Privacy Policy
Who runs SoloCogs: SoloCogs is the brand name for the online learning platform operated by Portsdown Tuition, a sole-trader business based in Portsmouth, England. Throughout this policy, "Portsdown Tuition", "we", "us", and "our" refer to the operator and legal entity. "SoloCogs" refers to the platform, service, and brand we provide to families, schools, and tutors. The data controller for personal data processed through SoloCogs is Portsdown Tuition.
Contact: hello@solocogs.co.uk
1. Who We Are
Data Controller: Portsdown Tuition (sole trader), trading as SoloCogs, Portsmouth, England.
Postal service address: Portsdown Tuition, c/o SoloCogs Data Requests, PO Box available on request via hello@solocogs.co.uk. We do not publish a residential home address (sole-trader business), but a written service address for legal correspondence will be provided within one working day of request.
ICO Registration: ZB916444 - searchable on the ICO public register.
Data Protection Officer: Portsdown Tuition is a sole-trader operation whose scale does not trigger the mandatory DPO appointment under UK GDPR Article 37(1). Data protection responsibilities are held directly by the operator (Jazz McCullough, qualified teacher and safeguarding-trained). Contact all data protection queries via hello@solocogs.co.uk. If our scale ever crosses the Article 37 threshold, we will appoint and publish a named DPO.
If you have any questions about how we handle your personal data, please contact us via the contact page.
2. What Data We Collect
Account holders (parents/carers)
- First name, last name, email address
- Account credentials (password stored as a secure hash - never in plain text)
- Optional contact phone number (used only for safeguarding contact where a child on the account has an active safeguarding concern; otherwise unused). Stored securely in Supabase Auth user metadata.
- Postal address, city and postcode (billing address; used for invoicing schools/tutors and for VAT records).
- Subscription status and billing tier
How we use your email address: we use it for (1) account login + password reset; (2) essential service emails such as billing receipts, subscription renewals, and safeguarding referrals where applicable; (3) limited service announcements about platform changes that materially affect you. We do NOT use your email for marketing without explicit opt-in, do not sell it, and do not share it with third parties except the strictly-necessary processors listed in section 5.
Student accounts
- First name, year group, generated anonymous username
- Date of birth - given by the parent / carer (or school) when the account is created. We use it to work out the right year group and science level, to apply age-appropriate defaults, and to check eligibility for time-limited founding offers. We do not display it to other users.
- Learning progress data (quiz scores, resource completion, confidence ratings)
- Emotional wellbeing check-in data (Zones of Regulation entries, including any notes left voluntarily)
- Optional recovery email - only if a parent / carer or school admin explicitly opts in (see the section below)
- Optional SEND / demographic flags - only if a parent / carer, tutor, or school admin explicitly adds them (see the "SEND and demographic flags" section below)
SEND and demographic flags (optional, special-category data)
Where a parent / carer, tutor, or school data contact chooses to add them, we store demographic and SEND flags against the student's account. These are treated as special-category data under UK GDPR Article 9 and are handled to a higher standard than ordinary account data.
The flags we can store are:
- SEND status - e.g. SEN-K (SEN-Support), EHCP (Education, Health and Care Plan), or "no SEND recorded". Free-text SENCo notes (up to a length cap) where added by the school data contact.
- English as an Additional Language (EAL)
- Pupil Premium (PP)
- Looked-After Child (LAC) / Young Carer (YC)
Purpose: to enable SoloCogs to auto-apply a sensible set of accessibility defaults (font, colour overlay, plain-language, longer-timing) so a SEND student does not have to configure the platform every session, and so tutors / parents / SENCos can see focused progress and adjust support. The flags are never used for advertising, profiling for commercial decisions, or gating content.
Lawful basis: UK GDPR Article 6(1)(b) (contract performance - the accessibility outcome you signed up for) plus the Article 9(2)(g) substantial-public-interest condition under Schedule 1 Part 2 of the Data Protection Act 2018 (safeguarding + support of children).
