Qwizflow collects minimal data required to facilitate personalized learning. This includes:
Grade level, content level preference (beginner through expert), learning interests (selected from a fixed list), and academic challenges to customize the AI's tone and content. Your content level preference is used to adjust mastery pass-thresholds, making progression requirements slightly easier or harder based on your selected level. You may also tell us how you like to start learning (pictures, listening, doing, or reading); we use this only to decide which format is offered first, you can change or clear it in settings, and for learners under 13 it only changes the order of options on screen.
Text and images from uploaded study materials used exclusively to generate your personalized learning paths.
Short, written notes that a linked parent or a verified classroom teacher may leave on a student's learner profile (for example, context about a recent exam, a known accessibility need, or a goal). Annotations are stored as text only and are never processed as raw content by the AI; they are read alongside the learner profile to personalize the tone and pacing of AI responses. Each student has a maximum of 25 active annotations. Annotations are visible per their author-set visibility (parent-only, teacher-only, student-visible, or private). Students can request removal of any annotation about them.
All data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256. This ensures that even in the unlikely event of data interception, the information remains unreadable.
Before any curriculum data is sent to our AI engines, we apply a PII Scrubbing layer. It masks email addresses and phone numbers, strips known prompt-injection patterns, caps prompt length, and redacts names where they appear behind an explicit label (for example Name: or Student:). We do not send your account name, email address or date of birth as part of a prompt.
Being precise about the limits, because “the AI never sees your identity” would overstate it: the scrubber is pattern-based, so it cannot reliably catch personal details a user types into free text themselves — writing “my name is …” or a home address inside a homework question would not be masked. Please don’t include personal details in what you type. Two things are different by design and disclosed separately below: AI prompts may include your learning history (topics, strengths and misconceptions) so that help is personalised, and voice typing — where a learner aged 13 or over chooses it — is transcribed by their browser rather than by Qwizflow.
Qwizflow enforces strict role-based access controls to limit who can see what data:
Can view and manage only their own learning data, progress, and AI consent settings. Students aged 16 and above may manage their own AI consent; students under 16 require parental consent.
Can view their linked child's progress summaries and manage AI consent via the AI Consent Centre. Parents never have access to raw AI conversation transcripts. Consent audit logs are visible to linked parents for transparency.
Can view aggregated classroom analytics and safety flag summaries for duty-of-care obligations. Teachers have read-only access to consent status and never see raw AI conversation transcripts or individual student consent settings.
Can manage school-wide policies and approve teacher registrations. School administrators do not have access to individual student AI conversation transcripts.
Where multiple parents or guardians are linked to a student account, each parent can independently manage AI feature consent settings. When parents set conflicting preferences, the most restrictive setting is applied to protect the student. When one parent changes a consent setting, the other linked parent is notified of the change.
We partner with industry leaders to host your data under strict educational privacy agreements:
Data is stored in Google Cloud Firestore and Google Cloud Storage (Australian Regions prioritized).
Qwizflow does NOT sell, rent, or trade student data to third-party advertisers or data brokers.
If we relocate or expand our cloud infrastructure to a different country, or change personnel with access to unencrypted customer data, we will notify affected customers and school administrators at least 30 days prior to the change.
Qwizflow stores a small number of identifiers in your own browser. None of them is an advertising identifier, none is shared with any third party, and none is used to track you across other websites.
When you use Qwizflow without an account (“guest mode”), we store one random value in your browser’s local storage and send it with requests to our own API. It contains no personal information and is not derived from your device in any way — we do not use device fingerprinting. Its only purpose is to measure how much of the free guest trial has been used, so that the free AI allowance cannot be reset indefinitely by signing out and starting a new guest session. We use the IP address of your request for the same purpose. Both are converted to a one-way hash before being stored, are kept for 2 days and are then deleted automatically. They are never linked to a registered account, never used to build a profile, and never used for advertising.
Clearing your browser’s site data for Qwizflow removes the guest trial marker, as does using a private browsing window. Doing so does not disadvantage you. The marker is deliberately NOT removed when you sign out, because a value that disappeared on sign-out could not serve its only purpose.
We also keep your display preferences (theme, text size, sound) and, in guest mode, your in-session learning progress in your browser’s own storage so the app behaves consistently between visits. That data stays on your device and is not transmitted to us.
Qwizflow uses the following sub-processors to deliver our service. Personal information may be disclosed to these providers as described below. The lawful basis for all processing is explicit user consent (Australian Privacy Principle 3, APP 8.2(b)), obtained through session-based AI consent and the per-feature AI Consent Centre.
