Privacy Policy
Last updated: 23 September 2026
Sandbox Learning Limited provides the Teachit service and Teachit Studio to you.
This policy explains what Teachit Studio (“Studio”) does with your information: what we collect, what we send to the AI providers that generate your resources, how long we keep it and how to get rid of it. It covers studio.teachit.co.uk and the resources you make there.
Your Teachit account, your subscription and the main Teachit website are covered by the Teachit Privacy Policy (opens in a new tab). This page sits alongside that one and describes Studio specifically; where the two differ about Studio, this page applies.
The short version
- You sign in with your Teachit account. We never see your password, and no card or payment details reach Studio.
- What you upload — PDFs, recordings, YouTube links and the topics you type — is used to build your resource and to keep it in your library so you can come back to it. To do that, we send your content to AI providers. We do not train AI models on your content, and we do not sell it.
- Live quiz sessions are deliberately short-lived. Students never make an account, and everything from the session is deleted within 24 hours.
- You can delete any note, resource or session — or your whole Studio account — yourself, at any time. For anything else, email dpo@teachit.co.uk.
This summary is here to be readable, not to be the agreement — the sections below are.
1. Who we are, and what this covers
Teachit Studio is operated by Sandbox Learning Limited, a company registered in England and Wales under company number 12635255 and trading as Teachit (“Teachit”, “we”, “us”), part of the Sandbox group. We are the data controller for the personal data described in this policy. Our registered office is 6th Floor Capital Tower, 91 Waterloo Road, London SE1 8RT, United Kingdom. You can reach us, or our Data Protection Officer, at dpo@teachit.co.uk.
Two groups of people are described in this policy:
- Educators who sign in and use Studio to build resources.
- Students who open a live quiz link. Students have no account and give us almost nothing — section 6 is about them.
2. Information we collect
From your Teachit account
There is no separate sign-up for Studio. When you sign in, Teachit passes us four things: your email address, your first and last name, your Teachit user ID, and your subscription tier (free, basic or premium). Teachit also sends the subject you teach, which Studio discards. That is the entire handoff. We do not receive your Teachit password, and no payment method, card number or billing address ever reaches Studio — billing happens on Teachit under its Subscription Terms (opens in a new tab).
What you upload and create
- Files you upload: PDFs up to 10 MB, and audio or video recordings up to 50 MB.
- Links you paste: YouTube URLs, up to 45 minutes long — or 30 minutes if the video has no captions of its own, because we then have to have a transcript made from its audio.
- What you type: the topic, subject, year group, reading level and any instructions you give, plus the titles you save things under.
- What we generate from it: transcripts, study notes, summaries, worksheets, quizzes, flashcards, lesson plans, answer keys, and the PDF and Word files you download.
- A search index: your content is split into passages and turned into numeric “embeddings”, so that when you ask a question about your own material we can find the passage that answers it.
- Chats: the messages you send the assistant about a note, and its replies.
- Feedback: the thumbs up or down you give a resource, and the reason tags you pick with it.
Text is pulled out of PDFs on our own servers — a PDF you upload is not sent to a third party just to be read. Audio and video are a different matter, because they have to be transcribed: see section 5.
Live quiz sessions
When you run a live quiz, we store the name each student types, the options they choose, and timestamps. See section 6 for the detail and the deletion schedule.
Technical information
- Session cookies that keep you signed in (section 4).
- A short description of the browser and device you signed in with, stored against that session so it can be identified and signed out. It includes the IP address the session was created from.
- Your IP address, also used to rate-limit requests and block abuse. Outside the session record above, it is not stored against your account.
- Ordinary web-server request logs kept by our hosting provider, which include IP addresses and are retained for a short period.
Studio does not ask you for a phone number, a home address, a date of birth or a photo.
3. How we use it
- To produce the resource you asked for.
- To keep your library, so you can find, re-open, re-download and rebuild your work later.
- To answer your questions about your own material.
- To apply the limits that come with your plan (your plan’s tier, and how many generations you have used).
- To run live quiz sessions and show you the class results.
- To keep the service working and safe: rate limiting, diagnosing errors, preventing abuse.
