Safety
What students can reach, and what happens to their work.
Every safeguard below describes something the product does. We would rather be specific than reassuring.
If your procurement process needs something this page does not cover, ask us directly and we will answer honestly about what we do and do not have.
No student keys
Students never reach a model directly
Private by default
Nothing is public until Published
Hard daily limits
Structural, not advisory
The four questions worth asking any AI tool
Ours, answered specifically. Ask the same four of anything else you are considering.
Safety, in four parts
Can a student reach the model?
“I just type to Ora.”
No. Every AI request is made by Ideora on the student's behalf. Students do not create, hold, or manage a model API key, and there is no path by which a student's browser talks to a model provider directly. There is nothing to leak because there is nothing in their hands to leak.
What a school should know
This also means no separate AI procurement, and no account a child could register for using a school email address.
How AI is reached
- Students never create, hold or manage a model API key.
- Every AI request runs through Ideora rather than from a student to a provider.
- Requests that are unsafe for the age range are refused.
- The language and behaviour throughout are written for Classes 6 to 12.
How work is separated
- Each Creation runs in its own sandbox with its own data.
- One student's Creation cannot reach another student's data.
- A Creation is private to the student who made it until it is Published.
- Publishing is always a deliberate action, never a default or a side effect.
How usage is capped
- Hard daily limits per project, set for a classroom rather than for an API.
- A project can show what it has used.
- Published Creations give each visitor a small free allowance of AI features.
- Past that allowance the Creation keeps working; only the AI part pauses.
What we will not tell you
We do not claim certification against any compliance standard — not COPPA, FERPA, GDPR, SOC 2 or ISO. Saying we hold one we do not would be false, and holding one is not the same thing as being safe for your students. If your process requires a specific standard, ask and we will tell you honestly where we stand rather than talk around it.
Why this page names no education board
Most platforms selling into schools lead with alignment to a named board or curriculum framework, and it is an effective sales line. We do not use it, because Ideora is not affiliated with or endorsed by any of them, and implying otherwise to win a sale would be dishonest.
What we can do is describe precisely what a student demonstrates: turning an open-ended problem into a specific plan, explaining an intention clearly enough for a system to act on it, testing something and changing direction, looking inside what they built rather than treating it as magic, and finishing with something that works. Your school is far better placed than we are to map that onto whatever framework you follow.
If a supplier tells you they are aligned to something, it is worth asking what that alignment consists of and who verified it. It is a fair question and it is one we would want asked of us.
Questions from procurement
Short, direct answers. If something here is not enough detail for your process, ask us for more.
No. All AI requests go through Ideora. Students never hold a model key and never talk to a provider directly.
No. Each Creation runs in its own sandbox with its own data, and stays private to the student who made it until it is Published.
The Creation gets a real web address that anyone with the link can open. It is a deliberate action taken by the student, and until they take it, nothing is public. Search engines are asked not to index Published Creations.
We do not claim any certification. This page describes the actual safeguards instead. If your process requires a specific standard, ask us directly and we will tell you honestly where we stand.
There are hard daily limits per project, and Published Creations give each visitor only a small free allowance. The limits exist specifically to make runaway usage impossible, and they are structural rather than advisory.
Enough to identify their account and return them to their own work: their Creations, the versions of those Creations, conversations with Ora inside the Studio, and usage figures that make the daily limits work. Our privacy page sets this out in full.
Ideora runs on Google Cloud infrastructure, including Firebase services. AI requests are processed by the model providers Ideora uses at the time of the request. Our privacy page has the detail.
Yes. Contact us and we will delete it and confirm when it is done. Where Ideora is provided through a school, the school can make that request on a student's behalf.
It is refused. Ora also stays within its scope — the project, its code, and how building software works — so questions outside that get a friendly decline and a redirect back to the project.
Ora does not attempt to counsel them and does not brush it off. It tells them kindly to speak to a trusted adult — a parent, their class teacher, or the school counsellor — today.
Still have a question we haven't answered?
Ask it directly. We would rather answer honestly than have you guess.