Privacy
Ribn holds children’s data, so this page is short and specific. The school decides what happens to that data. We only do what the school asks.
This website
This website sets no cookies, runs no advertising, embeds no third-party script and has no chat widget. The marking demonstration on the front page runs entirely in your browser: what you type into it is never sent anywhere, not even to us.
What we hold about a pupil
An identifier, a name, a username, a year group and a password hash. No date of birth, no email address, no photograph, no postcode, no free text profile. Beyond that we hold the work itself: the answers a pupil gave and the marks the engine produced.
Pupils do not create their own accounts. A school or a teacher creates them, which is what keeps the school in control of who is on the platform.
Who can see it
- The pupil, for their own work.
- Their teachers, and staff their school has given the relevant role.
- Nobody at another school, ever. That is enforced by the database rather than by our application code, and it is tested adversarially.
- Nobody at Ribn, except where a named member of staff needs access to fix a specific fault, which is written to an append-only audit log.
Where it never goes
- Never to a third-party model provider. A model may draft the wording of a question. It never sees a pupil, a response or a mark.
- Never to the payment processor. We bill on teacher seats, so no child is ever a line item on an invoice.
- Never used to train a model.Not ours, not anybody else’s.
- Never sold, and never shared for advertising.
How long we keep it
While the school is using Ribn, plus a defined period after that so a school can recover a year of work it deleted by accident. The exact retention schedule is being finalised with the data processing agreement, and both will be published on the school leaders page before the first pupil account exists.
Getting it back, or getting it deleted
A school can export its own data at any time, in a documented format, without asking us. A request from a parent or a pupil goes to the school, because the school is the controller. We act on the school’s instruction.
Safeguarding
Pupils have no free text message box and no way to contact each other, which is a deliberate design decision rather than a missing feature. Where a pupil can enter free text as part of an answer, a disclosure route to the school’s designated safeguarding lead exists before that surface reaches a pupil.
Asking us something
The contact page says how to reach us, including for a data protection question.