◂◂ POLICIES
What information the OLNA Trainer, the NAPLAN Trainer and the Scholarship Trainer collect about students, why we collect it, who sees it, where in the world it lives, and how a school or a parent gets it back or gets it deleted.
Any Trainer can be taken by a school for its students, or by a family — a parent or guardian subscribing for their own child. What we collect about a student is the same either way. What differs is who we deal with, and that a family subscription means we hold a parent's email address and a billing record, which a school subscription does not. Clauses limited to one route are marked SCHOOL or FAMILY.
R2 Education ("we", "us", "our") is an Australian sole‑trader business that builds and runs three practice tools for Western Australian school students:
This policy covers the homepage at r2education.com.au, all three Trainers, and every supporting system we run for them. Where the Trainers behave differently, the difference is marked with a badge like the ones above — please read those closely, because on two points (writing storage and data location) they genuinely differ.
Read it alongside our Terms of Use and our Security Policy.
R2 Education is a small business operator and may fall under the $3 million annual turnover threshold at which the Privacy Act 1988 (Cth) applies automatically. We do not rely on that exemption. We handle personal information as though bound by the Australian Privacy Principles (APPs), including the Notifiable Data Breaches scheme in Part IIIC. Where a school or department needs that commitment in a contract, we will sign it.
A WA public school is itself bound by the Privacy and Responsible Information Sharing Act 2024 (WA) and by confidentiality obligations under the School Education Act 1999 (WA). Our practices are built so a school can meet those obligations while using our Trainers, and we will help it do so.
Data location. All three Trainers' databases are in Sydney, so accounts and practice history stay in Australia. AI marking is still processed in the United States. Section 9 sets this out in full.
Writing responses. The OLNA Trainer stores the text of a student's writing along with its AI feedback. The NAPLAN Trainer does not — it marks and discards. Section 4.4 explains both.
All three Trainers are supplied either to a school, for its students, or to a family, for its own child. Which one it is shapes everything below.
We are a service provider to the school. It is the school, not us, that holds the relationship with the family.
If a school needs a data processing agreement, a departmental online‑services assessment or a privacy impact assessment before deploying, email hello@r2education.com.au and we will complete it.
There is no school in the middle, so we deal with the parent or guardian directly. That has three consequences worth being plain about.
This is a complete inventory. If something is not listed here, we do not hold it.
Created by a teacher or school administrator, or — on a family subscription — by us, from what the parent tells us at sign‑up. Identical across the Trainers. On a family subscription the class group and teacher notes fields are simply not used.
| Field | What it is | Why |
|---|---|---|
| Username | A short login name set by the school. Not an email address. | Identifies the account at sign‑in. |
| Display name | The name shown in the app — usually a first name, or first name and initial. The school chooses how identifying it is. | Personalises the app, certificates and teacher reports. |
| Password (hashed) | A one‑way bcrypt hash. We never store, and cannot recover, the password itself. | Verifies sign‑in. |
| Year group | The student's year level. | Serves year‑appropriate questions and marks writing to the right standard. |
| Adjustment setting | Whether the student gets extra time or another adjustment, and how many minutes. See the warning below. | Applies the right timing in practice tests. |
| Practice level flag | An optional teacher setting that holds practice questions at the easier level. | Pitches practice appropriately. |
| Class group | Which class group(s) the student is in. | Scopes a teacher to their own classes. |
| Subject / year access | What the school has unlocked for the student. | Controls what they can open. |
| Active status | Whether the account can be used. | Lets a school disable an account without deleting its history. |
| Teacher notes | Free text, 500 characters max. Also where the app records questions a student has flagged for help. See the warning below. | Supports teaching. |
The adjustment setting can imply something about a student's disability or health, which is sensitive information under the Privacy Act and gets stronger protection. We hold it only as a category and a number of minutes — never a diagnosis. Please do not enter diagnostic detail anywhere in any Trainer.
The teacher notes field is free text, so what goes in it is entirely the school's choice. Use it for short teaching observations. Health, behavioural, welfare, family and child‑protection information belongs in the school's own records system, which is built for it.