Default state: off. No SEND / demographic flag is stored unless explicitly added. Students, parents, tutors, and school data contacts can view, correct or clear the flags at any time via the account settings or by contacting us. Removing the flag also removes its knock-on accessibility default (though the student can keep any accessibility toggle they've enabled on their own).
Retention: flags are deleted when the account is deleted, or immediately when cleared. School-rostered flags follow the school's own retention arrangement in its DPA with us.
Student password recovery email (optional)
To let a student reset their own password without waiting for an adult, a parent / carer or school admin can add a recovery email address for that specific student. This is usually the child's own school email or a family-shared address. It is opt-in, off by default, and can be cleared at any time from the parent-settings page on SoloCogs.
Purpose limitation - what we use it for:
- Sending a one-time confirmation email so we know the address is real and the right person controls it.
- If the student forgets their password and self-recovery is on, sending them a password reset link.
- Sending the parent / carer a notification email each time a reset is requested.
What we never use it for:
- Marketing of any kind. We never email the recovery address with offers, newsletters, or anything outside the three purposes above.
- Profiling, advertising, or analytics. The address is not shared with Google Analytics or any third party.
- Sharing or selling. We do not pass the address to any other organisation.
Retention: the recovery email is stored only as long as it is needed for the purpose above. It is deleted within 30 days of:
- The parent / carer or admin clearing the field in parent-settings, OR
- The student account being deleted, OR
- The parent / carer turning the recovery toggle off without setting a new address.
Lawful basis: contract performance (article 6(1)(b) UK GDPR) - the recovery email exists only because the parent / carer or school admin chose to set it up to fulfil our agreed service of getting their child back into their account quickly.
All users
- Login timestamps and session data
- Browser-stored preferences (background colour, mute settings) held in your browser's local storage - not on our servers
Analytics data - only if you accept the cookie banner
If you accept analytics via the cookie banner, we use Google Analytics 4 (loaded via Google Tag Manager) to collect anonymised usage signals - which pages get viewed, where users come from, what device or browser is used, and which features get clicked. We do not pass your name, email, account ID, or any other personally identifying field to Google Analytics. The data is held by Google as an independent processor and is restricted to anonymised page-view and event-level signals.
If you reject the cookie banner, no analytics cookies are set and no analytics events are sent. See the Cookie Policy for the full list of GA4 cookies.
Payment information
We never see or store your card details. All payment processing is handled by Stripe (Stripe Payments Europe Ltd.), a separately accredited payment provider under PCI DSS. Stripe acts as an independent data controller for the financial data you give them. When you pay, your browser hands the payment information directly to Stripe; we receive only a confirmation that the payment succeeded plus the subscription tier you bought - no card number, no expiry date, no CVV. You can read Stripe's own privacy notice at stripe.com/privacy.
If Stripe sends you transactional emails (receipts, dispute notifications, etc.) those are sent by Stripe under their own terms, not by us.
3. How We Use Your Data
We collect and process personal data only for the following purposes:
- To provide the service - account management, access to resources and tools, progress tracking
- To safeguard students - wellbeing check-ins and flagged entries are reviewed by the DSL to identify students who may need support
- To improve the platform - aggregated, anonymised usage patterns may inform future development
- To communicate with you - account-related emails (password reset, subscription updates). We do not send marketing emails without your explicit consent.
What we infer about you
To deliver the learning experience, SoloCogs derives a number of inferences from your data - things we work out about you that you did not type in. Per the ICO Children's Code (standard 12 on profiling), we list these here so you know exactly what we calculate:
- Mastery level per sub-unit - whether your recent answers suggest you have grasped a topic, are still building it, or need to revisit it. Used to recommend what to study next.
- Common misconceptions - patterns in your wrong answers that suggest a specific misunderstanding (e.g. confusing mitosis and meiosis). Used so the platform can offer a targeted explanation, and so a tutor or parent can see what to focus on.
