Legal
Privacy Policy
Last updated: 13 July 2026
Applies to the Stroma web application (stromaapp.netlify.app) and related services.
Who we are
Stroma is operated by [OPERATOR ENTITY & ABN — pending confirmation] ("we", "us"). Stroma is a faculty-management tool for Australian secondary school teachers. Contact: hello@stroma.com.au.
We are committed to complying with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth).
The short version
- Teachers are our users. Students never have Stroma accounts.
- Schools stay in charge of their students' information. Teachers enter student first names, class lists and assessment marks so the product can do its job; we store that on the school's behalf and use it for nothing else.
- On the Solo Teacher plan, student names never leave your browser — our servers store marks against short codes you choose.
- We never sell personal information, and we never use it for advertising.
- AI features send lesson and report text to our AI providers (Anthropic and Google). Report-comment prompts are designed not to include student names. AI providers do not train on this data under our service terms.
- You can ask us at any time what we hold and to correct or delete it.
What we collect
About teachers and school staff (our users)
- Name, school email address, school and faculty, and role (Head Teacher / teacher / executive) — to create and route your account.
- The teaching data you enter: timetables, staffing allocations, programs, lesson-delivery records, meeting minutes, cover notes, calendar events, and private unit reflections.
- Sign-in is via Google (Firebase Authentication). We receive your email and basic profile from Google; we never see your password.
- Basic technical logs (from our hosting and database providers) for security and reliability.
About students (entered by teachers, on behalf of their school)
- Class roster names and preferred pronouns (faculty and school plans — see the Solo Teacher paragraph below for how the solo plan differs).
- Assessment marks and grades (the markbook).
- HSC assessment completion status and, where a teacher records one, a brief note and a link to documentation stored on the school's own systems — we never store the documentation itself (no medical certificates, no appeal forms).
- Class-level learning-adjustment profiles (NCCD categories). These are recorded per class, never per student — Stroma holds no individual disability, diagnosis, health or wellbeing records.
- We do not collect student email addresses, dates of birth, photos, addresses, or any government identifiers.
Solo Teacher plan — student names never leave your browser. On the Solo Teacher (and free) plan, the markbook is private by design: our servers store marks against short codes or initials you choose, together with preferred pronouns — student full names stay in your browser, on your device, and are never sent to or stored on our servers. Even a breach of our systems could not reveal your students' names alongside their results.
Because the names live only on your device, they are yours to manage: clearing your browser storage removes them (your marks are unaffected), and the app gives you a class-list file and a backup file — both created on your device — to restore them; those files contain student names, so store them as carefully as any class list. The codes, pronouns and marks we do hold may still be personal information in some contexts, and we treat them with the same care as the rest of your data. Free-text notes you write are synced, so we ask you (and the app reminds you) not to put student full names in them.
Payments
Handled entirely by Stripe. We never receive or store card details; we receive confirmation of your subscription and the sign-in email you provide at checkout.
Why we collect it
Solely to provide the product: running your faculty's timetable, programs and compliance records; generating teaching resources and report comments you request; showing your school executive the summaries their role permits; billing. We do not use personal information for marketing to third parties, profiling, or sale, and we will not use it for a secondary purpose you wouldn't reasonably expect without asking you first.
AI features (please read this one)
When a teacher uses an AI feature (report comments, lesson resources, minutes, extraction), the relevant text is sent to our AI providers — Anthropic (Claude) and Google (Gemini) — to generate the result:
- Report-comment prompts are constructed without the student's name; observation notes are anonymised to pronouns before sending. Marks-based achievement summaries are included so comments reflect real results.
- Teachers should avoid putting identifying student details in free-text notes; we provide in-app guidance on this.
- Under the commercial API terms we use, our AI providers do not use this content to train their models. Providers may retain data briefly for security and abuse monitoring.
- AI processing may occur outside Australia (see the next section).
Where your data lives, and overseas disclosure
- Our application database is Google Cloud Firestore in australia-southeast1 (Sydney). Our server functions run in australia-southeast1 (Sydney).
- Some service components process data outside Australia: Google's authentication service, Netlify (site hosting/CDN), Stripe (payments), and AI processing by Anthropic and Google, which may occur in the United States. Where the Privacy Act's APP 8 applies to these disclosures, we rely on the contractual safeguards in each provider's data-processing terms.
Who can see what
- Your faculty's data is readable and writable only by your faculty's Head Teacher and staff, enforced by database security rules.
- A school executive (Deputy/Principal) granted access by a Head Teacher can read faculty summaries but cannot read per-student marks, and can write only whole-school items (calendar, notes to faculties, class-level NCCD coordination).
- Private unit reflections are visible only to their author and the Head Teacher.
- Stroma's operator can access data for support and incident response, and accesses it only for those purposes.
Security
Data is encrypted in transit (TLS) and at rest by our cloud providers. Access is enforced by per-faculty database security rules that are version-controlled and tested. The app also keeps a working copy of your faculty's data in your browser's local storage on devices where you sign in — on shared computers, use your own operating-system profile and sign out. Backup files you export are your responsibility to store securely.
Retention and deletion
See our Data Retention & Deletion Policy. In short: we keep your data while your subscription (or free account) is active; after a subscription ends we delete the school's data within 90 days of a written request, or 12 months of inactivity, whichever comes first, except records we must keep (e.g. tax records of payments). Schools can export their data at any time (JSON export in-app).
Access, correction, complaints
Email hello@stroma.com.au to access or correct personal information we hold about you. Because student data is entered by schools, we will refer or coordinate student-data requests with the relevant school. If you have a privacy complaint, contact us first; we aim to respond within 30 days. You can also complain to the Office of the Australian Information Commissioner (oaic.gov.au).
Data breaches
We maintain a data-breach response plan. If a breach is likely to result in serious harm, we will notify affected schools/users and the OAIC in accordance with the Notifiable Data Breaches scheme, and affected schools promptly enough to meet their own obligations.
Changes
We will post changes here and, for material changes affecting schools, email subscribing schools before they take effect.