Username, display name, bcrypt password hash, administrator status (full administrator or class‑scoped teacher), and the class groups a class‑scoped teacher is assigned.
| Trainer | What happens to a student's writing |
|---|---|
| OLNA | Stored. When a student submits writing for marking, we save the essay text, the prompt it answered, the word count, and the full AI feedback including the level and score, against that student's record. Teachers can review it, and a student can see their own history. It is deleted when the student's account is deleted. |
| NAPLAN SCHOLARSHIP |
Not stored. The response is sent for marking, the feedback is shown on screen, and nothing is written to our database. Once the student leaves the page we no longer hold it, and it appears in no teacher report. A student who wants to keep a piece must save or print it. |
In both cases the response text is transmitted to our AI provider to be marked (section 9), and in neither case is it used to train an AI model.
Every AI call is metered so we can control cost and enforce fair‑use limits: the function called, the model, the outcome, token counts, cost, duration, the account that called it, and the year level, topic and difficulty requested. No question content, student answers or writing responses go into these records.
Collected only where a family subscribes directly, and entered by the parent on the sign‑up form on the Trainer's website. A school subscription involves none of this.
| Field | What it is | Why |
|---|---|---|
| Parent name | The name of the parent or guardian holding the subscription. | So we know who we are dealing with, and who is entitled to the student's records. |
| Parent email address | One email address per subscription. It is also the parent's sign‑in username. | Signing in to the parent dashboard, receipts, cancellation confirmations, service and policy notices. It is also how we verify a request about the child's data. |
| Parent password | Chosen by the parent on the sign‑up form. Stored only as a one‑way bcrypt hash — the plaintext is never written to a database or a log. | Signing in to the parent dashboard. |
| Which students it covers | The link between the parent and the student account or accounts they subscribed for. | Ensures a parent sees their own child's progress and no one else's. |
| Subscription status | Whether it is active, cancelled or lapsed, and the date the current period ends. | Controls access, and works out when the subscription stops. |
| Payment reference | The identifier Stripe gives the customer and the subscription. An opaque reference — not a card number, not a bank account. | Lets us match a payment to a subscription, and issue a refund if one is due. |
| Billing records | Amount, date and outcome of each charge, and any refund. Kept for tax purposes. | Required by Australian tax law (section 12). |
Payment is handled entirely by Stripe. Your card number is entered on Stripe's own checkout page and goes directly to Stripe. It is never transmitted to, processed by, logged by or stored on any system we run, and neither is your bank account, your CVC or your billing address. What we hold is the opaque reference above and the amount charged.
This is not just a privacy nicety — it is why a compromise of our systems could not expose anyone's card, and why we have no ability to charge you outside the subscription you set up.
No Trainer has any facility to collect these, and we hold none of them:
| Not collected | Not collected |
|---|---|
| Student email addresses | Card numbers, CVCs or bank account details |
| Dates of birth | Home or postal addresses |
| Phone numbers | Photographs, video or audio |
| Government identifiers (WASN, USI, Medicare, TFN) | Biometric data of any kind |
| Health records or diagnoses | Precise location or GPS data |
| Contacts, camera roll or device files | Cultural, religious or political information |
| Advertising or behavioural profiles | Anything about a parent beyond 4.7 |
Version 1.0 of this policy listed parent or carer contact details as never collected, which was true when we supplied schools only. Now that families can subscribe directly, we hold a parent's name and email address on a family subscription — set out in full at 4.7. We would rather correct the claim than leave a tidier sentence standing that is no longer accurate.
SCHOOL On a school subscription nothing has changed: we still hold no parent or carer contact details of any kind.
There is no third‑party analytics anywhere — no Google Analytics, no Meta pixel, no session recording, no heatmapping, no advertising SDK, no third‑party tracking cookie.
Because we collect no email address and no date of birth, the only identifying information we hold is the username and display name the school chooses. A school wanting to minimise identifiability can use initials or a pseudonym as the display name — everything still works. We are happy to advise during setup.
