Who we are

Staffroom is operated by Staffroom AI Ltd, a company registered in England and Wales. If you have any questions about this policy or how we handle your data, you can reach us at hello@staffroom-ai.com.

What data we collect

We collect only what we need to provide the service.

Account data: When you sign up, we collect your name and email address through our authentication provider, Clerk. This is used to manage your account and send you service-related emails.

Usage data: We collect anonymised analytics about how the product is used, such as which features are accessed and how often. This helps us improve Staffroom. We use Umami Analytics, which does not use cookies and does not track you across other websites.

Notes and content you enter: When you write pupil notes or generate reports, that content is stored securely and associated with your account. It is used only to provide the service to you.

Billing data: Payments are handled by Stripe. We do not store your card details. Stripe's own privacy policy governs how your payment information is handled.

Pupil data and AI processing

We take the protection of pupil data particularly seriously. Before any content containing pupil names reaches an AI model, those names are automatically replaced with anonymous identifiers. This means a pupil's name is never sent to OpenAI or any other AI provider.

Notes and content you enter about pupils are stored on our servers in the UK or EEA. They are used only to generate report content for you and are never shared with third parties, used for advertising, or used to train AI models.

Legal basis for processing

We process your personal data on the following legal bases under UK GDPR:

  • Contract: Processing your account data and content is necessary to provide the service you have signed up for.
  • Legitimate interests: Anonymised analytics help us improve the product. We have assessed that this processing does not override your rights and interests.
  • Consent: Where we send you marketing communications, we will ask for your consent first.

How long we keep your data

We keep your account and content data for as long as your account is active. If you delete your account, we will remove your personal data within 30 days. Aggregated, anonymised analytics data may be retained indefinitely as it cannot be linked to any individual.

Your rights

Under UK GDPR you have the right to access, correct, or delete your personal data. You also have the right to object to certain types of processing and to request that we restrict how we use your data. To exercise any of these rights, email us at hello@staffroom-ai.com and we will respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk if you believe we have not handled your data correctly.

Third-party services

Staffroom uses the following third-party services to operate:

  • Clerk — authentication and account management
  • Stripe — payment processing
  • OpenAI — AI text generation (pupil names are never sent)
  • Vercel — hosting and infrastructure
  • Umami — cookieless, anonymised analytics

Each of these providers has their own privacy policy. We choose providers that meet appropriate data protection standards and, where required, have data processing agreements in place with them.

Cookies

Staffroom uses only essential cookies required for authentication and session management. We do not use tracking cookies or advertising cookies. For more detail, see our Cookies page.

Changes to this policy

We may update this policy from time to time. If we make significant changes, we will notify you by email or through the product. The date at the top of this page reflects when it was last updated.