Google LLC
https://cloud.google.com/contact | privacy-questions@google.com
Student profiles, learning progress, quiz results, uploaded documents, consent records
Primary database and file storage for all user data
Australia (australia-southeast2, Melbourne)
Google LLC
https://cloud.google.com/contact | privacy-questions@google.com
Educational content prompts, topic names, education level (PII scrubbed)
AI quiz generation, quiz question image generation, study guides, tutoring, explanations, audio-style two-voice discussions of a quiz question when a student is stuck, kid-friendly vocabulary look-ups for words inside quiz questions, weekly portfolio captions (short AI summaries of work the student has saved that week), and AI-generated context briefs for student-initiated 'Ask my Teacher' help requests (the brief gives the teacher a PII-scrubbed summary of where the student is stuck, drawn from their learner model, recent errors, and the question they were on)
Prompts are processed via Google's GLOBAL Vertex AI endpoint, so text-generation prompts may transit and be processed outside Australia. This changed on 2 August 2026 when the default text model moved to a tier Google does not serve from australia-southeast1. Data AT REST — your account, learning records and generated content — remains in Australia (Firestore, australia-southeast2, Melbourne). Prompts carry educational content with contact details scrubbed; Google processes them under its Data Processing Addendum and does not use them to train its models.
Google LLC (no separate sub-processor — the two Google services named here are listed in their own rows)
https://cloud.google.com/contact | privacy-questions@google.com
The tutor's replies are text generated by Google Gemini (see Google Vertex AI — Text Generation above) and then read aloud by Google Cloud Text-to-Speech (see below). There is no live two-way voice call: that feature, and the parent listen-in that went with it, were withdrawn on 30 April 2026.
Text only — what is sent to generate a reply is described under Text Generation, and what is sent to speak it is described under Text-to-Speech. Qwizflow does not send microphone audio to Google. Where a learner aged 13 or over chooses to speak instead of type, their browser transcribes the speech (see Browser Speech Recognition below) and Qwizflow receives only the resulting text.
As listed for Text Generation and for Text-to-Speech.
Spoken audio has a daily allowance that varies by age band; once that allowance, and any purchased credits that extend it, are used, replies are spoken by your device's own built-in voice where it has one (see below). Gated under the existing AI Quiz Generation consent — turning that off immediately disables the tutor.
Google LLC
https://cloud.google.com/contact | privacy-questions@google.com
Server-side text-to-speech synthesis of already-consented content (quiz explanations, hints, study guides, tutor responses, mnemonics, story content, AI-generated guides). The TTS service does NOT generate AI content — it converts existing student-consented text into audio.
UTF-8 text only (no audio uploads from student devices). No PII in synthesis bodies — the text is server-built from already-consented AI outputs.
Australia (australia-southeast1)
90-day GCS audio cache at tts-cache/{sha256}.mp3; cache key derived from voice / mood / text SHA-256. Google retains per its Data Processing Addendum.
A daily spoken-audio allowance for each person, which varies by age band and role and is enforced server-side.
Google LLC
https://cloud.google.com/contact | privacy-questions@google.com
Educational content prompts only — no student PII
Quiz question images, comics, and visual learning content
Processed by Google through its GLOBAL Vertex AI endpoint, so image prompts may transit and be processed outside Australia and the location is not pinned to one region. This has applied since 18 September 2026, when image generation moved to a model Google serves only from that endpoint. It is a cross-border disclosure under Australian Privacy Principle 8; Google processes the prompts under its Data Processing Addendum.
Google LLC (no new sub-processor — the same Google Cloud Text-to-Speech and Google Vertex AI image services listed above)
https://cloud.google.com/contact | privacy-questions@google.com
An optional purchased extra, the Studio Pack. Studio Voice reads the same text aloud in a higher-quality voice. Studio Pictures, when it is offered, draws a picture for a quiz question; when it is not offered, nothing is sent for it.
Text only, on the same terms as the two services above. Studio Voice sends the text to be spoken; Studio Pictures sends an educational description of the picture to draw. No learner name, email address or date of birth is included.
Never to under-13s. A linked child aged 13 or over can use it only while a parent has turned on that child's Studio switch.
The same as the underlying service: see Google Cloud Text-to-Speech and Google Vertex AI — Image Generation above.
Your device or browser vendor — for example Google, Apple or Microsoft
When Qwizflow's own spoken audio is not available — for example once the daily spoken-audio allowance is used — text can be read aloud by the speech synthesis built into your device or browser instead.
