Security
What actually protects your account and your pupils’ data — described plainly, including the limits.
Last updated 18 September 2026
Authentication
Signing in to Kredits issues a Firebase Authentication session. Every server endpoint that touches your data verifies that session token on each request and derives your identity from it — not from anything the browser claims. There is no way to read or write another teacher’s data by changing a value in a URL.
Your PIN is stored as a hash. It is never stored in readable form, never logged, and cannot be recovered by us — only reset.
Encryption
- In transit — everything is served over HTTPS/TLS. There is no unencrypted route to the app.
- At rest — Google Cloud encrypts the underlying storage. On top of that, the two most sensitive values get their own encryption before they are written: Google Classroom access and refresh tokens, and your recovery email address, both using AES-256-GCM with a key held in Google Secret Manager and never stored alongside the data it protects.
Google Classroom access
Kredits requests six permissions and no others; each is listed with its purpose on the Privacy page. Three properties are worth stating explicitly, because they are the ones people ask about:
- The OAuth flow uses a single-use random
statevalue, so a link crafted by someone else cannot attach their Google account to your Kredits account, or yours to theirs. - Tokens are only ever used in response to an action you take in the app. There is no background job that reads your Classroom.
- Unlinking revokes the token with Google — it is not merely forgotten at our end — and deletes the stored tokens and pupil identifier mappings.
The drive.file permission is deliberately the narrow one: it reaches only files Kredits itself creates or that you explicitly choose. It cannot see the rest of your Drive.
Where data lives
The database is a Firebase Realtime Database in europe-west1 (Belgium). Server functions run in europe-west2 (London). Both are covered by Google Cloud’s physical and operational security; their compliance certifications are theirs, and are published by Google.
Your control over your data
- Export — Settings produces a machine-readable copy of everything held under your account.
- Delete — Settings deletes your account and its data. Deletion is immediate and is not a flag on a record that stays behind.
- Disconnect Google — revokes at Google and removes the tokens and mappings.
Development practices
- Server code is version-controlled, and the sensitive endpoints have an automated test suite that runs on every change.
- Secrets are held in Google Secret Manager, never in the codebase.
- Changes are deployed from version control rather than from a personal machine, so what is live matches what is reviewed.
What we do not claim
Kredits is a small product built by one teacher, and it is more useful to be straight about the boundaries than to imply a compliance programme that does not exist:
- We hold no security certification — no Cyber Essentials, no ISO 27001, no SOC 2. Where certifications matter, they are our cloud provider’s, not ours.
- There is no 24/7 staffed security team. Reports are handled by one person, promptly, but not instantly.
- We have not had an independent penetration test.
Reporting a vulnerability
If you think you have found a security problem, email hello@kredits.co.uk. Please include enough detail to reproduce it, and give us a reasonable opportunity to fix it before disclosing it publicly. We will acknowledge your report within 3 working days.
We will not pursue legal action against anyone who reports a genuine issue in good faith, who does not access or modify other people’s data, and who does not degrade the service for others.
If something goes wrong
If a breach affects pupil data, your school is the controller and the duty to notify the ICO sits with the school. We will tell you without undue delay, and in any event within 48 hours of becoming aware, with enough detail for the school to meet its own obligations. This commitment is set out formally in the Data Processing Agreement.