Privacy Policy

Version 1.4
Effective Date: 01/02/2025
Last Updated: 18/11/2025

Everybody Reads is committed to protecting the privacy, security and rights of teachers, students and schools. This policy explains how we collect, use and safeguard personal data and how we ensure the confidentiality, integrity and availability of our systems and information. It is designed to comply with UK GDPR, EU GDPR, COPPA and CCPA where applicable.

Schools act as Data Controllers for student data. Everybody Reads acts as a Data Processor on their behalf. For teacher accounts, Everybody Reads acts as the Data Controller.

1. Contact Details

Everybody Reads
58 Mill St
Kirkcaldy
Scotland
KY1 1SD

Email: info@everybodyreads.org.uk

2. Data We Collect

We follow strict data minimisation throughout the platform.

Teacher data

  • Name
  • School email address
  • Class or school affiliation
  • Platform activity needed to operate the service

Student data (pseudonymised)

Teachers create student profiles using labels such as initials or display names.

We do not collect:

  • Full names
  • Email addresses
  • Dates of birth
  • Home information
  • Special category data

Data linked to a pseudonymised student ID may include:

  • Reading age or band selected by a teacher
  • Generated story history
  • Comprehension responses and scores
  • Engagement and progress metrics

Platform usage data

  • Device type
  • Interactions within the platform
  • Stories generated and completed
  • Responses to comprehension tasks

This data is used only to deliver and improve our services. We do not use data for advertising or commercial resale.

3. Legal Basis for Processing

We process personal data under the following lawful bases:

  • Consent provided by teachers during account creation
  • Contract, where we provide access to schools under a subscription
  • Legitimate Interests needed to operate and improve the service
  • Legal compliance where required

Schools determine their own lawful basis when providing student data.

4. How We Use Data

We use data only for educational purposes, including:

  • Generating personalised stories and comprehension questions
  • Providing teachers with progress and insight dashboards
  • Operating core platform features
  • Improving accuracy and safety of AI outputs
  • Sending essential service communications to teachers

We do not use any personal data for profiling beyond assigning appropriate reading levels and content.

5. AI Content and Safety Controls

We use controlled, template-based prompts to generate literacy content. The system does not allow free chat or open-ended student input.

Safety layers include:

  • Fixed narrative structures
  • Age-banded vocabulary lists
  • Teacher-selected reading ages and themes
  • Banned word filters before generation
  • OpenAI moderation tools
  • Post-generation checks for reading age, tone and suitability
  • No pupil-to-pupil or pupil-to-AI messaging

The AI is purpose-built for children's reading. It does not have the ability to generate unrestricted content. All outputs follow age-appropriate vocabulary lists, fixed story structures and school-safe themes defined by our literacy guidelines.

Only anonymised data is sent to OpenAI. OpenAI does not train models on our data.

6. Sub Processors

We use a small number of GDPR-compliant sub processors to deliver the service:

  • Vercel for hosting and edge functions
  • Neon (AWS EU region) for database services
  • OpenAI API for story and question generation using anonymised data only
  • SendGrid (Twilio) for teacher onboarding and service emails

We do not sell or rent data and we do not share data with any independent Data Controllers.

7. Data Security

We apply technical and organisational measures to protect data including:

  • Encryption in transit and at rest
  • Role-based access control
  • Audit logging and monitoring
  • Pseudonymisation of all student data
  • Regular internal reviews of permissions and system behaviour
  • Controlled development and release processes
  • Independent sub processor security reviews

Only authorised personnel can access system-level data.

8. Information Security Framework

We maintain an internal security framework focusing on:

Risk management

Ongoing assessment of risks to confidentiality, integrity and availability. Controls are adapted as the platform evolves.

Secure development

Testing, code reviews where applicable, safety evaluation of prompts and moderation pipelines.

Monitoring

Tracking of unusual activity, system errors or potential misuse.

Access controls

Principle of least privilege applied across all systems.

Business continuity

Backups, disaster recovery processes and service resilience planning.

9. Incident Reporting and Response

We have a documented incident response process. If a security issue or content error occurs:

  • Immediate containment and removal of affected content
  • Internal investigation and root cause analysis
  • Notification to the school as soon as possible where required
  • Full transparency on findings and corrective steps
  • Support with parent communication if the school requests it
  • Review of filters and processes to prevent recurrence

10. International Transfers

Where data is processed outside the UK or EU, we use Standard Contractual Clauses and other approved safeguards.

11. Data Retention

  • Student data is retained only for the duration of the school subscription
  • Teacher accounts remain active until deletion is requested
  • Upon termination all associated data is deleted or anonymised
  • Schools may request erasure at any time

12. User Rights

Teachers and schools may request:

  • Access
  • Correction
  • Deletion
  • Restriction
  • Data portability
  • Objection

Requests can be submitted to info@everybodyreads.org.uk.

Schools may act on behalf of their students.

13. Third Party Links

Our platform may contain links to external resources. We are not responsible for their privacy practices and encourage users to review their policies.

14. Changes to this Policy

We may update this policy to reflect service improvements or regulatory changes. Significant updates will be communicated to schools or teachers through the platform or by email.

15. Acceptance

By using Everybody Reads, you agree to the practices described in this policy. If you do not agree, you should stop using the service.

16. Policy Review and Continuous Improvement

This Privacy Policy will be reviewed annually or whenever significant changes occur within our operations or IT infrastructure. Updates will be made to ensure the policy remains relevant and effective in addressing evolving security threats.

Privacy Policy | Everybody Reads