Privacy Policy
Effective Date: January 2025 · Last Updated: 8 October 2026
1. Introduction
Leibniz Education Pty Ltd (“we,” “our,” or “us”) is committed to protecting your privacy while providing adaptive mathematics education services, including personalised practice, AI-assisted grading, and teacher analytics for secondary students. This Privacy Policy explains how we collect, use, store, and protect your information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth).
This policy covers paid school subscriptions and pilots. Our School Subscription Agreement includes school service and data-protection terms. Where signed, it governs the parties' contractual rights for School Data; this policy explains our practices and cannot reduce those protections.
2. Information We Collect
2.1 Information You Provide
Account Information
- Email address and full name (provided during account creation or via OAuth)
- School association (assigned during school provisioning)
- Year level and course selection
Authentication is handled via Google or Microsoft SSO, or via email/password managed by Supabase Auth. Leibniz does not directly store passwords.
Educational Content
- Typed answers and working steps
- Uploaded handwritten work (images/PDFs)
- Time spent on questions
2.2 Information Collected Automatically
Usage Data
- Questions attempted and completion rates
- Topics and difficulty levels accessed
- Performance metrics and daily activity counts
Technical Data
- IP address and device fingerprint for free/guest rate limiting; school-provisioned Pro users are exempt from that quota. Hosting and security services process connection metadata separately.
- Session cookies for authentication
Server Logs
- Vercel runtime logs retained for 30 days under Observability Plus
- Logging is subject to data-minimisation and restricted-access requirements
2.3 Information from Third Parties
Google/Microsoft OAuth
- Email address and name during sign-in flow
Payment Information (Individual Subscribers)
- For individual paid subscribers, Stripe provides transaction and subscription status
- Not used for school-provisioned users
- We never directly handle credit card details
Information from Your School
For school accounts, your school decides who may use Leibniz and gives us the information needed to set up access. Depending on what your school chooses, this comes from:
- A list of student and teacher email addresses (and, where provided, names, year levels and classes) supplied by the school
- The school's learning-management system when you open Leibniz from it (for example Canvas or Schoolbox): your name, email address, role and course, and the class list for that course
- The school's student-information or rostering system, if the school connects it (for example Sentral, Wonde or another OneRoster source): names, email addresses, roles, classes and enrolments
These systems are run by your school or its own providers under the school's arrangements with them. We only receive the records the school authorises.
2.4 How We Hold Information
Account, learning and uploaded-work records are held in our primary database and storage in Sydney, Australia, protected as described in Section 6. Some processing is carried out by the providers listed in Section 4.
2.5 If You Do Not Provide Information
- An email address is required to create and sign in to an account. Without it we cannot give you an account.
- For school accounts, your school must supply your school email address before you can join your school's classes.
- Your name, year level and course help teachers recognise your work and set suitable questions. If they are missing, some reporting and personalisation will be less accurate.
- Answers and uploaded work are only collected when you choose to submit them. If you do not submit work, it cannot be marked or included in your progress.
- You can still read our public pages and try limited guest questions without an account.
3. How We Use Your Information
To Provide the Service
- Generate personalised questions
- AI-powered grading for typed and handwritten work
- Track progress and performance
- Provide hints and solutions
- Deliver class assignments and teacher reporting
To Improve the Platform
- Analyse anonymised aggregate usage patterns
- Develop new content
For Security
- Prevent abuse
- Enforce usage limits
- Detect fraudulent activity
- Maintain service stability
For Communication
- Transactional emails (password resets, account notifications) via Mailgun through Supabase Auth
- Teacher service newsletters provide factual information about platform features, important workflow changes and service operation, delivered via Mailgun. Recipients are identified from recorded communication preferences and existing teacher/pilot relationships, subject to applicable School instructions. We respect declined signup choices and unsubscribe requests. Student records are not used to select recipients. You can unsubscribe at any time using the link in each newsletter.
4. Data Sharing and Disclosure
We DO NOT:
- Sell your personal information to third parties
- Use School Data for marketing, advertising or profiling unrelated to the educational service. Teacher service communications are limited to the purpose described above, and newsletters include an unsubscribe option.
