← Back to sign in
Last updated: 18 June 2026
This Privacy Policy explains how cohort.run ("we", "us", "our") collects, uses, and protects personal data when you use our platform. We are committed to compliance with the UK GDPR, EU GDPR, and applicable data protection laws.
cohort.run is the data controller for teacher account data. For queries about this policy or to exercise your rights, contact us at: privacy@cohort.run
Teacher accounts:
Student data (entered by teachers):
Usage data:
| Purpose | Legal basis |
|---|---|
| Providing the service (account, sessions, lessons) | Contract performance (Art. 6(1)(b)) |
| Email verification and password reset | Contract performance (Art. 6(1)(b)) |
| Security, fraud prevention, server logs | Legitimate interests (Art. 6(1)(f)) |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) |
| Transactional emails (billing, receipts) | Contract performance (Art. 6(1)(b)) |
We do not sell your data, use it for advertising, or share it with third parties except as described below.
| Processor | Purpose | Location |
|---|---|---|
| Render | Cloud hosting (servers, database) | USA (SCCs applied) |
| Resend | Transactional email delivery | USA (SCCs applied) |
| Google (OAuth) | Optional sign-in via Google account | USA (SCCs applied) |
| OpenAI | AI-assisted lesson features (no personal data sent) | USA (SCCs applied) |
| AWS S3 | File and media storage | USA (SCCs applied) |
All processors outside the UK/EEA are subject to Standard Contractual Clauses (SCCs) or equivalent safeguards under UK GDPR Article 46.
We use only strictly necessary session cookies:
cohort_teacher — keeps you signed in as a teacher (30-day expiry, httpOnly)cohort_student — keeps a student in their session (4-hour expiry, httpOnly)These cookies are required for the service to function. No tracking, advertising, or analytics cookies are used. Under the UK PECR / EU ePrivacy Directive, strictly necessary cookies do not require prior consent.
You have the right to:
To exercise any right, email privacy@cohort.run. We will respond within 30 days. If you are unsatisfied, you have the right to lodge a complaint with your supervisory authority (in the UK: the ICO; in the EU: your national DPA).
We use industry-standard measures including TLS encryption in transit, bcrypt password hashing, signed httpOnly cookies, and access controls on our infrastructure. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.
cohort.run is a tool for teachers. Teachers may enter student names and IDs as part of their class management. We do not knowingly collect data directly from children. Teachers are responsible for ensuring they have appropriate authority (such as school policy or parental consent) before entering student data into the platform.
We may update this policy. Material changes will be notified by email to registered teachers. The "Last updated" date at the top reflects the most recent revision. Continued use of the platform after changes constitutes acceptance.
For any privacy-related questions: privacy@cohort.run