Leibniz.

Privacy Policy

Effective Date: January 2025 · Last Updated: 23 September 2026

1. Introduction

Leibniz Education Pty Ltd (“we,” “our,” or “us”) is committed to protecting your privacy while providing adaptive mathematics education services, including personalised practice, AI-assisted grading, and teacher analytics for secondary students. This Privacy Policy explains how we collect, use, store, and protect your information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth).

This policy covers paid school subscriptions and pilots. Our School Subscription Agreement includes school service and data-protection terms. Where signed, it governs the parties' contractual rights for School Data; this policy explains our practices and cannot reduce those protections.


2. Information We Collect

2.1 Information You Provide

Account Information

  • Email address and full name (provided during account creation or via OAuth)
  • School association (assigned during school provisioning)
  • Year level and course selection

Authentication is handled via Google or Microsoft SSO, or via email/password managed by Supabase Auth. Leibniz does not directly store passwords.

Educational Content

  • Typed answers and working steps
  • Uploaded handwritten work (images/PDFs)
  • Time spent on questions

2.2 Information Collected Automatically

Usage Data

  • Questions attempted and completion rates
  • Topics and difficulty levels accessed
  • Performance metrics and daily activity counts

Technical Data

  • IP address and device fingerprint for free/guest rate limiting; school-provisioned Pro users are exempt from that quota. Hosting and security services process connection metadata separately.
  • Session cookies for authentication

Server Logs

  • Vercel runtime logs retained for 30 days under Observability Plus
  • Logging is subject to data-minimisation and restricted-access requirements

2.3 Information from Third Parties

Google/Microsoft OAuth

  • Email address and name during sign-in flow

Payment Information (Individual Subscribers)

  • For individual paid subscribers, Stripe provides transaction and subscription status
  • Not used for school-provisioned users
  • We never directly handle credit card details

3. How We Use Your Information

To Provide the Service

  • Generate personalised questions
  • AI-powered grading for typed and handwritten work
  • Track progress and performance
  • Provide hints and solutions
  • Deliver class assignments and teacher reporting

To Improve the Platform

  • Analyse anonymised aggregate usage patterns
  • Develop new content

For Security

  • Prevent abuse
  • Enforce usage limits
  • Detect fraudulent activity
  • Maintain service stability

For Communication

  • Transactional emails (password resets, account notifications) via Mailgun through Supabase Auth
  • Teacher service newsletters provide factual information about platform features, important workflow changes and service operation, delivered via Mailgun. Recipients are identified from recorded communication preferences and existing teacher/pilot relationships, subject to applicable School instructions. We respect declined signup choices and unsubscribe requests. Student records are not used to select recipients. You can unsubscribe at any time using the link in each newsletter.

4. Data Sharing and Disclosure

We DO NOT:

  • Sell your personal information to third parties
  • Use School Data for marketing, advertising or profiling unrelated to the educational service. Teacher service communications are limited to the purpose described above, and newsletters include an unsubscribe option.
  • Share your data with other schools or organisations except through the service providers, authorised educational access and legal disclosures described in this policy
  • Use student data to train AI models

Sub-Processors

Current providers and planned replacements are listed below. Planned services receive data only after activation and applicable notice or authorisation.

ProviderPurposeData SentRegionRetentionAI Training
SupabaseDatabase, authentication, file storageAll application dataSydney, AUPrimary data store; encrypted backups 7 daysN/A
VercelApplication hosting, server-side API routes, website usage and performance analyticsRequest content needed to serve the feature, page/device metadata, performance measurements and runtime logsSydney production functions; global delivery edge and analytics processingRuntime logs: 30 days under Vercel Observability Plus; analytics follows the provider lifecycleN/A
SCXOptional Australian AI grading, OCR and submission mapping, enabled by Leibniz at the school's requestQuestion context and the submitted response, image or PDF required for the featureAustraliaZero data retention for inference; application records follow the retention scheduleNot used by Leibniz to train models
OpenRouterGlobal-path AI inference and non-submission AI featuresFeature-specific question, curriculum, assessment, response or uploaded-work content (identifiers not intentionally included)United States gateway; approved downstream endpoints may be overseasPer-request zero-data-retention routing requiredData collection denied per request
Apple / Google / MicrosoftOAuth authentication, mobile distribution and purchase verificationIdentity attributes and purchase/account metadata as applicableGlobalProvider account/platform lifecycleN/A
Amazon Web Services (AWS) — plannedReplacement infrastructure and SES emailData needed for activated workloads; email recipients, messages and delivery metadataSydney services; onward email delivery may be overseasApplicable service retention and deletion requirements; configuration confirmed before activationN/A
MailgunTransactional email and teacher service communicationsRecipient email address, message content and delivery metadataUSPer provider policyN/A
StripePayment processing (individual subscribers only)Transaction and subscription dataGlobalPer Stripe's data policyN/A

Stripe is not used for school-provisioned users. Student answers and uploaded work are processed by the hosting, storage and inference services required to deliver the requested feature. PostHog collection is disabled. Vercel provides website usage and performance analytics without advertising cookies. Mailgun remains the email provider pending the AWS SES cutover. We may also disclose information where required by law, limited to what is required.