- Confidence vs accuracy - you rate how confident you feel before each answer; we compare that to whether the answer was right. This produces a "calibration" pattern that helps surface where you are unsure even when you got the answer right.
- Engagement signals - daily login streak, time spent per session. Used to award XP and to alert a parent if a student stops engaging for a sustained period.
What these inferences are NEVER used for: targeted advertising; profiling for commercial decisions; gating access to content (you can always study anything you want, regardless of your "mastery"); sharing with third parties for any purpose other than the parent / tutor / school relationship the account was set up under; training third-party AI models.
Who can see your inferences: you, the parent on your account, any tutor your parent has invited, and a school's nominated data contact if your account was rostered from a school via Wonde. Nobody else, including other SoloCogs users.
Per UK GDPR Article 22, no decision with legal or similarly significant effects is made about you on a solely automated basis - all inferences are informational.
4. Legal Basis for Processing
- Contract - processing necessary to deliver the service you have signed up for (UK GDPR Art. 6(1)(b))
- Consent - analytics cookies and any optional marketing communications, only after you opt in via the cookie banner (UK GDPR Art. 6(1)(a)). You can withdraw consent at any time via the "Cookie settings" link in the footer. We do not currently send marketing emails; if that changes we will add a dedicated marketing-preference toggle to the parent settings.
- Legitimate interests - platform security monitoring and the fundamental operation of strictly-necessary functions (UK GDPR Art. 6(1)(f))
- Legal obligation - safeguarding records and referrals where required by law (UK GDPR Art. 6(1)(c))
- Vital interests - where processing is necessary to protect a child's life or safety (UK GDPR Art. 6(1)(d))
Where we process special category data (including data about a child's health or wellbeing), we rely on the substantial public interest condition under Schedule 1 of the Data Protection Act 2018, specifically in relation to safeguarding of children.
5. Who We Share Data With
We do not sell, rent, or trade personal data. We share data only with the following sub-processors, each under a written data processing agreement as required by UK GDPR Article 28. The full, dated, versioned list lives at policy-sub-processors.html for procurement records.
- Supabase Inc. - our secure database and authentication provider. Data hosted in the UK (London, eu-west-2 AWS region). Supabase Data Processing Addendum signed via Dashboard → Organization → Legal Documents in June 2026. Supabase privacy notice.
- Cloudflare, Inc. - our website hosting, content delivery network (CDN), and DDoS protection. Cloudflare handles connection-level metadata (IP address, request headers) but does not see personal data inside requests as the application layer is encrypted. Cloudflare DPA signed via Dashboard → Manage Account → Configurations. Cloudflare privacy notice.
- Google LLC (Google Cloud + Gemini API) - used for AI-assisted generation of teacher-side educational illustrations (no student data is ever sent to Google). Cloud Data Processing Addendum incorporated by reference into the Google Cloud Terms of Service, accepted at the time our Google Cloud project was created (June 2026). DPA text at cloud.google.com/terms/data-processing-addendum.
- Google LLC (Tag Manager) - manages which client-side tags fire and gates them on consent. No analytics data is sent until the cookie banner is accepted.
- Google LLC (Analytics) - only if you accept analytics via the cookie banner. Anonymised page-view and event signals only (no name, email, or account ID), with IP truncation enabled. Google acts as an independent data controller for the cookies it sets in your browser.
- Stripe Payments Europe Ltd. - our sole payment provider for both family and school / MAT / LA subscriptions (via Stripe Checkout). They receive the data they need to take payment (card details, transaction value, billing email + address). They do NOT receive any child's data or learning data. They act as an independent data controller. Stripe privacy notice.
- Statutory agencies - police, social services, NSPCC, ICO - where we have a safeguarding obligation or legal requirement to share. Not a routine sub-processor; engaged only when triggered by an incident or legal request.