The text being read aloud. Many devices turn it into speech on the device itself; some browsers and voices send the text to the vendor's servers to do it. It does not pass through Qwizflow's servers.
Determined by your device or browser vendor. Governed by their privacy policy, not ours.
Google LLC
https://firebase.google.com/support | firebase-support@google.com
Email address, display name, profile photo URL, authentication tokens
User authentication via Google OAuth
United States (global service)
Google LLC (already a sub-processor above — this discloses an additional data flow, not a new organisation)
https://cloud.google.com/contact | privacy-questions@google.com
IP address, browser and device characteristics, and interaction signals (mouse, touch, keyboard timing and page-behaviour telemetry) collected automatically by the reCAPTCHA script on pages where a sign-in can occur. No learning data, no quiz content, no AI prompts and no account details are sent.
Automated abuse prevention only. reCAPTCHA scores the interaction and Firebase App Check exchanges that score for a token proving the request came from the genuine Qwizflow app, which stops automated scripts creating unlimited accounts through the guest entry point. Not used for advertising, profiling or personalisation, and it never influences a learner's content or assessment.
United States. This is a cross-border disclosure under Australian Privacy Principle 8; Google LLC is bound by the Google Cloud Data Processing Addendum and the disclosure is limited to the technical signals listed above.
Per Google's reCAPTCHA retention policy. Qwizflow does not receive, store or log the raw signals — only the pass/fail attestation result.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Functional Software, Inc. (Sentry)
https://sentry.io/contact/ | privacy@sentry.io
JavaScript error stack traces, redacted URLs (query strings stripped), redacted breadcrumbs (fetch/xhr/navigation), SHA-256 hashed user id (first 16 hex chars only — never the raw uid). Email, name, DOB, authentication tokens, and Authorization headers are stripped before transmission via the client-side scrubber.
Production browser-error visibility (lazy-loaded SDK; only initialised when VITE_SENTRY_DSN is set). Performance tracing and session replay are disabled (tracesSampleRate = 0, replaysSessionSampleRate = 0).
AU/EU residency required for student deployments. The operator MUST configure VITE_SENTRY_DSN against a Sentry organisation provisioned in the EU region (de.sentry.io) or an AU region; US-residency DSNs are not deployed to Qwizflow.
Per Sentry's default retention policy (90 days for error events on the standard plan). Qwizflow does not extend retention.
Stripe Payments Australia Pty Ltd / Stripe, Inc.
https://stripe.com/contact | https://stripe.com/privacy
Parent / account-holder billing details (name, email, and card data entered directly into Stripe's hosted checkout). Card numbers are entered on Stripe's pages and are never seen or stored by Qwizflow. A child is never the payer and is never asked for payment details.
Processing one-off purchases of prepaid credits, and — only where the account holder explicitly turns it on — optional automatic 'auto-reload' top-ups (a recurring, off-session card charge using the saved card when the credit balance runs low). There is no subscription. Only present when credit purchasing is enabled; the free daily experience uses no payment processor.
For accounts where a child uses credits, the parent's successful card transaction is recorded as the verifiable parental consent event for that purchase — the charge to the parent's card is the consent. Students under 16 cannot purchase; students 16 or over may purchase for their own account.
A reference (pointer) to the Stripe customer record, plus a credit history / ledger of purchases, automatic top-ups, credit usage, refunds, and any bonus credits earned through learning. No card numbers, CVV, or full card details are stored by Qwizflow (PCI scope stays with Stripe). Parents can manage their saved card and view receipts via Stripe's Customer Portal; on account deletion the Stripe customer and saved card are deleted/detached.
United States (Stripe, Inc.), with billing entity Stripe Payments Australia Pty Ltd. Processing is governed by Stripe's Data Processing Agreement.
Microsoft Corporation
Operational monitoring of the backend API — request timings, error traces, dependency failures and performance counters. Used to detect outages and diagnose faults.
Request paths, status codes, latency, exception stack traces and a hashed session identifier. User identifiers are hashed before they reach telemetry, and prompt or response content is not sent.
Australia (Azure Australia Southeast — the same region as the backend API)
Your browser vendor — in Chrome and Edge this is Google LLC; in Safari, Apple Inc.
Optional voice-to-text input in the tutor chat composer, so a learner can speak instead of typing. Only active while the learner is holding the microphone control.
