Effective date: 8 August 2026
Policy URL (for Google Play and other stores):
https://portal.gcsewithrosi.co.uk/privacy-policy
This Privacy Policy explains how GCSE With Rosi (“we”, “us”, or “our”) collects, uses, shares, and protects personal information when you use:
By using the Services, you agree to this Privacy Policy. If you do not agree, please do not use the Services.
For most parent mobile-app accounts and portal use, GCSE With Rosi acts as the data controller for the personal information described in this policy.
For student records held primarily for teaching and safeguarding, your school may act as controller and we process data on their instructions as a data processor. Questions about a child’s school file should be directed to the school in the first instance.
We collect information you provide and information generated when you use the Services.
| Category | Examples | Source |
|---|---|---|
| Account and identity | Name, email address, phone number, username, password (stored in hashed form), account type (parent, student, staff) | You / your school |
| Child linkage (parents) | Child’s 6-digit registration code, linked student name and admission number after verification | You |
| Educational records | Attendance, homework, class summaries, assessments, exam results, feedback, timetables, messages, and files you submit | Use of Services / school |
| Communications | Support requests, complaints, and emails we send (e.g. login credentials after registration) | You / automated service |
| Technical and usage | IP address, device type, operating system, app version, browser type, log timestamps, and security events | Automatic |
| Account deletion requests | Email, name, account type, and details you submit on our deletion form | You |
We do not require payment card details in the parent app for core access. We do not knowingly collect special category data (such as health data) through the parent app unless you or the school choose to submit it in an educational context.
Sensitive permissions: The parent app is designed for account access and school-related information. We do not use the app to access your precise location, contacts, microphone, or camera unless a future feature clearly asks for permission and this policy is updated.
We use personal information to:
We do not sell your personal information. We do not use your personal information for cross-context behavioural advertising.
Where the UK GDPR or EU GDPR applies, we rely on one or more of the following legal bases:
We may share personal information with:
We require processors to protect personal information and use it only for the purposes we specify.
Our systems may be hosted in the United Kingdom or other countries. If personal information is transferred outside the UK or EEA, we use appropriate safeguards (such as UK International Data Transfer Agreements, EU Standard Contractual Clauses, or adequacy regulations) where required by law.
We keep personal information only as long as necessary for the purposes in this policy, including:
Account deletion requests are retained in a minimal form (e.g. request log) to evidence compliance with your request and applicable law.
We use technical and organisational measures appropriate to the risk, including access controls, encrypted connections (HTTPS/TLS) where supported, and hashed passwords. No method of transmission or storage is completely secure; please keep your login details confidential and tell us if you suspect unauthorised access.
Depending on where you live, you may have the right to:
To exercise these rights, contact us using the details in section 16. We may need to verify your identity. We will respond within the time required by law (typically one month under UK GDPR).
You may request deletion of your parent mobile-app account (and associated app login) without deleting your child’s official school record.
Request account deletion online:
https://portal.gcsewithrosi.co.uk/account-deletion-request
After we verify your request, we will delete or anonymise the app account and linked login credentials within a reasonable period (typically within 30 days), unless we must retain certain information for legal, safeguarding, or school record-keeping reasons. We will tell you if that applies.
You can also uninstall the app at any time; uninstalling does not by itself delete data we hold on our servers — use the deletion link above for that.
The Services are used in an educational setting. Student accounts are generally created and managed by the school. The parent app is intended for parents and guardians aged 18 or over.
We do not knowingly collect personal information from children through the parent registration flow for the purpose of marketing. If you believe a child has provided us information in error, contact us and we will take appropriate steps.
The parent mobile app may request permissions only when needed for a feature (for example, storage to open a downloaded PDF). You can manage permissions in your device settings. Denying a permission may limit a specific feature but will not usually block core login and viewing of school information.
We may collect crash logs or diagnostic data to fix errors. This is used to improve stability, not for advertising profiles.
Our web portals use cookies and similar technologies that are strictly necessary for login sessions and security. We may use limited analytics on public pages where configured. You can control non-essential cookies through your browser settings where applicable.
The Services may link to third-party sites (for example, our main school website). Their privacy practices are governed by their own policies. We are not responsible for third-party sites you visit from links within the app or portal.
If we use subprocessors for hosting or email, they process data under contract and only as instructed by us.
We may update this Privacy Policy from time to time. We will post the new version at the same URL and update the effective date at the top. For material changes, we may provide additional notice in the app or by email where appropriate. Continued use after the effective date means you accept the updated policy.
For privacy questions, data subject requests, or complaints:
This policy is provided to meet transparency requirements for app stores (including Google Play’s User Data policy) and UK data protection law. Your organisation should ensure the description matches actual app behaviour and complete the Google Play Data safety form consistently with this policy.