Teacher and School Access

For school participants, teachers can view performance data (marks, accuracy, time spent, topic performance) for students enrolled in their own classes. School administrators can view data for their school only. This access is part of the educational service and is governed by the school's applicable agreement.


5. Data Retention

Retention Period

Data is retained for the duration of your use of the service to support ongoing learning and teacher reporting.

Deletion on Request

Authorised deletion removes or detaches the account and related records, with separate verified cleanup of uploaded work. The affected data includes:

  • User account and profile
  • Role and access records
  • Class enrolments
  • Account-linked question attempts, submissions, and grades
  • Uploaded handwritten work (images and PDFs in storage)
  • Learning model data and AI-generated summaries
  • Provisioning records

Deletion Timeline

  • After verifying the request and resolving subscription or legal restrictions, account and related relational records are removed or detached in a transaction
  • Uploaded work is deleted immediately where available; provider failures are retained in a durable hourly retry queue and verified by re-listing the account prefixes
  • Encrypted database backups are retained for 7 days, then auto-expire
  • Vercel runtime logs are retained for 30 days under Observability Plus, separately from inference-provider zero data retention

Self-Service Deletion

Students and teachers can delete their own accounts via the Settings page. The request triggers transactional relational deletion and durable, verified storage cleanup.

Anonymised Data

Irreversibly anonymised aggregate statistics (where no individual is identifiable) may be retained.

Data Required by Law

Notwithstanding the above, data that is required to be retained by applicable law or regulation will be kept for the minimum period required and then deleted.


6. Data Security

Encryption

  • In transit: TLS 1.2+ on all connections (browser-to-server and server-to-database)
  • At rest: AES-256 encryption on all stored data

Authorised Data Access

Sensitive operations use permission-checked server-side routes. Client access uses scoped authentication and database policies. Privileged service credentials remain server-side; a public client key does not grant privileged access.

Database Security

  • Row-Level Security (RLS) enabled at the database layer as defence-in-depth
  • Internal UUIDs link learning records; linkable records remain personal information
  • All database queries parameterised to prevent SQL injection

Vendor Access Controls

  • Production access restricted to 2 personnel (CEO and CTO)
  • Policy requires multi-factor authentication for administrative infrastructure access
  • Policy requires periodic credential review and rotation on compromise or access changes
  • Audit logging via platform trails (Supabase database logs and Vercel access logs)

Incident Response

We notify affected schools within 24 hours of becoming aware of a data breach affecting their data, including while assessing its impact. This commitment is separate from statutory notification requirements. Incident response includes immediate containment, root cause analysis, patching, and verification before restoring service.


7. Your Rights and Choices

Access (APP 12)

You can view your own data at any time through the platform. Students can see their own submissions, grades, and progress. Teachers can see performance data for students in their own classes.

Correction (APP 13)

You can update your profile information at any time. If you believe any data we hold about you is inaccurate, please contact us and we will correct it.

Deletion

You can request deletion of your data at any time via the Settings page or by contacting us. Deletion follows Section 5, including shared-record detachment, storage cleanup, backup expiry and any applicable legal retention.

School Deletion

For school subscriptions and pilots, the school may request deletion of all school data at any time. Individual student or teacher records can also be deleted independently without affecting the rest of the school's data.


8. Cookies and Tracking

What We Use

  • Secure HTTP-only session cookies for authentication
  • Essential cookies and Vercel website usage/performance analytics — never advertising or cross-site tracking
  • Session tokens validated server-side on every request

What We Do Not Use

  • No third-party advertising cookies
  • No social media tracking pixels
  • No account-linked analytics profile containing your name, email, school, answers or grades
  • No tracking of browsing history outside Leibniz or collection of precise device location; hosting and analytics may derive an approximate region from connection metadata

9. Children's Privacy

You must be at least 13 years of age to use the Service. For individual users under 18, parental or guardian consent is required.

Leibniz is designed for secondary school students, including those under 18. We take the following measures to protect children's privacy:

  • We do not collect data beyond what is necessary for the educational service
  • We do not track behaviour outside the platform
  • We do not use student data for marketing or profiling unrelated to the educational service
  • We do not share data with social media or advertising networks
  • Schools arrange access and provide required notices and permissions, including parent or guardian consent where required. Purchasing access does not itself supply an individual's consent; Leibniz retains its own privacy obligations.

10. International Data Transfers

Data Stored in Australia

The primary application database, authentication records and uploaded-work storage are hosted in Sydney, Australia. The limited overseas processing and provider metadata described below are not represented as Australian storage.

