Draft — not yet legal advice
This document is a working draft prepared from primary-source research into the Saudi Personal Data Protection Law (PDPL), the EU and UK GDPR, the US Children's Online Privacy Protection Act (COPPA) and the US Digital Millennium Copyright Act (DMCA). It has not been reviewed by a lawyer. It is not legal advice and it does not create a solicitor-client or attorney-client relationship.
Before OLAYN launches, this document must be reviewed and signed off by qualified counsel: a Saudi PDPL practitioner as the primary reviewer, plus US counsel (COPPA and DMCA), and EU/UK counsel if the platform is offered to learners or schools in those markets. Passages marked in amber still need real information supplied by OLAYN.
Privacy Notice
This notice explains what personal information OLAYN ISLAMIC FOUNDATION collects when you or your child use our website, courses and classroom tools, why we collect it, who we share it with, and what you can do about it. We have tried to write it so that a parent can read it without a law degree.
1. Who we are and how to reach us
OLAYN ISLAMIC FOUNDATION ("OLAYN", "we", "us") operates this website and the learning platform on it. We are the data controller for the personal data described in this notice: we decide why it is collected and how it is used.
- Controller: OLAYN ISLAMIC FOUNDATION
- Operated by: Yarra Abdulaziz Alhamoud
- Established in: the Kingdom of Saudi Arabia
- Registered address: [ TO BE COMPLETED: full street address, city and postcode in Saudi Arabia ]
- Registration number: [ TO BE COMPLETED: commercial registration (CR) number or foundation registration number ]
- Email: olaynislamicfoundation@gmail.com
- Telephone: [ TO BE COMPLETED: working telephone number — required by COPPA 16 CFR 312.4(d) and by EU consumer law, an email address alone is not sufficient ]
- Enquiry form: yarra-atlas.com/hire
Data protection officer: [ TO BE COMPLETED: whether a data protection officer must be appointed under the PDPL Implementing Regulations, and if so their name and contact details ]
EU / UK representative: [ TO BE COMPLETED: an Article 27 representative in the EU and/or UK, if OLAYN offers the service to learners or schools there ]
2. The short version
The full detail is below, but in plain English:
- You sign in with a Google account. We receive your name, email address and Google profile picture. We never see or store your Google password.
- As you learn, we store your progress: lessons completed, test scores, game results, worksheet answers, grades and teacher feedback.
- If you use the speaking practice, your voice recording is sent to Google's speech recognition service to be turned into text, and we keep the text and the score.
- If your school uses OLAYN, your teacher and your school's staff can see your work and grades. That is the point of a classroom.
- We never sell personal data, never show advertising, and never use a child's data for marketing, profiling or to train artificial intelligence models.
- Our servers and service providers are outside Saudi Arabia, mainly in the United States.
- You can ask us for a copy of your data, ask us to correct it, or ask us to delete it. We will reply within 30 days.
3. Children, age and consent
OLAYN teaches Arabic and Islamic studies, and a large part of our audience is children. We take that seriously and this section is deliberately near the top.
Our age policy
Minimum age: [ TO BE COMPLETED: the minimum age for holding an OLAYN account, and the minimum age for using it under a parent or school account — this must be decided with counsel and stated here ]
Our intention is that a child never creates an account for themselves. A child uses OLAYN either through an account held and controlled by their parent or guardian, or through a school account created for them by their school.
How consent is obtained
- Parents and guardians. Where a child uses OLAYN at home, the parent or guardian creates the account, accepts our Terms of Service, and gives consent for the processing described in this notice. The parent or guardian is the account holder.
- Schools. Where a school enrols students, the school gives consent on behalf of parents for the educational use of student data. This is permitted under COPPA's school-consent route and is normal practice in EdTech, but it has hard limits, set out below.
The limits of school consent
A school can only consent to what a school has authority over. Specifically, school consent covers the delivery of lessons, marking of work and reporting of grades, and nothing else. It does not cover, and we will not treat it as covering:
- any commercial use of a student's data;
- marketing or advertising to a student;
- building a profile of a student for any purpose other than their own learning;
- disclosing a student's data to anyone other than their school and us.
