Privacy Policy
Last Updated: August 5, 2026
We care about privacy and classroom trust. This policy explains what data we collect, why we collect it, how we use it, and what choices you have. If anything is unclear, contact us and we will explain it in plain English.
Data Controller
Stuart Scott, based in Spain, is responsible for deciding how personal data is used for The Teachers' Room. For privacy questions or requests, email stuartscottai@gmail.com. The service is currently a non-charging beta side project.
1. What We Collect
- Account data: name, email, authentication identifiers, and optional avatar/profile details.
- Content you create: games, prompts, instructions, uploads, edits, and library items.
- Uploads: documents/images you attach for AI generation, plus game assets you choose to store.
- Community visibility data: whether content is public or private, plus public author display fields.
- Contact messages: name, email, and message text sent through the Contact form.
- Technical data: basic logs, request metadata, and error diagnostics from the app and hosting stack.
- Browser-local data (guest mode): games may be stored in your browser localStorage.
- Voice input (optional): if you use dictation, microphone audio is processed by browser speech recognition and/or local Whisper Web transcription, depending on availability.
- Live quiz data: a nickname, first name, or team label, avatar choice, answers, scores, response times, and quiz participation timestamps.
- Take-home student practice: nicknames, answers, and scores remain on the student's device and are not saved to an account or sent to the teacher. We record only an anonymous increase to the game's total play count.
- School account data: school name, teacher invitations and memberships, account roles, shared-school files, and limited teacher activity totals shown to authorised school administrators.
2. How We Use Data
- To provide core features (account login, generation, editing, saving, sharing).
- To generate AI-assisted content based on your prompts and uploaded source material.
- To support community libraries and visibility settings.
- To run live classroom quizzes, display the temporary leaderboard, and return feedback to participants.
- To provide school administration, shared storage, account allocation, security, and limited usage reporting.
- To operate, secure, troubleshoot, and improve reliability and safety of the service.
- To respond to support/contact requests and enforce legal terms.
3. Legal Bases (Where Applicable)
For people in the EU/EEA, the legal basis depends on the particular use:
- Contract: creating and managing adult teacher accounts and providing requested account features.
- Legitimate interests: service security, fraud and abuse prevention, reliability, support, and proportionate product-operation records. We balance these interests against the rights of affected people.
- School instructions or applicable educational legal basis: where a school asks us to process teacher or student data on its behalf, the school determines and documents the appropriate legal basis and we act under a data-processing agreement.
- Consent: optional device permissions such as microphone access, where consent is the appropriate basis. Permission can be withdrawn through browser controls.
- Legal obligation: records required for compliance, dispute handling, and lawful requests.
4. AI Providers and Data Handling
When you use AI features, prompts, uploaded source files, and related context are sent through our server to the AI provider selected for the site: either Google Gemini API or OpenAI API. Provider API keys are not sent to your browser.
Based on Google Gemini API documentation and terms currently published (including Google AI Studio terms effective December 18, 2025):
- For Google "Paid Services," Google states prompts/responses are not used to improve Google products.
- For Google "Unpaid Services," Google states prompts/responses may be used to improve its products and machine-learning technologies.
- Google may retain logs for abuse and safety monitoring under its own policies.
- When OpenAI is selected, requests are processed under OpenAI's API data-usage and retention policies.
Because provider plans and configuration can vary over time, do not submit highly sensitive personal data in prompts or uploads unless you are legally authorized and comfortable with provider-side processing terms.
5. Where Data Is Stored
- Supabase is used for authentication, database storage, and file storage.
- AI generation requests are processed through the selected provider: Google Gemini API or OpenAI API.
- Stock image search uses Pexels and may use Pixabay as a fallback, through our server-side API route/proxy.
- Vercel provides website hosting and server infrastructure and may process request and security logs.
- Cloudflare Turnstile provides human-verification checks on account and login forms.
- Google Fonts supplies the site fonts and receives the normal network information required to deliver those files.
6. How Long We Keep Data
- Account and saved content are kept while your account remains active, unless deleted earlier.
- Live quiz sessions, participant labels, answers, scores, and response times are automatically removed after they reach 24 hours old.
- AI generation usage records used for security, quota management, and cost control are kept for no more than 12 months.
- Guest localStorage content remains on your device until you delete it or clear browser data.
- Public community content may remain visible until removed by you or moderation action.
- Contact messages are kept for no more than 24 months, unless a longer period is required for an active dispute or legal obligation.
- Expired school invitation records are removed after a short 30-day administration and security window.
- Operational logs may be retained for security, abuse prevention, and diagnostics.
7. Data Sharing
We do not sell your personal data. We share data only when needed:
- With processors/service providers that run platform features (for example, Supabase, Google, OpenAI, Pixabay, hosting providers).
- With other users only for content you intentionally mark as public/community.
- During a live quiz, with the teacher hosting the quiz and with other participants to the limited extent needed for names/team labels and leaderboard scores.
- With authorised school administrators for school membership, allocation, security, and the limited activity information described in the school interface.
- When required by law, court order, or to protect rights, safety, and service integrity.
- As part of a merger, acquisition, or business transfer (with notice where required).
8. Cookies and Similar Technologies
- We use essential browser storage and auth/session mechanisms to keep the app working.
- Guest-mode saved items use browser localStorage.
- Cloudflare Turnstile may use strictly necessary security storage when a login or account form is opened.
- At the time of this policy update, we do not use advertising cookies, behavioural advertising, or third-party analytics trackers.
- Because the current storage is necessary for requested features or security rather than advertising or analytics, the site does not currently display a consent banner. We will add consent controls before introducing any optional tracking.
9. Your Rights and Choices
Depending on your location, you may have rights to access, correct, delete, or export your personal data, and to object/restrict certain processing.
- You can update profile information from the Profile page.
- You can delete saved content from your library.
- You can permanently delete your account and associated personal uploads from the Profile page.
- You can contact us via the Contact page for privacy requests.
- You may have the right to complain to your local data protection authority.
10. Student Data and School Use
A school is normally responsible for deciding why student and staff information is used. When we process that information on the school's instructions, we act as its processor under a data-processing agreement. Schools must provide their own required notices and establish an appropriate legal basis. Teachers should ask participants to use a first name, nickname, or team name and must not upload unnecessary or sensitive student information.
11. International Transfers
Some service providers may process data outside the EU/EEA. Where an adequacy decision does not cover the destination, we require an applicable transfer safeguard, such as the European Commission's Standard Contractual Clauses, and assess the provider's relevant protections. Information about the applicable safeguard can be requested through the Contact page.
12. Security
We use reasonable technical and organizational measures to protect data. No online service is perfectly secure, so we cannot guarantee absolute security. Please use strong passwords and avoid sharing account access.
13. Children
Account creation and teacher tools are intended for adults aged 18 or over. Students, including children, may use a teacher-started live quiz without creating an account. The join screen asks students to use a first name, nickname, or team name and explains what the class can see and that quiz participation records are removed after they reach 24 hours old. Schools and teachers remain responsible for providing any additional notice required for their educational use. If a child has created an account or unnecessary personal information has been submitted, contact us so it can be reviewed and removed.
14. Changes to This Policy
We may update this Privacy Policy as the service evolves or laws change. Updated versions will be posted here with a revised "Last Updated" date.
15. Contact
For privacy questions or data requests, email stuartscottai@gmail.com or use the Contact page on the site.
Friendly note: this document is for transparency and legal clarity; it is not legal advice to you.