Privacy Policy

How we collect, use and protect your personal data. Last updated October 2026.

1. Who We Are

LessonHQ Ltd operates the LessonHQ platform at www.lessonhq.us. We are the business responsible for personal data collected through this platform. Contact us at [email protected] with any privacy queries.

2. Data We Collect

When you use LessonHQ we may collect: • Account data: name, email address, username, hashed password, and a 6-digit sign-up code emailed to confirm your address • Age data: your date of birth, used to confirm you are 18 or over • School data: school name and where you teach (state), and, if you use the school brand kit, the school name, brand colour and logo image you upload (stored with your account) • Uploaded files: the text from PDF, Word or PowerPoint files you upload to build a resource • Pupil data you choose to enter: pupil first names (Report Writer, Markbook, homework-link completions) and pupil answers you paste into the Marking Assistant. We advise using first names or initials only • Profile data: school email domain, subscription plan, pack generation history • Student portal data: where you create student profiles, we store a nickname (no real name required), grade level, standards framework and chosen subjects, plus the study sessions generated for that profile • Payment data: processed by Stripe - we never see or store your full card details • Usage data: packs generated, slide decks created, marketplace listings and purchases • Communications: emails sent via Resend, support enquiries • Technical data: IP address, browser type, device information (via standard server logs) When you sign in with Google, we receive your name, email address, and a Google account identifier from Google's OAuth service. We do not receive or store your Google password, contacts, Google Drive files (other than files our application creates on your behalf), or any other Google account data.

3. How We Use Your Data

We use your personal data solely to: • Provide and maintain your LessonHQ account • Process subscription payments and marketplace transactions • Send account emails (sign-up codes, receipts, trial reminders, password resets) and, unless you unsubscribe, a few tips emails • Measure visits to our site and the performance of our adverts (Google Analytics and the Meta Pixel) • Detect and prevent fraud and abuse • Comply with legal obligations We use Google Analytics and the Meta Pixel to measure visits and our adverts. We do not sell your data to third parties. IMPORTANT - Google User Data: Information obtained via Google's OAuth service (your name, email, Google account identifier) is used ONLY to authenticate your account and to create Google Slides or Google Docs files on your behalf when you explicitly request an export. Google user data is NEVER used to train AI models, NEVER sent to third-party AI services (including OpenRouter, Groq, or Gemini), and NEVER used for any purpose other than directly providing our service to you.

4. Third-Party Services and Data Sharing

We share data with the following third-party processors only as necessary to provide our service: • Stripe - payment processing. Receives your payment card details directly. We never see or store card numbers. (stripe.com/privacy) • Resend - transactional email delivery. Receives your email address to deliver account emails. (resend.com/privacy) • hCaptcha - bot and fraud prevention on sign-up and sign-in forms. (hcaptcha.com/privacy) • Hetzner - cloud server hosting in Germany (EU). Your account data is stored on Hetzner servers. (hetzner.com/legal/privacy-policy) • Google LLC - we use Google's OAuth service for sign-in and (when you choose to export) Google's Slides, Docs and Drive APIs to create files in your Google Drive. (policies.google.com/privacy) • Google Analytics and Meta (Meta Pixel) - measuring site visits and the performance of our adverts, using cookies and similar technologies. (policies.google.com/privacy, facebook.com/privacy/policy) • Cloudflare - Web Analytics (Cloudflare Insights) and, as one of our AI providers, Workers AI. (cloudflare.com/privacypolicy) • Microsoft Azure Translator (UK South) and Google Cloud Translation - translating Irish, Welsh and Scottish Gaelic resources. They receive lesson text only, never pupil or account details. • Image libraries (Unsplash, Pexels, Wikimedia Commons) - finding photos for slides and documents. They receive topic keywords only. AI generation services: When you generate a resource, what you type or upload for that resource is sent to one of the following AI providers as a fallback cascade: Cerebras, Groq, Google Gemini, Cloudflare Workers AI, or OpenRouter. This means your topic and curriculum settings, the text of any file you upload (PDF, Word, PowerPoint), and, only for tools that work with pupil work (Report Writer, Marking Assistant), any pupil first names or answers you enter. No Google user data and no account details are included in these requests. Our full list of processors is on our Subprocessors page. We do NOT transfer, sell, or disclose your personal data to any other third parties.

