Back to ElevenKey
Beta privacy notice

Parent-owned data. No public child profiles.

This notice describes the information used by the current ElevenKey public beta. It will be updated before any paid launch.

Parent accounts

Authentication uses the parent’s email address and secure account identifiers. Children do not need their own email address.

Child learning records

ElevenKey stores a child display name, optional year group, answers, correctness, timing, retry status, reading or written responses, mock results and learning plans.

Goals and tutor records

Parents may add target schools, exam routes and dates. Tutors may store organisation, group, student-reference and assignment information.

Signed-out practice

Guest practice uses a private anonymous session identifier to provide unlimited, untracked answers from 25% of the verified question bank during public beta. The former five-answer control is inactive, and ElevenKey does not use an IP address to identify guest learners.

Why the information is used

  • To provide practice, feedback, retries and progress views.
  • To personalise daily missions and target-subject coverage.
  • To preserve completed assessments and coursework records.
  • To protect question quality and diagnose technical problems.
  • To operate tutor groups, invitations and School Pass requests when used.

Access and separation

Database row-level security is designed so parents can access only their own children and attempts, and tutors can access only their own workspace records. Question publishing and private editorial records are not open for normal browser writes.

Sharing and selling

ElevenKey does not sell child data and does not provide public child profiles, advertising audiences or social leaderboards. The beta uses Supabase for authentication and database hosting, and the ElevenKey site is hosted through OpenAI Sites. These providers process data only to operate the service under their own security and contractual controls.

Retention, access and deletion

Learning records are kept while the beta account remains active so progress and assessment evidence remain available. Parents may request access, correction or account deletion through the beta support channel. A final public-launch policy will publish defined retention periods and the operator’s formal data-controller contact before paid access begins.

Current limitation

This is a transparent beta notice, not a substitute for the final UK legal documentation. The public launch must add the legal operator’s name, postal address, privacy contact, lawful-basis schedule, international-transfer details, retention schedule and ICO information where applicable.