We do not buy, licence, scrape or otherwise obtain personal information from any third party, data broker or public source, and we do not match what we hold against any external dataset.
| Purpose | In practice |
|---|---|
| Running the Trainers | Signing people in, serving the right content, saving progress between sessions. |
| Adapting practice | Using accuracy per topic to pick the next question's difficulty. |
| Feedback and reporting | Showing a student their progress, and their teachers the progress of students in their classes. |
| Applying adjustments | Giving a student the extra time the school recorded. |
| Marking writing | Producing practice feedback against the marking criteria (section 10). |
| Security | Blocking password guessing and other abuse, and investigating suspected incidents. |
| Quality | Reviewing flagged questions and diagnosing faults a school reports. |
| Cost control | Metering AI usage and enforcing fair‑use limits. |
| Legal obligations | Meeting Australian legal requirements, including breach notification and tax record‑keeping. |
| Running a subscription FAMILY | Sending login details and receipts, taking the monthly payment, processing a cancellation or refund, and telling a parent about a price change or a change to these policies. |
We will not use personal information for a materially different purpose without the agreement of the school or the parent who holds the subscription, and without consent where the law requires it.
We never sell, rent, trade or licence personal information, and we never disclose it for anyone's advertising or marketing.
All three Trainers include an optional leaderboard showing display names and aggregate accuracy only — never usernames, account identifiers, teacher notes, individual answers or adjustment settings. A school that would rather students not be ranked can ask us to switch it off for them, and so can a parent.
We use the providers listed in section 9, and no others. We will not add a provider that receives personal information without updating this policy first.
We may disclose where Australian law requires or authorises it, or where necessary to lessen a serious threat to someone's life, health or safety. If we receive a compulsory request for student information we will tell the school — or, on a family subscription, the parent — unless legally prohibited.
If a Trainer were ever transferred to another operator, personal information would move only on condition the recipient is bound by protections no weaker than this policy, and we would notify every affected school and parent in advance so they can decide whether to continue.
Australian Privacy Principle 8 requires us to be explicit about information leaving Australia. This is complete and current.
| Provider | Role | What it receives | Where |
|---|---|---|---|
| Supabase (on Amazon Web Services) |
Database and server functions — the system of record. The three Trainers use separate databases. | Everything in section 4. | OLNA Sydney, Australia ap-southeast-2NAPLAN Sydney, Australia ap-southeast-2SCHOLARSHIP Sydney, Australia ap-southeast-2 |
| Anthropic | Generates practice questions and marks writing. | Writing response text, prompt, year level, topic, difficulty. No names, usernames, account identifiers or contact details. | United States |
| Stripe FAMILY |
Takes the monthly payment on a family subscription, hosts the checkout and billing portal, issues receipts and refunds. | Parent name and email address, card details entered directly by the parent on Stripe's own page, and the amount charged. No student name, username, results or writing. | United States, with global processing |
| Resend | Delivers the few emails a Trainer sends a parent: the welcome email after a payment, and password‑reset links. Nothing is ever emailed to a student. | Parent name and email address; and in a welcome email only, the first name, username and year level of that parent's own children. No results, no writing, no password, and nothing about any other family's child. | United States |
| Cloudflare | Serves the site files, provides TLS and network protection. | IP address and standard request metadata. No account data, no student work. | Global edge network, including Australia |
| Google Fonts, jsDelivr | Deliver the typefaces and one open‑source library to the browser. | IP address and browser type only — unavoidable in any web request. No account data, no student work. | Global content delivery networks |
Student account information and practice history are stored in Australia — all three Trainers' databases are in Sydney. Three things still leave the country. Writing responses are transmitted to the United States for marking. On a family subscription, the parent's name and email are held by Stripe in the United States. And the emails we send a parent pass through Resend in the United States — a welcome email names that parent's own children by first name, username and year level, so a child's login details do travel overseas once, to their own parent. All three are disclosures of personal information to overseas recipients.
Before disclosing overseas we take reasonable steps to ensure recipients handle information consistently with the APPs: we contract only with established providers publishing enterprise privacy and security commitments, everything travels over encrypted connections, we send the AI provider the minimum needed to do the marking, and no student information sits with any provider not listed above.
Some Australian education authorities require student personal information to stay in Australia, or require an approved exemption before an offshore service is used. All three Trainers' databases are in Sydney, so student accounts, results and practice history meet that requirement.