- Share your data with other schools or organisations except through the service providers, authorised educational access and legal disclosures described in this policy
- Use student data to train AI models
Sub-Processors
These are all the service providers that receive personal information from Leibniz in providing the service. Each receives only the information needed for its purpose. The planned AWS service receives no data until it is activated after notice to schools; Mailgun remains our email provider until then. For questions about a provider, contact us (Section 13) or use the provider's website below.
| Provider and contact | Purpose | Data shared | Processing countries | Retention | Basis |
|---|---|---|---|---|---|
| SupabaseSupabase, Inc.supabase.com | Primary database, sign-in and uploaded-work storage | All application data: account, school, class, learning and submission records, and uploaded work | Sydney, Australia | While the service is used; encrypted backups 7 days | Service delivery under our agreement with your school or with you |
| VercelVercel Inc.vercel.com | Website and application hosting, server-side processing, content delivery, website usage and performance analytics | Request content needed to run the feature, page and device information, connection data (including IP address), performance measurements and runtime logs | Sydney, Australia (application functions); global delivery and security network and website analytics, including the United States | Runtime logs 30 days; analytics per provider lifecycle | Service delivery and security |
| OpenRouterOpenRouter, Inc.openrouter.ai | AI gateway for grading, handwriting recognition (OCR), answer checking and question generation | Question, curriculum and marking content; the student’s answer, working or uploaded work. Names and email addresses are not deliberately added, but uploads and free text may contain them | United States | Every request containing student input must use a zero-data-retention endpoint with provider data collection denied, so it is not kept or used for training | Service delivery under our agreement with your school or with you |
| AI model endpoints reached through OpenRouterDeepInfra Inc.; Google LLC (Vertex AI and Google AI Studio)deepinfra.comcloud.google.com | Running the AI models that OpenRouter forwards requests to | The same request content as OpenRouter, for that request only | United States; Google may also process in other countries where it operates | As for OpenRouter above | Service delivery |
| ModalModal Labs, Inc.modal.com | Runs background question-generation jobs | Curriculum and question content only; no student information | United States and other regions where Modal operates (not pinned to one region) | Temporary job containers; results are stored with Supabase | Service delivery |
| RailwayRailway Corporationrailway.com | Hosts our background workers (question generation and rendering, PDF export of teacher tasks, learning-model updates), a relay for very large submission uploads, and our self-hosted Twenty customer-relationship tool (its data is stored with Supabase) and meeting-booking tool | Curriculum and task content; learning records linked to internal IDs for learning-model updates; very large uploaded submissions while they are passed on; for the relationship and booking tools, teacher and school contact details only (no student data) | United States; Singapore (large-upload relay) | Job files and service logs per provider lifecycle; the upload relay does not keep submissions; contact records while the school relationship continues | Service delivery; school relationship management |
| Voyage AIVoyage AI (MongoDB, Inc.)voyageai.com | Search for question ideas | The search text a teacher or visitor types; no account details | United States | Provider API data policy | Service delivery |
| Amazon Web Services (AWS) — plannedAmazon Web Services, Inc.aws.amazon.com | Planned replacement infrastructure and SES email. Not yet active | Data needed for activated workloads; email recipients, messages and delivery information | Sydney, Australia; onward email delivery may be overseas | Applicable service retention and deletion requirements, confirmed before activation | Activated only after advance notice to schools |
| Mailgun (until email cutover)Mailgun Technologies, Inc. (Sinch)mailgun.com | Sign-in and account emails, and teacher service communications | Recipient email address, message content and delivery information | United States | Provider delivery and log lifecycle | Service delivery; teacher communications (unsubscribe at any time) |
| StripeStripe, Inc. and its affiliatesstripe.com | Web payments for individual subscriptions only (not school accounts) | Customer email, payment and subscription details | United States and other countries where Stripe operates | Contractual and legal record-keeping periods | Your purchase |
| AppleApple Inc.apple.com | Sign in with Apple, mobile app distribution and in-app purchases for individual subscriptions | Sign-in identity details; purchase receipts and subscription details | United States and other countries where Apple operates | Provider account and platform lifecycle | Your choice of sign-in or purchase |
| GoogleGoogle LLCgoogle.com | Google sign-in, Google Play distribution and in-app purchases for individual subscriptions | Sign-in identity details; purchase and subscription details | United States and other countries where Google operates | Provider account and platform lifecycle | Your choice of sign-in or purchase |
| MicrosoftMicrosoft Corporationmicrosoft.com | Microsoft sign-in, and our own Microsoft 365 email and calendar used to correspond with teachers and schools | Sign-in identity details; teacher and school contact details and correspondence | Microsoft 365 email and calendar: Australia. Sign-in: the United States and other countries where Microsoft operates | Provider account lifecycle; correspondence while the school relationship continues | Your choice of sign-in; school relationship management |
| Expo650 Industries, Inc. (Expo)expo.dev | Delivers updates to the Leibniz mobile app | Device, app version and connection information (including IP address); no learning data | United States | Provider lifecycle | Service delivery |
| CalendlyCalendly LLCcalendly.com | Booking demonstration and onboarding calls with teachers and schools | Name, email address and meeting details entered when booking | United States | Provider lifecycle | Your request for a meeting |
Basis for sharing. We share personal information with these providers only to deliver the service we provide to your school or to you, which is the purpose it was collected for (Australian Privacy Principle 6). Your school authorises this under its agreement with us. Sign-in, purchase and meeting-booking providers are used only when you choose them.
