Privacy Policy
Last updated: 5 August 2026
1. Introduction
Sprout Lessons (“Sprout Lessons”, “Sprout”, “we”, “us”, or “our”) is a product operated by ROOTECH SOLUTIONS (ABN 28 315 635 680). We are committed to protecting your privacy and handling personal information in an open and transparent way. This Privacy Policy explains how we collect, use, disclose, and store personal information when you use Sprout to generate interactive lessons and videos.
This policy is written in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). By using Sprout, you agree to the handling of your personal information as described in this policy.
2. Personal Information We Collect
Account and identity information
When you create an account we collect:
- Full name and email address
- Subscription tier and status (Substitute, Educator, or Professor)
- One-off credit-pack purchases and your current credit balance
- Stripe customer ID and subscription reference (not your card details)
- Subscription period dates and renewal preferences
- The date your account was created
Lesson inputs
When you generate a lesson we collect and store the information you provide to create it, including the topic, subject, year level or age band, learning goals, and any interests or preferences you enter to personalise the lesson, along with the effort tier you select.
Please do not enter a child’s identifying details. Sprout is designed for teachers and parents to describe a child’s interests (for example, “loves dinosaurs and soccer”), not to identify them. Do not submit a student’s full name, contact details, photographs, or other directly identifying information as lesson input.
Generated lesson content
The interactive HTML lessons, lesson titles, and short videos generated on your behalf are stored in our database and file storage so you can revisit, edit, and share them.
Student roster information
If you add students to your roster, we store for each student the name or label you enter, an automatically generated public display pseudonym (for example “Curious Otter”), any interests you enter, an optional free-text group label, whether that student’s page is shared, and the lessons assigned to them. The name and interests you enter are private to your account and are never selected or displayed on a public student share page; only the pseudonym, lesson titles, and lesson statuses appear there.
Sprout Tutor practice records
Sprout Tutor is an adaptive practice mode that a student uses directly. It is disabled for every student by default and only operates for a student once you, the account holder, enable it for that student and assign them a subject. When it is enabled, we collect and store:
- A record of each question the student answers, including the curriculum code, difficulty tier, question type, the question content and options presented, the hint shown, the student’s response, whether the response was correct, whether a hint was used, whether the answer was revealed, and the time. This log is append-only.
- Adaptive progress state, including the curriculum code currently in progress, the current difficulty tier, and the counters the adaptive engine uses to decide when to change tier or working year level.
- A record of each change to the student’s working year level, including the direction, the reason, and the date.
- A hashed and separately encrypted copy of the 4-digit PIN you issue for that student, plus failed-attempt counters and any lockout time. The PIN is never stored in plain text, and the readable copy is decrypted only on authenticated routes belonging to you.
- The model used and the measured cost of each generated question, for cost accounting.
Sprout Tutor collects information directly from a student. That is its purpose: the practice record is what makes the difficulty adapt and what lets you see how a student is going. By enabling Sprout Tutor for a student, you confirm that you are the student’s parent or carer, or that you are their teacher acting within your school’s authority, and that you have any consent required in your setting. You can disable it, clear the record, or delete the student at any time.
Practice records are visible only to you and to the student concerned. They are never used to rank or compare students across accounts, are never disclosed to another account, are not reachable from the public student share page, and are not used for advertising or sold. A student’s responses are graded by deterministic server-side code and are not sent to any AI provider.
Payment information
When you purchase credits or a subscription we store the plan or pack name and payment status, the Stripe session ID and payment-intent reference, and subscription duration. Full payment card details are never stored by Sprout - all card processing is handled by Stripe.
Usage and analytics data
We collect internal usage events to operate and improve the service and to diagnose issues. This may include event types (such as lesson generation started or completed), job and generation records, the measured cost of each generation, event properties and timestamps, and internal error logs referencing your user ID for debugging only. This data is used internally and is not shared with third parties for advertising.
Automatically collected technical information
When you use Sprout we may automatically collect limited technical information including device and browser type, operating system, IP address, and cookies or similar technologies, to operate, secure, and improve the service.
3. How We Use Your Information
We collect and use personal information only for purposes reasonably necessary to operate Sprout, including to:
- Provide and manage your account
- Generate interactive lessons and videos using AI services
- Process payments and prevent fraud
- Communicate with you about your account, purchases, or support requests
- Diagnose errors and improve the service
- Send marketing communications where you have opted in
- Meet legal and regulatory obligations
We do not sell your personal information.
4. Disclosure of Personal Information
We share information with the following service providers to operate Sprout:
- Supabase: database hosting, user authentication, and file storage. Data is stored in cloud infrastructure operated by Amazon Web Services (AWS).
- Stripe: payment processing. Stripe handles card details directly; Sprout receives only non-sensitive references (customer ID, session ID).
- Anthropic: AI lesson and practice-question generation. The inputs you provide (topic or curriculum code, year level, and any interests you enter) are sent to Anthropic’s Claude models to generate lesson and Sprout Tutor content. A student’s answers and practice history are not sent.
- OpenRouter: AI request routing used to generate parts of lessons and practice questions (including via Qwen models). The same inputs may be sent through OpenRouter to the model that fulfils the request, on the same basis.
