Security

What actually protects your account and your pupils’ data — described plainly, including the limits.

Last updated 18 September 2026

Authentication

Signing in to Kredits issues a Firebase Authentication session. Every server endpoint that touches your data verifies that session token on each request and derives your identity from it — not from anything the browser claims. There is no way to read or write another teacher’s data by changing a value in a URL.

Your PIN is stored as a hash. It is never stored in readable form, never logged, and cannot be recovered by us — only reset.

Encryption

Google Classroom access

Kredits requests six permissions and no others; each is listed with its purpose on the Privacy page. Three properties are worth stating explicitly, because they are the ones people ask about:

The drive.file permission is deliberately the narrow one: it reaches only files Kredits itself creates or that you explicitly choose. It cannot see the rest of your Drive.

Where data lives

The database is a Firebase Realtime Database in europe-west1 (Belgium). Server functions run in europe-west2 (London). Both are covered by Google Cloud’s physical and operational security; their compliance certifications are theirs, and are published by Google.

Your control over your data

Development practices

What we do not claim

Kredits is a small product built by one teacher, and it is more useful to be straight about the boundaries than to imply a compliance programme that does not exist:

Reporting a vulnerability

If you think you have found a security problem, email hello@kredits.co.uk. Please include enough detail to reproduce it, and give us a reasonable opportunity to fix it before disclosing it publicly. We will acknowledge your report within 3 working days.

We will not pursue legal action against anyone who reports a genuine issue in good faith, who does not access or modify other people’s data, and who does not degrade the service for others.

If something goes wrong

If a breach affects pupil data, your school is the controller and the duty to notify the ICO sits with the school. We will tell you without undue delay, and in any event within 48 hours of becoming aware, with enough detail for the school to meet its own obligations. This commitment is set out formally in the Data Processing Agreement.