Privacy Policy
This Privacy Policy explains how we collect, use, store and protect your information when you use Teacher Task Manager. By using the app, you agree to the practices described here.
Information We Collect
We collect only the information necessary for the app to function. The following data may be stored in Google Firestore or Firebase Storage depending on which features you use:
Account information
- Name and email address (provided at registration or via Google sign-in)
- Profile photo URL, if signing in with Google (supplied by Google)
- Account tier (Free or Pro) and subscription status
No passwords are stored by us. Authentication is handled by Firebase Auth (Google).
Task and productivity data
- Tasks: titles, descriptions, subtasks, due dates, priority, categories, recurrence settings, and assignment details
- Notes: title and body text of notes you create, and images you attach to them
- Marking Tracker entries: work titles, class names, due dates, status, and notes (Pro only)
- Lesson plans you save in the Lesson Planner (Pro only)
- Cover work you generate and save in the Cover Work generator, including any topic and spec/syllabus context you enter or extract from an uploaded document (Pro only). An uploaded PDF is read in your browser and never stored; only the extracted text is saved as part of your spec/syllabus context
- Report comments you choose to save to your comment bank, which may include pupil first names or initials you have entered (Pro only)
- Timetable entries: class names, periods, and schedule information. Your timetable is private to you unless you choose to share it: in Timetable → Share you pick which of your teams may view it, and only members of those teams can then open it
- School calendar data: term dates, holiday periods, and INSET days you define or that are shared with you by a team
- Dashboard layout preferences (section order, sizes, and collapsed states)
- Task templates you save for reuse
Team and collaboration data
- Team names, join codes, and member lists (names, email addresses, and roles)
- Tasks assigned to or received from team members
- Team activity feed entries (e.g. task completions, members joining)
- Basic profile details (display name, email address, and online status) are visible to people you collaborate with, such as team members and chat participants
Chat and messaging data
- Messages sent in team chats and direct messages, including records of edits and deletions
- Emoji reactions, threaded replies, and pinned or bookmarked messages
- Draft messages: saved on your device only, not on our servers
- Poll choices and per-user voting records
- Read receipts: which messages you have read and when
- Presence status (online, away, or busy): shared with your team members in real time
- Typing indicators: transmitted in real time only and not stored persistently
- Images and files you upload in chat: stored in Firebase Storage. Chat images are automatically deleted after 7 days, and chat file attachments also expire automatically
Push notification tokens
- Firebase Cloud Messaging (FCM) device registration tokens: stored in your account to deliver push notifications for task assignments, due dates, and @mentions. These tokens identify your browser or device but contain no personal information beyond their association with your account.
Support, feedback and product usage data
- Bug reports you submit, including any screenshots you attach. Please check screenshots before attaching them, as they can capture whatever is on your screen
- A testimonial, if you choose to submit one. Testimonials are reviewed with you named only where you have agreed to that
- Onboarding and feature-tip events (for example which tour step you reached), linked to your account, so we can see where new users get stuck
- AI usage records: which AI feature you used, the model, and token counts, so we can monitor cost and abuse. These records contain no task, message, or report content
Weather widget (optional)
- If you allow location access when your browser asks, your device sends its approximate coordinates directly to the Open-Meteo weather service to fetch your local forecast. The coordinates go straight from your browser to Open-Meteo; our servers never receive or store them. The forecast and coordinates are cached on your device only. If you decline the browser prompt, the widget simply stays empty. Open-Meteo terms.
Google Calendar data (optional, Pro only)
- If you connect Google Calendar, we store OAuth access and refresh tokens to create, update, or delete calendar events on your behalf.
- If you also turn on live timetable sync, we read the timed events in your selected calendar for the week being viewed (titles, start and end times, and locations) so they can be shown on your timetable. You can limit which events are matched using keywords. Event details for the current week may be cached in your account so the timetable and your daily summary email work. If live sync is off, we do not read your calendar; we only manage events the app created.
- You can revoke this access at any time from within the app or at myaccount.google.com/permissions.
Outlook (Microsoft) Calendar data (optional, Pro only)
- Outlook Calendar sync is available to Pro subscribers only. If you connect Outlook Calendar, you sign in with Microsoft and grant the delegated permissions
User.ReadandCalendars.ReadWrite. This lets Teacher Task Manager create and update calendar events on your behalf. - Sign-in is handled directly by Microsoft using a public-client (PKCE) flow. We do not use or store a Microsoft client secret, and the Microsoft access token is held only in your browser session (it is cleared when you sign out or disconnect); we do not store it on our servers.
