We take the security of teacher and school data seriously. This page summarises our technical controls. Report a vulnerability to [email protected] (see also our security.txt).
In transit & hosting
- All traffic is served over HTTPS/TLS; HTTP is redirected to HTTPS.
- HSTS is enabled (2-year max-age, preload) to force secure connections.
- Hosted on Hetzner cloud servers in the EU (Germany).
Application security
- Security headers: Content-Security-Policy, X-Frame-Options (DENY), X-Content-Type-Options (nosniff), Referrer-Policy, Permissions-Policy.
- Authentication via industry-standard session tokens; hCaptcha protects sign-up/sign-in against bots.
- Access controls gate every account-scoped resource; the image optimiser is locked to an allow-list of image hosts.
- Payments are handled entirely by Stripe - we never see or store card numbers.
Data & deletion
- You can export your content (editable PowerPoint, Word, Google Slides/Docs and PDF) and it is yours to keep.
- Accounts can be deactivated and personal data erased on request - see our Privacy Policy.
- Third-party processors are listed on our Subprocessors page.