- jsDelivr (Prospect One) + Google Fonts - public content-delivery networks that serve the Supabase JavaScript SDK and the Atkinson Hyperlegible / Lexend web fonts to your browser. They only ever see the request itself (URL + connection metadata) and never any user data or account content. If you would prefer not to load these, block them in your browser or use a blocker extension - the site remains fully functional without them (default fonts + a self-hosted SDK fallback).
Wonde (UK MIS aggregator) will be added when school-roster sync goes live; affected customers will be notified at least 30 days in advance.
6. Data Retention
- Active accounts: Data is retained for the duration of the account
- Closed accounts: Non-safeguarding data is deleted within 90 days of account closure
- Safeguarding records: Retained for a minimum of 7 years, or until the student reaches age 25, whichever is later - in line with statutory guidance
- Learning data: Retained for up to 3 years after last login to allow re-engagement
- Archived learning records: A student can choose to start afresh - resetting their progress, XP and rewards so a unit can be worked through again from the beginning. When they do, a read-only snapshot of what they had achieved is kept in their account so they can still look back at it. It cannot be restored or used to change their current progress. It is covered by the same 3-year rule as the rest of their learning data, is included if you ask for a copy of your data, and is deleted when the account is deleted.
- Student recovery email (optional): Deleted within 30 days of being cleared in parent-settings, the recovery toggle being turned off, or the student account being closed. See the Student password recovery email section above for what it is used for.
- Password reset audit log: The internal log of password reset attempts (who requested, when, succeeded) is retained for 1 year for safeguarding + abuse-detection purposes. Rate-limit and audit only; not used for marketing or profiling.
7. Your Rights Under UK GDPR
You have the right to:
- Access - request a copy of the personal data we hold about you
- Rectification - ask us to correct inaccurate data
- Erasure - ask us to delete your data (subject to legal retention obligations)
- Restriction - ask us to limit how we use your data
- Portability - receive your data in a structured, machine-readable format
- Object - object to processing based on legitimate interests
To exercise any of these rights, please contact us via the contact page. We will respond within one calendar month of your request, in line with UK GDPR Article 12(3). If your request is complex or you make several requests, we may extend this by up to two further months and will tell you within the first month if we need to do so, and why.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk or by calling 0303 123 1113.
8. Data Security
We take appropriate technical and organisational measures to protect personal data, including:
- All data in transit encrypted via HTTPS/TLS
- Database access controlled via Row-Level Security policies
- Passwords never stored in plain text - hashed by Supabase Auth
- Access to student safeguarding data restricted to the DSL only
9. Children's Data
A significant proportion of our users are under 18. We follow the ICO's Age-Appropriate Design Code and take additional care with children's data:
- Student accounts are created by or with the consent of a parent / carer, or under a school-roster agreement.
- Students do not need to provide a real email address - accounts use an internal identifier.
- We do not use children's data for advertising or profiling.
- Wellbeing data is used only for pastoral and safeguarding purposes.
- High-privacy defaults (AADC Standard 7): every child's account launches with the strictest privacy settings switched on. Analytics is off unless the account-holding adult opts in. Learning inferences are visible only to the child, the account-holding parent, an invited tutor, and (where the account is rostered from a school) the school's nominated data contact - nobody else can see them by default.
- Profiling off unless justified (AADC Standard 12): the inferences described in section 3 are informational only, produced to help the child study more effectively. They never drive an automated decision with legal or similarly significant effect (UK GDPR Article 22).
- The best interests of the child come first (AADC Standard 1): where a decision about this service affects a child - what we collect, what we show, what we keep - we weigh the child's interests above our commercial ones, and we record that reasoning in our Data Protection Impact Assessment.
- How we establish age (AADC Standard 3): a date of birth is given by the account-holding adult when a student account is created, and we use it to set the year group and to apply age-appropriate defaults. We do not ask children to self-declare their age, and we do not use profiling or estimation to guess it. Because accounts are created by an adult rather than by the child, we apply the protections in this section to every student account regardless of age.