AI marking is the exception, and we are not going to present it otherwise. Writing responses are sent to the United States to be marked (section 9, Anthropic row) — without a student name, username or account identifier attached, but they leave Australia. A school or department that cannot accept that can run any Trainer with AI writing marking switched off, and everything else keeps working. If residency is a condition of your deployment, email hello@r2education.com.au before deploying and we will put it in writing.
Our AI provider's commercial API terms state that customer inputs and outputs are not used to train its models. Content may be retained briefly for safety and abuse monitoring, then deleted. We have not enabled, and will not enable, any arrangement under which student work trains a model.
All three Trainers use AI in two or three places. The limits matter, so they are stated plainly.
AI feedback is formative practice feedback only. It is not an OLNA result, not a NAPLAN result, not an official or moderated assessment, and it carries no weight in reporting, placement, streaming or any other decision about a student. It can be wrong.
This matters especially for OLNA, where the real assessment affects a student's WACE. Nothing any Trainer produces predicts or substitutes for that. Teachers should treat AI feedback as a starting point for a conversation and apply their own professional judgement.
No Trainer makes any automated decision with a legal or similarly significant effect on a student. All automated marking changes is which feedback text appears on screen. The only other automated process is the adaptive difficulty engine, which uses a student's own recent accuracy to choose the next question — and a teacher can override it.
Generated questions are validated against a strict format before display, and anyone can flag content that looks wrong. Student work is never used to train an AI model (section 9.2).
No Trainer sets a cookie. They use the browser's local storage for a few strictly necessary things, none readable by any other website:
| Stored | Purpose |
|---|---|
| Sign‑in token | Keeps you signed in without retyping your password. Expires after seven days. |
| Account summary | Display name, year group and settings, so the app can draw immediately. |
| Account type | Whether you are signed in as a student or a teacher. |
| Daily streak | A local count of consecutive practice days. Never leaves the device. |
Signing out clears the token and account summary; clearing site data removes everything. With no tracking or advertising cookies there is no consent banner and nothing to opt out of.
FAMILY The page where a family subscription is paid for is hosted by Stripe, not by us, and Stripe sets its own cookies there for fraud prevention and to make the payment work. That is Stripe's processing under Stripe's privacy policy, and it happens only on that page. It sets nothing on any Trainer, and it does not follow anyone around: no student ever visits it.
On shared or classroom devices, sign out. A token left behind stays valid on that device until it expires.
| Information | Retention | Then |
|---|---|---|
| Accounts | While the subscription is active and the account in use. | Deleted on the school's or parent's instruction, or within 90 days of the subscription ending. |
| Parent contact details FAMILY | While the subscription is active. | Deleted within 90 days of it ending, or immediately on request — except where it appears in a billing record below. |
| Billing records FAMILY | 5 years from the transaction. | Deleted. This is longer than everything else because Australian tax law requires records of a sale to be kept for five years, and we cannot delete them earlier on request. They contain the amount, the date and who paid — no card details, and nothing about the student's practice. |
| Practice history | As long as the account exists. | Deleted automatically with the account. |
| Writing responses | OLNA As long as the account exists. NAPLAN SCHOLARSHIP Not stored at all. | OLNA submissions are deleted with the account. |
| Sign‑in logs | 12 months. | Deleted. Only the last 15 minutes is used operationally. |
| AI usage records | 24 months. | Deleted, or reduced to non‑identifying totals. |
| Infrastructure logs | Provider default, typically 7–30 days. | Deleted by the provider. |
| Backups | Rolling backup window (see Security Policy). | Deleted records age out as the window rolls forward. |
Deleting a student removes the account and every linked record together — attempts, sessions, statistics, practice tests, writing submissions, group memberships and access grants. Deletion from live systems completes within 30 days of the request; backups follow within the backup window.
A school wanting results kept after a student leaves should export them first. Teachers can export class results at any time, and a parent can ask us for their child's results at any time (section 14).
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. In short:
Our Security Policy gives the full detail, including a frank list of current limitations. No online service can guarantee absolute security and we do not claim to.
The school controls the accounts, so ask the school first. A teacher or administrator can view a student's information, correct it, reset a password, deactivate the account or ask us to delete it — usually much faster than we can.
