cohort.run ← Back to sign in

Privacy Policy

Last updated: 18 June 2026

This Privacy Policy explains how cohort.run ("we", "us", "our") collects, uses, and protects personal data when you use our platform. We are committed to compliance with the UK GDPR, EU GDPR, and applicable data protection laws.

1. Data Controller

cohort.run is the data controller for teacher account data. For queries about this policy or to exercise your rights, contact us at: privacy@cohort.run

2. Data We Collect

Teacher accounts:

Student data (entered by teachers):

Usage data:

3. Legal Basis for Processing (GDPR Art. 6)

PurposeLegal basis
Providing the service (account, sessions, lessons)Contract performance (Art. 6(1)(b))
Email verification and password resetContract performance (Art. 6(1)(b))
Security, fraud prevention, server logsLegitimate interests (Art. 6(1)(f))
Compliance with legal obligationsLegal obligation (Art. 6(1)(c))
Transactional emails (billing, receipts)Contract performance (Art. 6(1)(b))

4. How We Use Your Data

We do not sell your data, use it for advertising, or share it with third parties except as described below.

5. Third-Party Processors

ProcessorPurposeLocation
RenderCloud hosting (servers, database)USA (SCCs applied)
ResendTransactional email deliveryUSA (SCCs applied)
Google (OAuth)Optional sign-in via Google accountUSA (SCCs applied)
OpenAIAI-assisted lesson features (no personal data sent)USA (SCCs applied)
AWS S3File and media storageUSA (SCCs applied)

All processors outside the UK/EEA are subject to Standard Contractual Clauses (SCCs) or equivalent safeguards under UK GDPR Article 46.

6. Cookies

We use only strictly necessary session cookies:

These cookies are required for the service to function. No tracking, advertising, or analytics cookies are used. Under the UK PECR / EU ePrivacy Directive, strictly necessary cookies do not require prior consent.

7. Data Retention

8. Your Rights (GDPR Art. 15–22)

You have the right to:

To exercise any right, email privacy@cohort.run. We will respond within 30 days. If you are unsatisfied, you have the right to lodge a complaint with your supervisory authority (in the UK: the ICO; in the EU: your national DPA).

9. Data Security

We use industry-standard measures including TLS encryption in transit, bcrypt password hashing, signed httpOnly cookies, and access controls on our infrastructure. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security.

10. Children's Data

cohort.run is a tool for teachers. Teachers may enter student names and IDs as part of their class management. We do not knowingly collect data directly from children. Teachers are responsible for ensuring they have appropriate authority (such as school policy or parental consent) before entering student data into the platform.

11. Changes to This Policy

We may update this policy. Material changes will be notified by email to registered teachers. The "Last updated" date at the top reflects the most recent revision. Continued use of the platform after changes constitutes acceptance.

12. Contact

For any privacy-related questions: privacy@cohort.run