- What a parent or carer can see (AADC Standard 10): the adult who holds the account can see the child's progress, quiz results, the topics flagged for revision, required-practical evidence and whether the child has been active. They cannot see the child's individual written answers or their Zones of Regulation notes. We tell the child, in the plain-words summary above, what the adults connected to their account can see - a child should never be monitored without knowing it.
- We do not collect location data (AADC Standard 9): SoloCogs has no geolocation feature. We do not request device location, we do not track it, and nothing in the service changes based on where a child is.
- How we treat streaks, XP and reminders (AADC Standard 13): SoloCogs uses XP, daily streaks and progress badges. They are deliberately tied to effort and returning - turning up, trying, finishing a section - and never to time spent on the site, so nothing rewards a child for staying longer. There are no infinite scrolls, no autoplay and no notifications designed to pull a child back. Two optional practice games (Quick Fire and Hex Path) do use an on-screen timer, because beating the clock is the point of that particular game - a child chooses to start them, they are never part of ordinary lesson work, and nothing is lost by not playing them. No points or progress are ever taken away for stopping, and no message tells a child off for a gap. A missed day first spends a banked "streak shield" so the streak survives - a deliberate choice for children whose attendance is uneven, including those with ADHD or who are educated outside school. If no shield is banked the streak resets to one, and nothing else changes.
- Where a child's account was created by a parent / carer or a school (Article 14): the personal data we hold about that child was obtained from the account-holding adult or from the school's MIS via a school-roster agreement, not directly from the child. We tell the child what data exists about them in the plain-words summary above, and both the child and the adult can access, correct or delete it via the routes in Section 7.
9.1 If you are under 18 and want to access or remove your data
You still have all the rights listed in Section 7 above - but the way you exercise them is a little different to make sure you're properly supported and that any safeguarding considerations are taken into account.
First step - speak to a trusted adult. If you have questions about your data, want to see what we hold (a Subject Access Request), or want to ask for it to be deleted, please speak to one of the following first:
- The parent, carer or guardian who holds your account - they can submit the request on your behalf through their Cognition Overview, or by contacting us directly.
- Your school's data protection lead if your account is set up through a school - they have a process for handling data requests for students.
If you would prefer to contact us yourself, you absolutely can - email hello@solocogs.co.uk and we'll work with you and your parent/carer to make sure the request is handled properly.
9.2 Why we may keep some data even if you ask us to delete it
In some circumstances, the law requires (or strongly encourages) us to keep certain data even if you ask for it to be erased. The main reasons are:
- Safeguarding - if a wellbeing check-in or referral has been made to a statutory agency, we are required to keep that record for a minimum of 7 years, or until the student turns 25, whichever is later. This is in line with the Department for Education's statutory guidance on safeguarding.
- Educational records - where data forms part of a school's educational record, the school is the data controller for that information and may have its own retention obligations.
- Legal disputes or unresolved complaints - data may need to be retained while a dispute or complaint is open.
Where we cannot delete data for one of the reasons above, we will tell you which reason applies and how long we expect to keep it.
9.3 If you are 18 or over
You can exercise any of your data rights directly. Email hello@solocogs.co.uk and we will respond within one calendar month as set out in Section 7.
10. Cookies and Local Storage
SoloCogs uses strictly-necessary cookies (for sign-in and security), browser local storage (for preferences and progress), and - only if you opt in via the cookie banner - Google Analytics 4 cookies for anonymised usage analytics. See our separate Cookie Policy for the full list of cookies, what each one does, and how to change your consent decision.
11. Changes to This Policy
We will notify registered users of any material changes to this policy via email and by updating the version number and review date above. Continued use of the platform after notification constitutes acceptance of the updated policy.
Data protection questions? Contact us via the contact page. For complaints, you can also contact the ICO at ico.org.uk.