Privacy Notice
Last updated: 30 July 2026
Pilot scope: this notice applies to the invitation-only ComeTalk Studio pilot. Public self-service payment is not currently enabled.
1. Who operates ComeTalk Studio
ComeTalk Studio (“CTS”, “we”, “us”) is currently operated by Jason Carter for the invitation-only pilot. Privacy, access, correction and deletion requests can be sent to lessons@cometalkstudio.com.
2. When CTS is controller or service provider
CTS determines how teacher, administrator, security, support and service-operation data is used and is responsible for that processing. When a teacher or organisation creates student accounts, assigns lessons and manages learning records, that teacher or organisation normally determines the educational purpose of the processing. CTS then handles the student data as an education technology service provider on their instructions, while remaining independently responsible for security, fraud prevention, legal compliance and operation of the platform.
3. Information we process
Depending on the features used, CTS may process:
- teacher, administrator and organisation names, email addresses, account roles and preferences;
- student display names or usernames, temporary and replacement password records stored only as secure password hashes, learning levels, groups and teacher relationships;
- lessons, assignments, answers, scores, completion history, attendance, teacher feedback and review decisions;
- saved Dictionary entries, Flashcards and language or time-zone preferences;
- lesson-generation instructions and content sent to authorised AI providers;
- IP address, browser, device, login, security, error, audit and server-log information;
- support messages, pilot-access requests and transactional email delivery records; and
- billing and transaction information if paid checkout is introduced. Payment-card details would be handled by the payment provider rather than stored by CTS.
CTS is designed to avoid collecting a child’s full legal name, exact date of birth, home address, phone number, precise location or personal email address unless a teacher or organisation has a documented educational need and lawful authority.
4. Why we use information
We use information to provide accounts and workspaces; create and deliver lessons; assign and review work; support Dictionary and Flashcards; record progress and attendance; send service messages; prevent abuse; secure and troubleshoot the platform; provide support; improve reliability; and meet legal obligations.
Depending on the context and applicable law, the legal basis may be performance of a contract or pilot agreement, legitimate interests in operating and securing the service, compliance with legal obligations, or consent where consent is specifically required. Teachers and organisations are responsible for selecting and documenting an appropriate basis for student use in their jurisdiction.
5. Children and student accounts
CTS may be used by children through accounts created and managed by a teacher, school, organisation or authorised adult. The person or organisation creating the account must have the authority required by local law and must provide any notices or obtain any permissions required from learners, parents or guardians.
CTS does not sell student information, use it for behavioural advertising or build unrelated advertising profiles. Student information is intended to be accessible only to the student, assigned teachers, authorised organisation administrators and CTS personnel or providers who need access to operate or support the service.
6. AI-assisted features
Lesson generation, media generation, supported answer checking, contextual definitions and related functions may use authorised AI providers. CTS aims to send only the lesson context, instructions and response content needed for the requested function. Student names, login details and complete profiles should not be included where they are not necessary. AI-supported checking may be imperfect, and teachers remain responsible for professional review of open, uncertain or consequential assessments.
7. Service providers
Current pilot providers may include:
- netcup for primary application and database hosting in Germany;
- Cloudflare for DNS, connection security, traffic protection and inbound email routing;
- OpenAI for authorised AI text, image, audio and answer-support functions;
- Resend for transactional email delivery; and
- Paddle only if paid checkout is later enabled.
Providers receive only the information reasonably required for their function and operate under their own legal and security obligations. This list may change when a provider is replaced or a new feature is introduced; material changes will be reflected in this notice.
8. Cookies and local storage
The CTS application uses a strictly necessary, secure session cookie to keep signed-in users authenticated. The website and application may use browser storage for preferences, onboarding state and the self-contained lesson demonstration. The pilot does not use behavioural advertising cookies. If non-essential analytics or marketing cookies are introduced, CTS will provide any consent controls required by applicable law before using them.
9. International processing
The primary CTS application server is hosted in Germany. Cloud, email and AI providers may process information in other countries where they or their approved infrastructure operate. Where applicable law requires transfer safeguards, CTS and the relevant account owner must use appropriate contractual or legal mechanisms. Hosting in the EU does not by itself resolve every country’s education, child-data or data-localisation requirements.
10. Retention and deletion
- Active account, lesson and learning records are kept while needed to provide the pilot or service.
- After an account or organisation is closed, live account and learning data is normally scheduled for deletion within 30 days, unless the account owner requests an export or a longer period is required by law or an active dispute.
- Encrypted backups may retain deleted records for up to a further 35 days before rotation.
- Security, access and server logs are normally retained for up to 90 days, unless needed longer to investigate an incident.
- Support and operational correspondence may be retained for up to 24 months.
- Financial and tax records, if paid service is introduced, may be kept for the period required by applicable law.
Teachers and organisations should delete student accounts and learning records when they are no longer needed for the educational purpose.
11. Security
CTS uses measures intended to protect information, including encrypted HTTPS connections, password hashing, role-based access, restricted database access, server firewalls, security updates, backups and administrative access controls. No online service can guarantee absolute security. Suspected security or privacy incidents should be reported promptly to lessons@cometalkstudio.com.
12. Your rights
Depending on applicable law, individuals may have rights to receive information about processing, access their information, correct it, request deletion or restriction, object to certain processing, receive portable data, withdraw consent and complain to a data-protection authority. A student or parent may need to make an education-record request through the teacher or organisation that created the account.
Requests can be sent to lessons@cometalkstudio.com. We may need to verify identity and authority before releasing or changing account information.
13. Changes to this notice
We may update this notice when the service, providers or legal requirements change. The revised date will appear at the top. Material changes affecting existing pilot users will be communicated through the platform or account contact where practical.