Privacy Policy

    Last updated: January 2026

    ReportRocket is an AI-powered report writing platform designed for Australian primary school teachers. We are committed to protecting your privacy and handling your data with transparency and care.

    This Privacy Policy explains how we collect, use, store, and protect your personal information in compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

    Who We Are

    ReportRocket provides AI-assisted generation of student report comments, aligned with the Australian Curriculum (ACARA). Our platform helps teachers create personalised, curriculum-aligned reports through collaborative review workflows.

    Information We Collect

    User Account Data

    • Email address (for authentication and notifications)
    • Full name (for display and identification)
    • School affiliation (for organisation membership)
    • User role (teacher, reviewer, or school admin)
    • Purchase/licence status (for access management)

    Student Educational Data (Minimised)

    We collect only the minimum student data necessary for report generation:

    • First name only (for report personalisation)
    • Pronouns (for grammatical accuracy)
    • Grade/Year level (for curriculum alignment)
    • Performance levels (for report generation)

    What We DON'T Collect

    ReportRocket explicitly does NOT collect:

    • Student home addresses or parent contact information
    • Student date of birth, age, or photographs
    • Medical, health, or disability information
    • Behavioural or disciplinary records
    • Family income or socioeconomic data
    • Religious or cultural background information
    • Student ID numbers or government identifiers

    How We Use Your Information

    • Providing AI-powered report comment generation
    • Managing your account and subscription
    • Enabling collaborative review workflows
    • Sending essential service notifications
    • Providing customer support
    • Improving our platform and services

    We do not use student data for marketing purposes or share it with third parties for their marketing use.

    Data Storage and Security

    Australian Data Residency

    All persistent data is stored on secure Australian-hosted infrastructure with data centres located within Australian jurisdiction. Student educational data never leaves Australia for storage purposes.

    Security Measures

    • TLS 1.2+ encryption for all data in transit
    • AES-256 encryption for data at rest
    • Row-Level Security (RLS) on all database tables
    • Role-based access control (RBAC)
    • Secure password hashing using bcrypt
    • Regular security assessments and monitoring

    AI Processing

    When generating report comments, minimal data is sent to Google Gemini (via the Google AI API):

    • Student first name and pronouns
    • Grade level
    • Selected curriculum criteria
    • Performance level
    • Style preferences (if configured)

    Important: AI processing is transient only—no permanent storage of student data occurs with Google. Data is processed and immediately discarded. Google does not use data sent through their API to train their models.

    Analytics & Cookies

    We use the following third-party services to improve our platform and protect against abuse:

    Google reCAPTCHA v3

    Our contact forms use Google reCAPTCHA v3 for bot prevention. This service processes your IP address and browser data to distinguish human users from automated bots. reCAPTCHA is subject to Google's Privacy Policy and Terms of Service.

    Cookies

    These services may use cookies to function. Cookies are small text files stored on your device. We use only essential cookies required for authentication and service functionality, plus analytics cookies for the services described above. You can control cookies through your browser settings, though this may affect some platform functionality.

    Australian Privacy Principles (APPs) Compliance

    ReportRocket is designed to comply with the Privacy Act 1988 (Cth) and all 13 Australian Privacy Principles:

    APPPrincipleOur Compliance
    APP 1Open & Transparent ManagementThis policy clearly explains our data practices
    APP 2Anonymity OptionNot practicable for service delivery — account identification is required to use the platform
    APP 3Collection of Personal InformationMinimum data collected; no sensitive student information
    APP 4Unsolicited InformationNot collected; would be deleted if received
    APP 5Notification of CollectionUsers informed at collection; documented in this policy
    APP 6Use & DisclosureData used only for stated educational purposes
    APP 7Direct MarketingNo direct marketing to users
    APP 8Cross-border DisclosureData stored in Australia; AI processing via Google API is transient only with no permanent cross-border storage
    APP 9Government IdentifiersNot collected
    APP 10Data QualityUsers can update their information at any time
    APP 11SecurityComprehensive technical and organisational measures
    APP 12AccessUsers can access their data through the application
    APP 13CorrectionUsers can update and correct their information via the app

    Third-Party Services

    We use trusted third-party services to operate our platform:

    ServicePurposeData Shared
    SupabaseDatabase & InfrastructureAll data (encrypted, Australian servers)
    Google Gemini (Google AI API)AI Comment GenerationMinimal student context (transient, not stored by Google)
    StripePayment ProcessingBilling email and school name only
    ResendEmail NotificationsTeacher email addresses only
    Google reCAPTCHABot PreventionIP address, browser data (contact form only)

    Data Retention and Deletion

    Retention Periods

    • User account data: Retained for the lifetime of your account
    • Student data: Controlled by teachers; retained until deleted
    • Generated reports: Controlled by teachers; retained until deleted
    • Error logs: Automatically deleted after 90 days

    Your Deletion Rights

    You can delete your data at any time:

    • Teachers can delete individual students, classes, or reports within the app
    • Personal accounts: You can delete your account directly from your profile menu. Deletion is immediate and permanently removes all your data including classes, students, reports, and settings.
    • School members: You must first leave your school (via School Admin settings), then you can delete your account. Your classes and reports will remain accessible to your school.

    Your Rights

    Under the Privacy Act 1988, you have the right to:

    • Access your personal information held by us
    • Request correction of inaccurate information
    • Request deletion of your data
    • Know how your information is being used
    • Complain to the Office of the Australian Information Commissioner (OAIC) if you believe your privacy has been breached

    Contact Us

    If you have questions about this Privacy Policy or wish to exercise your privacy rights:

    • Company: Report Rocket Pty Ltd
    • Contact: Contact Form
    • For security-related concerns, please mention "security" in your message subject.

    Changes to This Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the updated policy on our website with a new "Last updated" date. We encourage you to review this policy periodically.

    See also our Terms of Service