Processing Addendum, with the Standard Contractual Clauses as amended by the UK Addendum.

Google Maps Platform (Places) — location lookup

When an event has a location, or when someone types a place into a location field, we send that text — and nothing else about you — from our servers to Google's Places API, to suggest venues or find an address and map coordinates.

postcodes.io — UK postcode lookup

To show local weather for an event, we may send a UK postcode to postcodes.io to convert it to approximate coordinates.

Open-Meteo — weather and place lookup

To show weather and to look up place names, we may send location coordinates or a place name to Open-Meteo.

Apple, Google and Expo — push notification delivery

To deliver reminders and alerts, your device push token and the notification text are sent to the relevant push service — Apple (APNs), Google (FCM), and, in the mobile app, Expo.

Stripe Inc — payment processing

Subscription payments are processed by Stripe. We share only the minimum required (email, name, subscription plan); card details are handled by Stripe and never reach us.

Some of these providers process data outside the UK; where they do, we rely on the UK's adequacy arrangements or the provider's standard contractual clauses.

9. How Long We Keep Your Data

Account and profile data is retained until you delete your account. Events and calendar entries are retained until you delete them or your account. Email text and pasted text saved with your account (for example, on the event it produced) is retained until you delete the item or your account. In practice that means we keep: the snippet of source text stored on an event, the sender address and subject line of a school email we processed, and the summary and key points we generated from a school update. There is no automatic expiry. Deleting an event removes the snippet stored on it. The sender and subject of a processed email, and the summaries and key points of school updates, are kept until you delete your account. Uploaded files are deleted as soon as processing finishes (typically within seconds). Email and calendar connections are kept only while they are active: the Gmail, Outlook, Google Calendar and Outlook Calendar access tokens, and the encrypted iCloud Mail and iCloud Calendar app-specific passwords, are deleted from our systems as soon as you disconnect that connection. For Google, disconnecting also revokes the token with Google; Microsoft offers no way to revoke a single app's token, so it is deleted on our side; and you can revoke an iCloud app-specific password yourself at any time at account.apple.com. Push notification tokens are retained until you revoke permission. Billing and accounting records are kept for 6 years from the end of the financial year they relate to, as UK law requires for company accounting records. Server logs are retained for 90 days. Consent records are retained for 7 years.

10. Your Rights

Under UK GDPR, you have the right to access a copy of your data (use "Download My Data" in Settings); rectify inaccurate data; erase your account and all data (Settings → Delete Account); data portability (export as JSON via Settings); restrict processing in certain circumstances; object to processing based on legitimate interests; and withdraw consent at any time for Gmail, Outlook and iCloud Mail sync, Google, Outlook and iCloud calendar sync, push notifications, and email digest.

If you are in the EU/EEA, you have equivalent rights under EU GDPR and may lodge a complaint with your local supervisory authority. If you are in California, you have rights under CCPA/CPRA including the right to know what data we hold, the right to delete it, and the right to opt out of sale (we do not sell data).

To exercise any right, email privacy@schoolsphere.app. We will respond within 30 days.

11. Security

All data is transmitted over HTTPS (TLS 1.2+). Session cookies are httpOnly and secure. OAuth tokens are stored encrypted at rest. Uploaded files use randomised storage keys and are deleted as soon as processing finishes. We do not store passwords.

In the event of a data breach likely to risk your rights, we will notify you and the ICO within 72 hours as required by UK GDPR.

12. Cookies and Local Storage

SchoolSphere uses a single session cookie to keep you logged in. This cookie is strictly necessary for the app to function and does not track you across other websites. We do not use advertising cookies, analytics cookies, or third-party tracking cookies.

The app also uses browser local storage to cache your preferences (such as selected child filter and calendar view) so the app loads faster. This data is stored only on your device and is never transmitted to our servers. It is cleared when you log out or clear your browser data. We do not use device identifiers or fingerprinting techniques.

13. School Website Term Dates

Term dates retrieved from school websites are provided for convenience only and may not be accurate. Always verify important dates directly with your school. We are not affiliated with any school.

15. Changes to This Policy

If we make material changes to this policy, we will notify you by email (to the address associated with your account) and via an in-app banner, where possible, before the changes take effect. We will ask you to review and acknowledge the updated policy. Minor clarifications that do not affect your rights will be made without notice, but the version number and date at the top of this page will always reflect the most current version.

Previous versions of this policy are available on request by emailing privacy@schoolsphere.app.

16. Contact Us

Version 2.9 · Last updated 8 October 2026 · SchoolSphere Ltd, England and Wales