A school that enrols students must, under COPPA and under its own duties, tell parents which services it has authorised and what data those services collect. Parents keep the right to review and delete their child's data (see section 13) — a school cannot sign that right away.
Verifying that a guardian really is the guardian
Honest disclosure — this is not built yet. The PDPL Implementing Regulations require a controller to take reasonable steps to verify that a person giving consent for a child genuinely holds guardianship. COPPA requires "verifiable" parental consent, which is a higher bar than a tick-box. Today, OLAYN does not collect a date of birth, does not run an age check at sign-up, and has no mechanism for verifying guardianship. We rely on the school in the classroom product, and on the parent's own statement at home.
[ TO BE COMPLETED: design and build an age gate and a verifiable parental-consent method before opening to children — then replace this paragraph with a description of the method used ]
If you believe a child has given us personal data without the consent of their parent, guardian or school, email us and we will delete it. See section 13.
4. What personal data we collect
The table below is the real list, taken from the platform itself. The last column tells you whether the data is required (we cannot run the service without it) or optional (only collected if you choose to use that feature). This distinction is required by Article 13(2) of the Saudi PDPL.
| Category | What it actually is | Where it comes from | Required or optional |
|---|---|---|---|
| Account and identity | Your name, email address, Google profile picture, and the Google account identifier. We also store the access and refresh tokens Google issues so you stay signed in. | Google, when you sign in | Required — there is no other way to sign in |
| Learning progress | Lessons and chapters completed, XP and level, test attempts and scores, flashcard results, letter-mastery records. | Generated as you use the courses | Required for the courses to work |
| Voice recordings and transcripts | Short audio clips of you pronouncing an Arabic word, the text Google's speech service produces from them, a confidence score and a pass/fail result. We keep the text and score; the audio is sent to Google for recognition and is not stored in your account. | Your microphone, only when you press record | Optional — only if you use speaking practice and allow microphone access |
| Worksheet submissions | Handwriting you draw on-screen (saved as an image), and any image or PDF file you upload as an answer. PNG, JPG, WebP or PDF, up to 25 MB. | You, when you submit a worksheet | Optional at home; effectively required if your teacher sets a worksheet |
| Grades and feedback | Scores your teacher records, written feedback, calculated chapter grades and final grades. | Your teacher, and our grade calculations | Required if you are in a classroom |
| School and classroom membership | Which school and classroom you belong to, your role (student, teacher, school admin, owner), enrolment status, assignments set and submitted. | Your school, and you when you join with a code | Required for the school product |
| Games and multiplayer racing | Game scores and attempts, race results and answers, monthly leaderboard position, daily play counts, and an online/offline presence flag. A random device identifier is stored in your browser to keep race sessions apart. | Generated as you play | Optional — only if you play the games |
| Subscription and billing | Subscription status and tier, renewal date, and the customer and subscription identifiers issued by Paddle. We never receive or store card numbers — card details are entered on Paddle's or Stripe's own payment pages, not ours. | Paddle, via its webhooks | Optional — only if you buy a subscription |
| Email and marketing | For pre-launch signups: name, email address and the role you selected. For newsletters and coupon emails: your email address and whether you have unsubscribed. | You, when you fill in the signup form | Optional — nothing else depends on it |
| Technical and security data | Your IP address and browser user-agent, processed by our servers and by our hosting provider to apply rate limits, block abuse and keep server logs. | Automatically, from your browser | Required — a web service cannot function without it |
What we do not collect
We do not collect passwords (sign-in is handled entirely by Google), card or bank details, national ID or passport numbers, home addresses, phone numbers, precise location, or any special-category data such as health information. We do not run advertising trackers: there is no Google Analytics, no Meta or Facebook pixel, no TikTok pixel and no advertising network on this site.
