Privacy Policy
You own your data. We collect only what the Service needs to run — not what advertisers, profilers, or bulk “ed-tech” platforms habitually take.
This Privacy Policy explains how Work It In (“Work It In,” “we,” “us”) handles information when you use the Work It In learning hub (the “Service”). It prioritizes user sovereignty, data minimization, and transparency.
1. What “User Data” means (narrow definition)
User Data means only the information you provide, or that is generated by a feature you actively use, that is reasonably necessary to operate that feature. We define User Data as narrowly as possible.
Examples of User Data we may hold when you use the corresponding feature:
account credentials and contact details you submit (for example, email for login and account recovery — not for marketing lists); display name and role (learner, educator, guardian); community membership and join requests you make; learning content you create or upload (tasks, submissions, files); assignment and assessment records needed to show progress to you and authorized community members; optional fields you choose to fill (phone, city, notes); payment references needed only if you initiate a paid plan or session booking.
We do not treat the following as “necessary” User Data, and we do not collect them for profiling or secondary use:
precise geolocation; browsing history outside the Service; keystroke patterns or behavioural biometrics; device fingerprinting for advertising; cross-site tracking; microphone, camera, or audiovisual capture except when you deliberately upload a file or use a feature that requires it; or bulk technical metadata beyond what is strictly required to keep a session secure and the Service functioning for the request you made (for example, short-lived security logs). We explicitly repudiate expansive “student data” models that fold geolocation, device dossiers, and passive audiovisual capture into ordinary education records, and we do not claim “school official” status to obtain sensitive information without the consent path your community and the law require.
2. Data minimization — only what the Service needs
We collect the minimum data necessary to operate the Service you requested (for example, an email to sign in and recover an account — not to build marketing profiles). If a field is optional, it is optional. We do not require invasive metadata to use core learning features. Features that need extra information will ask for it in context.
3. No sale, no licensing, no “partners” loophole
Sale means any transfer, rental, disclosure, or provision of User Data for money or other valuable consideration — including advertising targeting, data brokerage, or use of User Data to train artificial intelligence or machine-learning models for anyone other than operating the Service for you. “Share” for behavioural advertising is treated as a sale under this Policy.
We do not sell, rent, license, or trade User Data. We do not share, sell, or license User Data to third parties — including so-called partners, affiliates, advertisers, data brokers, or “service providers” — except under the narrow cases below.
Only exceptions:
(a) User-initiated transaction — for example, processing a payment through a secure payment gateway when you choose to pay, limited to data needed to complete that payment; (b) Your explicit consent — for a specific transfer you request or approve in advance, with clear notice of who receives what and why; (c) Legal compulsion — only as described in Section 7 (government and law-enforcement requests); (d) Safety and abuse response — limited disclosure necessary to address an imminent risk of serious harm or ongoing criminal abuse, still minimized and documented where lawful.
We will not re-label data as “not student data” or “not personal data” to open a side channel for third parties. Infrastructure needed to host the Service (for example, a cloud host or email delivery) may process data only as a processor under our instructions to run the Service — not for their own marketing, profiling, or model training on your content — and only under contracts that reflect that limit, to the extent we control those vendors.
4. Who can see learning work inside the Service
Learners see their own work. Educators in an approved community role may review work needed to teach and assess. Guardians see only learners they are linked to, as the product allows. Uploads are served to authenticated users with a legitimate role — not as a public gallery. Community membership is gated by join credentials and educator approval; that is access control, not a data sale.
5. Your ownership, export, and right to delete
You own your User Data. Privacy is the default; you should not have to hunt for an opt-out of secondary use.
Export: You may request a copy of your User Data in a portable, machine-readable format (for example, common structured export such as CSV/JSON for account and progress records, plus your uploaded files). Contact us via the Contact page or Account management channels we provide. We will fulfil reasonable export requests without unnecessary delay.
Delete: On account deletion, or on a specific deletion request, we delete your User Data from active systems without an arbitrary multi-year “warehouse” retention window for secondary purposes. Residual copies in encrypted backups may age out on a short operational cycle and are not used for live product features. We may retain a minimal non-identifying record if the law requires (for example, a payment receipt or fraud blocklist entry), and we will not use retained legal records as a back door for marketing or profiling. Community-owned curriculum materials created by educators for shared teaching may remain for that community if they are not your personal submission; ask us if you need a specific item removed.
6. No psychological profiling or behavioural advertising
We do not use User Data or usage patterns to build psychological profiles, predict vulnerability, personalize commercial pressure, or manipulate behaviour. We do not sell access to your attention. Product analytics, if any, are limited to operating and improving reliability of the Service (for example, fixing errors) — not to profile individuals for ads or influence campaigns. See also the non-interference pledge in the Terms of Service.
7. Government and law-enforcement requests
If we receive a subpoena, warrant, court order, or other compulsory legal process for User Data, we will:
Notify you before complying, unless we are legally prohibited from doing so; narrow the request to what the law actually requires; and challenge requests that are overbroad, unlawful, or constitutionally defective where we have a reasonable basis and ability to do so.
We will not volunteer User Data to government actors outside lawful process. When volume and circumstances make it meaningful, we will publish a periodic transparency report summarizing the number and general nature of government data requests we receive and how we responded (for example, complied in part, challenged, or no data found) — without exposing individuals. Requests for that report, or to be notified of a request about your account, can start at Contact.
8. Security
We use reasonable administrative and technical measures appropriate to a learning hub (authenticated access, role-based views, protected file delivery). No method of transmission or storage is perfectly secure; report suspected incidents promptly via Contact.
9. Children and educational communities
Communities and families are responsible for lawful use with minors in their care, including consent and supervision required in their jurisdiction. We design the Service so that community access is gated and role-limited — not so that third parties can quietly become de facto custodians of student dossiers. Parents and guardians linked in the product see only what the product authorizes for their linked learners.
10. Changes to this Policy
We may update this Policy. The effective date above will change when we do. Material reductions in your rights will be called out clearly; continued use after the effective date means you accept the updated Policy. If you do not agree, stop using the Service and request deletion.
11. Contact
Privacy questions, export requests, deletion requests, or government-request notices: use our Contact page. Related rules of use: Terms of Service.
