Data Security and Privacy
How ReportRocket protects your data with Australian hosting, encryption, and strict access controls.
Our Commitment
ReportRocket is built by Australians, for Australian schools. We take student data privacy extremely seriously.
Australian Data Hosting
All data is hosted in Australia (AWS Sydney region). Your data never leaves Australian shores.
Why This Matters
- Complies with Australian privacy law
- Subject to Australian jurisdiction
- No international data transfers
- Faster performance for Australian users
Encryption
In Transit
All connections use TLS 1.3 – the same encryption banks use.
At Rest
Stored data is encrypted using AES-256, the government-grade encryption standard.
Access Control
Row Level Security (RLS)
Every database query is filtered to ensure:
- Teachers only see their own students
- Schools only see their own data
- Reviewers only see assigned packs
- No cross-account data leakage
Authentication
- Email-based sign-in with verification
- Secure session management
- Automatic logout on inactivity
What We Don't Do
❌ Share student data with third parties
❌ Use student data for AI training
❌ Sell any user data
❌ Store data outside Australia
❌ Access your data without permission
Comment Generation Processing
When you generate comments:
- Data is processed via Google Gemini (Google AI API)
- Google does not use API-submitted data to train its models
- Student data is transient and not retained
- Processing happens in real-time only
Admin Access
ReportRocket staff can only access your data:
- With explicit permission
- For technical support purposes
- Logged and auditable
School Policies
For school licences:
- School admins see aggregate stats only
- Individual student names are not visible to admins
- Teachers maintain privacy over their classrooms
Data Retention
- Active accounts: Data stored indefinitely
- Deleted accounts: Data permanently removed
- Inactive accounts: No automatic deletion
Compliance
We follow:
- Australian Privacy Principles (APPs)
- State education department guidelines
- AITSL privacy frameworks
Incident Response
In the unlikely event of a data incident:
- Immediate containment
- Affected users notified within 72 hours
- Full investigation and remediation
- Transparent communication
Questions?
Have specific privacy questions? Contact us – we're happy to discuss your school's requirements.
Next Steps
Was this article helpful?