5. What happens if you do not provide it
Saudi PDPL Article 13(5) requires us to tell you the consequences of refusing to provide personal data. Here they are, honestly:
| If you do not provide | What happens |
|---|---|
| A Google account to sign in with | You cannot create an OLAYN account at all, and cannot access any course, worksheet or classroom. There is no alternative sign-in method. |
| Microphone access for speaking practice | Speaking exercises will not work. You will not earn the XP attached to them, and if your teacher assesses pronunciation, that part of your work cannot be marked. Everything else in the course still works. |
| A worksheet answer, when one has been set | The assignment stays unsubmitted. Depending on your teacher's settings it may be recorded as late or missed, which can lower your chapter grade. |
| Payment details to Paddle | You cannot start or renew a paid subscription, and paid content stays locked. Free content is unaffected. |
| Your school or classroom join code | You will not be enrolled in the classroom, so your teacher cannot set you work or grade you. |
| Consent to marketing email | Nothing at all happens to your account. You simply will not receive launch news or newsletters. Marketing consent is never a condition of using OLAYN. |
| Your IP address or browser information | This is not something you can withhold and still browse the web — it is how your browser reaches our servers. If you block it entirely, the site will not load. |
6. Why we use it, and our lawful basis
Under the GDPR and UK GDPR we must have a lawful basis for each purpose. Under the PDPL we must have a legitimate legal justification. This table maps both.
| Why we process it | Which data | Lawful basis (GDPR / UK GDPR) | Basis under Saudi PDPL |
|---|---|---|---|
| Creating and running your account | Account and identity | Art 6(1)(b) — performance of a contract with you | Necessary to perform a contract to which the data subject is a party |
| Delivering lessons, tracking progress, awarding XP | Learning progress, games | Art 6(1)(b) — performance of a contract | Contract performance |
| Marking work, calculating and reporting grades | Worksheets, grades, classroom membership | Art 6(1)(b) — performance of a contract with the parent or school | Contract performance |
| Assessing Arabic pronunciation | Voice recordings and transcripts | Art 6(1)(a) — your consent, given when you allow microphone access | Consent |
| Taking payment and managing subscriptions | Subscription and billing | Art 6(1)(b) — performance of a contract | Contract performance |
| Keeping tax and accounting records | Transaction records | Art 6(1)(c) — compliance with a legal obligation | Compliance with a statutory obligation |
| Security, rate limiting, preventing abuse and cheating | Technical data, game and race records | Art 6(1)(f) — our legitimate interest in a safe, working service | Legitimate interest of the controller |
| Sending launch news and newsletters | Email and marketing | Art 6(1)(a) — your consent, withdrawable at any time | Consent |
| Improving the courses using aggregate, non-identifying statistics | Aggregated learning progress | Art 6(1)(f) — legitimate interest in improving teaching quality | Legitimate interest of the controller |
A note on children and "legitimate interests"
Where the person is a child, we do not rely on legitimate interests for anything beyond keeping the service secure and working. For everything else affecting a child, our basis is the contract with the parent or school, or consent given by the parent, guardian or school. [ TO BE COMPLETED: PDPL counsel to confirm the position on legitimate interests where the data subject is a minor, and whether a documented Legitimate Interests Assessment is required ]
Automated decisions
Chapter and final grades are calculated automatically from the scores your teacher enters, using the weightings your teacher sets. This is arithmetic, not profiling, and a teacher can always override the result. We do not make any decision about you by automated means alone that produces a legal effect or similarly significantly affects you.
7. What we never do with children's data
These are commitments, not aspirations. For any user we know or reasonably believe to be a child, and for every student enrolled through a school, we do not:
- use their data for marketing or advertising of any kind, ours or anyone else's;
- show them advertising, sponsored content or third-party promotions;
- build behavioural, commercial or advertising profiles of them — the only profile we build is their learning progress, shown to them and their teacher;
- use their work, voice recordings, worksheets or messages to train, fine-tune or evaluate artificial intelligence or machine-learning models;
- sell, rent, licence or trade their data, in any form, to anyone;
- share their data with data brokers, advertising networks or social media platforms;
- make their work public — a student's submissions are shown to that student and to their teacher and school staff, and there is no public gallery, leaderboard of submissions, or shareable feed of student work.