School-authorised platforms. If your school connects its own learning-management or student-information system (for example Canvas, Schoolbox, Sentral, Wonde or another OneRoster source), that system is run by the school or its provider under the school's own arrangements, and its processing country is set by that arrangement. We exchange only what the school authorises: roster and class information coming in, and for learning-management systems, task links and scores going back.
Stripe is not used for school-provisioned users. PostHog collection is disabled. Your browser or the mobile app also loads open-source maths-display files and styles from the jsDelivr and cdnjs (Cloudflare) public networks, which receive standard connection information such as your IP address. We may also disclose information where required by law, limited to what is required.
Teacher and School Access
For school participants, teachers can view performance data (marks, accuracy, time spent, topic performance) for students enrolled in their own classes. School administrators can view data for their school only. This access is part of the educational service and is governed by the school's applicable agreement.
5. Data Retention
Retention Period
Data is retained for the duration of your use of the service to support ongoing learning and teacher reporting.
Deletion on Request
Authorised deletion removes or detaches the account and related records, with separate verified cleanup of uploaded work. The affected data includes:
- User account and profile
- Role and access records
- Class enrolments
- Account-linked question attempts, submissions, and grades
- Uploaded handwritten work (images and PDFs in storage)
- Learning model data and AI-generated summaries
- Provisioning records
Deletion Timeline
- After verifying the request and resolving subscription or legal restrictions, account and related relational records are removed or detached in a transaction
- Uploaded work is deleted immediately where available; provider failures are retained in a durable hourly retry queue and verified by re-listing the account prefixes
- Encrypted database backups are retained for 7 days, then auto-expire
- Vercel runtime logs are retained for 30 days under Observability Plus, separately from inference-provider zero data retention
Self-Service Deletion
Students and teachers can delete their own accounts via the Settings page. The request triggers transactional relational deletion and durable, verified storage cleanup.
Anonymised Data
Irreversibly anonymised aggregate statistics (where no individual is identifiable) may be retained.
Data Required by Law
Notwithstanding the above, data that is required to be retained by applicable law or regulation will be kept for the minimum period required and then deleted.
6. Data Security
Encryption
- In transit: TLS 1.2+ on all connections (browser-to-server and server-to-database)
- At rest: AES-256 encryption on all stored data
Authorised Data Access
Sensitive operations use permission-checked server-side routes. Client access uses scoped authentication and database policies. Privileged service credentials remain server-side; a public client key does not grant privileged access.
Database Security
- Row-Level Security (RLS) enabled at the database layer as defence-in-depth
- Internal UUIDs link learning records; linkable records remain personal information
- All database queries parameterised to prevent SQL injection
Vendor Access Controls
- Production access restricted to 2 personnel (CEO and CTO)
- Policy requires multi-factor authentication for administrative infrastructure access
- Policy requires periodic credential review and rotation on compromise or access changes
- Audit logging via platform trails (Supabase database logs and Vercel access logs)
Incident Response
We notify affected schools within 24 hours of becoming aware of a data breach affecting their data, including while assessing its impact. This commitment is separate from statutory notification requirements. Incident response includes immediate containment, root cause analysis, patching, and verification before restoring service.
7. Your Rights and Choices
Access (APP 12)
You can view your own data at any time through the platform. Students can see their own submissions, grades, and progress. Teachers can see performance data for students in their own classes.
Correction (APP 13)
You can update your profile information at any time. If you believe any data we hold about you is inaccurate, please contact us and we will correct it.
How to Ask for Access or Correction
Email letterbox@leibniz.com.au with your name, the email address on your account and what you would like to see or correct. We may need to confirm your identity first. We will respond within 30 days. There is no charge for making a request. For school accounts, you can also ask your school, and we may involve the school where the records belong to it. If we refuse a request, we will tell you why in writing and how to complain (Section 13).
Deletion
You can request deletion of your data at any time via the Settings page or by contacting us. Deletion follows Section 5, including shared-record detachment, storage cleanup, backup expiry and any applicable legal retention.
