Privacy

Privacy Policy

Our users are children, so this policy starts with them. It says exactly what we hold, why we hold it, and how you get rid of it.

Who we are

Write to support@elvora.school and a person will answer.

Everything we hold

This list is complete.

Parent
Email and password, to create and secure your account. Your name, if you give one. Language preference.
Child
A first name or nickname and a year group, both typed in by you. Progress — which activities were finished, and the answers tapped inside them.
Payment
Subscription records: plan, amount, dates, status. Card details stay with PayOS and Polar.
Technical
Server logs, the ordinary kind a browser generates when it asks for a page.

A child exists in our records as a first name, a year group, and a list of finished activities. Everything is answered by tapping, so there's nothing for a child to type, say, photograph or post. There's no chat, no messaging, and no profile anyone else can see.

Children

Every child profile is made by a parent on their own account. Signing up is always an adult's job.

Parents are in control. View, correct or delete a child's profile whenever you like, from your account or by writing to us. Deleting a profile deletes the progress with it.

A child's data does one job: showing you how they're getting on. It stays inside the service. It's never sold, never passed to advertising networks, never used to target ads, and never used to train AI models. That's a permanent commitment, not a setting.

If you think a child has reached us without a parent involved, tell us and we'll delete the record.

Why we hold it

To run the app you subscribed to, which is our contract with you. To take payment and keep accounts, which the law requires. To keep things secure and working, which is our legitimate interest. Where consent is the basis — as with a child's data — you can withdraw it whenever you like.

Who else sees it

Only the suppliers that make Elvora run: Supabase for the database and sign-in, Vercel for hosting, Cloudflare for delivering media, and PayOS and Polar for payments. Each sees only what its job needs.

How long we keep it

Account and child data lasts as long as your account is open, then thirty days, then it's gone. Payment records last as long as tax law says they must. Server logs last a short operational period. Every category has an end date.

Where it lives

Our suppliers work internationally, so your data may be handled outside your country. We pick suppliers that apply recognised safeguards to those transfers.

Your rights

Ask us for a copy of your data, ask us to fix it, ask us to delete it, object to how we use it, or ask us to pause it. Write to support@elvora.school and we'll answer. You can also raise it with your local data protection authority.

Security

Access needs a password, data is encrypted in transit, and lesson media is served through an access-controlled layer rather than a public bucket. Only named staff can reach production data.

Changes

If we change this policy materially, we'll email you before it takes effect.

Contact

Write to support@elvora.school about anything here, including seeing or deleting your data.

Effective 26 July 2026

Terms · Privacy · Home