Klaviyo, our marketing-email provider, receives data only from the pre-launch signup form — a name, an email address, a self-declared role and a timestamp. It never receives student records, grades, worksheets, voice data or classroom information.
Speech recognition and AI training
Speaking practice sends the audio clip to Google Cloud Speech-to-Text to convert it into text. This is speech recognition, not a generative AI model, and we do not send it any other student data. Google Cloud's terms provide that customer audio is not used to improve Google's models unless data logging is deliberately enabled on the account. We do not enable it. [ TO BE COMPLETED: confirm in the Google Cloud console that audio data logging is disabled for the project used by OLAYN, and keep written evidence ]
Honest disclosure. At present the only consent step before a voice recording is sent to Google is your browser's own microphone permission prompt. There is no separate, explicit in-product consent screen explaining that the audio leaves our servers. [ TO BE COMPLETED: add a clear in-product consent step before the first voice recording, and a way for a parent or school to turn speaking practice off entirely ]
8. Who we share data with
We do not sell personal data. We share it in four situations: with the people in your own school, with the service providers that run our infrastructure, with payment companies, and where the law requires it.
People
- Your teacher and your school's staff can see your enrolment, your submissions, your grades and your progress in their classroom. Staff of one school can never see students of another school.
- Other players in a race see your display name and your live score during a multiplayer race, and your name may appear on the monthly leaderboard. They see nothing else.
- OLAYN administrators can access accounts and records for support, moderation and security.
Service providers (subprocessors)
These are the companies that process personal data on our behalf, or alongside us. The "capacity" column matters legally: a processor acts only on our instructions, while an independent controller decides things for itself and has its own privacy notice you should read.
| Provider | What they do for us | Capacity | Where data is processed |
|---|---|---|---|
| Vercel Inc. | Hosts the website and application; serves pages; keeps server logs | Processor | United States, plus its global edge network |
| Neon Inc. | Runs our PostgreSQL database — this is where almost all data lives | Processor | United States (AWS, us-east-1) |
| Upstash Inc. | Redis cache — live race state, rate-limit counters, temporary caches | Processor | [ TO BE COMPLETED: Upstash region — check the database region in the Upstash console ] |
| Pusher (Pusher Ltd) | Real-time messaging for multiplayer racing and live session updates | Processor | [ TO BE COMPLETED: Pusher cluster region — the value of NEXT_PUBLIC_PUSHER_CLUSTER ] |
| Google LLC / Google Ireland Ltd | Sign-in (OAuth); Cloud Speech-to-Text for pronunciation; embedded YouTube videos | Processor for speech recognition; independent controller for your Google account and for YouTube | United States and globally |
| Resend | Delivers our emails — newsletters, coupon codes, internal signup alerts | Processor | United States |
| Klaviyo Inc. | Marketing email for pre-launch signups only. Receives no student, grade or classroom data. | Processor | United States |
| Paddle.com Market Ltd | Sells subscriptions to you as the merchant of record — Paddle is the seller, takes the payment, handles tax and issues the invoice | Independent controller — not our processor | United Kingdom, European Union and United States |
| Stripe | Secondary payment route | Processor for payment execution; controller for its own fraud prevention | United States, Ireland |
Paddle is the seller, not a payment processor
This distinction is easy to miss and legally important. Paddle is our merchant of record: it resells OLAYN subscriptions to you in its own name. When you buy a subscription, your contract for that purchase is with Paddle, Paddle collects the money, Paddle handles sales tax and VAT, and Paddle's name appears on your bank statement and your invoice. Paddle is therefore an independent data controller for your purchase — not a processor acting on our instructions. Paddle's own privacy policy governs what it does with your payment data, and its refund policy applies to your purchase. See our Terms of Service for what that means for refunds and cancellations.
