Privacy Policy
Last updated: 6 October 2026
This policy explains what BA Productivity does with personal information – both yours as a teacher, and your students’ when you use the service to run a quiz or mark their work. Section 4 is the important one: it lists every outside company that sees the information you put in.
1. Who is responsible
BA Productivity is operated by BlueAcorn Education Ltd, registered in England and Wales under company number 17363744, registered office 66 Paul Street, London, England, EC2A 4NA. Our ICO registration number is ZC207937.
Contact us about anything in this policy at [email protected].
Our role depends on whose information it is:
- For your information as a teacher – your account, your subscription, your usage – we are the controller. We decide what to collect and why.
- For student information you put into the service, you and your school are the controller and we are a processor. We only handle it to run the service for you, and we act on your instructions.
2. Information about you
| What | Why |
|---|---|
| Your email address and, if you set one, a securely hashed password | To create your account, sign you in and send password resets. We store a one-way hash, never the password itself. |
| Your first and last name, given when you sign up | To credit you for anything you publish to the Marketplace. This name is shown to other teachers on your listings and is recorded alongside every copy they take, so it stays visible to them afterwards. If you never publish anything, no other user sees it. You can change it in Settings. Your email address is never shown to other users. |
| Your BlueAcorn Education user ID and access tokens, if you sign in that way | To connect the two services and export work into BlueAcorn Education. |
| The content you create: topics, pasted notes, presentations, worksheets, quizzes, booklets and workbooks, slide templates, mark schemes, and the class roster you build | To generate, store and show you your work. |
| Your membership of a school or trust’s organisation, if you have been invited into one: which organisation, your role in it, and when you joined | To give your account the plan your organisation has paid for, and to show its administrators who is using the seats they bought. Administrators of your organisation can see your name, email address, role, joining date and your monthly counts of what you generated, and can export those to a spreadsheet. They cannot see your content, your marking or your students. See section 4. |
| Your Stripe customer and subscription references, plan and renewal date | To run your subscription. We never receive your card details. |
| Usage counts and AI token counts per account | To apply your monthly allowances and to understand what the service costs us to run. |
| Server logs, including error records | To keep the service working and secure. |
We run no general analytics software – there is no Google Analytics or similar on this service. We do run the Meta (Facebook) Pixel and the TikTok Pixel on the main site, to measure how effective our Facebook, Instagram and TikTok advertising is at bringing in sign-ups and paying subscribers. Each records that a page was viewed and, separately, when you complete registration or a paid subscription, and shares this with Meta and TikTok respectively. See section 4 and Cookies below for what that involves. The pages students use – the quiz page, the lesson page and the pupil sign-in pages – never load either Pixel. The quiz and lesson pages set no cookies at all; the pupil sign-in pages set only the session cookie that keeps a pupil signed in, described in Cookies below.
Separately, our own referral links work without any of that. If you arrived here through a link one of our
partners shared (an address beginning /r/), we record that the click happened and, if you go
on to create an account, which partner to credit for it. That record holds no name, no email address, no IP
address and no information about your device.
3. Information about students
We never contact students. Most students never have an account either: a quiz link or a lesson code needs none, and outside a school on an organisation plan that is the only way in. Schools on an organisation plan can choose to give their pupils a sign-in, described below. Student information reaches us in five ways.
When you share a quiz
A student opens your quiz link, types the name they choose to enter, and answers the questions. Some question types let them draw an answer, and that drawing is saved as an image. We store the name, the answers and any drawing, and the time it was submitted, so that you can see the results in your dashboard.
When you set a lesson
A lesson is a workbook you have set for a class. A pupil opens the link or types the join code, enters the name they choose, and works through it. We store that name, what they write, and the marks and feedback produced for it, along with the time of the attempt, so that you can see how the class got on. Unlike a quiz, what a pupil writes in a lesson is sent to an AI model to be marked – the same provider that marks the answers you enter yourself, listed in section 4. The workbook’s answers are never sent to the pupil’s browser.
Each attempt is held by the browser that started it, using a secret issued at the time. Another device entering the same name cannot open somebody’s answers or marks; it starts a fresh attempt.
Your class roster
You can keep a list of the students you teach, so that quiz submissions and lesson attempts already coming in can be gathered under one person instead of sitting as unconnected rows. We store the names you enter or import. A student cannot add themselves: the pages students use never write to your roster. Where a name a student typed matches one on the roster exactly, the submission is linked to that student; anything else waits for you to file it, and we do not guess.
When you give pupils their own sign-in
Available to schools on an organisation plan, and entirely optional. You create sign-ins for the pupils in a class; we generate a username from the name you enter and a starter password which is shown to you once, to print and hand out. We store the username, the pupil’s name as you typed it, the password as a bcrypt hash (never in readable form), the time they last signed in, which classes they are in, and – for each piece of work you set them – whether they have opened it, handed it in and what they scored.