- To improve Studio. We read the feedback you leave and look at usage in aggregate — how often a resource type is used, how often generation fails.
- To meet legal obligations and enforce our terms.
If you are in the EEA or UK, our legal bases are: performing our contract with you (running the service); our legitimate interests (security, abuse prevention, improving the product); and compliance with legal obligations. We do not rely on consent, because we set no cookie that requires it.
We do not use your information, or a student’s, to make any decision about you or them by automated means alone, and Studio does not profile students (Article 22 GDPR). A generated resource is always a draft for a teacher to review — it is never used to decide anything about a student without a person in the loop.
4. Cookies and local storage
Cookies
| Cookie | Set by | What it does | How long |
|---|---|---|---|
| access_token | Studio | Keeps you signed in. HTTP-only and Secure, so page scripts cannot read it. | 24 hours |
| refresh_token | Studio | Issued with your session so it could be renewed. Studio does not currently renew sessions, so in practice it expires with access_token. | 24 hours |
| tv_entitlement | Studio | Remembers which plan you are on, so a page can show the right label before the server has answered. Cosmetic only: your browser can read and change it, and nothing is granted or refused on the strength of it. Set once you are signed in. | 24 hours |
We set no advertising cookies. Studio carries no advertising at all, and we do not use your content or your activity here to target ads anywhere. (The main Teachit website does carry advertising — its own policy covers that.)
That site is a separate one, and it sets its own cookies; its Cookie Policy (opens in a new tab) covers those, and this page covers studio.teachit.co.uk.
Stored in your browser, not sent to us
Some settings live in your browser’s local storage and never reach our servers: your light or dark theme, whether an answer key is shown or hidden, which view a document was last opened in, the library page to return to, a short-lived copy of a generation form so a failed attempt can be retried, and — for a student — the random token that identifies their own quiz attempt. Clearing your browser data clears all of it.
Analytics
We set no analytics cookies on this site. The only cookies are the three described above: the two that keep you signed in, and the cosmetic one that remembers which plan label to show you. There is no Google Analytics property and no measurement script of any kind, on any page, for any visitor — so there is nothing to accept or decline, no cookie bar, and no cookie settings to change. If that ever changes, this section and the table above change with it, and readers in the UK and the EEA would be asked before anything loaded.
Do Not Track
Studio does not currently respond to browser “Do Not Track” signals.
5. Who we share it with
We do not sell your personal data, and we do not share it for advertising. We use the following providers to run the service. Each one gets only what it needs, and is contractually limited to using it for us.
| Provider | What it does for us | What it receives |
|---|---|---|
| OpenRouter | Routes our requests to the AI models that write your resources and build the search index. We restrict it, on every request, to a named list of model hosts - see below | The text of the note or prompt being processed |
| DeepInfra | Speech-to-text using OpenAI's Whisper model: for audio and video you upload, and for a YouTube video whose own captions we could not fetch | The recording itself, or the audio track of that YouTube video |
| Supadata | Our last resort for a YouTube link, used only when our own caption fetch and our own transcription have both failed: it retrieves the video's caption transcript, or creates one from the video's audio with OpenAI's Whisper model — so that second path is an AI step, not just a fetch | The video URL, and nothing else |
| Backblaze B2 | File storage | Files you upload, and the PDF and Word documents we generate |
| Railway | Application, database and request-log hosting, in its EU West region (Amsterdam, Netherlands) | Everything the service stores, plus request logs |
| Teachit | Your account and subscription | Your account identifiers and your subscription tier |
Where each one operates
Your work is stored in Europe; the AI that writes it runs in the United States. Teachit Studio itself — the application, the database and the request logs — runs in Railway’s EU West region, in Amsterdam. Railway is a United States company, and its staff can reach that infrastructure in order to support it. The files you upload and the documents we generate are stored in Backblaze B2’s EU region (eu-central-003); Backblaze is also a United States company. Supadata, the last-resort step in the YouTube pipeline described below, is Dumpling Software UG, a German company based in Berlin, so that step stays inside the EU.
