Privacy Policy
Last updated: 23 July 2026
This Privacy Policy explains how Chapter Technologies Ltd ('Chapter', 'we', 'us', 'our') collects, uses, stores, and protects personal data when you use the Chapter Schools platform ('the Platform'). The Platform includes the Chapter Schools web application at chapterschools.com and the Chapter Schools mobile apps for iPhone and iPad. We are committed to protecting the privacy of all users, including children, in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who we are
Chapter Technologies Ltd is the data controller for personal data processed through the Chapter Schools platform. We are registered in England and Wales.
Contact: hello@chapterschools.com
Platform: chapterschools.com, and the Chapter Schools apps for iPhone and iPad
Where a school subscribes to Chapter Schools, the school acts as a separate data controller for its students, staff, and parents. Chapter Technologies Ltd acts as a data processor on behalf of the school for the purposes of delivering the Platform. This relationship is governed by our Data Processing Agreement (DPA), available at chapterschools.com/dpa.
2. What personal data we collect
School staff (careers leads, teachers, admins)
- Name and email address
- Job role and school affiliation
- Platform activity and usage logs
- Account preferences and settings
Students
- Name, year group, form group, and date of birth (where provided)
- School email address - where a student voluntarily adds and verifies their school email address within the Chapter student app, this is used to link their Chapter account to their school record on the Chapter Schools platform. This linking is student-initiated and confirmed via a one-time verification code sent to the school email address.
- Career exploration activity, interests, and goals (from the Chapter student app)
- Gatsby Benchmark evidence generated through school activities
- Guidance session records and notes
- UCAS application data (sixth form - subject to school enabling this feature)
- NEET risk indicators (computed, not stored as a categorical label)
- Work experience placements and apprenticeship exploration activity
Parents and guardians
- Name and email address (provided by the school or by the parent during registration)
- Communication preferences
- Email engagement data (opens, clicks) via Resend
Usage data (all users)
- IP address and device/browser information
- Pages visited and features used
- Session duration and interaction logs
3. The Chapter Schools mobile apps
The Chapter Schools apps for iPhone and iPad are staff tools. They are used by careers leads, teachers and school administrators, and are not intended for use by students. Students use the separate Chapter app, which has its own privacy notice.
The apps access the same school data as the web platform, using the same account, permissions and role-based access controls. Everything described elsewhere in this policy applies equally to them. The sections below cover what is specific to using Chapter Schools on a mobile device.
Device permissions we ask for
Each permission is requested only at the point you first use the feature that needs it, and each can be declined or later withdrawn in iOS Settings. Declining a permission disables that feature; the rest of the app continues to work.
- Location (while using the app): Used to sort courses, provider open days, apprenticeship vacancies and employers by distance from where you are. Your location is used on the device to order results and is not stored on our servers or used to build a location history.
- Microphone: Used only when you actively start a recording to dictate guidance session notes. Recording never starts on its own, and the app does not listen in the background.
- Photos: When you attach an image — a photographed page of handwritten notes, a signed consent form, a placement document — you select it through the standard iOS photo picker. The app receives only the images you choose and never has access to the rest of your photo library.
Guidance session dictation
Dictated audio never leaves your device. When you dictate a guidance session note in the app, speech is converted to text by iOS on the phone itself, using Apple's on-device speech recognition. The audio is not uploaded to Chapter Schools, not sent to any transcription service, and not written to a file — it goes from the microphone into the recogniser and no further. Only the text appears, for you to review and edit before you save it.
We built it this way deliberately: a dictated guidance note names a student and describes what was discussed about them, which makes it among the most sensitive information in the product. There is no server fallback, so if on-device recognition is unavailable on your device or in your language, the app tells you and asks you to type or photograph your notes rather than quietly uploading the recording instead.
Dictation in the web version of Chapter Schools works differently: browsers have no equivalent on-device capability, so audio recorded there is sent to Chapter Schools and forwarded to OpenAI's Whisper service for transcription. The audio is discarded once the transcript returns. If you want dictation that never leaves your control, use the iPhone or iPad app.
Data stored on your device
- Your sign-in tokens are held in the iOS Keychain, encrypted by the operating system and removed when you sign out.
- Cached school data is stored in the app's private container so recently viewed screens load quickly, and is cleared when you sign out or delete the app.
- Interface preferences, such as appearance settings, are stored locally on the device.