- Vercel: application hosting and content delivery.
These providers handle personal information in accordance with their own privacy policies and applicable laws. We may also disclose personal information where required or authorised by law, including to comply with legal obligations or respond to lawful requests by authorities.
5. Overseas Disclosure and Your Consent (APP 8)
Important notice - please read carefully. All of our core service providers - Supabase (database and storage), Stripe (payments), Anthropic and OpenRouter (AI generation), and Vercel (hosting) - are based in the United States and operate under US law.
Under the Privacy Act 1988 (Cth), specifically Australian Privacy Principle 8 (APP 8), when personal information is disclosed to an overseas recipient, that recipient may not be subject to the same privacy protections as required under Australian law.
By using Sprout, you expressly consent, for the purposes of APP 8.2(b), to the disclosure of your personal information to these overseas providers. This means the Australian Privacy Principles may not apply to how these overseas recipients handle your personal information; if an overseas recipient mishandles your personal information, you may not be able to seek redress against that provider under the Privacy Act 1988 (Cth); and Sprout remains your primary point of contact for privacy complaints, but our ability to enforce obligations against overseas providers is limited to contractual remedies.
We take reasonable steps to engage reputable providers, to review their privacy and security practices, and to enter into data processing agreements where possible. However, we cannot guarantee that all overseas recipients will comply with Australian privacy standards in every circumstance.
If you do not consent to overseas disclosure of your personal information on these terms, you should not use Sprout.
6. Data Security
We take reasonable steps consistent with APP 11 to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. Measures include:
- Row-level security (RLS) policies enforced at the database level so each user can only access their own data
- Encryption of data in transit (TLS)
- Restricted API access using service-role keys in server-side routes only
- Industry-standard authentication via Supabase Auth
Our database and file storage are hosted by Supabase (on AWS); the security of that infrastructure, including physical security and encryption at rest, is managed by Supabase and AWS under their respective security programmes. No system is completely secure, and we cannot guarantee absolute security of information stored or transmitted via our service or its underlying infrastructure.
7. Notifiable Data Breaches
Sprout is subject to the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth). If we become aware of a data breach likely to result in serious harm to any individual, we will assess the breach as quickly as possible; notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable; and provide guidance on steps you can take to reduce any risk of harm. Where a breach originates from an overseas provider (such as Supabase, Anthropic, OpenRouter, or Stripe), our notification obligations are triggered once we become aware of it, regardless of its source.
8. Data Retention
We retain personal information only for as long as necessary to provide the service and fulfil the purposes in this policy. You may request deletion of your account and associated personal information. Deleting a student from your roster deletes that student’s details, Sprout Tutor practice record, progress state, level-change history, and PIN immediately. Some information may be retained where required by law or for legitimate business purposes - for example, financial records, which we retain for 7 years in accordance with Australian tax law requirements.
9. Your Rights Under Australian Law
Under the Privacy Act 1988 (Cth) and the APPs you have the right to:
- Request access to personal information we hold about you (APP 12)
- Request correction of inaccurate, out-of-date, or incomplete information (APP 13)
- Request deletion of your account and associated data
- Make a complaint about how we handle your personal information
Requests can be made using the contact details below; we will respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with the OAIC at www.oaic.gov.au.
10. Children’s Privacy
Accounts are held by adults. A Sprout account must be held by a teacher, educator, parent, or carer aged 18 or over. Children cannot create an account, and there is no child sign-up, email address, or password. All account, billing, and roster decisions are made by the adult account holder.
What you must not enter about a child. While Sprout helps you create lessons for students, you must not submit a child’s full name, contact details, photographs, date of birth, school, location, or other directly identifying information as lesson input or roster information. Interest and year-level information should be kept non-identifying. If you believe a child’s identifying information has been provided to us, please contact us and we will take reasonable steps to remove it.
Sprout Tutor is used by the student, and does collect information from them. Outside Sprout Tutor, we do not knowingly collect personal information directly from children: a full-page lesson records nothing a student does, and self-check answers are checked in the browser and never transmitted. Sprout Tutor is the exception, and it is deliberate. It is disabled by default for every student, and when you enable it for a student we collect that student’s responses and practice history as described in section 2. That collection is what makes the difficulty adapt to the student and what allows you to see how they are progressing.
Your responsibility when you enable it. Because Sprout Tutor collects information from a student, you must only enable it for a student where you are that student’s parent or carer, or you are their teacher acting within your school’s authority and consent arrangements. You are responsible for obtaining any parental consent your jurisdiction or school requires. We rely on your confirmation of that authority, and we have no direct relationship with the student.
Control and deletion. You can disable Sprout Tutor for a student at any time, request that their practice record be cleared while keeping the student, or delete the student entirely, which deletes their practice record, progress state, level-change history, and PIN immediately. A student’s practice record is never visible to another account, never reachable from a public share page, never used to compare students across accounts, and never used for advertising or sold.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated “Last updated” date. Continued use of the service after changes indicates acceptance of the updated policy.
12. Contact Us
If you have questions, requests, or complaints regarding this Privacy Policy or how we handle personal information, please contact us at contact@sproutlessons.com.