A plain-language account of every type of data Thadus collects, what it is used for, and what we will never do with it.
Last updated: August 2026 · Applies to thaduscodelabs.com, the Partner Portal, and the Thadus CodeLabs desktop application🔍 01 — Overview
Thadus CodeLabs has two components with very different relationships to data. This policy covers both clearly.
The coding application students use day-to-day. It runs fully offline. When an internet connection is available, it sends basic session information — which device is active, which centre it belongs to, and progress through the course. It does not send anything students type or create.
The online platform used by educators, admins, and Thadus staff. It collects account information, survey responses, monthly reports, and support conversations. It also stores the session data sent by the desktop app.
A few things we want to be upfront about:
The desktop app collects basic session data automatically whenever it is connected to the internet — this includes devices that are being used without a valid licence. There is no in-app setting to turn this off.
We also want to be honest: the session data the app sends is not fully anonymous. While it does not include any student's name, the combination of a device identifier, centre name, and approximate location could in theory narrow to a small group in a very small deployment. We say this plainly rather than overstating our anonymisation.
🖥️ 02 — What the desktop app sends
When the app is connected to the internet, it sends session data to our servers. No student names, passwords, or content created by students is ever included.
The app does not send location data. However, every connection the app makes to our servers comes from an IP address, and our servers resolve that address to an approximate city and country using a third-party service. This gives admins a general sense of where devices are active. It is city-level only — not GPS, not an exact address.
The app periodically checks whether a newer version is available. These requests include the app version and licence details so we can confirm whether an update applies.
🌐 03 — What the partner portal collects
The Partner Portal collects information needed to manage your programme, track outcomes, and provide support.
Created by Thadus when your partnership begins. Users do not self-register.
Pre-course survey — completed once per participant:
Monthly reports — submitted each cycle:
🚫 04 — What we don't collect
The following have been verified against what the application actually does. These are facts about the software, not aspirational statements.
The app sends a device identifier and a centre licence key — nothing more. No student name, email, age, or any personal identifier is ever sent from the app. Our systems link device data to an organisation, not to an individual person.
Whatever students type in the coding editor stays entirely on the device. It is used only for local answer-checking and saving. None of it is sent to our servers at any point.
The app does not access the device camera or microphone at any point. The avatar feature takes a screenshot of a portion of the app itself — it is not a webcam photo and is never uploaded.
Individual keystrokes are not recorded or transmitted. The app does not include any form of input monitoring.
We know only the approximate city and country of a device, derived from its internet connection. We have no GPS data, no street addresses, and no precise location of any kind.
We do not handle payment cards or bank details. We collect no biometric data — no fingerprints, no facial recognition, and no voice data.
🎯 05 — How we use data
We do not collect data speculatively. Every piece of information we hold serves one of these purposes:
👁️ 06 — Who can see what
Access within the Partner Portal is strictly role-based. No organisation can see another organisation's data.
| User type | Own data | Their students | Their organisation | Other orgs | Analytics data |
|---|---|---|---|---|---|
| Student | Own only | No | No | No | No |
| Educator | Yes | Yes | No | No | No |
| Org admin | Yes | Yes | Yes | No | No |
| Thadus staff | Yes | Yes | Yes | Yes | Yes |
🚫 07 — What we never sell
The following will never be sold, licensed, shared, or disclosed to any external party for any commercial purpose, ever.
This commitment is unconditional. It does not have carve-outs for "trusted third parties," "service providers," or "business transfers." If we ever faced a situation that required us to reconsider this, we would contact affected partners directly and seek explicit consent first.
🔗 08 — Third-party services
Four external services handle data as part of running Thadus. We name them here with exactly what each receives.
| Service | What it receives | Why |
|---|---|---|
| Supabase | All portal data — user accounts, survey responses, session data from the app, support conversations, and login records. This is our primary database and login provider. | Hosting and securing the database and user authentication |
| Render | Standard server connection logs — request times and response codes. No user content. | Hosting the portal server |
| ip-api.com / ipinfo.io | IP addresses from app connections only, to convert them to a city and country. | Approximate device location for admin visibility |
| Email provider (SendGrid) | Name and email address of the recipient only. | Sending login credentials and programme notifications |
We do not share data with advertising networks, analytics platforms, or data brokers.
🔐 09 — Data security
We take security seriously, especially given the communities we serve.
All portal data is stored on Supabase. Data is encrypted at rest and in transit — meaning it cannot be read by anyone who intercepts it.
Users only see the data their role allows. Admin access to production data is limited and logged.
Personal data is retained for the duration of your active partnership and up to 24 months after. You can request deletion at any time.
The Partner Portal does not include advertising trackers, social media pixels, or any third-party behavioural tracking.
Programme data is anonymised and aggregated by our internal team before it is compiled into any report. Raw records are never shared.
In the unlikely event of a data breach, we will notify affected partners within 72 hours and report to relevant authorities.
✊ 10 — Your rights
We honour these rights for all users of the Partner Portal, regardless of where you are located.
Request a copy of all personal data we hold about you at any time.
Ask us to correct any inaccurate or incomplete information we hold.
Request that we delete your personal data. We will act within 30 days.
Request your data in a machine-readable format (JSON or CSV).
Object to specific uses of your data, including use in anonymised regional reporting.
Email neth@thaduscodelabs.com. We respond within 5 business days.
❓ 11 — Frequently asked questions
From partner organisations, educators, and parents.
📬 12 — Contact
Have a question about this policy, want to exercise a data right, or just want to speak to a human? We respond within 5 business days.
For all privacy, data, and policy enquiries:
neth@thaduscodelabs.com
Thadus Group
Thadus CodeLabs operates under Thadus Group
Brisbane, Australia
Download the complete document for your records, compliance team, or funding requirements.
Download Full Policy (PDF)