School Deletion
For school subscriptions and pilots, the school may request deletion of all school data at any time. Individual student or teacher records can also be deleted independently without affecting the rest of the school's data.
9. Children's Privacy
No minimum age applies to accounts a school provides; the school authorises student use. Individual (non-school) users must be at least 13 years of age, and individual users under 18 need parental or guardian consent.
Leibniz is designed for secondary school students, including those under 18. We take the following measures to protect children's privacy:
- We do not collect data beyond what is necessary for the educational service
- We do not track behaviour outside the platform
- We do not use student data for marketing or profiling unrelated to the educational service
- We do not share data with social media or advertising networks
- Schools arrange access and provide required notices and permissions, including parent or guardian consent where required. Purchasing access does not itself supply an individual's consent; Leibniz retains its own privacy obligations.
10. International Data Transfers
Data Stored in Australia
The primary application database, authentication records and uploaded-work storage are hosted in Sydney, Australia. The limited overseas processing and provider metadata described below are not represented as Australian storage.
Limited Cross-Border Processing
- AI features use OpenRouter's United States gateway and may use an approved overseas downstream endpoint; these requests are designed to exclude direct identifiers and require zero-data-retention eligibility with provider data collection denied
- Question generation runs on Modal in the United States or other regions where Modal operates, coordinated by our workers on Railway in the United States — curriculum content only, no student information
- Learning-model updates and teacher task PDF exports run on our Railway workers in the United States — learning records linked to internal IDs and task content
- Very large submission uploads from older app versions pass through a Railway relay in Singapore on the way to our Sydney storage; the relay does not keep them
- Our self-hosted relationship and booking tools on Railway (United States) and Calendly (United States) — teacher and school contact details only. Our Microsoft 365 email and calendar are in Australia
- Question-idea search text via Voyage AI (United States)
- Transactional email and teacher communications via Mailgun (United States) — recipient address, message content and delivery metadata. Planned AWS SES uses Sydney services; recipient email systems may be overseas
- Vercel delivery, usage analytics and performance monitoring — page, device and connection metadata, processed on Vercel's global network including the United States
- Mobile app updates via Expo (United States) — device, app version and connection information
- Apple/Google/Microsoft sign-in and app-store services — the United States and other countries where they operate, when selected by the user
- Stripe payment processing (individual subscribers only) — the United States and other countries where Stripe operates
The countries where overseas recipients are located are therefore the United States and Singapore, and, for the global providers named above, other countries where those providers operate. The full list, with each provider's purpose and data, is in the sub-processor table in Section 4.
These practices are aligned with APP 8 (Cross-border Disclosure of Personal Information) under the Privacy Act 1988.
11. Australian Privacy Principles
| Principle | How Leibniz Complies |
|---|---|
| APP 3 (Collection) | Only data necessary for the educational service is collected |
| APP 6 (Use/Disclosure) | Data used for the stated educational and service-communication purposes; School Data is not used for marketing. Teacher newsletters follow Section 3 and include an unsubscribe option. |
| APP 8 (Cross-border) | Primary application storage is in Australia; global hosting/analytics, inference, email and user-selected platform processing are disclosed above |
| APP 11 (Security) | Encrypted data (see Section 6), permission-checked server operations, scoped client/database access and role-based authorisation |
| APP 12 (Access) | Students can view their own data; teachers can view their class data; access requests answered within 30 days (Section 7) |
| APP 13 (Correction) | Users can update their profile information at any time; correction requests answered within 30 days (Section 7) |
12. Changes to This Policy
We may update this Privacy Policy as the platform evolves. When we make material changes to our data handling practices, participating schools will be notified.
We encourage you to review this policy periodically. The “Last Updated” date at the top of this page indicates the most recent revision.
13. Contact Us
For privacy-related questions or concerns:
Leibniz Education Pty Ltd
ABN 18 692 154 162
36 Bangalla St, Warrawee 2074, NSW
Email: letterbox@leibniz.com.au
Website: leibniz.com.au
If you wish to make a complaint about how we have handled your personal information, please contact us at letterbox@leibniz.com.au. We will acknowledge your complaint within 5 business days, investigate the matter, and provide a written response within 30 days.
If you are unsatisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Schools may request a Data Processing Agreement (DPA) by contacting us at the address above.
14. Specific Feature Disclosures
14.1 AI Grading
When you submit an answer (typed or handwritten), the question, its solution, and your response are sent via a server-side API call to OpenRouter's United States gateway and an approved downstream endpoint for grading. For handwritten submissions, the image or PDF of your work is sent for vision-based grading and OCR extraction.