Limited Cross-Border Processing

  • Australian sovereign inference is available on request. Contact Leibniz to enable it; we confirm activation and covered features. Covered authenticated school grading, OCR and submission-mapping requests use SCX in Australia with zero data retention and no global-provider fallback
  • Schools on the global path and non-submission AI features use OpenRouter's United States gateway and may use an approved overseas downstream endpoint; these requests are designed to exclude direct identifiers and require zero-data-retention eligibility with provider data collection denied
  • Transactional email via Mailgun (US) — recipient address, message content and delivery metadata. Planned AWS SES uses Sydney services; recipient email systems may be overseas
  • Vercel delivery, usage analytics and performance monitoring — page, device and connection metadata, with global processing
  • Apple/Google/Microsoft authentication and platform services — global when selected by the user
  • Stripe payment processing (individual subscribers only) — global, per Stripe's data policy

These practices are aligned with APP 8 (Cross-border Disclosure of Personal Information) under the Privacy Act 1988.


11. Australian Privacy Principles

PrincipleHow Leibniz Complies
APP 3 (Collection)Only data necessary for the educational service is collected
APP 6 (Use/Disclosure)Data used for the stated educational and service-communication purposes; School Data is not used for marketing. Teacher newsletters follow Section 3 and include an unsubscribe option.
APP 8 (Cross-border)Primary application storage is in Australia; global hosting/analytics, inference, email and user-selected platform processing are disclosed above
APP 11 (Security)Encrypted data (see Section 6), permission-checked server operations, scoped client/database access and role-based authorisation
APP 12 (Access)Students can view their own data; teachers can view their class data
APP 13 (Correction)Users can update their profile information at any time

12. Changes to This Policy

We may update this Privacy Policy as the platform evolves. When we make material changes to our data handling practices, participating schools will be notified.

We encourage you to review this policy periodically. The “Last Updated” date at the top of this page indicates the most recent revision.


13. Contact Us

For privacy-related questions or concerns:

Leibniz Education Pty Ltd
ABN 18 692 154 162
36 Bangalla St, Warrawee 2074, NSW
Email: letterbox@leibniz.com.au
Website: leibniz.com.au

If you wish to make a complaint about how we have handled your personal information, please contact us at letterbox@leibniz.com.au. We will acknowledge your complaint within 5 business days, investigate the matter, and provide a written response within 30 days.

If you are unsatisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Schools may request a Data Processing Agreement (DPA) by contacting us at the address above.


14. Specific Feature Disclosures

14.1 AI Grading

When you submit an answer (typed or handwritten), the question, its solution, and your response are sent to the school-selected AI processing path via a server-side API call for grading. For handwritten submissions, the image or PDF of your work is sent for vision-based grading and OCR extraction. Australian-selected schools use SCX in Australia; the global path uses OpenRouter's United States gateway and an approved downstream endpoint.

  • SCX-routed student submission content remains on the Australian processing path and is not sent to OpenRouter
  • Each OpenRouter request requires an eligible zero-data-retention provider and denies provider data collection; otherwise it fails closed
  • Direct identifiers are not deliberately added to grading prompts, but free text or uploads may contain them. The teacher-summary prompt uses a generic student reference with selected mastery context. OpenRouter applies sensitive-information and prompt-injection redaction inside its gateway before downstream inference; coverage is not universal.
  • Grading is processed per request; the necessary context may include marking criteria, prior feedback or selected mastery information. Application records have their own retention schedule
  • Provider routing is configured to deny data collection and exclude endpoints that cannot satisfy zero-data-retention

14.2 Adaptive Learning

Leibniz uses a statistical model to personalise question difficulty. This model operates on pseudonymised data (UUIDs, not names or emails) and stores only mathematical parameters representing estimated mastery per concept.

  • Student data is not used to train or tune models, including when anonymised or aggregated
  • Processing for personalised practice, grading and authorised school reporting remains part of the service

14.3 Progress and Teacher Reporting

For class-assigned work, your progress is visible to your assigned teacher and school administrator (see Section 4). Authorised school reporting may include class-level summaries.

14.4 Guest Usage Controls

Guest usage limits are enforced using a signed pseudonymous guest-session cookie and a server-derived network signal. Signed-in free accounts are metered against their authenticated account instead. For anonymous guest requests, a device fingerprint and request IP may also be mirrored into a legacy daily usage-metering record for compatibility analytics; that record is not the authoritative access decision and cannot increase or reset the signed-session allowance.

  • School-provisioned Pro users are not subject to this guest quota; hosting and security request metadata are separate
  • Used only for service metering and abuse prevention, not advertising or cross-site tracking

14.5 School Provisioning

For school subscriptions and pilots, the onboarding process works as follows:

  • The school provides an email whitelist for students and teachers
  • On first login, the system matches the user's email, assigns the appropriate role, and activates Pro access
  • Teacher access is granted only to approved, school-provided addresses
  • Students can only join classes belonging to their own school — cross-school access is blocked

15. Data Protection Commitments

Our commitments are detailed throughout this policy. In summary: primary application data is stored in Sydney, limited overseas processing is disclosed above, we never sell your data or use it to train AI models, primary deletion is transactional with durable verified storage cleanup and seven-day backup expiry, and access is restricted to authorised personnel under administrative MFA requirements. Schools can read and download our Data Processing Agreement. For full details, see the relevant sections above.


This Privacy Policy is designed to be clear, comprehensive, and respectful of your privacy rights while enabling us to provide effective educational services.

Privacy Policy - Leibniz