Storage of uploaded worksheet files
Honest disclosure — do not publish a claim here until this is fixed. Uploaded worksheet files are currently written to the application server's own file storage and served from a web address that is not access-controlled. The database record of a submission is properly restricted to the student and their teacher, but the file itself can be opened by anyone who has or guesses its address. Cloud object storage (DigitalOcean Spaces, in Singapore) is written into the codebase but is not switched on.
[ TO BE COMPLETED: fix the file storage so worksheet uploads are private and served through signed, expiring links — then replace this disclosure with the real storage provider, its country and its safeguards ]
Legal disclosures
We may disclose personal data where we are legally required to — for example a valid order from a Saudi authority or a court of competent jurisdiction — or where it is necessary to establish, exercise or defend legal claims, or to protect someone's safety. Where we are permitted to tell you about such a request, we will.
9. Transfers outside Saudi Arabia
Your personal data is transferred to, stored in and processed in countries outside the Kingdom of Saudi Arabia. This is not incidental — essentially all of our infrastructure is abroad. The destination countries are:
- United States — hosting (Vercel), the main database (Neon), email delivery (Resend, Klaviyo), speech recognition and sign-in (Google), payments (Stripe).
- United Kingdom and European Union — Paddle, as merchant of record.
- Singapore — planned location for worksheet file storage, once cloud object storage is enabled. It is not in use yet (see section 8).
- [ TO BE COMPLETED: add the Upstash and Pusher regions once confirmed, and any other country introduced by a new provider ]
What protects data when it leaves
Article 29 of the Saudi PDPL and Chapter V of the GDPR both restrict sending personal data abroad. We rely on:
- written data processing agreements with each provider, incorporating the European Commission's Standard Contractual Clauses and, for UK data, the UK International Data Transfer Addendum;
- the safeguards permitted by the PDPL Implementing Regulations on transfer, including appropriate contractual protections and the requirement that the transfer does not prejudice national security or the vital interests of the Kingdom;
- keeping the transfer to the minimum needed to run the service.
Honest disclosure. The safeguards described above must actually be in place, in writing, before this notice is published. [ TO BE COMPLETED: sign or accept a data processing agreement with every provider listed in section 8, keep copies, and confirm each one covers onward transfers and children's data ]
10. How long we keep data
We keep personal data only for as long as we need it for the purpose we collected it for, or for as long as the law requires.
| Data | How long we keep it | Why |
|---|---|---|
| Account and identity | While your account is open, then deleted within 30 days of a valid deletion request or account closure | Needed to give you access |
| Learning progress, grades, worksheets | While you are enrolled, plus [ TO BE COMPLETED: retention period after leaving — suggest one academic year ] | So a student can return to their course, and so a school can produce records and handle grade appeals |
| Voice transcripts and pronunciation scores | Kept with the learning record and deleted at the same time | Progress tracking |
| Voice audio | Not stored by us — sent for recognition and discarded | Only the text result is needed |
| Game and race records, leaderboards | Monthly leaderboards reset each month; individual records follow the account | Fair play and progress |
| Billing and transaction records | [ TO BE COMPLETED: statutory retention period for Saudi tax and accounting records — confirm with an accountant or counsel ] | Tax and accounting law |
| Marketing signups | Until you unsubscribe | Consent-based |
| Unsubscribe records | Kept indefinitely | So we can honour your opt-out permanently — deleting it would risk emailing you again |
| Server and security logs | [ TO BE COMPLETED: log retention period set by our hosting provider — confirm and state it ] | Security and abuse investigation |
Honest disclosure. These retention periods are our policy, but they are not yet enforced automatically. There is no scheduled job that deletes old data, and there is no self-service "delete my account" button. Today, deletion happens manually when someone asks us. [ TO BE COMPLETED: build automated retention deletion and a self-service account deletion and data export flow — these are needed for PDPL, GDPR and COPPA compliance ]
11. Children's data retention policy
This is our written retention policy for personal information collected from children, published here as required by the US Children's Online Privacy Protection Rule, 16 CFR 312.10. It applies to every student who uses OLAYN through a parent or a school.