- Each OpenRouter request requires an eligible zero-data-retention provider and denies provider data collection; otherwise it fails closed
- Direct identifiers are not deliberately added to grading prompts, but free text or uploads may contain them. OpenRouter applies sensitive-information and prompt-injection redaction inside its gateway before downstream inference; coverage is not universal.
- Grading is processed per request; the necessary context may include marking criteria or prior feedback. Application records have their own retention schedule
- Provider routing is configured to deny data collection and exclude endpoints that cannot satisfy zero-data-retention
14.2 Adaptive Learning
Leibniz uses a statistical model to personalise question difficulty. This model operates on pseudonymised data (UUIDs, not names or emails) and stores only mathematical parameters representing estimated mastery per concept.
- Student data is not used to train or tune AI models, including when anonymised or aggregated
- Processing for personalised practice, grading and authorised school reporting remains part of the service
14.3 Progress and Teacher Reporting
For class-assigned work, your progress is visible to your assigned teacher and school administrator (see Section 4). Authorised school reporting may include class-level summaries.
14.4 Guest Usage Controls
Guest usage limits are enforced using a signed pseudonymous guest-session cookie and a server-derived network signal. Signed-in free accounts are metered against their authenticated account instead. For anonymous guest requests, a device fingerprint and request IP may also be mirrored into a legacy daily usage-metering record for compatibility analytics; that record is not the authoritative access decision and cannot increase or reset the signed-session allowance.
- School-provisioned Pro users are not subject to this guest quota; hosting and security request metadata are separate
- Used only for service metering and abuse prevention, not advertising or cross-site tracking
14.5 School Provisioning
For school subscriptions and pilots, the onboarding process works as follows:
- The school provides an email whitelist for students and teachers
- On first login, the system matches the user's email, assigns the appropriate role, and activates Pro access
- Teacher access is granted only to approved, school-provided addresses
- Students can only join classes belonging to their own school — cross-school access is blocked
15. Data Protection Commitments
Our commitments are detailed throughout this policy. In summary: primary application data is stored in Sydney, limited overseas processing is disclosed above, we never sell your data or use it to train AI models, primary deletion is transactional with durable verified storage cleanup and seven-day backup expiry, and access is restricted to authorised personnel under administrative MFA requirements. Schools can read and download our Data Processing Agreement. For full details, see the relevant sections above.
16. How We Use AI
This section summarises how personal information is used with artificial intelligence (AI) in Leibniz. It is linked from the sign-in page, so it is available before you create an account or submit any work.
What information is used
- The question, its marking guide and solution
- Your typed answer and working, or photos and PDFs of handwritten work you upload
- For question-idea search: the search text typed in
We do not deliberately add names or email addresses to AI requests, but anything written in an answer or on uploaded work is sent as it is.
Why it is used
- To mark answers and give feedback, and to read handwriting
- To search for and generate practice questions; generation uses curriculum content only
We do not use student information to train or tune AI models.
Who it is shared with
OpenRouter and the model providers it uses (DeepInfra and Google), listed in the sub-processor table. Voyage AI receives question-idea search text. Modal runs question generation on curriculum content only and receives no student information. Your teacher and school see the results as described in Section 4.
How long it is kept
- Every AI request that contains student input must use a provider that keeps no copy after answering and is not allowed to collect the data (zero data retention, provider data collection denied), so it is not retained or used for training
- The results we store — marks and feedback — are kept with your learning records and deleted as described in Section 5
- AI operational records are kept for 90 days
Your rights
- You can see your AI marks and feedback in Leibniz, and ask for access to or correction of your information (Section 7)
- Your teacher can see AI-assisted marks and feedback. If you think a mark is wrong, ask your teacher or contact us and we will have it reviewed and corrected
- You can delete your account from the Settings page (Section 5)
Stopping AI use or withdrawing consent
A school administrator can turn AI marking off for the whole school in Settings. While it is off, nothing students submit is sent to an AI model: students still answer by typing, handwriting or uploading their work, it is saved for their teachers, and it gets no marks or AI feedback. Work marked before the change keeps its marks. Students and parents should contact their school, or contact us at letterbox@leibniz.com.au and we will work with the school. Individual account holders can contact us directly or delete their account.
We will give schools advance notice before switching on any new AI feature that uses student information. The current version of AI marking and a dated history of changes are in our AI guidance.
This Privacy Policy is designed to be clear, comprehensive, and respectful of your privacy rights while enabling us to provide effective educational services.