The AI is the part that leaves Europe. OpenRouter, Inc. is a United States company, and it may route our requests only to a named list of model hosts, which we enforce on every single request: OpenAI, Microsoft Azure, Amazon Bedrock, Baseten, Cloudflare, CoreWeave, DeepInfra, Fireworks and Together, all of them headquartered in the United States. DeepInfra, which also runs the speech-to-text model for recordings you upload and for a YouTube video we could not fetch captions for, is on that list. Section 11 covers what that means for international transfers.
We also disclose information when:
- the law requires it — a subpoena, court order or other legal process;
- it is needed to protect the service, our rights, or someone’s safety; or
- Teachit goes through a business transition such as a merger, acquisition or sale of assets, in which case your information is normally part of the assets transferred.
A note about the AI processing
Generating a resource means sending your content to an AI provider and getting the result back. We send it for that purpose and no other. We do not train any AI model on your content, and we do not build datasets from it. Providers keep their own operational logs under their own terms, and we choose providers on that basis.
How we turn speech into text
It is OpenAI’s Whisper model doing the work in every case. What differs is who runs it and what they receive, so it is worth separating.
- A recording you upload goes to DeepInfra, in the United States. Your file is the thing being transcribed.
- A YouTube link you paste takes up to three steps, and most links stop at the first. First we fetch the video’s own captions ourselves, on our own servers: nothing is sent to anyone and no AI model runs. If the video has no captions, we download its audio and have it transcribed by Whisper at DeepInfra — the same route an uploaded recording takes, except that what is transcribed is someone else’s published video rather than anything of yours. Only if both of those fail does the link go to Supadata, in Germany, which receives the video address and nothing else — never a file of yours — and either retrieves the captions or makes a transcript from the audio itself. We do not AI-transcribe a video longer than 30 minutes by either route, and we do not accept a YouTube link longer than 45 minutes at all.
AI output can be wrong. Everything Studio generates is a draft for you to check before you put it in front of a class.
6. Students, children and recordings
Studio is a tool for educators, not a student product. Two things in it can nonetheless involve students, so this section is specific about both.
Live quiz sessions
Students do not create accounts, are never asked for an email address or a password, and are never tracked across sessions. A student opens the join link, types a name — whatever you have told them to use — and answers the questions. We store the name they typed, the options they chose, timestamps, and a random token kept in their browser so that one student cannot read another’s answers.
Sessions are built to disappear:
- A session stops accepting answers 4 hours after it is created, or as soon as you close it.
- Everything in the session — names, answers, all of it — is deleted within 24 hours.
- Results are not kept as a record, and no student profile exists anywhere in the system.
Teachers: you decide what pupils type in the name box. We recommend a first name and last initial, or a seat number — whatever is enough for you to read the results. Do not ask pupils to enter an email address, a pupil number, or anything else you would not write on the board.
This is also why live quiz data disappears so quickly. Under the UK GDPR personal data may be kept no longer than is necessary for the purpose it was collected for (Article 5(1)(e)), and that purpose ends when the lesson does; we do not keep it beyond the session at all.
Recordings you upload
A recording of a lesson may capture students’ voices and names, and both end up in the transcript. That recording is stored with the note, and is sent to our transcription provider to be turned into text. Only upload classroom recordings where your school permits it and you have any consent you need. Deleting the note deletes the recording.
Children
Studio is not directed to children, and we do not knowingly collect personal information from children under 13 for our own purposes. Where an educator or school uses Studio with students, the school decides what information is entered; we act on its instructions. We do not use anything a student enters for our own purposes, we do not advertise to students, and we do not build profiles of them.
Where a school or teacher chooses to use Studio with a class, the school decides what is entered and we act only on its instructions: for that pupil data the school is the controller and we are its processor. We do not use anything collected this way for any purpose of our own: not advertising, not profiling, not building a dataset, nothing beyond running the session the school asked for. The Information Commissioner’s Age Appropriate Design Code sets the standard we design the live quiz against — no account, no login, nothing that could build a profile, and the shortest retention the feature can run on.
If you believe you or a child have given us personal information beyond what is described here, email dpo@teachit.co.uk and we will delete it. A parent, or the school acting on their behalf, can ask us to review what data about a child, if any, has been entered, have it deleted and refuse to let us collect any more of it by emailing us at the same address.