Why we hold a child's data at all
We collect a child's personal information for exactly three purposes: to deliver their lessons and remember where they got to; to let their teacher set, mark and give feedback on their work; and to report their progress and grades to their teacher, their school and their parent. We do not collect a child's information for any purpose beyond these.
How long we hold it
- While it is needed. We keep a child's information only for as long as is reasonably necessary to fulfil the purposes above — in practice, while the child is enrolled and actively learning.
- After they leave. When a child leaves a classroom or school, or the parent closes the account, the retention clock starts. We delete or irreversibly anonymise their information within [ TO BE COMPLETED: number of days after a child leaves — we recommend 30 days for personal data and one academic year for grade records the school may need ].
- On request. Where a parent, guardian or school asks us to delete a child's information, we delete it within 30 days of verifying the request, and sooner where we can.
- Dormant accounts. Where a child's account has not been used for [ TO BE COMPLETED: dormancy period — we recommend 24 months ], we will contact the parent or school and then delete the account and its contents.
We do not keep children's data indefinitely
OLAYN does not retain personal information collected from a child for longer than is reasonably necessary to fulfil the purpose for which it was collected, and never indefinitely. There is no circumstance in which we keep a child's work, voice transcripts, grades or account details "just in case". Where we need to keep something for a legal reason such as a tax record, we keep the minimum — a transaction reference — and not the child's learning record.
How deletion actually works
- Deleting a child's account removes their profile, their sign-in records, their worksheet submissions, their voice transcripts, their grades and their game records. This is a permanent deletion, not a hidden flag.
- Encrypted backups are kept by our database provider on a rolling schedule, so a deleted record can persist in a backup for a short period. Backups are never used to restore an individual deleted record, and they age out automatically within [ TO BE COMPLETED: backup retention window — confirm with Neon and state it here ].
- We delete using reasonable measures to protect against unauthorised access during and after deletion.
Honest disclosure. The timeframes in this policy are not yet enforced by an automated process. Until they are, deletion is carried out manually on request. This gap must be closed before OLAYN is offered to children in the United States.
12. Your rights and how to use them
You have the following rights over your personal data.
| Right | What it means |
|---|---|
| To be informed | To know what we do with your data — that is what this notice is for. |
| Access | To ask for a copy of the personal data we hold about you. |
| Rectification | To have inaccurate or incomplete data corrected. |
| Erasure / destruction | To ask us to delete your data. Under the PDPL this is a right to destruction; under the GDPR it is the right to be forgotten. Both have limits where we must keep something by law. |
| Restriction | To ask us to pause processing while a dispute or correction is resolved. |
| Objection | To object to processing based on legitimate interests, and to object to direct marketing at any time — the marketing objection is absolute. |
| Portability | To receive the data you gave us in a structured, commonly used, machine-readable format, and to have it sent to another provider where technically feasible. |
| Withdraw consent | To withdraw consent at any time, for anything based on consent — marketing email, microphone access. Withdrawing does not undo processing already carried out. |
| Not to be subject to automated decisions | To ask for human review of any decision made solely by automated means that significantly affects you. As explained above, we do not make such decisions. |
How to exercise them
Email olaynislamicfoundation@gmail.com with the subject line "Data request", or use our enquiry form. Tell us what you want and which account it concerns. We may need to verify who you are before we act, so that we do not hand someone's data to the wrong person — we will ask for the minimum needed to be sure.
We will respond within 30 days. This is the Saudi PDPL standard, and it is stricter than the GDPR's one-month-plus-extension. If a request is unusually complex we will tell you within those 30 days why, and how long we need. Exercising your rights is free; we will only charge for a request that is manifestly unfounded or excessive, and we will tell you before we do.
