Skip to main content

Legal

Privacy Policy

How Mathidia Mathematics Academy collects, uses and protects personal data, including the data of children.

Who we are

Mathidia Mathematics Academy operates mathidia.com and is the data controller for the personal data described here. For anything in this policy, including data requests, email support@mathidia.com or use the contact page. This policy applies worldwide and is written to meet UK GDPR and EU GDPR standards.

What we actually collect

Account information

Your name, email address, password (stored only as a secure hash), the role you sign up as, and your chosen curriculum. If you sign in with Google we receive your name, email and profile image from Google.

Learning data

Placement assessment answers and recommended track, first-week plan progress, lesson position and completion, practice and quiz attempts with your answers and scores, streaks, points and badges.

Child accounts

Where a parent adds a child, we store the child's first name, age group and curriculum, and a confirmation record linking the child to that parent.

Preferences

Accessibility and display settings, language, and speech settings such as chosen voice and reading speed.

Shared notes

If you share an attempt comparison, the note author's display name and the note text are stored against that share link.

Support and enquiries

Messages you send us through contact forms or email, and the email address you give if you subscribe to the newsletter.

What we do not collect

  • No advertising identifiers and no ad-network tracking anywhere on the platform
  • No file uploads — Mathidia has no learner file-upload or document storage feature
  • No payment card details are held by us; card data would be handled by a payment provider, and no card is required during beta
  • No microphone recordings are stored — spoken answers are transcribed by your browser on your device and only the resulting text is checked

Why we process it, and our legal basis

  • Contract — to create your account, deliver lessons, mark answers and keep your progress
  • Legitimate interests — to keep accounts secure, prevent abuse, and improve teaching quality
  • Consent — for non-essential cookies, the newsletter, and optional features you turn on; you can withdraw consent at any time
  • Legal obligation — to meet safeguarding, tax and record-keeping duties where they apply

Children's data

Accounts for learners under 13 are linked to a parent or school and confirmed by email to the responsible adult. There are no public profiles, no open messaging between learners and no advertising. Parents can view, correct, export or delete a child's records at any time. See the Child Safety page for the full safeguarding position.

Who processes data for us

  • Supabase — authentication, database and hosting of learner records
  • Google — optional Google sign-in, and Google Calendar links only when you choose to add study sessions
  • Resend — delivery of authentication and notification email from notify.mathidia.com
  • AI model providers — process lesson prompts and generated explanations; they are not permitted to use your data to train their models
  • Cloudflare — content delivery and application hosting

International transfers and retention

Our processors may handle data outside your country, including in the United States. Transfers rely on standard contractual clauses or an equivalent safeguard. Account and learning records are kept while your account is active and for up to 12 months after closure so progress can be restored, then deleted or anonymised. Support email is kept for 24 months. Newsletter addresses are kept until you unsubscribe.

Your rights

  • Access a copy of the data we hold about you
  • Correct anything inaccurate
  • Delete your account and its records
  • Export your learning records in a portable format
  • Object to or restrict certain processing
  • Withdraw consent, including cookie consent, at any time
  • Complain to your data protection authority

Security

All traffic is encrypted in transit with HTTPS, and data at rest is encrypted by our hosting provider. Passwords are hashed, never stored in readable form. Every learner record is protected by row-level access rules so an account can only reach its own data, with role checks enforced on the server rather than in the browser. Privileged administrative access is limited to named staff.

Related policies and changes

Read this alongside our Cookie Policy, Data Protection Information, AI Disclaimer, Acceptable Use Policy and Terms & Conditions. If we make a material change to this policy we will highlight it in the product before it takes effect.

Ready to begin?

Create a free account, tell us your age and curriculum, and get a study plan built around you.