- Task and event details needed to create or update an event are sent to the Microsoft Graph API. You can disconnect Outlook in Profile or revoke access at myaccount.microsoft.com/permissions.
School pricing enquiries
- If you complete the enquiry form on our school pricing page, we collect the details you provide: your name, work email address, school name, an approximate staff-count band, and any optional message. You do not need an account to send an enquiry.
- We use these details only to respond to your enquiry about school pricing. We do not use them for marketing or add you to any mailing list, and we do not sell them.
- Our lawful basis is our legitimate interest in responding to enquiries you choose to send us. We keep enquiry details for up to 24 months and then delete them automatically; you can ask us to delete them sooner at any time by emailing service@teacheradmin.com.
How We Use Your Information
We use the information we collect to:
- Create and manage your account
- Sync and display your tasks, notes, timetable, and calendar data across sessions and devices
- Enable collaboration features such as team task boards, shared calendars, and team chat
- Send push notifications for task assignments, due dates, and @mentions (Pro only)
- Send notification and summary emails (task assignments, @mentions, tasks due today, and daily or weekly summaries). Each category can be turned off in your profile settings
- Provide AI-powered features that process your task and context data (Pro only)
- Process your subscription payments via Stripe
- Sync events with Google Calendar or Outlook Calendar when you enable the integration (Pro only)
- Respond to enquiries you send us through the school pricing page
- Provide customer support
- Improve app functionality and user experience
- Communicate important information about the Service
We do not sell your data.
Legal Basis for Processing
We process your personal data under the following legal bases:
- Contract performance: processing necessary to provide the Service and manage your account and subscription.
- Consent: for optional features such as Google Calendar and Outlook Calendar integration (Pro only), push notifications, and AI features. You may withdraw consent at any time by disconnecting the feature within the app.
- Legitimate interests: for security monitoring, abuse prevention, service improvement, and responding to enquiries you send us (such as through the school pricing page), where these interests are not overridden by your rights.
- Legal obligation: where we are required by law to retain or disclose data (e.g. financial records for tax purposes).
How We Store and Protect Your Information
We use industry-standard security practices to protect your information, including encryption in transit (HTTPS/TLS) and access controls. Structured data is stored in Google Firestore and images are stored in Firebase Storage, both of which provide server-side encryption at rest.
Access to your data is restricted by Firestore security rules that permit only authenticated users to read their own data or data explicitly shared with them. Third-party services used for authentication and storage are required to follow strong data protection practices consistent with UK GDPR.
Data Sharing and Third-Party Services
We do not sell your personal data. We share data with the following third-party services only to the extent necessary to provide the Service:
- Firebase / Google: authentication (Firebase Auth), database (Firestore), image storage (Firebase Storage), and push notifications (Firebase Cloud Messaging). Google Privacy Policy.
- Vercel: hosts the app and our server-side API, so app traffic passes through Vercel's infrastructure. We also use Vercel's cookieless, aggregate page-view analytics inside the app; it sets no cookies, stores nothing on your device, and does not track you across sites. Vercel Privacy Policy.
- OpenAI: AI-powered features (Pro, plus the Timetable calendar setup helper on any plan). The data described in the AI Features section above is sent to OpenAI's API. Your data is not used to train OpenAI's models. See our AI & Data page and OpenAI Privacy Policy.
- Stripe: payment processing for Pro subscriptions. Stripe receives your email address and payment details. We do not store card numbers. Stripe Privacy Policy.
- Meta (Facebook): advertising measurement. When a Pro subscription is first purchased, we send Meta a single conversion event containing the amount paid, the currency, a hashed (unreadable) version of the purchaser's email address, and the purchaser's IP address and browser type at that moment. If you arrived via a Facebook or Instagram advert, the event also includes that advert's click identifier. All of this is so we can tell which of our adverts led to a purchase. No pupil data, class names, school details, or any app content is ever included. Separately, and only with your consent, the Meta Pixel described in the Cookies section runs on our public marketing pages. Meta Privacy Policy.
