< Back to home

Privacy Policy

Version 1.1 · Last updated 27 July 2026

In shortWe collect the minimum a study tool needs. We never collect a student's email address, phone number or photograph. Student records are stored in Australia. Schoolwork - but not the student's name or account - is sent to our AI provider in the United States to be marked and explained. We do not sell data, we do not advertise, and no one trains an AI model on a student's work. We never send marketing to a student.
Graspera is operated by David Williams (ABN 50639154277), a sole trader, of 297 Miller Road, Bass Hill, NSW 2197. In this document, "we", "us" and "our" mean David Williams trading as Graspera.

1. Our commitment

Graspera is used by school students, most of whom are children. That shapes every decision in this policy. We collect as little as the product needs, we keep student data in Australia, we do not sell it, we do not advertise to students, and we do not let anyone train an AI model on a student's work.

A note on the law. As a small business under the $3 million annual turnover threshold, Graspera is not currently required to comply with the Privacy Act 1988 (Cth). We have chosen to comply with the Australian Privacy Principles (APPs) anyway, and we hold ourselves to this policy as if the Act applied to us. We also intend to meet the OAIC Children's Online Privacy Code once it is registered.

This policy explains what personal information we handle, why, where it goes, and what you can do about it. If anything here is unclear, email admin@graspera.au and we will explain it in plain terms.

2. Who this policy covers

This policy applies to:

  • parents and guardians who hold an account;
  • students whose accounts are created by a parent, guardian or school;
  • teachers and school staff who use the Service; and
  • visitors to our website.

Where a school uses Graspera, the school also has its own privacy obligations to its students. This policy describes what we do; it does not replace the school's own privacy policy.

3. What we collect

3.1 From parents and guardians

InformationWhy we need it
Email addressTo identify the account, sign you in, and send account and billing notices.
PasswordStored only as a cryptographic hash by Google Firebase Authentication. We never see or store your actual password.
Name (if provided)To address you correctly in the Service and in correspondence.
Billing details, where a paid plan appliesHandled by our payment processor. We receive a record that a payment succeeded, not your full card number.

3.2 From and about students

We do not collect a student's email address, phone number, home address, photograph or school class list. A student signs in with a username issued by the account that created them. Internally the system converts that username to a non-deliverable address so that Google Firebase Authentication can identify the account. No mail can be sent to it and it is never shared.

The fields a parent or school supplies when creating a student are:

FieldWhy we need it
First name or preferred nameSo the student is addressed by name in the app.
Age and year levelTo pitch questions at the right level and to apply age-appropriate settings.
Avatar style and seedA generated cartoon avatar. It is not a photograph and does not identify the student.
Country and curriculum packageTo select the correct syllabus, currently the NSW Stage 6 curriculum.
SubjectsTo decide which practice content to offer.
UsernameFor the student to sign in. Choose one that is not the student's full name.
PasswordSet by the parent or school, stored only as a hash.

3.3 Learning activity

As the student uses the Service we record what is needed to show progress and to mark work: questions presented, answers and working submitted, marks and feedback, hints used, time taken, and study session timestamps.

3.4 From teachers and schools

Name, work email address, school, role, and the seats allocated to that school. Where a school agreement exists, we also hold the agreement and the contact details of the school's authorised representative.

3.5 Technical and security information

  • IP address, browser and device type, and pages requested, in server and security logs.
  • Session tokens stored in your browser so you stay signed in.
  • Error and performance diagnostics when something in the app fails.
  • Administrative audit records of significant actions - for example that a parent created or deleted a student account, and when. These record who did what and when, not the content of a student's work.

3.6 How the Service is used

For each account we keep a simple record of use, so we can tell which parts of Graspera are worth building on and when people need them. For each day, we record: how many times the account signed in, roughly how many minutes were spent actively using it, which hours of the day those minutes fell in, and how many times each AREA of the Service was opened - for example practice, quizzes, the study planner or the coach.

We record the area, never the page. We do not keep a list of pages visited against your account, so this record cannot say which student, which assessment, which quiz or which class was opened. It holds counts and nothing else - no question, no answer, no piece of a student's work, and no address or device.

We use it to decide what to improve and when to offer help, and to plan our own announcements. We do not sell it, we do not share it with advertisers, and we do not use it to make automated decisions about anybody. It is kept for as long as the account exists and is deleted with the account.

3.7 When you contact us

Support messages, the email address you sent them from, and our replies.

3.8 What we never collect

  • Student email addresses, phone numbers or home addresses.
  • Photographs, video or voice recordings of students.
  • Precise location data.
  • Health information, or any other sensitive information as defined by the Privacy Act, except where a parent volunteers it to us in a support request.
  • Information from advertising networks, data brokers or social media trackers. We do not run any.

