Ideora

Legal

Privacy policy

What we collect, why we collect it, and what happens to student work. Written to be read rather than to be survived.

Who this covers

This policy covers people who use Ideora — students creating Creations, teachers and school staff, and anyone who opens a Published Creation or contacts us through this website.

Where Ideora is provided through a school, the school decides which students have access. Questions about that decision are best directed to the school in the first instance; questions about what Ideora itself does with information belong here.

What we collect

Account information, so a student can return to their own work. This is the minimum needed to identify an account.

The Creations a student makes — the description they typed, the code produced, the versions kept, and any information their Creation saves while it runs.

Conversations with Ora inside the Studio, because they are part of building a Creation and are used to answer follow-up questions about it.

Usage information, including how much AI a project has used. This is what makes the daily limits work and lets a project show what it has consumed.

Anything you send us directly, such as a demo request through this website.

What we do with it

We use it to run the product: to build and show Creations, to let students return to their work, to keep version history, to enforce usage limits, and to answer questions people send us.

AI requests are sent to the model providers Ideora uses in order to produce a response. Students never hold a key or reach a provider directly.

We do not sell personal information, and we do not use student work to advertise to students.

Who can see student work

A Creation is private to the student who made it until somebody chooses to Publish it. Publishing is always a deliberate action.

Once Published, a Creation is at a web address that anyone holding the link can open. Students should be told this plainly, and they are, in the product.

Each Creation runs in its own sandbox with its own data. One student's Creation cannot reach another student's data.

Where a school provides Ideora, staff at that school may be able to see the work of students at that school.

Where information is held

Ideora runs on Google Cloud infrastructure, including Firebase services for accounts, stored data and files. Information may therefore be processed in the regions where those services operate.

AI requests are processed by the model providers Ideora uses at the time of the request.

How long we keep it

We keep a student's Creations and account for as long as the account is active, so that a student can come back to work they made earlier in the year.

If a school ends its use of Ideora, or a student asks for their work to be removed, contact us and we will delete it. We will confirm when it is done.

Your rights

You can ask what information we hold about an account, ask for a copy of it, ask us to correct it, or ask us to delete it. Where Ideora is provided through a school, the school may make these requests on a student's behalf.

Contact us through this website and we will respond. If we cannot do something you have asked for, we will tell you why rather than ignore it.

What we do not claim

We do not claim certification against any compliance standard. Describing safeguards we actually have is more useful to a school than naming a standard we do not hold. Our safety page sets out those safeguards in detail.

If your procurement process requires a specific standard, ask us and we will answer honestly about where we stand.

Changes to this policy

If this policy changes in a way that affects how student information is handled, we will say so rather than quietly update the page.