Privacy Policy
Last updated: January 2026
ReportRocket is an AI-powered report writing platform designed for Australian primary school teachers. We are committed to protecting your privacy and handling your data with transparency and care.
This Privacy Policy explains how we collect, use, store, and protect your personal information in compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Who We Are
ReportRocket provides AI-assisted generation of student report comments, aligned with the Australian Curriculum (ACARA). Our platform helps teachers create personalised, curriculum-aligned reports through collaborative review workflows.
Information We Collect
User Account Data
- Email address (for authentication and notifications)
- Full name (for display and identification)
- School affiliation (for organisation membership)
- User role (teacher, reviewer, or school admin)
- Purchase/licence status (for access management)
Student Educational Data (Minimised)
We collect only the minimum student data necessary for report generation:
- First name only (for report personalisation)
- Pronouns (for grammatical accuracy)
- Grade/Year level (for curriculum alignment)
- Performance levels (for report generation)
What We DON'T Collect
ReportRocket explicitly does NOT collect:
- Student home addresses or parent contact information
- Student date of birth, age, or photographs
- Medical, health, or disability information
- Behavioural or disciplinary records
- Family income or socioeconomic data
- Religious or cultural background information
- Student ID numbers or government identifiers
How We Use Your Information
- Providing AI-powered report comment generation
- Managing your account and subscription
- Enabling collaborative review workflows
- Sending essential service notifications
- Providing customer support
- Improving our platform and services
We do not use student data for marketing purposes or share it with third parties for their marketing use.
Data Storage and Security
Australian Data Residency
All persistent data is stored on secure Australian-hosted infrastructure with data centres located within Australian jurisdiction. Student educational data never leaves Australia for storage purposes.
Security Measures
- TLS 1.2+ encryption for all data in transit
- AES-256 encryption for data at rest
- Row-Level Security (RLS) on all database tables
- Role-based access control (RBAC)
- Secure password hashing using bcrypt
- Regular security assessments and monitoring
AI Processing
When generating report comments, minimal data is sent to Google Gemini (via the Google AI API):
- Student first name and pronouns
- Grade level
- Selected curriculum criteria
- Performance level
- Style preferences (if configured)
Important: AI processing is transient only—no permanent storage of student data occurs with Google. Data is processed and immediately discarded. Google does not use data sent through their API to train their models.
Analytics & Cookies
We use the following third-party services to improve our platform and protect against abuse:
Google reCAPTCHA v3
Our contact forms use Google reCAPTCHA v3 for bot prevention. This service processes your IP address and browser data to distinguish human users from automated bots. reCAPTCHA is subject to Google's Privacy Policy and Terms of Service.
Cookies
These services may use cookies to function. Cookies are small text files stored on your device. We use only essential cookies required for authentication and service functionality, plus analytics cookies for the services described above. You can control cookies through your browser settings, though this may affect some platform functionality.
Australian Privacy Principles (APPs) Compliance
ReportRocket is designed to comply with the Privacy Act 1988 (Cth) and all 13 Australian Privacy Principles:
| APP | Principle | Our Compliance |
|---|---|---|
| APP 1 | Open & Transparent Management | This policy clearly explains our data practices |
| APP 2 | Anonymity Option | Not practicable for service delivery — account identification is required to use the platform |
| APP 3 | Collection of Personal Information | Minimum data collected; no sensitive student information |
| APP 4 | Unsolicited Information | Not collected; would be deleted if received |
| APP 5 | Notification of Collection | Users informed at collection; documented in this policy |
| APP 6 | Use & Disclosure | Data used only for stated educational purposes |
| APP 7 | Direct Marketing | No direct marketing to users |
| APP 8 | Cross-border Disclosure | Data stored in Australia; AI processing via Google API is transient only with no permanent cross-border storage |
| APP 9 | Government Identifiers | Not collected |
| APP 10 | Data Quality | Users can update their information at any time |
| APP 11 | Security | Comprehensive technical and organisational measures |
| APP 12 | Access | Users can access their data through the application |
| APP 13 | Correction | Users can update and correct their information via the app |
Third-Party Services
We use trusted third-party services to operate our platform:
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Database & Infrastructure | All data (encrypted, Australian servers) |
| Google Gemini (Google AI API) | AI Comment Generation | Minimal student context (transient, not stored by Google) |
| Stripe | Payment Processing | Billing email and school name only |
| Resend | Email Notifications | Teacher email addresses only |
| Google reCAPTCHA | Bot Prevention | IP address, browser data (contact form only) |
Data Retention and Deletion
Retention Periods
- User account data: Retained for the lifetime of your account
- Student data: Controlled by teachers; retained until deleted
- Generated reports: Controlled by teachers; retained until deleted
- Error logs: Automatically deleted after 90 days
Your Deletion Rights
You can delete your data at any time:
- Teachers can delete individual students, classes, or reports within the app
- Personal accounts: You can delete your account directly from your profile menu. Deletion is immediate and permanently removes all your data including classes, students, reports, and settings.
- School members: You must first leave your school (via School Admin settings), then you can delete your account. Your classes and reports will remain accessible to your school.
Your Rights
Under the Privacy Act 1988, you have the right to:
- Access your personal information held by us
- Request correction of inaccurate information
- Request deletion of your data
- Know how your information is being used
- Complain to the Office of the Australian Information Commissioner (OAIC) if you believe your privacy has been breached
Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights:
- Company: Report Rocket Pty Ltd
- Contact: Contact Form
- For security-related concerns, please mention "security" in your message subject.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the updated policy on our website with a new "Last updated" date. We encourage you to review this policy periodically.
See also our Terms of Service