4. Why we handle it

We use personal information only for these purposes:

  • to create and run accounts, and to sign people in securely;
  • to generate practice questions, mark answers and produce feedback and progress reports;
  • to show a parent, and where enabled a teacher, how a student is progressing;
  • to provide support when you ask for it;
  • to bill accounts on a paid plan, and to keep the financial records the law requires;
  • to keep the Service secure, to investigate misuse, and to protect users - particularly child users;
  • to improve the Service, using aggregated and de-identified information wherever that is sufficient; and
  • to meet our legal obligations.

We do not use personal information for behavioural advertising, for profiling unrelated to study, or for any automated decision that has a legal or similarly significant effect on a person.

5. The AI features and what is sent to them

The Service uses AI models supplied by Anthropic PBC (the Claude family of models) to generate questions, mark answers and explain solutions. This section explains exactly what leaves our systems.

5.1 What is sent

  • The text of the question being worked on.
  • The answer and working the student submitted.
  • The subject, module and year level, so the model marks against the right standard.
  • The question the student typed, where they use a free-text study question.

5.2 What is not sent

We do not send the student's name, username, age, avatar, account identifier, school, parent details, or any other account information to the AI provider. The provider receives the schoolwork, not the identity of the child who wrote it.

Students should still avoid typing personal details into free-text boxes. We remind them of this in the app.

5.3 Training

Under our commercial agreement with Anthropic PBC, content submitted through their API is not used to train their models. We do not use student work to train any model of our own.

5.4 The limits of the AI

AI marking and explanations can be wrong. We check generated questions and marks against our own independent solvers where we can, but errors get through. See the AI and Academic Integrity Statement for the detail.

6. Where information is stored

Our database, file storage and application logic run on Google Cloud Platform (Firebase) in the australia-southeast1 (Sydney, Australia) region. Student records, learning history and audit records are stored there.

Two exceptions are worth stating plainly, because we would rather tell you than have you discover them:

  1. Google's authentication service, which holds sign-in credentials and password hashes, is a global Google service. Google may process that credential data in data centres outside Australia. It does not contain a student's learning history.
  2. Text sent to the AI provider is processed in the United States, as described in section 7.

7. Overseas disclosure

Plainly stated: when a student submits an answer for marking or asks a study question, the text of that schoolwork is sent to Anthropic PBC, a company in the United States of America, which processes it and returns the mark or explanation. No name, username or account identifier is sent with it.

Australian Privacy Principle 8 requires us to tell you about disclosures of personal information to overseas recipients. The recipients are:

RecipientCountryWhat they receive
Anthropic PBCUnited States of AmericaQuestion text, submitted answers and working, and free-text study questions. No identifying account data.
Google LLC (Firebase Authentication)United States and other Google regionsSign-in credential data and password hashes. No learning history.

Before using an overseas provider we take reasonable steps to satisfy ourselves that it handles information in a way consistent with the APPs, including by reviewing its published security, retention and sub-processor commitments and contracting on its commercial terms rather than consumer terms.

If you do not want schoolwork processed overseas, the AI marking and explanation features cannot be provided to that account. Contact us and we will discuss what is possible.

8. Who else can see the information

8.1 The people you would expect

  • The parent or guardian who holds the account can see their own students' work and progress.
  • A teacher can see a student's work only where that student's own parent or guardian created the teacher's account and named the subjects the teacher may see. It is off until the parent or guardian does that, it covers only the subjects they name, and they can end it at any time. Nothing a school does switches it on, and a school's own staff accounts carry no access to a student's work.
  • Our own staff, only where needed to run the Service, provide support, or investigate a security or safety issue - and subject to confidentiality obligations.

8.2 Service providers

ProviderRole
Google (Firebase, Google Cloud)Hosting, database, authentication, file storage and application logic.
Anthropic PBCAI question generation, marking and explanation.
Payment processorHandling card payments, where a paid plan applies. We do not store full card numbers.
Email delivery providerSending account and support email to adults. We do not send email to students.

Every provider in that table is bound by a written agreement that requires it to protect the information, to use it only to provide the service we have engaged it for, not to use it for its own purposes, not to disclose it to anyone else except as that agreement allows, and to return or delete it when our arrangement ends. We choose providers that publish their security practices, and we review that choice.

8.3 Legal and safety

We may disclose information where required by law, or where we reasonably believe it is necessary to prevent a serious threat to a person's life, health or safety - particularly a child's. Our Child Safety Policy explains exactly what we do, and who we contact, if we become aware that a student may be at risk of harm.

8.4 What we never do

  • We do not sell personal information.
  • We do not disclose personal information to advertisers or data brokers.
  • We do not allow third-party advertising or tracking scripts in the Service.
  • We do not disclose one family's data to another family, or one school's data to another school.

