Privacy Policy
How Atlas AI looks after your data
Last updated: 19 August 2026
Quick version for students
We collect the information needed to run your Atlas AI account, teach you, mark your work, keep you safe, and help your parent, guardian, or school support your learning.
We do not sell your personal data. We do not show your AI chat transcripts or wellbeing information to parents or guardians. Parents can see learning progress only where Atlas AI allows it and the visibility settings permit it.
You can ask what data we hold about you, ask us to correct it, or ask us to delete it. If you are unsure, ask a trusted adult or contact us at support@edseducation.com.
You can also read our Safety and Safeguarding page for urgent-help signposting, tutor rules, AI limits, and recording notices.
Who we are
Atlas AI is a service of EDS Education Ltd, a company registered in England and Wales with company number 11334874. EDS Education Ltd is the data controller for Atlas AI when you use our direct consumer services, parent services, billing, support, public website, and Atlas Review/Live services. That means we decide why and how personal data is used for those parts of Atlas AI.
Where a school provides or controls learner data, the school will usually be the data controller and EDS Education will usually act as the school's processor under written instructions or a data processing agreement. This controller/processor posture is reviewed before school launch claims expand.
Sahil Ahmad is the Atlas AI privacy lead and data-protection contact. Atlas AI does not currently claim a formal DPO appointment. You can contact us about privacy at support@edseducation.com.
What we collect
- Account details, such as name, email address, role, and age band.
- Learning data, such as subjects, progress, answers, marks, notes, flashcards, and lesson evidence. Teacher-assigned homework is School-context data only.
- Personal family links and, separately, School memberships, classes, invitation status, and under-13 approval receipts where those contexts apply.
- Billing records for paid plans, handled through Stripe.
- Safety and security records, such as sign-in activity, audit logs, and safeguarding review records.
- Cookie and consent-audit records, including choices, consent-session identifiers, user agent, and hashed IP address.
- Review/Live learning records, credit state, tutor-support records, and recording notices where those services are enabled.
Personal and School separation
A Personal learner does not need a school, organisation, class, or teacher. Personal pages do not use School homework, messages, reports, behaviour, attendance, classes, or teacher controls. People who have both contexts choose the active context before Atlas loads context-sensitive navigation, entitlement, learning, AI, billing, or analytics data.
A linked Personal parent can receive appropriate progress, activity, strengths, and next-step information. Raw AI conversations, private learner notes, and wellbeing answers are not automatically shared with parents. School information is available only after explicitly entering an authorised School context.
Why we use it
- To create and protect your account.
- To provide tutoring, practice, marking, revision, and Premium family lesson tools.
- To show progress to students and, where permitted, to parents, guardians, teachers, or school staff.
- To process subscriptions, invoices, refunds, and plan access.
- To meet legal, safeguarding, security, accounting, and consumer-rights obligations.
- To improve Atlas AI where you have allowed optional analytics cookies.
Legal basis
We use different legal bases depending on the data and purpose: contract for providing the service you sign up for, legal obligation for accounting and safeguarding records, legitimate interests for security and service improvement, and consent for optional cookies and some communications.
Who can see it
Students can see their own account and learning data. Parents, guardians, teachers, school coordinators, and Atlas AI administrators can see only the parts of the service their role needs. AI chat transcripts and wellbeing data are not shared with parents or guardians through Atlas AI parent visibility controls.
Safeguarding records, school statutory records, raw report files, AI provider internals, and sensitive support records need a manual privacy review before they are shared or exported.
Personal wellbeing, voice, and uploaded work
The answer stays in this browser tab for the current session and is not written to the Atlas database. The Personal check-in is optional, is not a School safeguarding record, and is not shown through parent controls.
Voice Tutor asks for microphone permission for each session. The browser or device may provide speech recognition. Atlas receives the resulting text and stores it in the learner's private tutor conversation; Atlas does not store raw audio.
Atlas checks the declared type, size, and matching file signature. Atlas does not run a dedicated malware scanner, so do not upload executable or untrusted files.Written-work uploads use a published retention deadline and deletion workflow. Private Image Analysis sources remain in the learner's source library until the learner deletes them or an applicable account-retention process removes them.
Suppliers we use
We use trusted suppliers to run Atlas AI, including Supabase for database, authentication, and storage; Stripe for payments; Anthropic and OpenAI for AI features; Resend for email; Vercel for hosting and analytics tooling; and GitHub for private code hosting. Some suppliers may process data outside the UK. Where that happens, we rely on appropriate transfer safeguards.
We review subprocessors and providers before new live uses, especially where children's data, AI/OCR processing, email, payments, storage, or school records are involved.
How long we keep it
We keep account and learning records while the account is active. We keep billing, audit, and safeguarding records for as long as we need them for legal, safety, dispute, and accounting reasons. We delete or anonymise data when it is no longer needed.
A low-severity AI safety receipt follows our Restricted Routine Review policy. The Atlas AI safeguarding lead reviews it within 24 hours, and only authorised safeguarding reviewers can see it. We use it under our safeguarding legal obligations and legitimate interests in protecting children. If review finds a false positive or no actionable concern, the encrypted content snippet is purged immediately. A genuine concern becomes a safeguarding record and follows the applicable controller's documented safeguarding retention schedule.
Review/Live recordings, if enabled, have a 28-day default retention target unless a safeguarding, dispute, legal, billing, or regulatory hold applies.
Your rights
You can ask for a copy of your personal data, ask us to correct inaccurate data, ask us to delete data, object to some uses, limit some uses, or ask for data portability. Children have data protection rights too, and we will handle requests in an age-appropriate way.
A request for a copy of personal data is called a Subject Access Request. Self-service exports are limited to safe account and learning data. Chat transcripts, wellbeing information, safeguarding information, school statutory records, Stripe internals, provider internals, and third-party records may need a manual review, redaction, and recipient-authentication check.
You can also complain to the UK Information Commissioner's Office if you are unhappy with how we use personal data.
Cookies
Strictly necessary cookies keep Atlas AI secure and signed in. Optional analytics and marketing cookies stay off until a user chooses to allow them. Cookie choices are saved with a timestamp, policy version, consent-session identifier, user agent, and hashed IP address. We do not store the raw IP address in the consent audit row.