- Brevo: delivers our notification, summary, and service emails. Brevo processes the recipient address and the email content, which can include names and task titles. Brevo Privacy Policy.
- Sentry: crash and error monitoring. When the app hits an unexpected error, a technical error report is sent to Sentry to help us diagnose and fix it. This report contains the error message and code stack trace, the page address where it happened, and your browser and device type; Sentry also records the IP address the report is sent from. It does not include your name, email, or the contents of your tasks, notes, or messages, and Sentry sets no cookies and does not track you across sites. Reports are sent to Sentry's EU (Germany) region. Sentry Privacy Policy.
- Open-Meteo: if you enable the weather widget, your browser sends your approximate coordinates directly to Open-Meteo to fetch a forecast. No account information is sent, and our servers are not involved in the request.
- GIPHY: GIF search in team chat (Pro only). When you search for GIFs, your search query is sent to the GIPHY API. No account-linked data is transmitted. GIPHY Privacy Policy.
- Google Calendar API: if you connect Google Calendar (Pro only), task data is sent to Google's Calendar API to create, update, or delete events on your behalf.
- Microsoft Graph: if you connect Outlook Calendar (Pro only), you sign in with Microsoft and task and event data is sent to the Microsoft Graph API to create or update events on your behalf. See Microsoft Privacy Statement.
- Legal disclosure: we may disclose data where required by law, court order, or to protect the rights, property, or safety of our users or the Service.
We never sell personal information to advertisers or data brokers.
Google API Services User Data
Teacher Task Manager's use and transfer to any other app of raw or derived user data received from Google APIs, including Google Workspace APIs, will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
AI Features and Automated Processing
Pro users can access AI-powered features, and one setup helper is available on the Free plan too (see the end of this section). What is sent to OpenAI depends on the feature. Smaller assists send only the relevant task's title, category, and dates. Smart Add sends the single line you typed into it, and only when the keyword rules running on your device cannot read that line on their own. The AI Assistant chat sends your message together with context: your task titles and descriptions, team names and descriptions, team member display names (but not their email addresses), recent team chat messages, your school calendar, and your timetable class names. The day planner and free-period scheduler send your pending task and marking job titles alongside your timetable. The Report Assistant sends the report details you type, but not the pupil's name: the name is swapped for a placeholder on our server before the request is made and restored in the finished comment, so it never reaches OpenAI. The Lesson Planner sends the lesson details you enter. The Cover Work generator sends the class, subject and lesson details from the timetable slot you are covering plus any topic and spec/syllabus context you type or upload as a PDF (the PDF itself is read in your browser and never uploaded to us; only the extracted text is sent, the same as pasted text); it does not send any pupil names, and the spec/syllabus context is your own text and is not verified against a live or external source. The Timetable calendar setup helper, which is the one AI feature a Free-plan account can use, sends the event titles from the single week shown in the Live Sync settings so it can work out your class code format and what your school calls non-contact time; it sends titles only, with no event times, locations, guests or descriptions, it runs only when you press the button, and the settings it suggests are then applied by the app itself with no further AI calls. Notes page content is never sent to OpenAI. This data is used only to generate your response and is not used to train AI models under our API agreement with OpenAI. See our AI & Data page for a feature-by-feature table.
AI outputs, including priority suggestions, task descriptions, and follow-up recommendations, are advisory only and are never applied to your data without your explicit action. No automated decision-making within the meaning of UK GDPR Article 22 takes place; you remain in control at all times. See our AI & Data transparency page for a full feature-by-feature breakdown.
International Data Transfers
Some third-party services we use are based in the United States. Transfers of personal data to these services are made under appropriate safeguards:
- Google (Firebase, Google Calendar): Google LLC participates in the EU-US Data Privacy Framework and processes UK personal data under UK Standard Contractual Clauses (SCCs). Google may store data in globally distributed data centres.
- Microsoft (Outlook via Microsoft Graph): Microsoft Corporation participates in the EU-US Data Privacy Framework and processes UK personal data under SCCs. Microsoft may store data in globally distributed data centres.
- OpenAI: data is transferred to OpenAI's US-based infrastructure under SCCs included in OpenAI's API data processing addendum.
- Stripe: Stripe participates in the EU-US Data Privacy Framework and processes UK data under SCCs.