We hold no email address for a pupil, and never contact one. That is deliberate: an account with an email address is one that can be recovered by email, and a reset link sitting in a child’s inbox is a risk this feature has no need to take. A pupil who forgets their password is given a new one by their teacher. A pupil must choose their own password the first time they sign in, so the password printed on your handout stops working as soon as it has been used.
A signed-in pupil can see the work set to them, what they have handed in, and their marks once you have handed those back – and nothing else. There is no way to reach another pupil’s work, no messaging, no profile and no public presence of any kind. Marks are held back from the pupil until you release them.
Deleting a class deletes the sign-ins of the pupils who were only in it. Work already handed in is kept, so that removing a leaver’s login does not erase your record of the term – delete the work itself if you want that gone too. To erase a single pupil entirely, write to [email protected].
When you use marking
You enter or paste student answers, or upload photographs of handwritten work. We store the student name you enter, the answer text, and the marks and feedback the service produces. Photographs are read by an AI vision model to produce a transcription, which is shown to you to correct before anything is marked. The photograph itself is not kept: once the text has been read out of it, only that text is stored.
We do not ask for, and you should not enter, anything more than the student’s name and their work. In particular please do not include dates of birth, contact details, medical or SEN information, safeguarding notes or any other special category data.
Student information is used only to provide the service to you. We do not analyse it for our own purposes, we do not sell it, and we do not train any AI model on it. The providers that see student work – CoreWeave and Baseten, which run the model that marks answers and lesson attempts, and Anthropic, which reads photographs – do not train on what we send them and do not keep it (see section 5). Section 4 sets out who sees what.
4. Who else sees it
Other teachers, if you publish to the Marketplace. This only ever happens because you chose to publish. Your listing shows your name and the presentation or template itself, and any teacher who copies it keeps that copy and your name against it – taking the listing down later does not remove copies already taken. Never publish a deck containing student information.
Your colleagues, if you share into your organisation’s library. If your account belongs to a school or trust, you can share a worksheet, quiz, presentation or booklet into a library that only that organisation can see. Your name is shown against it. As with the Marketplace, copies colleagues have already taken stay with them if you take yours down or leave. This never goes on the public web. Never share anything containing student information.
Your organisation’s administrators, if you are in one. They can see your name, email address, role, joining date and monthly counts of how much you generated, and can export those. They cannot see your content, your marking or your students.
Those are the only parts of the service where something of yours reaches another user, and each of the first two happens only because you chose it. Nothing else you create is visible to other users, and your email address is never shown to teachers outside your own organisation.
Beyond that, we use a small number of outside companies to run the service. They may only act on our instructions. The “sees student data” column is the one to check if your school is assessing this service.
The current list is kept on its own page, so that changes to it have a date and a history: our sub-processors. It names every company, what it does, where it is, and whether it sees student information. That page forms part of this policy, and we give schools 30 days’ notice before adding a sub-processor that would have access to student information.
BlueAcorn Education is not an outside company – it is us. It is another service run by BlueAcorn Education Ltd, so signing in with it, or exporting your work to it, keeps that information with the same controller and inside the United Kingdom. It has its own privacy policy covering what it does with your information there.
What this means in practice. Student work never goes to China. Answers you submit for marking are processed in the United States by CoreWeave, or by Baseten when CoreWeave is unavailable, reached through OpenRouter. Photographs of handwritten work go to Anthropic, which we contract with through its Irish entity, and which is contractually prohibited from training its models on what we send it.
Nothing you send for marking is kept. Neither CoreWeave nor Baseten stores the question or the answer after it has been marked, and neither uses it to train or improve any model. They hold no copy of a student’s work.
Nor do we keep one outside the database. We monitor the service to keep it working and to understand what it costs us to run, and those monitoring records deliberately exclude the text of anything sent to a model: what is recorded is which model ran, how many tokens it used and how long it took. No question, no answer, no photograph and no name goes into them. They are held by Coralogix and stored on our own Amazon Web Services account, both in Sweden, and are deleted after 30 days.
DeepSeek, in China, is used to generate teaching material from a topic and any notes a teacher chooses to paste in, and to choose which picture belongs in a booklet. For that second job it is also shown small copies of images that an image search has found on the public web, so that it can judge which one fits the section – those are public pictures from other websites, never anything you or a student uploaded. No student name, no student answer and no photograph of student work is ever sent to it. Please do still avoid pasting anything about a named person into the generation tools, because DeepSeek does use what it receives to improve its own models.
Section 5 explains the international transfers in more detail.
We may also disclose information if we are legally required to, or to establish or defend legal claims.
