Privacy Policy

How IoTClass.org collects, uses, and protects your data across browsing, accounts, and classrooms.

This page shows genuine platform policy, not teaching material. The date it was last substantively edited is shown automatically in the banner at the top of every IoTClass.org page — that date is generated from our version-control history at each site build, not typed in by hand, so it cannot drift out of sync with the text below.

This Privacy Policy describes how IoTClass.org (“we”, “us”, or “our”) collects, uses, and protects your information when you use our educational website. Our purpose is education, not data monetization: we do not sell personal data, and we do not use it for advertising.

1. Who we are

IoTClass.org is operated by IOTCLASS CIC, a community interest company registered in England and Wales (company number 17293282). For any question about this policy or your data, contact admin@iotclass.org.

2. What we collect, and why

2.1 If you just browse — no account

  • Usage analytics: pages viewed, referrer, browser/user-agent string, screen size, time on page, and scroll depth, recorded to our own database together with a session identifier generated in your browser that expires after 30 minutes of inactivity.
  • Approximate country only: on your first visit in a browser session, your approximate country is resolved via a third-party IP-geolocation lookup (ipapi.co, with ip-api.com as a fallback if the first is unavailable). That service briefly processes your IP address to resolve it to a country; we do not store your IP address ourselves. We store only an aggregate per-country visit counter — country code, country name, a running visit count, and the timestamp of the most recent visit — for the world-map visualisation of our learner community. This aggregate record is never linked to any individual visitor or account.
  • Cookie-free web analytics via Cloudflare, which does not identify you across visits (see our Cookie Notice for the full detail on what is and is not stored in your browser).

Lawful basis: legitimate interest — understanding which content helps learners and keeping the platform reliable. No advertising, no cross-site tracking, no sale of data — ever.

2.2 If you create an account (optional)

Signing in uses Google OAuth: we receive the name, email address, and avatar image Google shares for authentication (nothing beyond that). Once signed in, we also hold your learning records: chapter and unit progress, quiz results, XP transactions, badges, streaks, any work you save in the Design Studio, and any chapter/activity feedback you submit (below). Accounts that previously received a certificate may also retain that dormant legacy database record; certificates are no longer issued or shown in the learner experience.

Chapter and activity feedback (signed-in users only): on a chapter or an embedded interactive, you may optionally submit a helpful/needs-work rating, up to 6 tags chosen from a predefined list, and an optional free-text comment (up to 2000 characters). This feedback is linked to your account, is visible to IoTClass administrators and content reviewers, and is used solely to improve course content — never for advertising or profiling.

If you are signed in, the usage-analytics records described in §2.1 are linked to your account so you can review your own history; if you are not signed in, they are linked only to the temporary session identifier, not to any identity.

Purpose: providing your learning experience. Lawful basis: contract (providing the service you signed up for).

2.3 If you join or teach a Classroom (optional)

  • As a student: joining a classroom creates a membership record. Before you join, you are shown the statement “Your teacher will be able to see your progress and quiz results for this classroom’s curriculum” — your teacher can then see your progress and quiz results for that classroom’s curriculum, and only for that classroom. Leaving the classroom ends that visibility.
  • As a teacher: creating a classroom requires an admin-approved teacher role — it is not open to everyone who signs in. To apply, you provide your institutional (e.g. university) email address, institution name, role/title, and intended use; this is linked to the Google identity you sign in with, and an administrator reviews and approves or rejects each application before classroom-creation access is granted.
  • A classroom’s roster and per-member progress are visible only to that classroom’s teacher, enforced by database access rules — never to another classroom’s teacher, and never beyond the classroom’s own curriculum.

3. Cookies and local storage

We keep this brief here; see our Cookie Notice for the complete picture. In short: IoTClass.org does not set advertising or tracking cookies. Sign-in state and most preferences are kept in your browser’s local storage rather than in cookies. A small number of third-party embeds you choose to use (for example, a YouTube video) may set their own cookies once you interact with them.