- Vercel: Vercel Inc. is a US company and processes UK personal data under SCCs in its data processing agreement.
- Brevo: Brevo is based in the EU and processes email data within the EU.
- Sentry: error reports are stored in Sentry's EU (Germany) region. Sentry is a US-headquartered company; where its US operations access the data, this is covered by SCCs in Sentry's data processing addendum.
- GIPHY (Meta): GIF search queries are processed by GIPHY (a Meta company) in the US. Only the search text is transmitted; no account-linked data is sent.
If you have questions about international transfers or wish to review the applicable safeguards, please contact us at service@teacheradmin.com.
Data Retention
We retain your data for as long as you maintain an account, with one exception for accounts nobody uses any more (see "Inactive free accounts" below). Specific retention periods are as follows:
- Account and profile data: retained until account deletion, then removed within 30 days.
- Inactive free accounts: if you are on the free plan and have not signed in for about six months, we email you to say the account is due to be closed, and we wait at least 14 days after that. Signing in at any point before the deadline keeps the account and everything in it. If you do not sign in, the account and its data are deleted permanently. Accounts with a current or past paid or gifted subscription are not affected.
- Tasks, notes, timetable, and school calendar data: retained until deleted by you or until account deletion, then removed within 30 days. Completed tasks are additionally deleted automatically 14 days after completion, and completed marking jobs 48 hours after being marked as entered.
- Chat messages: retained until deleted by you or until account deletion. When you delete your account, images and files you uploaded are deleted; messages you sent remain visible to the other participants, as they are part of their conversation history too.
- Chat images and file attachments: deleted automatically after a short period (7 days for images) even if the message remains.
- Bug reports and screenshots: retained while we investigate and removed when your account is deleted.
- Guided tour usage records: if you open the guided tour from your profile, we record which steps you reached and whether you finished, so we can tell where it is unclear. These are deleted automatically after 180 days, and your account identifier is removed from them straight away if you delete your account.
- FCM device tokens: retained until you sign out of a device or delete your account.
- Google Calendar OAuth tokens: retained until you disconnect Google Calendar from within the app or delete your account.
- Outlook Calendar (Microsoft) tokens: not stored on our servers. The Microsoft access token is held only in your browser session and is cleared when you sign out or disconnect.
- School pricing enquiries: the name, email, school, staff-count band, and message you submit through the school pricing page are kept for up to 24 months from submission, then deleted automatically. You can ask us to delete them sooner by emailing service@teacheradmin.com.
- Stripe billing records: we keep your Stripe customer and subscription identifiers for 6 years after your account is closed, so that we can meet UK tax and accounting record-keeping requirements. These identifiers are an exception to deletion: we keep them even if you delete your account, because UK GDPR Article 17(3)(b) allows us to retain data where we have a legal obligation to do so. They identify a payment record rather than anything you created in the app, and we do not use them for any other purpose once your account is closed. Stripe separately keeps its own transaction records for up to 7 years under its own legal and financial compliance obligations.
Where we are required by law to retain data beyond these periods, we will do so only to the extent required.
Your Rights
Under UK GDPR and the Data Protection Act 2018, you have the right to:
- Access: request a copy of the personal data we hold about you
- Rectification: request correction of inaccurate data
- Erasure: request deletion of your data (subject to legal retention obligations)
- Data portability: request your data in a structured, machine-readable format
- Objection: object to processing based on legitimate interests
- Restriction: request that we limit how we process your data in certain circumstances
- Withdraw consent: withdraw consent at any time for processing based on consent (e.g. Google Calendar, Outlook Calendar, push notifications)
- Automated processing: not be subject to decisions based solely on automated processing that produce legal or similarly significant effects. All AI suggestions in this app require your explicit action to take effect and do not constitute automated decision-making under Article 22.
To exercise any of these rights, contact us at service@teacheradmin.com.
You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection. Visit ico.org.uk/make-a-complaint or call 0303 123 1113.
Children's Privacy and Pupil Information
Teacher Task Manager is intended for school staff only and is not designed for use by students. We do not knowingly collect information from anyone under the age of 16. If you believe a person under 16 has created an account, please contact us and we will remove it promptly.
