Privacy Policy

Last updated: 2 August 2026

This is a template privacy policy describing how PostDeck currently handles data. It has not been reviewed by a lawyer and should be replaced with reviewed legal copy, tailored to your school or organisation's obligations, before public launch.

1. Overview and commitment to privacy

PostDeck is a TeachSmarts product that lets a teacher turn a Google Slides deck into a live, self-paced classroom session: students join with a PIN or link, work through slides and interactive activities at their own pace, and the teacher reviews and exports what students submitted. We collect the minimum information needed to run that workflow, and we do not sell teacher or student data or use it for advertising.

2. Scope of this policy

This policy applies to the PostDeck web application and its associated backend services. It covers information collected from teachers who create an account, and from students who join a PostDeck session using a PIN or link. It does not cover third-party sites you may reach through links inside imported slide content, or Google's own services, which are covered by Google's privacy policy.

3. Definitions

"PostDeck", "we", "us" and "our" refer to the PostDeck service operated as part of the TeachSmarts product family. "Teacher" means an account holder who creates and runs sessions. "Student" means a participant who joins a session using a PIN or link. "Session" means a single PostDeck deck instance, including its slides, activities, and the student responses and events recorded against it.

4. What personal information we collect

4.1 Teacher account and identity information

When a teacher signs in with Google, we store their name, email address, Firebase user ID, and their PostDeck plan (free, Pro, or Power). Where a deployment is configured to a specific school or domain, sign-in may be restricted to approved email addresses.

4.2 Authentication and security information

We rely on Firebase Authentication with Google Sign-In or email/password accounts to verify identity. Passwords are handled by Firebase Authentication and are not stored by PostDeck. Email accounts must verify their address before using teacher features. We may log authentication events (sign-in, sign-out, session-token issuance) for security and abuse-prevention purposes.

4.3 Google service data (authorised by you)

Depending on the permissions a teacher grants at the point a feature is used, this may include: the single Google Slides presentation selected through Google's own file picker or supplied through a shared link (PostDeck never receives access to a teacher's whole Drive), Google Classroom course and topic names and IDs when posting or scheduling a session to Classroom, and the identifiers of any Google Sheet or Google Doc created when a teacher exports results. Google access tokens are used for the specific request they were issued for and are not stored by PostDeck's backend beyond that request. Email-authenticated teachers may instead import a presentation shared as “Anyone with the link can view,” without providing a Google OAuth token.

4.4 Student session data

When a student joins a session, we store the first name, surname, and school email address they provide (or, where guest join is enabled, a display name only), together with their responses to activities, word counts, teacher feedback left on those responses, and participation events such as joining, submitting, navigating slides, and losing or regaining browser focus. A session also stores the join PIN, imported slide content and speaker notes, and teacher-configured settings such as lock mode, maximum allowed focus losses, and minimum time per slide.

4.5 Usage and operational data

We collect standard operational data needed to run the service, such as request logs, error logs, and rate-limit counters. This data is used to keep PostDeck reliable and secure and is not used to build advertising profiles.

4.6 Billing information

Where a teacher subscribes to a paid plan, billing is handled by Stripe. We store the subscription status and plan tier associated with a teacher's account; we do not store full payment card details, which are handled directly by Stripe.

5. Sensitive information

PostDeck does not intentionally collect sensitive information (such as health, racial or ethnic origin, or religious belief) as part of its ordinary operation. Teachers should not include sensitive information in slide content, activity prompts, or session names unless it is genuinely necessary for the lesson and permitted under their school's own policies.

6. How we collect information

We collect information directly from teachers when they sign in, configure a session, or use an export/Classroom feature, and directly from students when they join a session and submit responses. We do not purchase personal information from third parties.

7. Purpose of collection and use

We use the information described above to: run live and self-paced sessions; let teachers review, provide feedback on, and export student results; enforce plan limits and lock-mode/focus-loss rules a teacher has configured; operate account and billing features; and maintain the security and reliability of the service.

8. Disclosure of information

8.1 Third-party service providers

We share information with service providers who help us run PostDeck, including Google Cloud Platform and Firebase (hosting, authentication, and data storage), Stripe (billing), and email delivery providers where a teacher chooses to email results to students. These providers are only given the access needed to perform their function.

8.2 Google

Where a teacher uses a Google-integrated feature (Slides import, Classroom posting or scheduling, Sheets/Docs export), the relevant request is made directly to Google's APIs using a short-lived access token obtained from the teacher's own Google session; PostDeck does not proxy or retain a persistent copy of the underlying Google file beyond what is needed to render the imported deck.

8.3 Legal and regulatory disclosure

We may disclose information where required to comply with a legal obligation, enforce our Terms of Use, or protect the rights, property, or safety of PostDeck, our users, or others.

9. Overseas disclosure

PostDeck is hosted on Google Cloud Platform, which may process and store data in data centres outside your country. By using PostDeck, you acknowledge that your information may be transferred to, and processed in, jurisdictions with different data protection laws than your own.

10. Data security

We use industry-standard measures to protect information, including encryption in transit, Firestore security rules that scope access to a session's own teacher, and short-lived, scope-limited Google access tokens. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Retention

Session, response, and participation data is retained for as long as the teacher's account and session records exist, so teachers can review past sessions and re-export results. A teacher can archive or delete a session from their dashboard; archived sessions remain accessible to the teacher, while deleted sessions are marked as closed and are no longer accessible to students.

12. Access and correction

Teachers can review, edit, and delete their own sessions and the responses recorded within them directly from the PostDeck dashboard. A student who wishes to access, correct, or delete their information should contact the teacher who ran the session, since the teacher is the one able to manage that session's records.

13. Children and student data

PostDeck is designed to be used by students under a teacher's supervision as part of a school-directed activity, not signed up to directly by children. Teachers and schools are responsible for obtaining any parental or guardian consent required under their own jurisdiction's laws before using PostDeck with students, and for configuring session settings (such as disabling guest join or restricting join to a school email domain) appropriately for the age of their students.

14. Cookies and local storage

PostDeck uses essential cookies and browser local storage to keep a teacher or student signed in and to remember in-progress session state (such as the current slide). We do not use third-party advertising or tracking cookies.

15. Changes to this policy

We may update this policy from time to time to reflect changes to the service. The "Last updated" date at the top of this page will change when we do. Continued use of PostDeck after an update constitutes acceptance of the revised policy.

16. Complaints and contact

Questions or complaints about this policy can be directed to the school or teacher administering the PostDeck session, or to TeachSmarts directly.