Privacy Policy
Effective Date: January 2025 · Last Updated: 23 September 2026
1. Introduction
Leibniz Education Pty Ltd (“we,” “our,” or “us”) is committed to protecting your privacy while providing adaptive mathematics education services, including personalised practice, AI-assisted grading, and teacher analytics for secondary students. This Privacy Policy explains how we collect, use, store, and protect your information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth).
This policy covers paid school subscriptions and pilots. Our School Subscription Agreement includes school service and data-protection terms. Where signed, it governs the parties' contractual rights for School Data; this policy explains our practices and cannot reduce those protections.
2. Information We Collect
2.1 Information You Provide
Account Information
- Email address and full name (provided during account creation or via OAuth)
- School association (assigned during school provisioning)
- Year level and course selection
Authentication is handled via Google or Microsoft SSO, or via email/password managed by Supabase Auth. Leibniz does not directly store passwords.
Educational Content
- Typed answers and working steps
- Uploaded handwritten work (images/PDFs)
- Time spent on questions
2.2 Information Collected Automatically
Usage Data
- Questions attempted and completion rates
- Topics and difficulty levels accessed
- Performance metrics and daily activity counts
Technical Data
- IP address and device fingerprint for free/guest rate limiting; school-provisioned Pro users are exempt from that quota. Hosting and security services process connection metadata separately.
- Session cookies for authentication
Server Logs
- Vercel runtime logs retained for 30 days under Observability Plus
- Logging is subject to data-minimisation and restricted-access requirements
2.3 Information from Third Parties
Google/Microsoft OAuth
- Email address and name during sign-in flow
Payment Information (Individual Subscribers)
- For individual paid subscribers, Stripe provides transaction and subscription status
- Not used for school-provisioned users
- We never directly handle credit card details
3. How We Use Your Information
To Provide the Service
- Generate personalised questions
- AI-powered grading for typed and handwritten work
- Track progress and performance
- Provide hints and solutions
- Deliver class assignments and teacher reporting
To Improve the Platform
- Analyse anonymised aggregate usage patterns
- Develop new content
For Security
- Prevent abuse
- Enforce usage limits
- Detect fraudulent activity
- Maintain service stability
For Communication
- Transactional emails (password resets, account notifications) via Mailgun through Supabase Auth
- Teacher service newsletters provide factual information about platform features, important workflow changes and service operation, delivered via Mailgun. Recipients are identified from recorded communication preferences and existing teacher/pilot relationships, subject to applicable School instructions. We respect declined signup choices and unsubscribe requests. Student records are not used to select recipients. You can unsubscribe at any time using the link in each newsletter.
4. Data Sharing and Disclosure
We DO NOT:
- Sell your personal information to third parties
- Use School Data for marketing, advertising or profiling unrelated to the educational service. Teacher service communications are limited to the purpose described above, and newsletters include an unsubscribe option.
- Share your data with other schools or organisations except through the service providers, authorised educational access and legal disclosures described in this policy
- Use student data to train AI models
Sub-Processors
Current providers and planned replacements are listed below. Planned services receive data only after activation and applicable notice or authorisation.
| Provider | Purpose | Data Sent | Region | Retention | AI Training |
|---|---|---|---|---|---|
| Supabase | Database, authentication, file storage | All application data | Sydney, AU | Primary data store; encrypted backups 7 days | N/A |
| Vercel | Application hosting, server-side API routes, website usage and performance analytics | Request content needed to serve the feature, page/device metadata, performance measurements and runtime logs | Sydney production functions; global delivery edge and analytics processing | Runtime logs: 30 days under Vercel Observability Plus; analytics follows the provider lifecycle | N/A |
| SCX | Optional Australian AI grading, OCR and submission mapping, enabled by Leibniz at the school's request | Question context and the submitted response, image or PDF required for the feature | Australia | Zero data retention for inference; application records follow the retention schedule | Not used by Leibniz to train models |
| OpenRouter | Global-path AI inference and non-submission AI features | Feature-specific question, curriculum, assessment, response or uploaded-work content (identifiers not intentionally included) | United States gateway; approved downstream endpoints may be overseas | Per-request zero-data-retention routing required | Data collection denied per request |
| Apple / Google / Microsoft | OAuth authentication, mobile distribution and purchase verification | Identity attributes and purchase/account metadata as applicable | Global | Provider account/platform lifecycle | N/A |
| Amazon Web Services (AWS) — planned | Replacement infrastructure and SES email | Data needed for activated workloads; email recipients, messages and delivery metadata | Sydney services; onward email delivery may be overseas | Applicable service retention and deletion requirements; configuration confirmed before activation | N/A |
| Mailgun | Transactional email and teacher service communications | Recipient email address, message content and delivery metadata | US | Per provider policy | N/A |
| Stripe | Payment processing (individual subscribers only) | Transaction and subscription data | Global | Per Stripe's data policy | N/A |
Stripe is not used for school-provisioned users. Student answers and uploaded work are processed by the hosting, storage and inference services required to deliver the requested feature. PostHog collection is disabled. Vercel provides website usage and performance analytics without advertising cookies. Mailgun remains the email provider pending the AWS SES cutover. We may also disclose information where required by law, limited to what is required.