13. Rights of parents and schools
If you are a parent or guardian, or a school that has enrolled students, you have specific rights over that child's information. Under COPPA these rights are not optional — a school cannot lawfully consent on a parent's behalf unless the parent keeps them.
You can review your child's information
You can ask us for a description of the types of personal information we have collected from your child, and for a copy of that information. We will provide it after taking reasonable steps to confirm you are the child's parent or guardian, or an authorised member of staff at their school.
You can have it deleted
You can ask us to delete your child's personal information. We will delete it within 30 days of verifying your request. Where the child is enrolled in a school classroom we will tell the school, because deleting the record also removes their submitted work and their grades.
You can stop further collection
You can tell us to stop collecting or using your child's information while leaving their existing record in place. In practice this means closing or suspending the account. Note that we cannot run the lessons without collecting progress, so refusing all collection means the child can no longer use the service.
Consent is revocable
Consent you have given as a parent, guardian or school can be withdrawn at any time, and withdrawing it is as easy as giving it — one email to the address above.
If you are a school
- You are responsible for telling parents that you have enrolled their children with OLAYN, and for making this notice available to them.
- You must have the authority to consent on parents' behalf for educational use under the law that applies to you.
- You must pass on any parent request to review or delete a child's data, or direct the parent to us.
- [ TO BE COMPLETED: a separate school data processing agreement should be prepared, covering the school as controller and OLAYN as processor for student records, plus any FERPA arrangement for US schools ]
14. How to complain
Please come to us first — most things are quickest to fix directly. But you always have the right to go to a regulator instead, and you do not need our permission.
- Saudi Arabia. The Saudi Data and Artificial Intelligence Authority (SDAIA) supervises the PDPL. You can complain to SDAIA at sdaia.gov.sa.
- United Kingdom. The Information Commissioner's Office (ICO), ico.org.uk/make-a-complaint, or by telephone on 0303 123 1113.
- European Union. The data protection supervisory authority of the country you live or work in, or where the issue happened. The list is at edpb.europa.eu.
- United States. COPPA is enforced by the Federal Trade Commission. You can report a concern at reportfraud.ftc.gov.
15. Cookies and browser storage
A cookie is a small file a site stores in your browser. We also use localStorage, which does the same job with a different mechanism and is treated the same way by the law. Here is everything we set.
Strictly necessary — no consent needed
These are set by NextAuth, the sign-in system, and the site cannot work without them. They contain no advertising or tracking information.
| Name | What it does | How long |
|---|---|---|
next-auth.session-token | Keeps you signed in. This is your session. | 30 days |
next-auth.csrf-token | Protects against cross-site request forgery — stops another site submitting forms as you. | Session |
next-auth.callback-url | Remembers which page to return you to after sign-in. | Session |
next-auth.pkce.code_verifier, next-auth.state, next-auth.nonce | Security values used during the Google sign-in exchange. | 15 minutes |
In production these carry the __Host- or __Secure- prefix, are marked HttpOnly and Secure, and cannot be read by scripts.
Stored in your browser, not as cookies
The categories in this table are the same ones the consent banner uses, so you can match a row here to a switch there. Nothing in this table is an advertising or tracking identifier.
| Key | What it does | Category | How long it lasts |
|---|---|---|---|
| Theme preferences | Remembers whether you chose light or dark mode. | Strictly necessary | Until you clear it — localStorage entries have no expiry date and are never removed by the browser on their own |
| Course map progress cache | A local copy of your course progress so the map draws instantly instead of waiting for the server. | Strictly necessary | Until you clear it — no expiry |
visitorId | A random identifier for your device, created the first time you open the multiplayer race. It is how a race tells four players apart, including players who are not signed in and so have no account to be told apart by. | Strictly necessary — see the note below | Until you clear it — no expiry |
| Race data cache (session storage) | Temporary race information. | Strictly necessary | Cleared automatically when you close the tab |
Why visitorId counts as strictly necessary. The law that governs browser storage exempts anything that is strictly necessary to provide a service you explicitly asked for. This identifier is created when you start a race, not when you arrive on the site, and the race cannot work without it — with four spaceships on screen and anonymous players allowed, something has to say which one is yours. It is a random value, it is not linked to advertising, it is never sold or shared with anyone, and it is used for nothing except running races and stopping one player answering as another.
