For Schools
Everything your IT, DPO and procurement teams need to evaluate ArielEd.
At a glance
- UK data residency. All student data is stored in the UK (London region) via Supabase. No student PII leaves the UK.
- GDPR compliant. ArielEd Ltd is registered with the ICO and operates under UK GDPR.
- Anonymisation before AI processing. Student names, school names, teacher names, emails, phone numbers, and postcodes are stripped before any text is sent to the Anthropic API.
- Row-level security. Every database table uses Supabase RLS — a teacher can only access data for students in their own classes.
- HTTPS-only, security headers, hardened cookies. See Technical security.
- No advertising trackers. No Facebook Pixel and no advertising cookies. Google Analytics runs only if a visitor accepts analytics cookies, and never receives essay text or student names.
Data processed
When a teacher uploads a student essay, ArielEd processes:
- Essay text (typed or transcribed from a scan)
- Student name — first/last name as provided by the teacher
- Class membership — which class the student belongs to
- Marking results — AO scores, strengths, weaknesses, feedback
ArielEd does not process: home addresses, parent contact details, SEND status, attendance, pupil premium status, photographs, or any other safeguarding-sensitive data.
Sub-processors
ArielEd uses these sub-processors. All are GDPR-compliant; data residency is UK or EU only:
- Supabase (UK / London region) — database, file storage, authentication
- Vercel (London region) — application hosting
- Anthropic (US) — AI marking. Receives ONLY anonymised essay text. No student names, school names, or other PII reaches Anthropic.
- Stripe (UK/EU) — payment processing (school billing only — student data is never sent to Stripe)
- Resend (US) — transactional email only (password resets, marking-complete notifications)
Full sub-processor register including DPA details: contact [email protected].
Data Processing Agreement (DPA)
ArielEd will sign a Data Processing Agreement with any school or MAT before processing student data. Email [email protected]with your school name and we will send you our standard DPA (based on the ICO's recommended model clauses) within one working day.
Data retention and deletion
- Active data is retained while the school account is active.
- On account closure all student data is deleted within 30 days.
- Right to erasure requests can be submitted at /data-deletion. Processed within 30 days.
- Backups are retained for 30 days for disaster recovery only, then deleted.
Safeguarding
- ArielEd does not allow direct student-to-student communication.
- The platform produces no public profiles, leaderboards, or content visible to other students.
- Student data is only visible to (a) the student themselves, (b) the student's class teacher, (c) the Head of Department (if applicable) at the same school. Cross-school visibility is technically impossible.
- AI marking output is reviewed by a teacher before being released to students — students never see raw AI output without teacher approval.
- If you observe behaviour you believe could constitute a safeguarding concern arising from use of ArielEd, contact [email protected].
Technical security
- HTTPS only with HSTS (max-age 2 years, includeSubDomains, preload-eligible).
- Security headers: X-Frame-Options: SAMEORIGIN, X-Content-Type-Options: nosniff, Referrer-Policy: strict-origin-when-cross-origin, Permissions-Policy locks camera/microphone/geolocation/cohorts.
- Cookies: HttpOnly, Secure, SameSite=Lax. 7-day session lifetime.
- Authentication: Password-based with strong hashing. SSO available on request for MATs.
- Rate limiting: Per-user limits on all sensitive endpoints to prevent abuse.
- Database: Postgres with Row Level Security policies on every table. Service-role access is restricted to the backend.
- No raw API keys in source. All secrets managed by Vercel's encrypted environment variables.
Responsible disclosure
Found a security issue? Email [email protected]. We do not currently operate a bug bounty, but we acknowledge all reports within 72 hours and publicly credit responsible disclosure.
See /.well-known/security.txt for machine-readable details.
For your IT team
If your school's web filter is blocking ArielEd, please forward our whitelist guide to your IT team. It contains the exact domains, ports, and filter-categorisation submission links they will need.
Procurement contacts
- General enquiries: [email protected] or directly to founder [email protected]
- Data protection (DPO): [email protected]
- Safeguarding: [email protected]
- Security: [email protected]