5. Sending information outside the UK
Where your information is stored. The application runs in London and the database is hosted by Aiven, on DigitalOcean infrastructure, in Amsterdam, the Netherlands. The Netherlands is covered by UK adequacy regulations, so information stored there has the same protection as it would in the UK. Nothing is stored at rest outside the UK or the EEA.
Where it is sent to be processed. Generating and marking material means sending the relevant text or image to an AI provider and receiving the result back:
- CoreWeave and Baseten, in the United States – student answer text, for marking, reached through OpenRouter, also in the United States. Neither retains what we send once the answer has been marked, and neither trains on it. Every marking request we make carries a setting that excludes any provider that would do either.
- Anthropic, in the United States – photographs of handwritten work, for transcription, slide edits, and choosing between pictures an image search has found for a slide.
- DeepSeek, in China – teacher-authored topics and notes, for generating teaching material, and small copies of publicly available images found by an image search, for choosing which picture belongs in a booklet. No student information is sent to DeepSeek.
The United States and China are not covered by UK adequacy regulations, so those two transfers need an appropriate safeguard under Chapter V of the UK GDPR.
Because we are a UK company, our contract is with Anthropic Ireland, Limited rather than Anthropic’s US entity, and a transfer to Ireland is covered by UK adequacy regulations. The processing itself still takes place in the United States. That onward transfer is governed by Anthropic’s data processing addendum, which is incorporated automatically into our commercial agreement with them and includes the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum. Under it Anthropic acts as our processor and we remain the controller. Anthropic publishes its own sub-processors at anthropic.com/subprocessors and must give us notice before adding one.
Marking is sent to the United States on the same basis. OpenRouter routes the request and CoreWeave or Baseten runs the model; each acts as our processor under its data processing terms, which incorporate the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum. We remain the controller. We restrict every marking request to those named providers, and we exclude any provider that stores or trains on what it receives, so the set of companies that can see a marked answer is fixed by us rather than chosen at the time of the request.
We send no student name with an answer. What leaves us is the question and the answer text, and nothing that identifies whose work it is – the link between an answer and a student stays in our own database. That reduces the risk but does not remove our duties: the answer is still personal data in our hands, and everything in sections 6 to 10 continues to apply to it.
For DeepSeek, in China, we send only the subject, exam board, level, topic and any notes a teacher chooses to type or paste when generating a presentation, worksheet, quiz or booklet – and, when a booklet is asking for a diagram, the heading of the section together with small copies of the pictures an image search returned for it, so that it can pick the one that fits. Those pictures are already published on other people’s websites; we neither took them nor received them from you. No student name, answer, drawing or photograph of student work is ever sent, and nothing about your account goes with it. This is lesson material written by an adult professional about a curriculum topic, not information about an identifiable person, so we do not treat it as a transfer of personal data and no Chapter V safeguard is engaged. We have recorded that assessment and review it if the generation tools change.
That position depends on you, which is why we ask: please do not type or paste anything about a named person – a pupil, a colleague, a parent or anyone else – into the generation tools. They are built for topics and lesson notes, and nothing you put there needs to identify anybody. If you do need to work with material about a person, don’t use these tools for it.
For completeness: DeepSeek’s own privacy policy states that the service is provided and controlled by Hangzhou DeepSeek Artificial Intelligence Co., Ltd., registered in China, that it “directly collect[s], process[es] and store[s]” personal data in the People’s Republic of China, and that it uses what it receives to improve its own models. So treat anything you paste into the generation tools as leaving our control – that is a reason to keep your own confidential material out of them too, quite apart from data protection. DeepSeek appoints Prighter Group as its EU and UK Article 27 representative.
Stripe and the image search providers are also in the United States, but they receive no student information – only billing details and search terms respectively. The Meta Pixel, also United States-based, receives page views and sign-up/subscription events from the main site, along with a browser identifier; again, never anything about a student. The TikTok Pixel receives the same, and TikTok may process it outside the UK, including in the United States and Singapore.
6. Why we are allowed to use it
- To perform our contract with you – running your account, generating your material, taking payment.
- Our legitimate interests – keeping the service secure, preventing abuse, understanding usage and costs, and improving the product. We have considered your rights and do not think these uses affect them unfairly.
- Legal obligation – keeping tax and accounting records.
For student information, the lawful basis is your school’s, not ours: it is normally the performance of a public task in providing education. Your school should have decided this and recorded it before you use the service.
7. How long we keep it
- Your account and content – until you delete the content or close your account. When an account is deleted, everything attached to it, including student responses and marking, is deleted with it, and any Marketplace listings you had are taken down.
- Presentations and templates you published to the Marketplace – copies that other teachers took while your listing was up stay in their accounts, with your name recorded against them, until those teachers delete them. We cannot remove another user’s copy on your behalf, and closing your account does not remove them. If you need one taken down, contact us at [email protected] and we will look at what we can do.