Microphone audio. This uses the browser's built-in Web Speech API — in most browsers, including Chrome, that means the audio is sent to the browser vendor's speech servers for transcription. It does NOT pass through Qwizflow's servers, and we receive only the resulting text.
Learners aged 13 and over only. Under-13 Kids Mode is tap-only and listen-only — the microphone composer is never rendered for a child, so no under-13 audio reaches this path.
Determined by your browser vendor, typically the United States. Governed by their privacy policy, not ours.
Qwizflow publishes its blog content to a small set of public developer / professional / social platforms as a growth channel. This is author tooling — only the platform team is authenticated against these services, and only blog post content (which contains no student personal information by design) is transmitted. No student account data, learning data, or identifiers are ever sent to these platforms.
Blog post markdown + tags + canonical URL → published under the author persona's dev.to account. United States. https://dev.to/privacy
Blog post markdown + tags + canonical URL → uploaded as a draft via the Medium Integration API. United States. https://policy.medium.com/medium-privacy-policy-f03bf92035c9
Long-form post text + canonical URL → posted to the author persona's LinkedIn account via the UGC API. United States. https://www.linkedin.com/legal/privacy-policy
Blog post markdown + tags + canonical URL → published to the author persona's Hashnode publication via GraphQL. United States. https://hashnode.com/privacy
Numbered thread text staged on disk for manual copy-paste (export-only in v1; no API publishing). United States. https://twitter.com/en/privacy
Author tooling — the team posts under named author personas (with AI-assisted disclosure on each byline). No student personal information is ever transmitted to these platforms.
Google services are operated by Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) and processing is governed by the Google Cloud Data Processing Addendum. Ready Player Me (Wolf3D OÜ, Estonia) was a sub-processor for the Custom Character Creator feature until 2026-01-31, when the Ready Player Me service was shut down following Wolf3D OÜ's December 2025 acquisition by Netflix Inc.; the feature and its sub-processor entry were fully retired on 2026-05-09 and there is no active data flow to Ready Player Me, Wolf3D OÜ, or Netflix Inc. No student personally identifiable information was ever transmitted to Ready Player Me — only avatar design configuration. Content syndication platforms (dev.to, Medium, LinkedIn, Hashnode, X/Twitter) are listed as author-tooling sub-processors above and are governed by their own privacy policies linked in the same list. Qwizflow does not use any other sub-processors beyond those listed above.
As a linked parent or guardian, you have the right to see what the AI knows about your child's learning and how our sub-processors are used on their behalf. The AI Transparency Ledger surfaces, for each of your linked children:
Access is strictly limited to verified linked parents and is enforced by ownership checks at the API layer. Teachers, school administrators, and other parents never see this surface for your child.
Qwizflow's core experience is free, and there is no subscription. Every account has a generous free daily AI allowance. If you choose to keep using AI features beyond that allowance, you can optionally buy prepaid credits in one-off bundles. How credits work, who can buy, the shared family wallet, and optional auto-reload are described in our Terms of Use. This section explains what payment-related data we handle.
Qwizflow is used by children. This section is written for parents and guardians and sets out what we collect from a child, what we do with it, and what you can ask us to do.
Every AI feature is switched off until it is consented to, feature by feature. For a learner under 16, that consent must come from a linked parent or guardian; from 16 a learner may consent for themselves. Consent can be withdrawn at any time in Settings → AI Consent Centre, and withdrawing it disables that feature immediately.
Being straightforward about the limits of that mechanism: a parent or guardian is linked by entering a code the child gives them, and we verify that the linked account is a different person from the child — not their real-world identity or relationship. So the consent record shows that a linked adult approved a feature, not that we have independently confirmed who that adult is. Non-AI features such as quizzes and learning paths are available to a child before any adult is linked, and the account details listed above are collected at sign-up.
As a linked parent or guardian you can: review what we hold about your child, including the AI Transparency Ledger described in section 4a; turn any AI feature on or off; erase the AI learning context we have built about your child; and request that we delete your child’s account and its associated records entirely. To make any of these requests, contact us through the in-app feedback portal or the complaints route in section 6. We will acknowledge within 5 business days. There is no charge for any of this, and we will not ask your child to justify it.
If you would prefer your child not use AI features at all, you can simply leave every feature switched off — the rest of the platform works without them.
Under the Australian Privacy Principles, you have the right to:
If you believe your privacy has been breached, or you wish to make a complaint about how we handle your personal information, please contact us through the in-app feedback portal. We will acknowledge your complaint within 5 business days and provide a written response within 30 business days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au/privacy/privacy-complaints.