4. How we use your information

We use the information above to:

  • provide your learning experience — track progress, award badges and XP, and remember your preferences;
  • operate Classrooms as described in §2.3;
  • understand which content is and isn’t working, so we can improve it;
  • keep the platform secure and reliable;
  • show aggregated, anonymised community statistics, such as the country breakdown on the world map.

We do not: sell your personal data, use it for advertising, or share an individual’s learning data with anyone outside a Classroom they’ve joined, without your consent.

5. Third-party services

Each of the following processes some data on our behalf, under its own terms:

  • Google — sign-in (OAuth). See Google’s Privacy Policy.
  • Supabase — our backend database and authentication service; accounts and learning records are stored on Supabase’s hosted PostgreSQL infrastructure. See Supabase’s Privacy Policy.
  • GitHub Pages — static hosting for the website itself.
  • Cloudflare — cookie-free web analytics (§2.1).
  • YouTube, Wokwi, and amCharts — embedded educational videos, hardware simulators, and interactive charts; see the Cookie Notice for what each may set in your browser.

6. Data retention

DataRetention
Account and learning records (progress, quiz results, XP, badges, chapter/activity feedback, and any dormant legacy certificate record)While your account exists; deleted on request (§7)
Classroom membership and rostersUntil the classroom is archived, then 12 months, after which the roster is deleted
Raw analytics events (individual page views)13 months, after which only aggregated figures are kept
Country-level visit counters (country code, country name, visit count, last-visit timestamp — no per-individual record)Kept as an aggregate count only, for as long as the platform operates
Browser-side session identifierExpires automatically after 30 minutes of inactivity

7. Data security

  • All traffic to and from our servers uses HTTPS/TLS encryption.
  • We use OAuth for sign-in, so we never see or store a password.
  • Database access is restricted by row-level access rules: a signed-in user can see only their own account data, and a classroom teacher can see only the members of their own classroom.
  • We rely on Supabase and Google, both of which maintain industry-standard security certifications.

No method of transmission over the internet is completely secure, and we cannot guarantee absolute security.

8. Your rights

You have the right to access, correct, export, and delete your personal data, and to object to certain processing.

At present these requests are handled directly by us rather than through a self-service button: email admin@iotclass.org with enough detail (for example, the email address on your account) for us to find your record safely. We aim to respond to any privacy-related inquiry within 30 days and to complete deletion requests within 30 days.

You can already see your own progress and badges at any time from your progress page without needing to ask us. To access a dormant legacy certificate record, email admin@iotclass.org.

If you are in the UK, you may also complain to the Information Commissioner’s Office (ICO) at ico.org.uk.

9. Children and young learners

  • All site content can be read without an account, by anyone.
  • Creating an account requires Google sign-in. You must be at least 13 years old to create an account. Children under 13 may use IoTClass only under the supervision of a parent, guardian or teacher, and must not create an account of their own.
  • Classrooms used with students under 18 must be created by an admin-approved teacher acting on their institution’s behalf (§2.3); that teacher/institution is responsible for obtaining any consents their context requires.
  • We follow the ICO’s Age-Appropriate Design Code principles: we collect the minimum data needed for the service to work, we do not profile learners for commercial purposes, we avoid dark patterns, and defaults favour privacy — for example, your progress and achievements are visible only to you (the platform has no public rankings), and classroom membership never exposes more than progress on that classroom’s own curriculum.
  • We comply with the U.S. Children’s Online Privacy Protection Act (COPPA): we do not knowingly collect personal information from a child under 13 without appropriate consent, and if we learn we have done so in error, we will delete it promptly.

10. International users

IoTClass.org is used worldwide, and our infrastructure (Supabase, GitHub Pages) may process data outside the country you’re in. If you are in the UK or the European Economic Area, you have the rights set out in §8, including the right to lodge a complaint with your local supervisory authority, and we process your data on the lawful bases described in §2.

11. Changes to this policy

We edit this page directly whenever our practices change; the banner at the top of the page always shows when that last happened, so there is no separate stale date to maintain here. Material changes that affect existing accounts will be announced by email and by a notice on the site in addition to being reflected on this page.