We are stating the reasoning rather than just asserting the label, because the exemption is narrow and it depends entirely on those limits holding. If this identifier were ever used to recognise you across the site, to build a profile, or for anything unrelated to a race you started, it would no longer be exempt — and it would appear on the consent banner as a switch you can refuse.
Third parties that may set their own cookies
- Paddle. Paddle's checkout script loads only when you actually start a checkout, not on ordinary pages. Paddle may then set its own cookies.
- YouTube. Video embeds do not load until you allow the “Embedded video from YouTube” category on the consent banner. Until then we show a still image served from our own servers, so YouTube is not contacted at all. Once you allow it, YouTube sets its own cookies and receives your IP address as soon as the player loads — before you press play.
- Google. Signing in takes you to Google's own pages, where Google's cookies and privacy policy apply.
We do not use Google Analytics, Meta or Facebook pixels, TikTok pixels, advertising networks, session-replay tools or third-party error trackers. Our fonts are served from our own servers, so loading a page does not tell Google that you visited.
Your choices
The first time you visit, we ask before anything that is not strictly necessary is stored on or read from your device. There is exactly one optional category — embedded video from YouTube — because that is the only thing on this site that needs your permission. Refusing is exactly as easy as accepting: the two answers are the same button in the same size and colour, with refusal listed first, and nothing outside the strictly necessary category loads until you say otherwise. Your answer is kept in a first-party cookie called olayn_consent for six months.
Two things that banner does not do, so there is no confusion. It does not offer an analytics option, because we have not installed an analytics tool — if we ever choose one we will name it and ask you then, rather than collecting a yes now for something we cannot yet describe. And it does not control marketing email: consent for that is given by submitting the signup form, is separate from this one, and can be withdrawn from any email we send.
You can change your mind at any time using the Cookie choices link in the footer of every page. Withdrawing is as easy as giving permission, and takes effect immediately — embedded media reverts to the still-image placeholder straight away.
Still to confirm. The YouTube channel section of the home page shows video thumbnails served from Google's image servers. These set no cookies, but loading them does reveal your IP address to Google. [ TO BE COMPLETED: decide whether to self-host those thumbnails as well, which would remove the last third-party request made before you have chosen anything ]
You can delete cookies and local storage at any time through your browser settings. If you delete the sign-in cookies you will simply be signed out.
16. How we protect data
- All traffic to this site is encrypted in transit using HTTPS.
- Sign-in is delegated entirely to Google. We never handle, see or store a password.
- Session cookies are
HttpOnly,Secureand use cookie name prefixes that browsers enforce, so a script cannot read your session. - Access to student work and grades is checked on the server for every request, against the requester's own account and their role in that classroom.
- Sessions can be revoked centrally, so access can be cut off immediately if an account is compromised.
- Our API applies rate limits to resist automated abuse.
- Database access is restricted to the application and its administrators.
No system is perfectly secure. If we become aware of a personal data breach that poses a risk to you, we will notify SDAIA and, where required, the relevant EU or UK authority within the legally required time, and we will tell affected users and schools. [ TO BE COMPLETED: write a short breach response plan naming who is contacted, in what order, within the 72 hour notification deadline ]
17. Changes to this notice
We will update this notice when what we do changes. The version number and date at the top always tell you which revision you are reading. Where a change materially affects how we use your personal data — a new purpose, a new category of data, a new recipient — we will tell account holders directly by email before it takes effect, and where the change relies on consent we will ask again rather than assume.
Material changes affecting children's data require fresh consent from the parent, guardian or school. We will not apply such a change to an existing child account until that consent is given.
Version 1.0 (draft, unreviewed) — last edited 4 August 2026. This draft is not yet in force.
