Privacy Policy
Effective 4 September 2026 · Version 1.1
This policy explains what personal information EdPrax collects, how we use it, and what you can ask us to do with it. We handle personal information in line with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
We have written this to describe what the platform actually does today, not what we intend it to do. Where a protection has limits, we say so.
Who we are
EdPrax is an independent platform for Australian educators. We are not affiliated with any school, employer, regulator, or vendor.
What we collect
When you sign up
- Email address — required for verification, sign-in and account recovery
- A display name and handle you choose
- Self-declared role (e.g. "classroom teacher (secondary)")
- Optional profile details you write yourself: bio, avatar image, pseudonym
When you use the platform
- Posts, articles, comments, endorsements and reactions you create
- Direct messages you send, and who you sent them to
- Topics you follow, communities you join, and your role in them
- Files you upload (article images, community resources)
When you pay
- Subscription status, plan, and transaction history, so we can give you what you paid for and issue receipts and refunds.
- Card details are entered with Stripe and handled by Stripe. We never see or store your card number.
Automatically
- Standard web-server logs held by our hosting provider (Vercel), which include IP addresses. These are used for security, abuse prevention and debugging.
- Error reports, when something goes wrong (see "Error monitoring" below).
What we don't collect
- Information about students. EdPrax is a student-free zone. Posts referring to identifiable students are removed under the Code of Conduct.
- Advertising or cross-site tracking data. We run no ads and no third-party tracking cookies.
- Product analytics. We currently run no analytics or behavioural-tracking product at all. If we add one, we will ask for your consent before it runs and update this policy first.
- Sensitive information (health, religion, political opinions, sexual orientation and the like), unless you choose to put it in something you write.
How we use it
- To operate the platform: authenticate you, show you the right content, and deliver notifications you have turned on.
- To prevent abuse: rate limiting, flag handling and moderation.
- To keep the service working: diagnosing errors and outages.
We do not sell your data. We do not share it except with the service providers listed below, or where the law requires it.
Pseudonymous content
When you post pseudonymously:
- Your pseudonym is shown publicly; your real name and handle are not shown or linked from that post.
- Your real identity is still stored in our database, because the platform must know who you are to manage permissions, prevent abuse and let you sign in.
- Only the platform administrator can unmask a pseudonym, and only with documented justification for a serious Code of Conduct breach. See the Code of Conduct.
AI features
AI assistance (discussion summaries and topic suggestions) is opt-in by action: nothing is sent to a model unless you press the button, and the features are available only inside communities on a Community Pro plan. If you never use them, no content of yours reaches an AI provider.
When you do use them:
- The relevant post, article or comment text is sent to Anthropic via the Vercel AI Gateway, under a zero-data-retention arrangement. Your content is not retained by the provider and is not used to train their models.
- Author names are replaced before the text is sent. Every participant becomes a positional label — "Participant 1", "Participant 2" — so the model never receives an educator's display name, handle or pseudonym.
- Limits you should know about. De-identification applies to author names, not to the words people type. If someone writes a person's name inside the body of a post, that text is sent as written. Do not put names or identifying details of colleagues or students into content you then summarise.
- These providers are outside Australia. Using an AI feature is a cross-border disclosure under APP 8, and pressing the button is your consent to it.
We do not run AI features over health or wellbeing data, and we do not send personal information about students to any AI provider.
Error monitoring
We use Sentry to find out when the application breaks.
- Sentry receives error reports and a sample of performance traces.
- It also records a small sample of browser sessions ("session replay") so we can see what sequence of actions caused an error. These recordings are masked: all text and all images are blocked before the recording leaves your browser. A replay shows the shape of the page and what was clicked, not what was written or read.
- We have disabled the option that would attach your IP address and cookies to error reports.
Sentry processes this data outside Australia.
Service providers (who else handles your data)
| Provider | What they do | Where |
|---|---|---|
| Supabase | Database, authentication, file storage | Australia (Sydney, ap-southeast-2) |
| Vercel | Application hosting, server logs | Application runs in Sydney (syd1); logs on global infrastructure |
| Resend | Transactional and digest emails | Outside Australia |
| Stripe | Payments for subscriptions and paid memberships | Outside Australia |
| Vercel AI Gateway + Anthropic | AI features only, when you use them | Outside Australia |
| Sentry | Error and performance monitoring | Outside Australia |
Each processes data under its own terms, and we hold data-processing arrangements consistent with the Australian Privacy Principles. This list is complete as at the effective date above; we will update it before adding another provider.
Data residency
Your account and content — everything in the database and file storage — is held in Australia, in Supabase's Sydney region (ap-southeast-2), and the application itself runs in Sydney.
Operational data leaves Australia: server logs (Vercel), outbound email (Resend), payment records (Stripe), error reports and masked session replays (Sentry), and AI requests when you use an AI feature (Vercel AI Gateway, Anthropic).
Your rights
You can, at any time:
- Correct your profile — directly, in Settings.
- Ask for a copy of your data. Email
privacy@edprax.com.auand we will send you your account data within 30 days. There is no self-service export button yet; when we build one, this policy will say so. - Ask us to delete your account. Email
privacy@edprax.com.au. We will confirm, then remove your account within 30 days. Content you posted under your real identity is anonymised and kept for the community, attributed to "Deleted Educator"; pseudonymous content remains with your real identity unlinked. Tell us if you want specific posts removed outright rather than anonymised. - Ask us to delete specific posts you wrote.
- Decline AI features simply by not using them — this has no effect on the rest of your account.
We do not charge for any of these requests.
Retention
We keep your account data for as long as your account exists. After deletion, we retain what the law requires — principally payment and tax records, which Stripe and we must keep for seven years. Backups are cycled out within 30 days.
Children
EdPrax is for adults (18+). We do not knowingly collect data about minors. If you believe a minor has created an account, email us and we will remove it.
Cookies
We use only essential cookies: those needed to keep you signed in and to protect the session. We use no analytics, advertising or cross-site tracking cookies. If that ever changes, we will ask for your consent first.
Data breaches
If a breach occurs that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner in line with the Notifiable Data Breaches scheme.
Changes to this policy
Material changes will be announced in-app and by email at least 14 days before they take effect.
Contact
- General:
hello@edprax.com.au - Privacy:
privacy@edprax.com.au - Conduct:
conduct@edprax.com.au
If you believe we have mishandled your information, you can complain to us first, and you also have the right to complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Last updated 4 September 2026.