Privacy Policy
Kredits is a set of classroom tools built by a practising teacher. This policy explains what it stores, why, where, and what you can do about it.
Last updated 18 September 2026 · Applies to kredits.co.uk and the Kredits apps
1. Who is responsible for your data
Kredits is operated by Kredits (“Kredits”, “we”).
Two different roles apply, and which one applies depends on whose data it is:
| Data | Our role | What that means |
|---|---|---|
| Your teacher account — teacher code, PIN, optional recovery email, plan tier, linked Google account address | Controller | We decide why and how this is processed, and this policy is the notice for it. |
| Pupil data — names, class lists, seating positions, points, marks, group history | Processor | Your school is the controller. We act on your instructions, given through the app, under the terms of our Data Processing Agreement. |
This split matters. We do not decide what pupil data goes into Kredits, we do not use it for our own purposes, and we never use it to train machine-learning models or to advertise.
2. Teacher account data
When you create an account we store a teacher code you choose, a PIN, and — only if you opt in to account recovery — an email address. The PIN is stored as a hash, never in readable form. A recovery email is encrypted before storage using AES-256-GCM.
We use this only to sign you in, to keep your data separate from other teachers’, and, if you have opted in, to send you a recovery code. We do not send marketing email.
Lawful basis: performance of a contract (providing the account you asked for). For the optional recovery email, consent, which you can withdraw in Settings at any time.
3. Pupil data
Kredits stores what you put into it: pupil names, the classes they belong to, card or seat numbers, points awarded in the Scoreboard, marks in the Markbook, seating layouts, grouping history, and — if you link Google Classroom — the mapping between a pupil in Kredits and their Google Classroom identifier.
It is designed for ordinary classroom information. Do not put special category data into Kredits — SEN details, medical information, safeguarding notes, free school meal status or similar. There is no field intended for it and no additional protection applied to it.
Lawful basis: your school’s, as controller — normally public task or legitimate interests. We process it only on your school’s documented instructions.
4. Google Classroom
Linking Google Classroom is entirely optional and Kredits works fully without it. If you link it, we ask Google for these permissions and nothing else:
| Permission | Why Kredits needs it |
|---|---|
classroom.courses.readonly | List your courses so you can choose which to import. |
classroom.rosters.readonly | Import pupil names into a class instead of typing them. |
classroom.coursework.students | Read assignments and marks into the Markbook, and write marks back when you choose to. |
classroom.courseworkmaterials | Read the materials attached to an assignment. |
drive.file | Open only the files Kredits itself creates or you explicitly pick. It gives no access to the rest of your Drive. |
userinfo.email | Show which Google account is linked, so you can tell whether it is the right one. |
The access and refresh tokens Google issues are encrypted with AES-256-GCM before being stored. They are used only to make the Classroom requests described above, in response to something you do in the app.
Limited Use. Kredits’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer this data to others except as necessary to provide the features above, do not use it for advertising, and do not allow humans to read it except with your explicit permission, for security purposes, to comply with applicable law, or where the data is aggregated and anonymised.
You can disconnect at any time in Settings. Unlinking revokes the token with Google and deletes the stored tokens and the Classroom identifier mappings.
5. Where your data is stored
Kredits runs on Google Cloud and Firebase:
- The database is a Firebase Realtime Database in europe-west1 (Belgium).
- Server functions run in europe-west2 (London).
Data is therefore held in the EU and the UK. Where our providers transfer data outside the UK or EEA, they do so under the transfer mechanisms in their own terms, including the UK International Data Transfer Addendum and EU Standard Contractual Clauses.
6. Who else is involved
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Ireland Limited — Firebase, Google Cloud | Hosting, database, server functions, authentication | EU / UK |
| Twilio SendGrid | Sending account recovery codes, only if you opt in to a recovery email | United States |
We do not sell data, and we do not share it with anyone else.
7. How long we keep it
Your data stays for as long as your account exists. You can delete individual classes and pupils at any time in the app, and you can delete your whole account in Settings, which removes your data immediately.
We do not automatically delete inactive accounts — a teacher who does not open Kredits over a long holiday should not come back to an empty class list. Deletion is always yours to trigger. Once you delete, the data is removed from the live database straight away; our hosting provider keeps its own backups and those rotate on its standard cycle.
8. Your rights
Under UK GDPR you have the right to access your data, correct it, delete it, restrict or object to processing, and receive it in a portable form. Two of these are built into the app:
- Export — Settings gives you a machine-readable copy of everything held under your account.
- Delete — Settings deletes your account and its data.
For anything else, contact hello@kredits.co.uk. We respond within one month.
If pupil data is involved, the request usually belongs to the school as controller — ask your school’s data protection lead, who can contact us.
You can complain to the Information Commissioner’s Office at ico.org.uk.
9. Security
Our security measures are described on the Security page.
10. Children
Kredits is for teachers. Pupils do not have accounts and cannot sign in. Pupil data reaches Kredits only because a teacher puts it there or imports it from Google Classroom.
11. Changes
If this policy changes materially we will say so in the app before the change takes effect.