How CurriculumHub collects, uses, and protects information — and what we deliberately never collect.
CurriculumHub is provided by [business name], based in the UK. For any questions about this policy or your data, contact hello@curriculumhub.co.uk.
CurriculumHub is a curriculum planning and organisation tool for school staff. It is not a pupil-facing product and contains no pupil records, pupil names, pupil data, or any special category data relating to children.
The only personal data we collect and store is:
| Data | Who it relates to | Why we collect it |
|---|---|---|
| Name | Staff members (co-admins) invited by their school | To identify who made changes to curriculum records |
| Email address | Staff members (co-admins) | To create a login and send account-related communications |
| Login credentials | Staff members (co-admins) | To authenticate access (handled securely via Supabase Auth — passwords are never visible to us in plain text) |
| School name | The subscribing school | To identify and label the account |
We also store the curriculum content itself (subjects, units, learning objectives, National Curriculum links, and similar) entered by staff. This content is created and owned by the school and does not include or reference any individual pupil.
We do not collect: pupil names, pupil data of any kind, special category data, or payment card details (handled by our payment processor, never stored by us).
We process staff name and email data under contract — it's necessary to provide the service the school has signed up for.
CurriculumHub is built on Supabase (database and authentication) and hosted on Vercel. Your data is stored in London, UK (AWS region eu-west-2). We do not transfer personal data outside the UK.
Sub-processors used to run the service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database hosting and authentication | London, UK (eu-west-2) |
| Vercel | Application hosting | [confirm region] |
We retain staff and curriculum data for as long as the school's subscription is active. If a school cancels, we delete account data within 30 days of cancellation unless asked to do so sooner. You can request a full data export at any time before cancelling.
Access to each school's data is restricted using database-level security rules (Row Level Security), so one school's data cannot be accessed by another. Authentication uses industry-standard password hashing; we never store plain-text passwords.
Under UK GDPR, staff members have the right to ask what data we hold about them, ask us to correct or delete it, request an export, or object to processing. Contact hello@curriculumhub.co.uk to exercise any of these rights.
CurriculumHub's website and application use only essential cookies required for login sessions to function. We do not use tracking or advertising cookies.
CurriculumHub is designed for use by school staff only and contains no functionality for entering pupil information. If you believe pupil data has been entered in error, contact us immediately and we will assist with removal.
We may update this policy from time to time. The "last updated" date above reflects the most recent change. Significant changes will be emailed to school admin accounts.
Contact us at hello@curriculumhub.co.uk in the first instance. You also have the right to lodge a complaint with the UK's Information Commissioner's Office (ICO) at ico.org.uk.