Schools and pupil data
The names pupils type into a live quiz session are personal data the school is the controller for; we process them on the school’s instructions and for nothing else. We treat them accordingly: used only to run that session, never disclosed to anyone else, never used to build a profile, and purged within 24 hours. Schools that need a data processing agreement, or our input into a data protection impact assessment, before using Studio with a class should contact us at dpo@teachit.co.uk.
7. How long we keep things
| What | How long we keep it |
|---|---|
| Notes, generated resources, uploaded files, chats | Until you delete them, or your account is deleted. Deleting a note also deletes its uploaded file and any cached export from storage. |
| Cached PDF and Word exports | Regenerated on demand; deleted when you rename or delete the note. |
| Live quiz sessions (names, answers) | Closed after 4 hours; deleted within 24 hours of creation. |
| Sign-in sessions | 24 hours, after which you sign in again. |
| Resource feedback | Kept while your account exists — it is linked to your user ID. |
| Your account record | Until you delete it yourself from Account & data, or ask us to. |
| Backups and server logs | Deleted content can persist in routine backups and request logs for a short period before those age out. |
8. Security
- Everything travels over HTTPS.
- Session cookies are HTTP-only and Secure, and expire after 24 hours.
- Uploaded files sit in access-controlled storage, reachable only by the application’s own scoped credentials.
- A student’s quiz attempt is addressed by a random, unguessable token, so sharing a join link does not expose one student’s answers to another.
- Access to production systems is limited to the people who need it. A small number of authorised staff can view account and content records through internal tooling, for support and abuse investigation.
No system is perfectly secure, and we cannot guarantee that yours will never be compromised. If we discover a breach affecting your personal information, we will notify you and the relevant authorities as the law requires.
9. Your rights and choices
Inside Studio, at any time, you can:
- delete any note, resource, chat or uploaded file — which removes the stored file too;
- close a live quiz session early; and
- delete your whole Studio account from Account & data in your profile menu.
Deleting your account
Deleting your Studio account removes your entire library — every note and generated resource, the files you uploaded, your folders, chats, flashcards, quizzes, feedback and any live sessions — permanently and immediately. It cannot be undone, and we do not keep a hidden copy for a grace period. You are shown exactly what is about to go, and asked to type the word DELETE, before anything happens.
It deletes your Studio account only. Your Teachit account and your subscription are not touched — you remain a member and continue to be billed as normal. Cancel a subscription through Teachit, using its Subscription Terms (opens in a new tab). Signing in to Studio again afterwards simply gives you a new, empty library.
The reverse is also true: closing your Teachit account does not by itself erase your Studio library. Delete it here, or ask us to.
Everything else
For a copy of your data, a correction, or any request you would rather we handled — email dpo@teachit.co.uk with the subject line Data request – Studio and the email address on your account. We may ask you to confirm your identity first, and we will respond within one month (section 11).
We will not deny you service or treat you differently for exercising any of these rights.
10. Why the UK GDPR applies, and why COPPA may too
The UK GDPR and the Data Protection Act 2018 govern how we handle personal data here. They apply because the service is offered to, and used by, teachers and schools in the United Kingdom - not because of where any company in the chain happens to be incorporated (Article 3(2) UK GDPR). Section 11 sets out your rights and how to exercise them.
Children. Studio is a tool for teachers, not for pupils, and a pupil never holds an account. A pupil is involved in one case only: when a teacher runs a live quiz, the name the pupil types and the answers they give pass through our systems briefly. Section 6 explains how that is handled and how quickly it is deleted. Where a school asks us to process pupil data in this way, the school is the controller and we act on its instructions.
COPPA may also apply. The United States Children’s Online Privacy Protection Act can reach a pupil taking part from the United States. A pupil can be protected by both at once, and we do not treat that as two rulebooks to pick between; we apply whichever is more protective.
