Classfolio
Privacy Policy
Last updated: 17 August 2026
Overview
Classfolio helps teachers run live lessons and save student learning evidence into Student Folios. This policy explains the personal data handled by the app and how it is used.
One distinction runs through everything below: for staff accounts — teachers, administrators and other staff — Classfolio decides how the data is handled, so this policy is our own account of it. For student data, the school decides, and we act only on its instructions. If you are asking about a pupil, the school is the right place to start.
Who we are
Classfolio is a trading name of Classfolio Ltd, a company registered in England and Wales (company number 17384601), registered office 66 Paul Street, London, EC2A 4NA. We are registered with the Information Commissioner’s Office under reference ZC215629.
For the account data of teachers, school administrators and other staff users, Classfolio Ltd is the data controller. For student data — class membership, responses, marks and Student Folio evidence — the school or organisation is the controller and Classfolio acts as a processor on its instructions. That is why requests about a student’s data should go to the school first; see Your rights below.
Data we collect
- Account details from Firebase Authentication, such as email address and provider sign-in ID.
- Teacher approval status and role information.
- Student class membership using Firebase Auth UID and a minimal display label.
- Lesson responses, confidence ratings, scores, feedback, and Student Folio evidence.
- Uploaded lesson assets, including imported PDF page images and teacher-created resources.
Student privacy
Classfolio is designed to avoid storing full student names in class membership records. Teachers see display labels such as "Smith, J" or a school-managed alias such as "9X-01". Firebase Auth UID is used as the stable identity for signed-in students.
How data is used
Data is used to authenticate users, manage classes, join live lessons, record responses, create Student Folios, and provide teacher analysis. Student work is not sold or used for advertising.
Processors and hosting
Classfolio uses a small number of processors. Each one is listed here with what it does and what it receives:
- Google (Firebase and Google Cloud) — hosting, sign-in, the database, file storage and server-side processing. Application data, uploaded files and server-side processing are all in Google Cloud’s London region (europe-west2).
- Google Vertex AI — the AI features. When a teacher generates content or asks for marking assistance, the relevant lesson content or answer text is processed by Vertex AI, also in the London region. Student answers are sent without any name, email address or identifier. Submitted data is not used to train Google’s models. AI image generation is the exception to the London region and is described under “Where data goes” below.
- Stripe — subscription billing. Stripe receives a billing contact email address and an account identifier. Card details are entered on Stripe’s own pages and never reach Classfolio. No student data is sent to Stripe.
- Resend — sending service emails such as invitations and account notices, from servers in Ireland. No email is ever sent to a student.
Where a teacher connects an external AI assistant (see below), their teaching content is additionally processed by that assistant’s provider. The current list of processors, with the safeguards for each, is kept in our Data Processing Agreement.
Where data goes
Classfolio deliberately keeps processing in the UK: the database, uploaded files, server-side processing and AI processing are all in Google Cloud’s London region. Five exceptions are worth stating plainly rather than leaving you to find them:
- AI image generation. When a teacher generates an image, the written description they type is processed on Google’s global infrastructure, which may include servers outside the UK. No image model is available in the London region. This feature is off unless a school switches it on, only teachers can use it, and a request contains nothing but that written description — no pupil data, no pupil work, and nothing uploaded.
- Read Aloud. When a pupil asks for text to be read to them, the words to be spoken are sent to Google’s text-to-speech service, which processes them in the EU rather than specifically in London. The audio that comes back is stored in the London region and reused, so the same sentence is only ever sent once. For reading a lesson or a question aloud, the text is the teaching material itself, not the pupil’s work. In an AI-led lesson it is what the AI teacher says next, which is written in response to the pupil and may reflect what they just said. No pupil name is sent, and no recording is ever made of anyone’s voice.
- Sign-in. Firebase Authentication is a global Google service and some of its processing takes place outside the UK, including in the United States. This covers account identifiers and sign-in records, not lesson content or student work. It is governed by Google’s own data protection terms and transfer safeguards.
- Service email. Resend processes in Ireland, inside the European Economic Area, which UK law recognises as providing adequate protection.
- Billing. Stripe processes in the EEA and may transfer billing data onward to the United States under its own transfer safeguards.
Separately, a teacher who chooses to connect an external AI assistant is sending their own teaching content to a provider based in the United States — see below. That is off unless three separate approvals are given.
Connecting an external AI assistant
A teacher may connect an approved external AI assistant (currently Claude, provided by Anthropic, and ChatGPT, provided by OpenAI) to their own Classfolio account. This is off by default and requires three separate approvals: Classfolio must enable it for the platform, the school administrator must enable it for the school, and the individual teacher must enable it for their own account. A teacher can disconnect at any time, and a school administrator can withdraw access for the whole school.
When connected, the assistant can read and create that teacher’s own teaching content — lessons, assessments, assignments, questionnaires and printable resources — and everything it creates is saved as a private draft for the teacher to review. It cannot publish, share, deploy or send anything to a class.
No student data is shared. The connection has no interface to student records at all: it cannot read student responses, assignment submissions, marks, Student Folio evidence, questionnaire answers, live session activity, or even class lists and who is in them. This is a property of how the connection is built rather than a setting, so it cannot be switched on by mistake. Where a questionnaire is read, only the total number of replies is visible — never the replies themselves, including those from parents and staff.
One limit is worth stating plainly: teaching content is free text, so if a teacher types a student’s name into a lesson slide, a mark scheme or a resource, that text is sent to the assistant along with the rest of that content. Teachers are asked not to put student names into teaching materials.