Teacher and School Access
For school participants, teachers can view performance data (marks, accuracy, time spent, topic performance) for students enrolled in their own classes. School administrators can view data for their school only. This access is part of the educational service and is governed by the school's applicable agreement.
5. Data Retention
Retention Period
Data is retained for the duration of your use of the service to support ongoing learning and teacher reporting.
Deletion on Request
Authorised deletion removes or detaches the account and related records, with separate verified cleanup of uploaded work. The affected data includes:
- User account and profile
- Role and access records
- Class enrolments
- Account-linked question attempts, submissions, and grades
- Uploaded handwritten work (images and PDFs in storage)
- Learning model data and AI-generated summaries
- Provisioning records
Deletion Timeline
- After verifying the request and resolving subscription or legal restrictions, account and related relational records are removed or detached in a transaction
- Uploaded work is deleted immediately where available; provider failures are retained in a durable hourly retry queue and verified by re-listing the account prefixes
- Encrypted database backups are retained for 7 days, then auto-expire
- Vercel runtime logs are retained for 30 days under Observability Plus, separately from inference-provider zero data retention
Self-Service Deletion
Students and teachers can delete their own accounts via the Settings page. The request triggers transactional relational deletion and durable, verified storage cleanup.
Anonymised Data
Irreversibly anonymised aggregate statistics (where no individual is identifiable) may be retained.
Data Required by Law
Notwithstanding the above, data that is required to be retained by applicable law or regulation will be kept for the minimum period required and then deleted.
6. Data Security
Encryption
- In transit: TLS 1.2+ on all connections (browser-to-server and server-to-database)
- At rest: AES-256 encryption on all stored data
Authorised Data Access
Sensitive operations use permission-checked server-side routes. Client access uses scoped authentication and database policies. Privileged service credentials remain server-side; a public client key does not grant privileged access.
Database Security
- Row-Level Security (RLS) enabled at the database layer as defence-in-depth
- Internal UUIDs link learning records; linkable records remain personal information
- All database queries parameterised to prevent SQL injection
Vendor Access Controls
- Production access restricted to 2 personnel (CEO and CTO)
- Policy requires multi-factor authentication for administrative infrastructure access
- Policy requires periodic credential review and rotation on compromise or access changes
- Audit logging via platform trails (Supabase database logs and Vercel access logs)
Incident Response
We notify affected schools within 24 hours of becoming aware of a data breach affecting their data, including while assessing its impact. This commitment is separate from statutory notification requirements. Incident response includes immediate containment, root cause analysis, patching, and verification before restoring service.
7. Your Rights and Choices
Access (APP 12)
You can view your own data at any time through the platform. Students can see their own submissions, grades, and progress. Teachers can see performance data for students in their own classes.
Correction (APP 13)
You can update your profile information at any time. If you believe any data we hold about you is inaccurate, please contact us and we will correct it.
Deletion
You can request deletion of your data at any time via the Settings page or by contacting us. Deletion follows Section 5, including shared-record detachment, storage cleanup, backup expiry and any applicable legal retention.
School Deletion
For school subscriptions and pilots, the school may request deletion of all school data at any time. Individual student or teacher records can also be deleted independently without affecting the rest of the school's data.
9. Children's Privacy
You must be at least 13 years of age to use the Service. For individual users under 18, parental or guardian consent is required.
Leibniz is designed for secondary school students, including those under 18. We take the following measures to protect children's privacy:
- We do not collect data beyond what is necessary for the educational service
- We do not track behaviour outside the platform
- We do not use student data for marketing or profiling unrelated to the educational service
- We do not share data with social media or advertising networks
- Schools arrange access and provide required notices and permissions, including parent or guardian consent where required. Purchasing access does not itself supply an individual's consent; Leibniz retains its own privacy obligations.
10. International Data Transfers
Data Stored in Australia
The primary application database, authentication records and uploaded-work storage are hosted in Sydney, Australia. The limited overseas processing and provider metadata described below are not represented as Australian storage.
Limited Cross-Border Processing
- Australian sovereign inference is available on request. Contact Leibniz to enable it; we confirm activation and covered features. Covered authenticated school grading, OCR and submission-mapping requests use SCX in Australia with zero data retention and no global-provider fallback
- Schools on the global path and non-submission AI features use OpenRouter's United States gateway and may use an approved overseas downstream endpoint; these requests are designed to exclude direct identifiers and require zero-data-retention eligibility with provider data collection denied
- Transactional email via Mailgun (US) — recipient address, message content and delivery metadata. Planned AWS SES uses Sydney services; recipient email systems may be overseas
- Vercel delivery, usage analytics and performance monitoring — page, device and connection metadata, with global processing
- Apple/Google/Microsoft authentication and platform services — global when selected by the user
- Stripe payment processing (individual subscribers only) — global, per Stripe's data policy
These practices are aligned with APP 8 (Cross-border Disclosure of Personal Information) under the Privacy Act 1988.
