Privacy notice

Last reviewed: September 2026 · This notice describes how Praxis actually works today, not how we intend it to work.
Praxis is in beta and is run by one person. Before it takes payment it will move to a company and this notice will be checked by a solicitor; if either changes who is responsible for your data, we will tell you rather than quietly editing this page.

Who we are

Praxis is a planning and evidence tool for trainee and early career teachers. The data controller is Cole Poppleton, an individual based in England. You can reach us about anything in this notice at hello@praxistool.online.

If you think we have handled your data badly you can complain to us first, and to the Information Commissioner’s Office at ico.org.uk either way.

The short version

  • We store what you write (your plans, reflections, review notes and uploaded files) because that record is the product.
  • We do not keep records about pupils. Praxis has no register, no safeguarding log and no per-pupil data; anything about a class is at class level.
  • We never store audio or raw transcripts from voice capture.
  • We do not send what you write to advertisers, and we do not sell it.
  • You can export everything as JSON at any time, on any plan, free. You can delete your account and we really do erase it.

What we collect, and why

Account details. Your email address and, if you give them, your first and last name. These come from our authentication provider and are used to sign you in and address emails to you. Lawful basis: performance of a contract.

What you create. Lesson plans and activities, reflections, progress reviews and their actions, comments, syllabuses and objectives, timetable structure, classes, and any files you upload. This is the service. Lawful basis: performance of a contract.

Free text is treated as sensitive. We assume anything you type may contain personal or professional detail, so it is encrypted at rest, access-controlled per user, and never used as an example or for training anyone’s model.

Usage events. A deliberately named set of events, such as “plan created”, “coverage viewed”, “reflection logged”, so we can see which parts of the product work. These carry counts, identifiers and short labels only: no free text you have written is ever attached to an analytics event. Lawful basis: legitimate interests (improving the service).

AI generation logs. When you generate something we record which feature was used, the model, token counts, cost and how long it took, so we can keep the service affordable and spot failures. We do not store the text of your prompts or the generated output in those logs. Lawful basis: legitimate interests.

Voice capture

Where Praxis offers voice capture, transcription happens in your browser. The audio never reaches our servers and we never store it. The live transcript exists only in the page in front of you; it is sent to be turned into structured items and is not saved or logged in the process. Only the items you confirm are written down.

Meeting capture needs both people to agree before it starts, a visible recording indicator runs throughout, and either person can decline; typed notes lose nothing. Revoking a session deletes everything derived from it. The extraction step removes names and drops anything that looks like safeguarding, health or third-party detail, and tells you how much it dropped.

Children's data

Praxis is for the adult professional using it. We do not knowingly collect personal data about children, and there is no feature for storing it: no register, no pupil records, no safeguarding module, no per-pupil notes. Where a feature touches a class it stays at class level (for example, “homework completion 72%”).

You should not type a pupil’s name or identifying detail into Praxis. Some fields warn you when they think you have. If you do it anyway, that text is yours to remove, and deleting the item removes it.

Who else processes it

We use a small number of providers, each under a data processing agreement, each doing one job:

  • Clerk: sign-in and account management. Holds your email, name and session.
  • Supabase: the database and file storage holding everything you create. Hosted in the European Union (Dublin, Ireland), where the application’s own functions also run.
  • Vercel: runs the application and serves the pages.
  • Anthropic: the AI model behind generation features. Prompts are sent to produce your result and are not used to train their models.
  • Resend: sends transactional email (mentor invitations, the weekly digest).
  • Vercel Analytics: cookieless, anonymous page and event counts (no cross-site tracking, no advertising identifiers). Sentry receives error reports when enabled, with no user content attached.
  • Inngest: runs scheduled jobs such as the weekly digest and the retention purge.

Some of these operate outside the UK. Where they do, the transfer is covered by the safeguards in that provider’s data processing agreement: UK adequacy regulations (including the UK extension to the EU-US Data Privacy Framework) or the UK International Data Transfer Addendum.

How long we keep it

  • Your record (reflections, plans, reviews): kept until you delete it or close your account. It is evidence you may need years later, so we do not expire it for you.
  • Incidental free text: cover reasons, upgrade notes, and the email addresses on revoked invitations, deleted automatically after 90 days.
  • Read notifications: removed after 30 days.
  • Audit records of administrative actions, including proof that a deletion was carried out, are kept as our record that we did what we said.

Your rights

Under UK GDPR you can ask for a copy of your data, correct it, delete it, restrict or object to how we use it, and take it elsewhere. Two of these are buttons rather than requests:

  • Export: a complete JSON copy, from your account page, on any plan including free.
  • Deletion: closing your account erases your data from our database first, then closes your sign-in. If any part of the erasure fails, we stop and tell you rather than leaving you half-deleted.

One deliberate exception. If you wrote feedback on someone else’s lesson or review, as a mentor, say, that comment stays with them when you leave. It is their evidence of having been observed, and removing it would take evidence away from a person who did not ask for anything. Your identity is severed from it: they see “former collaborator”, not your name. If you want such a comment removed as well, ask the person whose record it sits on, or contact us.

For anything else, email hello@praxistool.online. We reply within one month, usually much sooner.

Research, and your choice

We would like to learn what actually helps teachers develop. Any such analysis is off by default, aggregate-only, and never includes anything individual. You turn it on yourself in Settings, and you can turn it off again at any time. Nothing happens unless you opt in.

Cookies

We use cookies that are necessary to keep you signed in, and product analytics as described above. We do not use advertising cookies and we do not share cookie data with ad networks.

Changes

If we change how we handle your data we will update this notice and, where the change is significant, tell you in the product or by email rather than quietly editing this page.

See also our terms of use and accessibility statement.