Privacy
Last updated 28 September 2026
The short version
Essential holds some of the most sensitive data a school keeps: records about children with special educational needs. This page explains what we hold, how staff AI features can use it, and who to contact with questions. Your school decides how it uses Essential and should explain that use in its own privacy notice.
Who we are
Your school or trust is the data controller for pupil information and Essential acts as its data processor. This means the school decides why the information is used, and we handle it under the school’s instructions and data processing agreement. Parents and carers can ask the school for its privacy notice and data protection contact.
What we hold
- Pupil records you enter or import: names, year groups, SEND status, support plans, review notes, and any professional reports you upload. Some of this is special category data under UK GDPR and requires additional safeguards.
- Staff accounts and family sharing: names, email addresses, staff roles, the information school chooses to share and any conversation on a shared update.
- Activity records, including changes to pupil information and access to shared updates. Ordinary app users cannot edit the audit trail.
Where your data lives
Essential uses hosted services. The current database is in Ireland, in the EEA. Other processing locations depend on the service and its configuration, including the AI model selected. We do not make a UK-only processing claim. Schools can ask us for the current supplier, location and transfer details before using pupil information.
The suppliers we rely on
- Supabase provides records storage and sign-in.
- Vercel hosts the application.
- AWS Bedrock processes requests for the configured staff AI features.
- Resend delivers application emails where configured.
The applicable service settings and agreements determine where information is processed and how long provider logs are kept. Ask us for these details; using an AI service is different from using information to train a model.
How AI uses information
Essential sends AI requests through a gateway that removes identifying information before anything leaves our servers. Names, preferred names and initials, dates of birth, unique pupil and learner numbers, addresses and postcodes, contact details for parents, staff and professionals, and the names of the school, trust and local authority are replaced with placeholders, or the request is held for a member of staff to check, before it is sent to AWS Bedrock. The model never sees the real values; the placeholders are turned back into the real text on our server once it replies.
Today the only AI feature in use is general writing and conversation guidance from fixed questions. The Assistant does not read pupil records, family views, uploaded reports or the school provision catalogue. It has no free-text prompt or file attachment. Further AI features described in our product plans, such as suggesting targets and strategies, are not yet live; when they are, they follow the same gateway.
AI is off for a school by default. A verified Essential platform operator turns it on and chooses the AWS Bedrock model, from a list Essential has approved, as part of setting up the school and afterwards. Schools cannot change this setting themselves; Settings then Assistant shows the school whether it is on, the provider, the model and its region, in plain words. A verified platform operator can also run a fixed connection test, without pupil information.
The Assistant records account, school, request and token-count metadata for access and usage monitoring. It does not save the generated text. Earlier drafts and indexed evidence, where they exist, remain school records subject to the school’s retention arrangements; disabling a feature does not delete its previous records.
AI can make mistakes. Staff should check general ideas for suitability and current official guidance before using them. They can write and manage records without AI. Opening the parent portal does not itself ask AI to generate a response.
AWS states that inputs and outputs from Bedrock are not used to train its or third-party models. This does not mean that no information is sent or retained. See AWS’s explanation.
Ask your school which features it uses, the information involved and how it has assessed that use with its data protection lead. The Department for Education provides guidance on AI and data protection in schools.
Access to information
Access is checked against the signed-in identity and school permissions. Parents see information deliberately shared with their verified email address, for the sharing period set by school. A family contact entry alone does not grant portal access. Authorised school staff can preview these shared copies using their own identity; the preview cannot post comments as a parent. Essential platform operators need a verified account and multi-factor authentication.
Contact your school promptly if information is incorrect or you think someone has access they should not have. For a concern about Essential itself, use the contact below.
Beta feedback
When you submit beta feedback, we receive your description and any screenshot or video you choose to attach, together with your account, organisation, page area, browser family, screen size and app version. This helps authorised Essential operators investigate problems and improve the service. Please use fictional records or remove identifying details before sending an attachment. Screen capture starts only when you choose it; built-in recordings have no audio. We do not run automatic session replay.
Feedback is private to its author and authorised Essential operators. Attachments expire after 30 days and feedback after 180 days. You can request deletion from My feedback; feedback is hidden immediately and files and report text are queued for permanent deletion. Minimal audit entries record access and actions without copying your feedback text or media.
How long we keep it
Your school’s retention policy and its agreement with Essential determine how long pupil records are kept. A pupil leaving school does not automatically erase their records. Requests to export or delete information are handled with the school, taking account of its record-keeping duties and the agreed treatment of backups and audit records.
Your rights
Because your school is the controller, requests from parents or pupils to see, correct, or delete data usually go through the school first. We will always help your school act on those requests quickly. If you work at a school using Essential and you want us to export or delete data, just ask.
Get in touch
If you have a question about how we handle data, email support@inhouselabs.co.uk. We aim to reply within five working days. If you have a concern we haven't resolved, you can also contact the Information Commissioner's Office.