Information
Privacy
This is a local-first learning tool. The person or organisation operating this installation is the data controller and must provide their identity and contact details to learners and families.
What is collected and why
The service records an email address, display name, school year, subscription identifier and subscription start and end dates, generated question, submitted answer, mark, retry number, topic, difficulty, learner-level snapshot and date/time. It also records progress resets, including their scope, time and whether the learner or an administrator initiated them. Authentication, subscription-access, payment and progress-reset audit events record the source network address. If Google or Microsoft sign-in is enabled and chosen, the service additionally records the provider, its stable account identifier, provider email, applicable Microsoft tenant identifier, and link and last-login times. If Stripe Checkout is enabled and used, the service records Stripe Customer, Checkout Session, PaymentIntent and webhook-event identifiers, the Price identifier, payment status, amount, currency and processing times against the internal account identifier. Card details and the payer's billing details are collected directly by Stripe and are not stored by this service. The service uses this information to authenticate the learner, enforce and extend paid access, prevent duplicate payment fulfilment, protect accounts, adapt practice, show learner progress and provide a password-protected administrator maintenance area. It does not ask for a date of birth or school identifier. Locally created passwords are stored only as salted one-way hashes.
Storage, hosting and sub-processors
Account, session and practice records are stored in SQLite and an append-only record for local development, or in PostgreSQL for a configured deployment. Production connections are required to use HTTPS so account and learning data is encrypted in transit. During the first account registration after an upgrade, the browser may read its old opaque learner identifier to claim matching progress; it removes that obsolete mapping after a successful claim. New credentials and sessions are not stored in browser storage.
If a learner chooses Google or Microsoft sign-in, the browser is sent to that provider and the provider learns that its account is being used to sign in to Maths Step. Maths Step requests identity and email information only. It does not request or receive email messages, contacts, calendars, cloud files, provider passwords or multi-factor authentication secrets. Short-lived provider tokens are validated during sign-in and are not retained. Google or Microsoft processes the sign-in under its own privacy terms. The app sends no learning answers or progress to either identity provider, or to an advertising, analytics or AI provider. The operator must identify enabled identity providers and any hosting, backup, monitoring, reverse-proxy, email or support providers in its deployment information.
If a parent or guardian starts Stripe Checkout, the browser is sent to Stripe and Stripe processes the payer's billing and payment information under its own privacy terms. Maths Step sends only the internal account identifier and purchase type needed to apply access; it does not send learning answers or progress. The operator must identify Stripe as a payment processor when Checkout is enabled.
Retention and deletion
Expired sign-in sessions and invalid subscriptions stop granting access, but account, subscription and learning records are retained until the operator removes them under its retention process; there is currently no automatic account or attempt deletion. Ask the operator named on the Contact page to access or delete a learner record. The operator should verify the request, securely remove the matching account and attempt records and applicable backups, then confirm the outcome. Deleting an entire file or volume affects every learner and requires the data owner’s explicit approval.
Your rights
Depending on the operator’s lawful basis and circumstances, UK data-protection rights can include access, correction, erasure, restriction and objection. Raise a request with the operator first. You may also complain to the UK Information Commissioner’s Office.