What we rely on, purpose by purpose. Producing the resource you asked for, keeping your library, answering your questions about your own material, applying your plan’s limits and running live quiz sessions are all performance of our contract with you (Article 6(1)(b)). Keeping the service working and safe, preventing abuse, answering support requests and improving Studio rest on our legitimate interests (Article 6(1)(f)) in running a service that works and is not misused; you can object to that at any time, and section 11 says how. Where the law requires us to keep or disclose something, the basis is legal obligation (Article 6(1)(c)). We do not rely on consent for anything on this site, because we set no cookie and run no measurement that would need it.
Special category data. Studio is not designed for it, and none of the bases above would cover it. Please do not upload EHCPs, medical notes, safeguarding records or anything else revealing health, religion, ethnicity or a similar protected characteristic about a named pupil (Article 9 UK GDPR). We cannot detect it if you do. If you do upload it, it is processed only to produce the resource you asked for, stored as part of your note until you delete it, and used for nothing else — but the safe course is not to put it in.
11. If you are in the UK or the EEA
You have the right to ask for a copy of the personal data we hold about you, to have it corrected or erased, to restrict or object to how we process it, and to have it sent to another provider. Where we rely on your consent, you can withdraw it at any time. We will respond within one month; where a request is complex or we have received a number of them, we may extend that by a further two months and will tell you if we do (Article 12(3) UK GDPR). Ask by emailing dpo@teachit.co.uk.
If you are not satisfied with how we handle a request, you can complain to the Information Commissioner’s Office, the UK supervisory authority, at ico.org.uk/make-a-complaint (opens in a new tab) or on 0303 123 1113. You do not have to come to us first, though we would rather you did.
Sending your data outside the UK
The AI that writes your resources runs in the United States. Every prompt you type, every file you upload for transcription and every question you ask the tutor is sent to an AI provider outside the UK to be processed. That is not incidental: we restrict AI processing to a named list of providers, and every provider on that list is headquartered in the United States. The restriction exists to keep your material out of jurisdictions whose data rules we cannot stand behind, and its effect is that a UK teacher’s material is transferred to the United States on every generation.
Your own material is not all sent there. The files you upload and the documents we generate are stored in Backblaze B2’s EU region. Supadata, the last-resort step for a YouTube link, is Dumpling Software UG, a German company based in Berlin, and processes inside the EU. The application, the database and the request logs run in Railway’s EU West region, in Amsterdam. What still leaves the UK is the AI processing itself, and the support access the United States companies in section 5 have to the systems they run for us.
Who receives it. The recipients outside the UK are OpenRouter, Inc.; the model hosts it is permitted to route to — OpenAI, Microsoft Azure, Amazon Bedrock, Baseten, Cloudflare, CoreWeave, DeepInfra, Fireworks and Together; DeepInfra, Inc. again, which runs the speech-to-text model for recordings you upload; Railway, which hosts the service; and Backblaze, which stores your files. Every one of them is in the United States.
Where personal data is transferred out of the UK, we rely on standard data protection clauses under Article 46 — the UK Addendum to the European Commission’s Standard Contractual Clauses, or the Information Commissioner’s International Data Transfer Agreement — as set out in each provider’s own data processing terms, together with that provider’s commitment not to use your content to train models. Which of the two instruments applies is settled provider by provider.
12. Links to other sites
Studio links out to Teachit and to other sites, and the resources you generate may cite sources elsewhere. Once you leave, the privacy policy of the site you are on applies, not this one. We do not control what those sites collect.
13. Changes to this policy
We update this page when Studio changes. The date at the top is the last time it changed. If a change materially affects how we handle your information, we will say so in the product rather than relying on you to re-read this page. Using Studio after a change means you accept the updated policy.
14. How to contact us
Questions about this policy, or about what we hold on you:
- Email: dpo@teachit.co.uk
- Post: Teachit Studio, Sandbox Learning Limited, 6th Floor Capital Tower, 91 Waterloo Road, London SE1 8RT, United Kingdom
- Data Protection Officer: dpo@teachit.co.uk
- Complaints: you can complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint (opens in a new tab), or by telephone on 0303 123 1113. We would rather you came to us first, but you do not have to.
See also the Teachit Privacy Policy (opens in a new tab), the Terms of Use (opens in a new tab) and the Subscription Terms (opens in a new tab), which govern your account and your subscription.