← Home

Classroom Poet

Privacy Policy

Effective date: 1 September 2026

This policy covers Classroom Poet, a web application operated by Fourwords Pty Ltd ABN 64 700 678 851 (“we”). Classroom Poet lets a teacher run a poetry-writing session in class: students write on their own devices, the teacher reviews every poem, and the session ends in a class gallery. Because the people writing are children, this policy is deliberately short and specific.

Our relationship with your school

Schools are our customers, and each school controls its own data. We operate the system on the school's behalf: we provision the school's account, the school decides which teachers can use it, how parental consent is handled, and what is shared with families. We do not use school or student data for any purpose other than running the service for the school.

What we collect

About teachers and school leaders: name, school email address, and records of sign-ins. Teachers sign in by emailed link; we hold no passwords.

About students:a display name the child chooses when joining a session; the child's real name where the school collects it, held separately and visible only to school staff; the poems and drafts they write; and the comments their teacher writes to them. Students never create accounts, and we never ask a child for an email address, password, phone number, date of birth, photo or home address. A student's device holds an anonymous identifier so the child can return to their own work; unused identifiers are removed automatically after about three months.

About families: nothing. Families view shared galleries through a private link and are never asked to sign in or provide anything.

Technical records: ordinary short-lived operational records, such as server logs and records of session join attempts (kept for days, not months), used only to keep the service working and to prevent abuse. There is no advertising and no behavioural tracking; the only cookies are the ones that keep a session working (a teacher's sign-in, or a student's anonymous session). A student's unsent draft is saved on their own device only and never reaches our servers until they press send.

How information is used

To run the sessions, galleries and sharing the school asks for; to deliver safeguarding oversight to the school's nominated reviewers; and to operate, secure and support the service. Nothing else.

Who can see what

Students see their own work, and classmates' approved poems under display names. Teachers see their own class's work and real names. The school's nominated safeguarding reviewers can read any session at their school, including the comments teachers wrote to students. Families see only what a teacher deliberately shares: approved poems and display names. Our own administration tools cannot read student names or poems; that restriction is enforced in the database itself. The separation between schools is enforced the same way. The detail is in our Security and Privacy Statement and Safeguarding Statement, available to any school.

Where information is stored, and who processes it

All school and student data is stored and processed in Sydney, Australia, on Supabase (database and sign-in). The application is hosted by Vercel, which stores no school or student data at rest. Email is sent through Resend, a United States provider: most email involves adults only, but safeguarding reports sent to a school's nominated reviewers can contain student names and the comments written to them, so that content passes through Resend's US systems in transit. We hold data processing agreements with each provider. We do not sell data, share it with any other third party, or disclose it except to these providers, or where the law requires it.

How long we keep it

Sessions are archived after the school year ends, at which point students and families can no longer reach the work. Twelve months after archiving, the student data in a session (names, poems, comments) is deleted permanently and automatically, and each deletion is recorded in a register the school can see. A school can ask for an individual student's data to be removed at any time, and teachers can do this themselves immediately. Teacher and school account details are kept while the school uses the service and deleted when the relationship ends. The full schedule is in our Student Data Retention Statement.

Security

Access rules are enforced inside the database itself and verified by an automated test suite that runs on every change, checking both what must be visible and what must not. The system receives independent-style security reviews at each new boundary, and the running production system was reviewed before any school used it. Teachers can only be added by invitation; administration accounts use multi-factor authentication.

Data breaches

If a breach occurs that is likely to result in serious harm, we will notify the affected schools promptly, tell them what happened and what we are doing about it, and notify the Office of the Australian Information Commissioner in line with the Notifiable Data Breaches scheme.

Access, correction and complaints

Requests about a student's information should go to the school in the first instance, since the school holds the relationship with families and can act immediately in the application. You can also contact us directly at privacy@classroompoet.com for access, correction or deletion requests, or with any privacy concern. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).

Changes to this policy

If this policy changes, the current version will always be at this address, and schools will be told about any change that affects how their data is handled.

← Home