5. Google API Data - Limited Use Disclosure

LessonHQ's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: • Google user data (name, email, Google account ID) obtained via Google OAuth is used ONLY to authenticate your LessonHQ account and to create export files (Google Slides / Google Docs) in your own Google Drive when you explicitly request an export. • We do NOT use Google user data to train, improve, or fine-tune any AI or machine learning model. • We do NOT share Google user data with OpenRouter or any third-party AI service. AI generation uses only what teachers type or upload for a resource - it is architecturally isolated from Google OAuth data. • We do NOT use Google user data for any purpose unrelated to providing the LessonHQ service directly to you. • Google Drive files created by LessonHQ on your behalf are accessible only to you (and temporarily to our server during the export process). We do not retain, read, or analyse the contents of your Google Drive.

6. Data Protection Mechanisms

We implement the following technical and organisational measures to protect your personal data: • Encryption in transit: All data between your browser and our servers is encrypted via HTTPS/TLS. • Encryption at rest: Database credentials and API keys are stored as environment variables, never in source code. Database connections use password authentication over encrypted channels. • Access controls: Google OAuth tokens (access tokens and refresh tokens) are stored encrypted in our database and are only accessible server-side during export operations. They are never exposed to the browser or to third-party services. • Minimal data retention: We store only the Google account identifier, name, and email from Google OAuth - no Google Drive contents, no contacts, no calendar data. • Isolated AI pipeline: The AI generation pipeline is a separate code path from the Google OAuth pipeline. There is no code path that allows Google OAuth tokens or profile data to flow into AI generation requests. • Regular security reviews: We review our data handling practices regularly and update this policy accordingly.

7. Data Retention & Deletion

We retain your account data for as long as your account is active. Deactivation: You can deactivate your account at any time from Account Settings. This closes your account, cancels any active subscription, and removes your listings from the marketplace. Your personal data is retained in case you wish to return. Permanent erasure: You can request permanent erasure of your personal data directly from Account Settings ("Permanently erase my data"), or by emailing [email protected]. When you do, your account is closed immediately and your personal data (name, email, login credentials, date of birth, school name, and any connected Google account tokens) is irreversibly anonymised after a 30-day grace period. The grace period protects against accidental or fraudulent requests. What we keep after erasure, and why: To protect teachers who have bought resources from you, any packs you have sold remain available to those buyers, and the associated transaction, purchase and earnings records are retained in anonymised form for financial and legal compliance for up to 7 years (as required by US federal and state tax law). These records no longer identify you personally. Google OAuth tokens are deleted when you disconnect your Google account, deactivate, or erase your account. We will respond to any erasure request sent by email within 30 days.

8. Your Rights (US State Privacy Laws)

Depending on your state of residence - including under the California Consumer Privacy Act (CCPA/CPRA) and comparable state privacy laws - you have the right to: • Know what personal information we collect and how it is used • Access a copy of the personal information we hold about you • Request deletion of your personal information - you can do this yourself from Account Settings, or by contacting us • Correct inaccurate personal information • Opt out of the "sale" or "sharing" of personal information, and of targeted advertising LessonHQ does NOT sell or share your personal information, and we do NOT use it for targeted advertising, so there is nothing to opt out of. We will not discriminate against you for exercising any of these rights. Most actions are available directly from your Account Settings; for anything else, contact [email protected] and we will respond within the time required by applicable law (generally 45 days). As explained in Section 7, certain anonymised financial records are retained where the law requires it even after deletion.

9. Children's Privacy (COPPA)

In compliance with the Children's Online Privacy Protection Act (COPPA), LessonHQ does not knowingly collect personal information directly from children under 13. The student portal is designed to be managed entirely by a parent or guardian. Children do not create accounts, provide an email address, or log in. A parent creates and controls each student profile and, in doing so, provides consent for the limited information it holds: a nickname (no real name required), grade level, standards framework and chosen subjects - never a child's email, login, contact details or precise location. We do not show children advertising, and we do not use a student's study activity for any purpose beyond providing the learning features the parent has enabled. A parent may review, or delete, a student profile and all of its associated data at any time from the portal dashboard, or by emailing [email protected]. If you believe we have inadvertently collected information from a child without parental consent, contact us and we will delete it promptly.

10. Cookies

LessonHQ uses essential cookies for authentication (session management) and security (hCaptcha). We also use analytics and advertising cookies (Google Analytics and the Meta Pixel) to measure visits to our site and the performance of our adverts. These are on by default; you can opt out at any time using "Cookie settings" at the bottom of every page. Cloudflare Web Analytics counts visits without cookies. You can also block or clear cookies in your browser settings, though blocking essential cookies may prevent you from signing in.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email. Continued use of LessonHQ after changes constitutes acceptance of the updated policy. Last updated: October 2026