No tracking, and no third-party SDKs
The Chapter Schools mobile apps contain no third-party software development kits at all — no advertising, analytics, attribution or crash-reporting SDKs. We do not use the Advertising Identifier (IDFA), we do not track you across other companies' apps or websites, and we do not ask for App Tracking Transparency permission because we have nothing to ask for. The apps communicate only with Chapter Schools' own servers.
Apple provides the App Store distribution channel and may collect its own data about downloads and crashes under Apple's privacy policy. We receive only aggregated, anonymised download and crash statistics from Apple, and never data that identifies an individual user.
4. How we use personal data
We use personal data to:
- Deliver and maintain the Chapter Schools platform and its features
- Enable Gatsby Benchmark tracking and Ofsted evidence reporting for schools
- Support careers guidance, lesson planning, and student career development
- Link a student's Chapter app account to their school record, where the student has verified their school email address and consented to this connection
- Send parent digest emails and school communications
- Generate AI-powered insights, lesson plans, and worksheet content
- Process payments and manage school subscriptions via Stripe
- Provide customer support and platform onboarding
- Improve the platform through anonymised analytics
- Comply with legal obligations
Legal basis for processing
- Contract: Processing necessary to deliver the service to subscribed schools
- Legitimate interests: Platform security, fraud prevention, service improvement
- Legal obligation: Compliance with safeguarding and data protection law
- Consent: Where we send optional marketing communications (school contacts only)
5. AI processing
Chapter Schools uses AI to power features including Chappy (our AI assistant), lesson plan and worksheet generation, student insight summaries, guidance session preparation and summaries, UCAS reference and personal statement drafting, employer contact research, and dictation.
Which providers we use
- Anthropic (Claude): All text generation and analysis features.
- OpenAI (Whisper): Audio transcription for dictation in the web app only. Dictation in the iPhone and iPad apps is transcribed on the device and reaches no provider at all.
We access both providers through their commercial APIs. Under those API terms, content we submit is not used to train their models. We do not use any other AI provider, and we do not operate our own models trained on your data.
What is sent, and when
AI features run only when a user actively invokes them. Nothing is sent to an AI provider in the background.
We do not send student names to any AI provider. Where a feature needs to write about a particular student — a guidance summary, a UCAS reference, a parent digest — the name is swapped for an anonymous placeholder before the request leaves us, and put back into the result afterwards. The model writes just as naturally around a placeholder, and never learns who the student is. Elsewhere, students are referenced only by an opaque code and year group, and models are instructed never to infer or invent a name, or to guess gender or pronouns.
There are two exceptions, both because the information sits inside material you supply rather than a field we build. Dictated audio and photographed notes may contain any name you have spoken or written. And free text — an existing reference draft, a personal statement, session notes — may mention a student by name in prose. We do not try to strip names out of free text, because doing it reliably enough not to corrupt the document is not something we can promise.
In every case the request is triggered by a deliberate action you take. Content sent to an AI provider is used only to generate the response returned to you. It is not retained by us beyond the output you choose to save, and is subject to the providers' own limited abuse-monitoring retention under their API terms.
Human oversight
AI-generated content is always presented to the user for review, editing and approval before it is saved or shared. No automated decision with legal or similarly significant effect on a student is made solely by AI. Where the Platform surfaces computed indicators such as NEET risk, these are decision-support signals for trained staff, not automated decisions.
6. Data sharing and sub-processors
We use the following third-party sub-processors to deliver the Platform:
- Supabase (database and authentication): Stores school, staff and student records. Data held on servers within the EU (Ireland). supabase.com
- Cloudflare (hosting and content delivery): The web application and its APIs run on Cloudflare Workers, which also serves the mobile apps' API traffic. cloudflare.com
- Anthropic (AI text features): Receives the content submitted to an AI feature. No persistent storage of school data. anthropic.com
- OpenAI (audio transcription): Receives guidance session dictation audio from the web app only, for transcription. The mobile apps transcribe on the device and send OpenAI nothing. openai.com
- Resend (transactional email): Used for invitations, parent digests and notifications. resend.com
- Stripe (payment processing): Used for school subscription billing. No student data is shared with Stripe. stripe.com
- Mixpanel (product analytics): Used to understand how the web platform is used so we can improve it. Configured against Mixpanel's EU data residency endpoint, so analytics data is processed in the EU. Not used in the mobile apps. mixpanel.com
- Apple (app distribution): Distributes the mobile apps via the App Store and provides us with aggregated, anonymised download and crash statistics. apple.com
- Google Fonts: The web platform loads typefaces from Google's font service, which receives the requesting IP address. Not used in the mobile apps, which bundle their fonts. google.com
An up-to-date list of sub-processors is maintained in our Data Processing Agreement. We will give schools notice of any new sub-processor before it begins processing personal data, so that the school has an opportunity to object.