11. Australian Privacy Principles
| Principle | How Leibniz Complies |
|---|---|
| APP 3 (Collection) | Only data necessary for the educational service is collected |
| APP 6 (Use/Disclosure) | Data used for the stated educational and service-communication purposes; School Data is not used for marketing. Teacher newsletters follow Section 3 and include an unsubscribe option. |
| APP 8 (Cross-border) | Primary application storage is in Australia; global hosting/analytics, inference, email and user-selected platform processing are disclosed above |
| APP 11 (Security) | Encrypted data (see Section 6), permission-checked server operations, scoped client/database access and role-based authorisation |
| APP 12 (Access) | Students can view their own data; teachers can view their class data |
| APP 13 (Correction) | Users can update their profile information at any time |
12. Changes to This Policy
We may update this Privacy Policy as the platform evolves. When we make material changes to our data handling practices, participating schools will be notified.
We encourage you to review this policy periodically. The “Last Updated” date at the top of this page indicates the most recent revision.
13. Contact Us
For privacy-related questions or concerns:
Leibniz Education Pty Ltd
ABN 18 692 154 162
36 Bangalla St, Warrawee 2074, NSW
Email: letterbox@leibniz.com.au
Website: leibniz.com.au
If you wish to make a complaint about how we have handled your personal information, please contact us at letterbox@leibniz.com.au. We will acknowledge your complaint within 5 business days, investigate the matter, and provide a written response within 30 days.
If you are unsatisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Schools may request a Data Processing Agreement (DPA) by contacting us at the address above.
14. Specific Feature Disclosures
14.1 AI Grading
When you submit an answer (typed or handwritten), the question, its solution, and your response are sent to the school-selected AI processing path via a server-side API call for grading. For handwritten submissions, the image or PDF of your work is sent for vision-based grading and OCR extraction. Australian-selected schools use SCX in Australia; the global path uses OpenRouter's United States gateway and an approved downstream endpoint.
- SCX-routed student submission content remains on the Australian processing path and is not sent to OpenRouter
- Each OpenRouter request requires an eligible zero-data-retention provider and denies provider data collection; otherwise it fails closed
- Direct identifiers are not deliberately added to grading prompts, but free text or uploads may contain them. The teacher-summary prompt uses a generic student reference with selected mastery context. OpenRouter applies sensitive-information and prompt-injection redaction inside its gateway before downstream inference; coverage is not universal.
- Grading is processed per request; the necessary context may include marking criteria, prior feedback or selected mastery information. Application records have their own retention schedule
- Provider routing is configured to deny data collection and exclude endpoints that cannot satisfy zero-data-retention
14.2 Adaptive Learning
Leibniz uses a statistical model to personalise question difficulty. This model operates on pseudonymised data (UUIDs, not names or emails) and stores only mathematical parameters representing estimated mastery per concept.
- Student data is not used to train or tune models, including when anonymised or aggregated
- Processing for personalised practice, grading and authorised school reporting remains part of the service
14.3 Progress and Teacher Reporting
For class-assigned work, your progress is visible to your assigned teacher and school administrator (see Section 4). Authorised school reporting may include class-level summaries.
14.4 Guest Usage Controls
Guest usage limits are enforced using a signed pseudonymous guest-session cookie and a server-derived network signal. Signed-in free accounts are metered against their authenticated account instead. For anonymous guest requests, a device fingerprint and request IP may also be mirrored into a legacy daily usage-metering record for compatibility analytics; that record is not the authoritative access decision and cannot increase or reset the signed-session allowance.
- School-provisioned Pro users are not subject to this guest quota; hosting and security request metadata are separate
- Used only for service metering and abuse prevention, not advertising or cross-site tracking
14.5 School Provisioning
For school subscriptions and pilots, the onboarding process works as follows:
- The school provides an email whitelist for students and teachers
- On first login, the system matches the user's email, assigns the appropriate role, and activates Pro access
- Teacher access is granted only to approved, school-provided addresses
- Students can only join classes belonging to their own school — cross-school access is blocked
15. Data Protection Commitments
Our commitments are detailed throughout this policy. In summary: primary application data is stored in Sydney, limited overseas processing is disclosed above, we never sell your data or use it to train AI models, primary deletion is transactional with durable verified storage cleanup and seven-day backup expiry, and access is restricted to authorised personnel under administrative MFA requirements. Schools can read and download our Data Processing Agreement. For full details, see the relevant sections above.
This Privacy Policy is designed to be clear, comprehensive, and respectful of your privacy rights while enabling us to provide effective educational services.