8.5 If the business changes hands

If the Service is sold or transferred, personal information may transfer with it. We would notify Account Holders beforehand, and any acquirer would be bound by commitments no less protective than this policy.

9. Children and young people

Most students using Graspera are under 18, and many are under 15. The design reflects that:

  • A child cannot create an account. Only a parent, guardian or authorised school can.
  • The consent that matters is the parent's or guardian's, given when they create the student account. A child cannot give that consent for themselves.
  • No email address, phone number or photograph is collected from a student.
  • There is no public profile, no friend list, no direct messaging between users, and no way for a student to be contacted through the Service by anyone outside their own account.
  • There is no advertising and no behavioural profiling.
  • At first sign-in, a student is shown a short plain-English explanation of what Graspera records about their work and who can see it.

The OAIC is developing a Children's Online Privacy Code, which must be registered by 10 December 2026. We expect it to apply to Graspera and we are building to it. When it is registered we will review this policy against it and publish any changes.

A student aged 15 or over may ask us directly to access or correct their own information, and we will consider whether they have the capacity to make that request on their own behalf. Requests to delete an account come from the Account Holder.

10. Cookies and browser storage

We use only what the Service needs to function. There are no advertising cookies and no third-party analytics trackers.

WhatPurpose
Authentication tokenKeeps you signed in between page loads. Cleared when you sign out.
Local preferencesRemembers small interface choices on your device.
Offline app cacheLets the app load quickly and work with an unreliable connection.

You can clear these through your browser settings. Clearing the authentication token signs you out.

11. Email and direct marketing

We never send marketing to a student. Not now, and not if the business grows. Students do not give us an email address, and we do not obtain one for them.

11.1 Email we send because you have an account

Some email is not marketing and you cannot unsubscribe from it, because without it the Service does not work. That is limited to: confirming your account, resetting a password, receipts and billing notices, changes to these documents, security and outage notices, and answers to a support request you made.

11.2 Marketing email

Anything else - product news, tips, offers, a survey - is marketing. We send it only to an adult Account Holder, teacher or school contact, and only where that person has chosen to receive it. We treat the Spam Act 2003 (Cth) as binding on us, so every marketing message we send will:

  • be sent only with consent, which you give by ticking a box rather than by us assuming it from silence, and which you can withdraw at any time;
  • identify us clearly as the sender and include accurate contact details, including support@graspera.au; and
  • contain an unsubscribe link that works, is free, and does not ask you to sign in, give a reason, or provide any information you have not already given us.

We action an unsubscribe request within 5 business days of receiving it, which is the period the Spam Act allows. In practice it is usually immediate. You can also unsubscribe by emailing admin@graspera.au with the word "unsubscribe", and we will treat that as a valid request even though it did not come through the link.

11.3 What we do not do

  • We do not buy, rent or scrape email addresses.
  • We do not send marketing to an address a school gave us for administrative purposes, unless that person separately opts in.
  • We do not use a student's work, results or study patterns to target marketing at anyone, including at their parent.
  • We do not pass your address to another business so that it can market to you.

We keep a record of the consent you gave, when and how you gave it, and when you withdrew it. That record exists so we can prove we had permission, and so an unsubscribe is not quietly lost. If you want to see the record we hold for you, ask.

If you receive marketing from us that you did not consent to, tell us at admin@graspera.au and we will stop it and find out why. You may also complain to the Australian Communications and Media Authority at acma.gov.au.

12. How we protect information

  • All traffic is encrypted in transit using TLS, and data is encrypted at rest by our cloud provider.
  • Passwords are stored only as cryptographic hashes; we cannot read them.
  • Database access rules restrict every record to the accounts entitled to see it, enforced on the server rather than in the browser.
  • Administrative actions are recorded in an audit trail.
  • Access to production systems is limited to those who need it and protected by multi-factor authentication.
  • API keys and credentials are held in a managed secret store, not in our source code.

No online service can promise perfect security. If you believe you have found a vulnerability, please tell us at admin@graspera.au before disclosing it publicly. We will not pursue action against anyone who reports a genuine issue responsibly.