As a tool for teachers, some features let you type information that relates to pupils, for example the Report Assistant, task descriptions, or notes. The app asks you to use first names or initials only and to keep safeguarding, medical, and other sensitive details out of the app. You remain responsible for following your school's data protection policies when deciding what to enter. Where you use an AI feature, whatever you have typed into that feature is sent to OpenAI as described above; pupil information you save (such as comment bank entries) stays private to your account and is deleted with it.
Institutional Use
This app is designed for individual teacher professional use. Schools, multi-academy trusts, or other organisations wishing to deploy Teacher Task Manager at an institutional level should carry out their own Data Protection Impact Assessment (DPIA) in accordance with UK GDPR Article 35 before doing so.
We are not currently a registered data processor under a formal data processing agreement with schools or local authorities. Individual teachers using the app are responsible for ensuring their use is consistent with their school's data protection policies. If your organisation wishes to discuss a formal data processing arrangement, please contact us.
Cookies and Local Storage
When you first visit Teacher Task Manager we ask for your consent to use cookies and local storage. Below is a full explanation of what we use and why.
Essential storage (required for the app to work)
- Authentication tokens: set by Firebase Auth (Google) to keep you signed in across sessions. Without these you would be signed out on every page load.
- App preferences: values stored in
localStoragesuch as your timetable view, notification preferences, display settings, unsent chat drafts, and (if you enable the weather widget) your cached coordinates and forecast, so the app remembers your choices between visits. These stay on your device. - Cookie consent record: a single
localStorageentry (ttm_cookie_consent) that records your response to the consent banner. It stores the valueaccepted-v3-all,accepted-v3-analytics, ordeclinedwhen you choose, so the banner is not shown again on your next visit. (Visitors who consented under earlier banner wording may still have the legacy valueaccepted-v2, which covers analytics only.)
Optional analytics cookies (only with your consent)
- Google Analytics: if you choose “Analytics only” or “Accept all” on the consent banner, we use Google Analytics 4 on our public marketing pages (the home page, features, pricing, the blog and similar public pages) to understand how visitors find and use them. It sets cookies such as
_ga. It is never loaded inside the app itself, and it is never loaded if you choose “Essential only”. See Google's Privacy Policy.
Optional advertising cookies (only with your consent)
- Meta Pixel: if you choose “Accept all” on the consent banner, we use the Meta (Facebook) Pixel on our public marketing pages to measure whether our advertising brings visitors to the site. It sets cookies such as
_fbp. It is never loaded inside the app itself, and it is never loaded if you choose “Essential only” or “Analytics only”. See Meta's Privacy Policy.
What we do not use
- We do not set advertising or retargeting cookies without your explicit consent, and never inside the app.
- We do not use analytics or tracking cookies inside the app, and no analytics cookies are set anywhere without your consent.
- We do not share browsing data with data brokers, and nothing about your visit is shared with Google or Meta unless you have consented to their cookies above.
Third-party services that may set storage
- Firebase / Google: used for authentication and the Firestore database. See Google's Privacy Policy.
- Stripe: used for Pro subscription payments. Stripe may set cookies on payment pages for fraud prevention and security. See Stripe's Privacy Policy.
- GIPHY: used for GIF search in team chat (Pro only). GIPHY may set cookies or use browser storage for its own analytics when the GIF picker is opened. No account-linked data is transmitted. See GIPHY's Privacy Policy.
Managing cookies
You can clear cookies and local storage at any time through your browser settings. Clearing authentication storage will sign you out of the app. If you decline the cookie consent banner, strictly necessary storage (such as keeping you signed in once you log in) may still be used because it is essential for the service to function.
To withdraw cookie consent at any time, clear your browser's local storage for this site. The consent banner will reappear on your next visit.
Changes to This Policy
We may update this Privacy Policy from time to time. If we make significant changes, we will notify you through the app or by email.
Data Controller
Teacher Task Manager is operated by Teacher Admin Ltd, a company registered in England and Wales (company number 17319126), whose registered office is at 167-169 Great Portland Street, London, W1W 5PF. For the purposes of UK GDPR, Teacher Admin Ltd is the data controller for personal data collected through this Service.
Contact Us
If you have questions or requests related to this Privacy Policy or wish to exercise your data rights, please contact:
Company: Teacher Admin Ltd, 167-169 Great Portland Street, London, W1W 5PF
Service: Teacher Task Manager (teacheradmin.com)
Email: service@teacheradmin.com