Content sent to the assistant is processed by that provider under the teacher’s own agreement with them, and is subject to that provider’s privacy policy. Both currently approved providers are based in the United States, so a teacher who connects one is sending their own teaching content outside the UK. Classfolio’s own processing and storage remain in the UK and EU as described above.
Only assistants explicitly approved by Classfolio can connect; an arbitrary third-party application cannot register itself. Schools that do not wish teachers to use this feature can leave it switched off, and it is switched off unless enabled.
How data is protected
Data is encrypted in transit and at rest, access is enforced at the database layer rather than only in the interface, and Classfolio holds no user passwords at all — sign-in is delegated to your school’s Microsoft or Google account. Classfolio Ltd is Cyber Essentials certified (whole organisation, valid to 17 August 2027). Our Security page describes the measures in detail, including what we do not have.
Retention and deletion
For the accounts Classfolio controls — teacher, administrator and other staff accounts — a deleted account is first soft-deleted and excluded from processing, then permanently removed after a default 90 days. Immediate anonymisation is available instead if you would rather not wait. Administrative audit logs are kept for 365 days by default, archived live-session data for 180 days, and uploaded media for 365 days.
These windows are enforced automatically by a job that runs every night, not by someone remembering to do it. The one deliberate exception is unused uploaded files, which are flagged automatically but need a person to confirm the final deletion — a safeguard against automatically deleting a file that is still in use.
Where a teacher has turned on a class workspace or a Class Space, every comment a student writes is read and approved by a member of staff before anyone else can see it. That cannot be switched off. A comment that is declined, or withdrawn by its author before it is read, is never shown to the class — but it is kept for 365 days rather than deleted immediately, so that a school can still see what was written if it later needs to. After that it is permanently deleted by the same nightly job.
A school can also allow students to attach a photograph, an image or a PDF to a Class Space message. This is off unless the school switches it on and the individual teacher switches it on for their own class, and a school can switch it off again for everyone at once. Where it is allowed, files are limited to 1.5 MB each, location and camera information is removed from photographs before they are uploaded, and the file is not visible to other students until a member of staff has approved the message. If a member of staff declines a message, any file attached to it is deleted rather than kept — unlike the text of the comment, which is retained for 365 days as described above.
Separately, a school can allow students to hand in a photograph, an image or a PDF as part of an assignment — the digital equivalent of handing in an exercise book. This is a different permission from the one above and is also off until a school switches it on. Because this work is never published to a class, a wider range of files is accepted than in a Class Space — photographs, PDFs, documents, presentations, spreadsheets and similar coursework, up to 5 MB each. Programs and files that run when they are opened are refused, so that a teacher can open a pupil’s work safely. Location and camera information is still removed from photographs before the file leaves the student’s device. Work handed in this way is seen only by the teachers who mark that class — never by other students — and it is marked by a person: we do not give a handed-in file to an AI model. A student can remove a file they have handed in until the work has been marked, after which it is kept as part of their work, along with the mark it earned.
Staff training cohorts work differently, because the people in them are colleagues rather than children. A trainer may choose to let staff in a cohort publish without approval; where they have not, comments are approved by the trainer in the same way. Students are never members of a staff cohort, and a comment written by anyone without a staff role is always held for approval regardless of that setting.
For student data the school is the controller, so it sets the retention schedule for classes, lessons, student evidence and imported files. Requests to delete or export student data should be sent to the organisation administering the Classfolio workspace, and we support them in answering.
Why we are allowed to use this data
For teacher, administrator and staff accounts, we process personal data to perform our contract with you — creating and running your account is the service you signed up for. We also rely on our legitimate interests to keep the service secure, prevent misuse, fix faults, and understand how the product is used, balanced against your interests and limited to what that requires.
We do not currently rely on consent for anything: there are no advertising or analytics cookies to agree to. If that changes we will ask you first, and you will be able to withdraw your consent at any time.
For student data, the school or organisation decides the lawful basis as controller, and Classfolio processes that data only on its instructions.
We do not make decisions about anyone by automated means alone. AI-assisted marking produces a suggested mark and written feedback: a teacher decides whether a question is marked by AI at all, can change any mark or comment at any time, and chooses whether marks are held for review or shown to a pupil as soon as marking finishes. AI output is formative. It does not determine a pupil’s progression, set or placement, and no consequential decision about a pupil is made without a person making it.
Your rights
Under UK data protection law you have the right to:
- ask for a copy of the personal data we hold about you;
- have inaccurate data corrected;
- ask for data to be deleted, where there is no overriding reason to keep it;
- ask us to restrict how we use your data while a concern is looked into;
- object to processing we carry out on the basis of legitimate interests;
- receive data you gave us in a portable, machine-readable form; and
- withdraw consent at any time, where consent is what we relied on.
For a teacher, administrator or staff account, contact privacy@classfolio.co.uk and we will respond within one month. For a student, contact the school or organisation that runs the Classfolio workspace — they are the controller, and we will support them in answering. Exercising any of these rights is free, and we will not treat you differently for asking.
Complaints
If you are unhappy with how we have handled your personal data, please tell us first at privacy@classfolio.co.uk so we can try to put it right. You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority, at any time — you do not have to come to us first.
Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. Telephone 0303 123 1113. ico.org.uk
Contact
Which route to use depends on whose data you are asking about. For your own teacher, administrator or staff account, write to privacy@classfolio.co.uk — we are the controller for that. For a student’s data, contact the school or organisation running the Classfolio workspace, because the school is the controller and we can only act on its instructions.
For anything else about privacy or data at Classfolio, privacy@classfolio.co.uk reaches us directly. It is the address published on our ICO registration.