We do not sell personal data to third parties. We do not share personal data with third parties for their own marketing purposes.
Where data is transferred outside the UK or EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or UK International Data Transfer Agreements (IDTAs).
7. Data retention
- Student data: Retained for the duration of the school's subscription. Upon termination, schools may request a data export; data is deleted from our systems within 90 days of subscription end.
- Staff accounts: Retained until the account is closed or the school subscription ends.
- Parent accounts: Retained until the parent requests deletion or the school subscription ends.
- Dictation audio: Never retained. In the mobile apps it never leaves the device at all; in the web app it is discarded as soon as the transcript returns. Either way, only the transcript you choose to save is kept, as part of the guidance session record.
- Billing records: Retained for 7 years in accordance with UK financial record-keeping requirements.
- Audit logs: Retained for 12 months for security and compliance purposes.
8. Children's data
Chapter Schools processes personal data relating to children (students under 18). We treat this data with the highest level of care and apply the following protections:
- Student data is only accessible to authorised school staff with appropriate roles
- No student data is used for advertising, commercial profiling, or to build any advertising or marketing profile
- We do not sell student data, and we do not use it to train AI models — ours or anyone else's
- Where an AI feature necessarily processes identifiable student data, as described in section 5, it is sent only to the provider powering that feature, used only to produce the response, and always reviewed by a member of staff before it is saved
- Schools are responsible for ensuring they have appropriate lawful basis to share student data with Chapter Schools (typically public task or legitimate educational interest)
- Parents/guardians may request access to or deletion of their child's data via their school's careers lead
The Chapter Schools mobile apps are staff tools and are not designed for or directed at children. They are rated for ages 4+ in the App Store because they contain no age-restricted content, not because they are intended for young users.
We have regard to the ICO's Age Appropriate Design Code in how student data is presented and handled across the Platform.
9. Your rights
Under UK GDPR, individuals have the following rights:
- Right of access: Request a copy of your personal data
- Right to rectification: Request correction of inaccurate data
- Right to erasure: Request deletion of your data (subject to legal obligations)
- Right to restriction: Request we limit how we use your data
- Right to data portability: Receive your data in a structured, machine-readable format
- Right to object: Object to processing based on legitimate interests
- Rights related to automated decision-making: We do not make solely automated decisions with significant legal effects
To exercise any of these rights, contact us at hello@chapterschools.com. We will respond within one calendar month.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
Deleting your account
Chapter Schools staff accounts are created and administered by your school, not self-registered in the app. To close a staff account, ask your school's Chapter Schools administrator to remove it, or email us at hello@chapterschools.com and we will action the request directly, confirming with your school first. Either route deletes the account and its associated personal data within 30 days, subject to any records we must retain by law.
Signing out of or deleting the mobile app removes locally cached data from your device but does not delete your account. Use one of the routes above to do that.
10. Security
We implement appropriate technical and organisational measures to protect personal data, including:
- Encryption in transit (TLS/HTTPS) and at rest
- Row-level security policies in our database (users can only access data they are authorised to see)
- Role-based access control across all features
- API authentication using JWT tokens with short expiry
- Passwordless sign-in using a one-time code sent to your school email address, with optional two-factor authentication via an authenticator app
- On mobile, session tokens stored in the iOS Keychain and protected by the device's own encryption
- Regular security reviews and dependency updates
Because the mobile apps hold school and student data, we ask that any device used with Chapter Schools is protected by a passcode or biometric lock, and that lost or stolen devices are reported to your school promptly so that sessions can be revoked.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify school administrators of material changes via email or in-platform notification at least 30 days before they take effect.
The current version is always available at chapterschools.com/privacy.
12. Contact
For any privacy-related queries, data subject requests, or to request our Data Processing Agreement:
Email: hello@chapterschools.com
Subject line: Privacy / Data Request