- Student information – for as long as you keep the quiz, the lesson, the marking set or the roster entry it belongs to. Please delete these when you no longer need them; your school’s retention policy applies.
- Anything you shared into an organisation’s library – until you or an administrator takes it out of the library. Copies colleagues took while it was there stay in their accounts, with your name recorded against them, until those colleagues delete them – the same as a Marketplace copy above, and closing your account or leaving the organisation does not remove them.
- Password reset links – the record expires after one hour and can only be used once. We store a hash of the link, not the link itself.
- Sign-in sessions – up to seven days, or until you sign out.
- Billing records – kept for as long as tax law requires, normally six years.
- Backups – our database backups are kept for two days on a rolling basis, so anything you delete has gone from those within 48 hours as well.
- Monitoring records – the error, performance and AI cost records described in section 5, which hold no student work and no name, are deleted after 30 days.
8. Cookies
BA Productivity sets two cookies of its own. Neither can be read by scripts, and both are sent only over HTTPS in production.
psid– holds your sign-in session. Set for everyone who signs in – teachers, and pupils where a school uses pupil sign-ins – and lasts up to seven days. Strictly necessary for the service to work, and deleted when you sign out.baref– set only if you arrive through one of our referral links. It holds nothing but the referral code from that link and a random number, so that if you create an account later we know which partner to credit. It lasts up to 90 days, and it is deleted the moment you register. It is never used to build a profile of you, is never shared with anyone, and cannot follow you to any other website.
The Meta Pixel (see section 4) additionally sets cookies belonging to Meta, on the main
site only – typically _fbp, and _fbc if you arrived via a Facebook or
Instagram ad. These let Meta recognise your browser across visits and, if you also use Facebook or
Instagram, potentially match it to your Meta account, so that they can measure and target advertising. They
are controlled by Meta, not us; see
Meta’s cookie
policy for how Meta uses them. The TikTok Pixel works the same way, setting cookies
belonging to TikTok – typically _ttp – which let TikTok recognise your browser
across visits and, if you also use TikTok, potentially match it to your TikTok account; see
TikTok’s
cookie policy. Because these cookies are not strictly necessary, neither Pixel loads
at all until you say yes to the banner shown on your first visit; choosing “Decline”, or simply
not choosing, means they never load and no Meta or TikTok cookie is ever set. Your choice is remembered on
that device so you are not asked again. The student quiz page never shows the banner, never loads either
Pixel and sets no cookies at all. Neither does the lesson page. The pupil sign-in pages set the
psid session cookie above and nothing else: no banner, no Pixel, no Meta or TikTok cookie.
If you would rather we did not keep the referral cookie, delete it in your browser or block cookies for this site – nothing about the service stops working, and it is never set again unless you follow another referral link.
9. Security
Passwords are stored using bcrypt hashing and are never recoverable. Traffic is encrypted with HTTPS. Access to the production database is limited to the people who need it. Sign-in and password-reset endpoints are rate-limited, and password reset tokens are single-use and short-lived.
No service can promise perfect security. If a breach affects your information and is likely to be a risk to you, we will tell you and the ICO as the law requires.
10. Your rights
Under UK data protection law you can ask us to give you a copy of your information, correct it, delete it, restrict how we use it, provide it in a portable format, or object to our use of it where we rely on legitimate interests.
Email [email protected] and we will respond within one month. Deleting an account is currently handled by us on request rather than by a button in the app; we will confirm by email once it is done.
If you want student information removed, you can delete the quiz or marking set yourself, or ask us. Requests from students or parents about student information should go to the school in the first instance, since the school is the controller.
If you are unhappy with how we have handled your information, you can complain to the Information Commissioner’s Office at ico.org.uk or on 0303 123 1113. We would appreciate the chance to put things right first.
11. Children
BA Productivity is a tool for teachers. It is not directed at children, children are not permitted to create accounts, and we do not knowingly collect information directly from a child. If you believe a student has created an account, tell us and we will remove it.
Children’s information does reach the service – names, answers, drawings and photographs of work – but only because a teacher has put it there or shared a quiz link. We handle it as a processor for the school, use it only to provide the service, and do not profile children, target them, or train any model of our own on their information.
The same applies to the providers we rely on. Student answers are marked in the United States by CoreWeave or Baseten, and photographs of handwritten work are read by Anthropic; none of them trains on what we send or retains it for their own purposes (see section 5). Answers are sent without the student’s name. Student information is not sent outside the UK, the EEA or the United States, and the United States transfers are covered by the safeguards in section 5.
12. Changes and contact
We will update this policy as the service changes, and will post the new version here with a new date. If a change materially affects how we handle your information, we will tell you by email or in the app.
Questions, requests or complaints: [email protected], or write to BlueAcorn Education Ltd, 66 Paul Street, London, England, EC2A 4NA.