Version 0.3 · 6 August 2026 · Senapses Ltd, United Kingdom
The short version. This website sets no cookies and runs no analytics. The demo app keeps everything on your own device and sends us nothing. In the hosted school service, your school, not Senapses, controls the pupil data. We process it on the school's written instructions under a signed data-processing agreement, and the dataset is deliberately minimal. We never sell data, never advertise, and never use school data to train AI models.
1 · Who we are
Senapses is a UK education platform for pupil voice and support in schools, operated from the United Kingdom by Senapses Ltd, a company registered in England and Wales, company no. 17369349, registered office 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. Contact for anything in this policy: hello@senapses.co.uk.
2 · Visiting this website
We set no cookies and use no analytics or tracking of any kind.
Our hosting provider (Vercel Inc.) keeps standard, short-lived server logs (IP address, request time, page requested) for security and operational purposes, as any web host does.
If you email us, we hold your email and its contents to reply to you, and keep the thread only as long as the conversation is live or a pilot relationship follows from it.
3 · The demo app
The Senapses demo runs entirely on the device it is opened on. Check-ins, settings and every other record stay in that device's own storage; nothing is transmitted to Senapses. Clearing the browser's site data removes everything. The demo is intended for exploration with fictional pupils only.
4 · The hosted school service: pupil data
When a school uses the hosted Senapses service, the school is the data controller and Senapses is a data processor acting on the school's documented instructions under a UK GDPR Article 28 data-processing agreement signed with each school. In plain terms:
The dataset is deliberately minimal: first name, optional middle name where the school's export includes one, optional surname, year and form, an optional EHCP yes/no marker, timetable entries the school chooses to import, and the pupil's own check-ins, support records and ratings. Our import software rejects files containing dates of birth, UPNs, addresses, contact details, medical information and similar.
Data is hosted in the United Kingdom, encrypted in transit and at rest, with role-based access for the school's own staff only.
Nothing is used for advertising, profiling beyond the school's own dashboards, AI model training, or any purpose other than supporting the school's provision for its pupils.
Pupils never have accounts. No pupil has a username, a password or an email address in Senapses. A pupil uses the app either on a shared classroom tablet that a member of staff has signed into and handed over, or on a tablet the school has enrolled as that pupil's own. In the second case the tablet holds a randomdevice token, set by our server and stored by us only as a one-way fingerprint, bound by a member of school staff to one pupil for one term (a school admin can revoke it at any time, and extend it by a term, never beyond a year ahead). The pupil types a one-time set-up code to link the tablet; it is spent the moment it is typed. That tablet shows only that pupil's own screen: it never receives another pupil's name, a member of staff's name, or any note a member of staff has made about the pupil (staff cannot type free text about a pupil at all). It is told only that help was given, and which kind from a fixed list, so the pupil can rate it, and that a worry has been closed. We keep, for each enrolled tablet, its label (the one the school gave it, or, for a printed code sheet, the year group and first name we labelled it with), which pupil it is bound to, which members of staff issued and bound it, when it was enrolled, bound, expires or was revoked, and when it last checked in. A revoked or expired tablet record is deleted 30 days later, or, if the tablet had sent records, when the last of those records is deleted under the school's own retention period. A revoked or expired tablet is refused, and told so, from its next request; the fingerprint on its record opens nothing from that moment and goes with the record.
Questions or rights requests about pupil data (access, correction, erasure) should go to the school's SENDCO or Data Protection Officer. The school controls the data and we assist it in responding. If you contact us directly we will pass the request to the school without delay.
5 · The hosted school service: staff accounts
For the staff accounts a school asks us to create, Senapses is the controller of a small amount of account data: name, role, work email address, and three security records of account activity. We process these to run and secure the service (legitimate interests / performance of the contract with the school), and we delete accounts when the school tells us to or when the contract ends.
The three records, and how long each is kept:
Sign-in events — work email address, time, network address and whether the attempt succeeded. Kept 90 days.
A record-view log — which member of staff opened which pupil's record, and when. Kept 365 days, because a question about access can arrive a full term later.
A change log — every change to who holds which seat in a school, and every pupil tablet enrolled, bound, unbound, extended or revoked, with who made it. Kept 365 days.
These exist so that a question like “who saw this child's record in March?” has an answer. They are read by Senapses, not by your school, and they are never used to measure or compare the work of any individual member of staff. That is a term of our contract with the school, not only a policy of ours: the product contains no feature that groups, averages or ranks this activity by person, and we do not build one. If you are a member of school staff and you want to know what these records hold about you, ask us using the address below.
6 · AI-drafted reports (optional, off by default)
Schools may optionally enable a drafting feature that prepares review documents from pseudonymised aggregate statistics only: no pupil name, no identifier, no free text and no pastoral entries are ever included in a drafting request. The pupil is referred to by a placeholder token and the name is re-inserted on the school's own device. Drafts are reviewed and edited by the school's SENDCO team before any use, and the AI provider does not use the data to train models. The feature is enabled per school, in writing, and is off by default.
7 · Sub-processors and transfers
We use a short list of infrastructure providers, set out in the data-processing agreement each school signs (hosting and email in the UK; the optional AI drafting provider under the UK International Data Transfer Addendum). Schools receive 30 days' notice of any change.
8 · Your rights
Under UK GDPR you can ask for access to, correction of, or deletion of personal data we hold about you, and you can complain to the Information Commissioner's Office (ico.org.uk). For pupil data, the right route is via the school, as described in section 4.
9 · Changes
We will update this page as the service develops and mark the version and date above. Material changes affecting schools are notified to schools directly.
This policy describes the product accurately as built, and remains under review as part of our pre-pilot legal pack. The signed agreements with each school take precedence for the hosted service.