If the school cannot resolve it, email hello@r2education.com.au. We will verify the request with the school before acting, because we cannot independently confirm that someone contacting us is who they say they are or is entitled to a particular student's records.
There is no school in the middle, so come straight to us at hello@r2education.com.au. We will, free of charge:
We verify the request by replying to the email address on the subscription — which is why it matters that you keep it current. We will not act on a request about a child from an address that does not hold their subscription, and we will not discuss a child's records with anyone who is not the parent or guardian who subscribed. If parental responsibility is shared or disputed, we will not take sides: tell us and we will act only on instructions we can properly verify.
Deleting your child's data does not require you to cancel first, and cancelling does not immediately delete it — the retention schedule in section 12 applies. If you want both, say so and we will do both.
On request from an authorised school contact we will, free of charge:
We respond within 30 days. If we refuse a request in whole or part we will explain why in writing and how to complain. Requests are free; if a large or complex one would involve substantial cost we will discuss it first, and we never charge for a correction.
Our full breach response plan is in the Security Policy. If we become aware of a suspected breach involving personal information we will:
We will not delay telling a school or a parent while we investigate, and we will not minimise or withhold detail.
FAMILY On a family subscription there is no school to route a notification through, so it comes straight to you, at the email address on the subscription — which is the other reason we ask you to keep it current.
We do not use student personal information for direct marketing, and no Trainer displays advertising of any kind. We disclose personal information to nobody for their own marketing.
SCHOOL We may contact a school's nominated staff about the service itself — outages, security notices, policy changes, renewals, new features. Those go to school staff at school addresses, never to students.
FAMILY We email a parent about their own subscription: login details, receipts, failed payments, cancellation confirmations, price changes, security and policy notices. These are the emails that make the subscription work, and you cannot unsubscribe from them while it is running — cancelling the subscription stops them.
We will not add a parent to a mailing list, send promotional email, or tell you about anything we are selling, unless you have separately opted in — and if you ever do opt in, every message will carry a working unsubscribe link. We never sell or pass on a parent's email address, and we never market to a student.
We review this policy at least annually and whenever our handling of personal information changes. The current version always sits at r2education.com.au/privacy, with its version and effective date at the top.
For any change materially affecting how student information is handled — a new overseas recipient, a new category collected, a new purpose, a longer retention period — we give notice at least 30 days before it takes effect: to each school's nominated contact, and to each parent holding a family subscription, at the email address on it. That way you can review the change and, if you prefer, stop using the Trainer and have the data deleted before it applies.
Version 1.1 was such a change. It added family subscriptions, and with them a parent's name and email address (4.7), a new overseas recipient in Stripe (section 9) and a five‑year retention period for billing records (section 12). Section 5 flags the one claim from version 1.0 that this made inaccurate.
Version 1.2 replaced manual family account creation with a payment‑gated sign‑up form. Parent details are now entered on the Trainer's own sign‑up form rather than only on Stripe's checkout page, and the parent's password — held only as a one‑way hash — was added to 4.7. No new category of student information, no new recipient and no new retention period came with it; the matching account‑creation changes are in the Terms (6.1) and the Security Overview (6.1). It took effect before any family subscription had been sold, so no existing subscriber was affected.
Version 1.3 added Resend, the provider that delivers our email (section 9). It is a new overseas recipient, and the first one that receives anything about a student: a welcome email lists the parent's own children by first name, username and year level so that the family can sign in. It carries no results and no writing, it goes only to the parent who paid, and nothing is ever emailed to a student. It took effect before any family subscription had been sold.
Version 1.4 added the Scholarship Trainer (section 1). It is built from the NAPLAN Trainer and handles student information identically: the same categories in section 4, writing not stored (4.4), a database in Sydney (section 9), the same providers and the same retention periods. No new overseas recipient, no new category of information and no new retention period came with it, so nothing changed for OLNA or NAPLAN families or schools.
Include enough detail to identify the school or the subscription and, if relevant, the student. We will investigate, tell you what we find, and say what we will do about it.
You can go to a regulator at any time. You do not have to come to us first, though it is usually quicker.