13. How long we keep it

InformationRetention
Student account and learning historyWhile the account is active. Deleted within 30 days of the Account Holder requesting deletion.
An account a student under 18 set up that a parent or guardian has not approved30 days from when we asked them, then the account and everything on it is deleted. The same 30 days applies if they say no. Until somebody answers, the account cannot be used at all.
Email we have sent youThe queue keeps a copy of each message - who it went to and what it said - for 30 days, so that a message that failed can be sent again and a question about one can be answered. Then it is deleted.
How much of each day's allowance an account has usedA count per account per day: how many coach turns, tutor questions and decks. It holds no question, no answer and no topic - only how many. Deleted after 60 days.
A hashed record that one visitor used the free previewNot an address. A one-way hash of it that is different the next day, so the preview can be capped at 20 questions without anyone being followed from one day to the next. Deleted after 60 days.
A record that a page stopped workingWhat went wrong and which screen it was on, with any account id taken out of the address before it leaves your browser and again when it arrives. No name, no email address and nothing you wrote. Deleted after 60 days.
How many people opened the site and how many finished signing upTotals for each day, and nothing else: no address, no device, no cookie, nothing that could be joined back to a person or to one visit. It records that a page was opened, not who opened it, and it records the reason a sign-up did not finish - a password that did not match, an address already registered, an age below our floor - as a count, so we can tell whether the way in is working. Kept indefinitely, because a total about nobody is the only record here that does not age into a risk.
Accounts inactive for 24 monthsWe contact the Account Holder, and delete the student records if there is no response within 60 days. Signing in is the response - there is nothing to click in the email.
When an account was last usedOne date per account, and the date we contacted an inactive one. It is what the row above is measured against. Deleted with the account.
A copy of your data that you asked us to build7 days, then deleted automatically. Only your account can open it and no link to it is emailed.
Parent, teacher and school account recordsWhile the account is open, then up to 12 months after closure to handle disputes.
What the coaches did - which coach ran on which turn, what it cost, what it refusedKept indefinitely. It carries no part of what your child wrote. It is how we can answer a question about our own behaviour, including a refusal, after the work itself has been deleted.
Billing and tax records7 years, as required by Australian tax law.
Security and audit logsUp to 24 months.
Support correspondenceUp to 24 months.
Marketing consent and unsubscribe records5 years after the consent is withdrawn, so we can show we had permission and that we acted on the withdrawal.
Privacy complaints and our responses7 years from when the complaint is closed.
Child safety concerns, and any report we make7 years from when the matter is closed, or until the youngest student involved turns 25, whichever is later. These records are held separately from ordinary account data and are accessible only to the person handling the matter.
Data breach assessments and notifications7 years from the date of the assessment, whether or not the breach was notifiable.
BackupsA copy of the whole database is taken every night and kept for 30 days, so that a failure or a mistake can be undone. A record you delete is gone from Graspera straight away and gone from the last copy holding it within 30 days. Nothing reads a backup in the ordinary running of the product.

Where we no longer need information and are not required to keep it, we delete it or de-identify it.

14. Accessing, correcting and deleting information

You can ask us to:

  • give you a copy of the personal information we hold about you or a student in your account;
  • correct anything inaccurate or out of date;
  • delete a student account and its learning history; or
  • close your own account and delete your records, subject to the retention periods in section 13.

The first and the last of those you can now do yourself, without asking us and without waiting: Settings has a Your data section with a button that builds a copy of everything on your account as one file, and a button that closes the account and deletes it. The copy is deleted from our servers a week after it is made, and only your account can open it. Deleting a single student is on that child’s page.

For anything else, or if you would rather we did it, email admin@graspera.au. We will respond within 30 days and there is no charge. We may need to verify your identity first, and for a request about a student we need to confirm you are the Account Holder for that student.

If we refuse a request we will tell you why in writing and explain how to complain.

15. Data breaches

We maintain a data breach response plan. If a breach occurs that is likely to result in serious harm to any individual, we will notify the affected Account Holders and the Office of the Australian Information Commissioner as soon as practicable, and in any case consistently with the Notifiable Data Breaches scheme, whether or not that scheme strictly applies to us.

Where a breach affects students, we will also notify the relevant school so that it can meet its own obligations.

16. Complaints

If you think we have mishandled personal information, email admin@graspera.au with the details. We will acknowledge within 5 business days and give you a written response within 30 days.

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner:

The OAIC will normally ask that you have complained to us first and given us 30 days to respond. You do not have to wait if you would rather not, and we will not treat you differently for going straight to them.

If your complaint is about marketing email rather than privacy, the Australian Communications and Media Authority handles it, at acma.gov.au. If it is about a consumer matter - billing, a refund, or something we promised and did not deliver - see clause 19 of the Terms of Service, which names the bodies you can go to.

17. Changes to this policy

We will update this policy as the Service changes and as the law changes, including when the Children's Online Privacy Code is registered. Where a change materially affects how we handle personal information, we will notify Account Holders by email at least 30 days before it takes effect.

The version number and date at the top of this page always reflect the current version.

18. How to contact us

Privacy enquiries, access and correction requests, and complaints:

David Williams trading as Graspera
ABN 50639154277
297 Miller Road, Bass Hill, NSW 2197
admin@graspera.au

Questions about this document? Email admin@graspera.au.