Data Protection
Classfolio is designed to help schools use digital learning and artificial intelligence safely, transparently and responsibly.
Classfolio gives teachers powerful tools for creating lessons, assessments, assignments and learning resources while keeping schools in control of their data.
Data Controller
Under UK GDPR, there is an important distinction between the school as Data Controller and Classfolio as Data Processor.
Schools remain the Data Controller
Your school decides how Classfolio is used, which classes and students are created, and how teaching content is organised.
Classfolio acts as Data Processor
Classfolio processes data only to deliver the educational service your school has configured. We act on your instructions.
Schools own their educational data
All lessons, assessments, student work, and resources created in Classfolio belong to your school. You can request exports or deletion at any time.
Data Processing
Classfolio processes personal data solely to deliver educational functionality. Below is a clear breakdown of what is processed and for whom.
Purpose of processing
Data is used solely to deliver educational functionality, including:
Classfolio does not sell school, teacher or student data.
AI & Privacy
Classfolio does not use school, teacher or student data to train AI models.
Classfolio is designed to keep teachers in control. AI helps create content faster, but teachers decide what students see.
Student Privacy
Classfolio is built around a layered access model. Students can only see their own work. Teachers can only access students they teach. Administrative access is restricted by role.
Classfolio supports a pseudonymous identity model. Display names — such as “Smith, J” or a school-managed alias — help minimise unnecessary personal data exposure while still allowing teachers to identify students appropriately within their school environment.
Classfolio does not claim to anonymise students. Display names are linked to authenticated identities.
Microsoft and Google sign-in
All users sign in using Microsoft or Google accounts. Classfolio does not manage user passwords — authentication is delegated entirely to Microsoft or Google identity providers.
Role-based permissions
Students only access their own information. Teachers access only the students they teach. Separate administrative roles exist for school-level management.
Data access boundaries
Firestore security rules enforce that students cannot read other students' data, results, or submissions — regardless of class membership.
Important Commitments
Many schools are understandably concerned about AI products that record classrooms or use student data without consent. Here is what Classfolio explicitly does not do.
Sell student data
Student data is never sold to any third party for any purpose.
Use student data for advertising
Classfolio contains no advertising. Student data is not used for ad targeting.
Train AI models on school data
School, teacher and student data is not used to train or fine-tune AI models.
Share school data with unrelated third parties
Data is only shared with subprocessors required to deliver the service.
Replace teacher professional judgement
All AI-generated content is a suggestion. Teachers review, edit and approve before students see it.
Make autonomous educational decisions
Classfolio does not automatically assign grades, stream students, or make consequential decisions about pupils.
Continuously record classrooms
Classfolio does not capture audio, video or screen recordings of lessons.
Continuously record student conversations
There is no continuous monitoring or recording of student activity beyond their session responses.
Security
Classfolio continually reviews and improves security controls. Below is an overview of the measures in place.
Classfolio Ltd is Cyber Essentials certified — the UK National Cyber Security Centre’s scheme, assessed through IASME, covering the whole organisation and valid to 17 August 2027. Our Security page sets out the measures in detail, including an honest list of what we do not have.
Data Management
Your school sets the retention schedule for its own educational data, aligned with its data protection policy. For the account data Classfolio controls in its own right, we apply default windows: a deleted account is soft-deleted and excluded from processing, then permanently removed after 90 days; administrative audit logs are kept for 365 days, archived live-session data for 180 days, and uploaded media for 365 days. A minimal record of which pupils joined and answered each live lesson (identifiers only — no answers, marks or names) is kept with the class beyond the 180 days, so participation can be shown across a school year. Immediate anonymisation is available as an alternative to waiting out the deletion window.
These windows are enforced automatically by a job that runs every night, rather than depending on someone remembering. Deleted content can be recovered from the platform’s recycle bin until its window expires. The one deliberate exception is unused uploaded files, which are flagged automatically but need an administrator to confirm the final deletion — a safeguard against automatically removing a file that is still in use.
Request a data export
Schools can request an export of their data — including classes, student records, lessons, and assessments.
Request data deletion
Schools can request deletion of their data. Contact privacy@classfolio.co.uk to submit a deletion request.
Access your data
Schools have access to their educational data through the platform. Additional access requests can be submitted to Classfolio.
Subprocessors
Classfolio only shares data with service providers where necessary to deliver platform functionality.
| Provider | Purpose |
|---|---|
| Firebase / Google Cloud | Hosting, database, storage and authentication services. Core platform infrastructure. |
| Google Vertex AI | AI-assisted lesson, assessment and resource generation, and marking suggestions. Used only when a teacher activates an AI feature. Text generation and marking are processed in Google Cloud's London region (europe-west2), the same region as all other Classfolio data. Requests are not used to train Google's models. Vertex AI may keep a request in memory, in the London region, for up to 24 hours to answer repeated requests faster, and a request that Google's automated abuse checks flag may be kept for a limited period for review. |
| Google Vertex AI — image generation | Generating an illustration from a description a teacher types. One of two Classfolio features processed outside the London region: no image model is available there, so it runs on Google's global infrastructure. It is switched off unless a school turns it on, only teachers can use it, and the request contains nothing but the teacher's written description — no pupil data, no pupil work and nothing uploaded. |
| Google Cloud Text-to-Speech | Reads text aloud to a pupil who asks for it — home-language audio for pupils learning English, and the spoken turn of the AI teacher in an AI-led lesson. The second of the two features processed outside the London region: it uses Google's EU text-to-speech endpoint, and the audio that comes back is cached in London. It receives the text to be spoken. For read-aloud that is lesson and assessment content the teacher authored; in an AI-led lesson it is the AI teacher's own spoken turn, which responds to what the pupil has just said. No pupil name or identifier is sent, cached audio is keyed by a hash of the text and reused across pupils so no file is tied to anyone, and no recording is ever made of a pupil's voice. |
| Google Authentication | Google sign-in for teachers, students, and administrators via Google OAuth. Schools using Google Workspace benefit from school-managed identity. |
| Microsoft Authentication | Microsoft sign-in for teachers, students, and administrators via Microsoft OAuth. Schools using Microsoft 365 benefit from school-managed identity. |
| Stripe | Subscription billing for paid plans. Receives a billing contact email address and an account identifier. Card details are entered on Stripe's own hosted pages and never reach Classfolio. No student data is sent to Stripe. |
| Resend | Sending service emails to staff, such as invitations and account notices, from servers in Ireland. No email is ever sent to a student. |
Legal Documents
Privacy Policy
Full details on how Classfolio collects, uses and protects personal data.
Cookie Notice
Information about the cookies and similar technologies used by Classfolio.
Terms of Service
The terms governing use of the Classfolio platform by teachers, students and schools.
Data Processing Agreement
A DPA is available on request for schools and trusts that require a signed agreement.
Related compliance pages
Security & Infrastructure
Authentication, access controls, encryption, infrastructure overview
Read moreSafeguarding
What Classfolio does and doesn't do in a safeguarding context
Read moreData Processing Agreement
DPA summary, commitments, and how to request a signed agreement
Read moreProcurement FAQ
Common questions from Headteachers, SBMs, DPOs and IT Managers
Read moreGet in touch
If you have questions about how Classfolio handles data, want to submit a data subject access request, or need to discuss a Data Processing Agreement for your school or trust, please get in touch.
For privacy questions about your school's use of Classfolio, also contact the administrator for your Classfolio workspace.