🔒 Privacy & Data Policy

Honest about what
we collect and why.

A plain-language account of every type of data Thadus collects, what it is used for, and what we will never do with it.

Download Full Policy (PDF) 📬 Questions? Email us
Last updated: August 2026  ·  Applies to thaduscodelabs.com, the Partner Portal, and the Thadus CodeLabs desktop application
🛡️

Our core promise: We will never sell your name, email, or any identifiable personal information to anyone. Not now, not ever.

Contents

🔍 01 — Overview

Two products. Two different data footprints.

Thadus CodeLabs has two components with very different relationships to data. This policy covers both clearly.

🖥️

The Desktop App

The coding application students use day-to-day. It runs fully offline. When an internet connection is available, it sends basic session information — which device is active, which centre it belongs to, and progress through the course. It does not send anything students type or create.

🌐

The Partner Portal

The online platform used by educators, admins, and Thadus staff. It collects account information, survey responses, monthly reports, and support conversations. It also stores the session data sent by the desktop app.

ℹ️

A few things we want to be upfront about:

The desktop app collects basic session data automatically whenever it is connected to the internet — this includes devices that are being used without a valid licence. There is no in-app setting to turn this off.

We also want to be honest: the session data the app sends is not fully anonymous. While it does not include any student's name, the combination of a device identifier, centre name, and approximate location could in theory narrow to a small group in a very small deployment. We say this plainly rather than overstating our anonymisation.

🖥️ 02 — What the desktop app sends

Basic session and progress information.

When the app is connected to the internet, it sends session data to our servers. No student names, passwords, or content created by students is ever included.

📡

What is sent during a session

  • A device identifier — a random code generated when the app is first installed. It identifies the machine, not the person using it.
  • The centre's licence key — this identifies which organisation and location the device belongs to.
  • Which type of event occurred — for example, the app opening, a module being viewed, a module being completed, or the session ending. The app also sends a regular check-in signal while it is open.
  • The app version currently installed.
  • Whether the device is licensed or unlicensed.
  • The centre name.
  • How long the session has been active.
  • Which course and activity the student is currently on, and how far through it they are.
📍

Approximate location

The app does not send location data. However, every connection the app makes to our servers comes from an IP address, and our servers resolve that address to an approximate city and country using a third-party service. This gives admins a general sense of where devices are active. It is city-level only — not GPS, not an exact address.


🔄

Version checks

The app periodically checks whether a newer version is available. These requests include the app version and licence details so we can confirm whether an update applies.

🌐 03 — What the partner portal collects

Account, programme, and support information.

The Partner Portal collects information needed to manage your programme, track outcomes, and provide support.

👤

Account information

Created by Thadus when your partnership begins. Users do not self-register.

  • Full name and email address
  • Role — student, educator, admin, or partner manager
  • Organisation and centre assignment
  • Programme start date
  • For student accounts: the supervising educator's email
  • A device or location label if set by an admin (e.g. "Lab Room 2")
🔑

Login and access

  • Passwords are stored in encrypted form only. They are never visible to Thadus staff.
  • Login sessions are managed securely and expire automatically.
  • The licence key assigned to each user, organisation, or centre.
  • Whether the app installer and licence file have been downloaded, and when.
📋

Survey and programme data

Pre-course survey — completed once per participant:

  • Career aspirations and areas of interest
  • Interest in STEM pathways
  • Self-reported confidence and prior experience with technology
  • Demographic information (age range, gender, location, school year)

Monthly reports — submitted each cycle:

  • Self-reported module completion
  • Self-reported change in confidence
  • Any open-text responses
💬

Support and communications

  • Support requests submitted through the portal, including the message content, priority, and status.
  • Conversations with the in-portal AI assistant. Every message is stored and may be reviewed by Thadus staff for support and quality purposes.

📅

Activity and milestones

  • When students first interact with the portal
  • When the installer was first downloaded
  • Completion certificates issued per user per monthly cycle

🚫 04 — What we don't collect

Confirmed not collected.

The following have been verified against what the application actually does. These are facts about the software, not aspirational statements.

🙅

No student identity from the app

The app sends a device identifier and a centre licence key — nothing more. No student name, email, age, or any personal identifier is ever sent from the app. Our systems link device data to an organisation, not to an individual person.

⌨️

No student code or work

Whatever students type in the coding editor stays entirely on the device. It is used only for local answer-checking and saving. None of it is sent to our servers at any point.

📷

No camera or microphone

The app does not access the device camera or microphone at any point. The avatar feature takes a screenshot of a portion of the app itself — it is not a webcam photo and is never uploaded.

🔤

No keystroke logging

Individual keystrokes are not recorded or transmitted. The app does not include any form of input monitoring.

📍

No precise location

We know only the approximate city and country of a device, derived from its internet connection. We have no GPS data, no street addresses, and no precise location of any kind.

💳

No financial or biometric data

We do not handle payment cards or bank details. We collect no biometric data — no fingerprints, no facial recognition, and no voice data.

🎯 05 — How we use data

Everything has a clear purpose.

We do not collect data speculatively. Every piece of information we hold serves one of these purposes:

🤝

Running your programme

  • Providing access to the Partner Portal
  • Communicating with partner organisations
  • Providing programme support and training
  • Delivering monthly reports and completion certificates
📡

Understanding app usage

  • Knowing whether the app is being used at a centre
  • Tracking programme-level course progress
  • Identifying devices running without a valid licence
  • Keeping the app up to date
  • Giving admins a general view of where devices are active
📈

Measuring and improving impact

  • Understanding which parts of the programme are most effective
  • Tracking outcomes across programmes and regions
  • Supporting grant applications and funding reports
  • Publishing anonymised programme statistics

👁️ 06 — Who can see what

Clear access levels for every user type.

Access within the Partner Portal is strictly role-based. No organisation can see another organisation's data.

User type Own data Their students Their organisation Other orgs Analytics data
Student Own only No No No No
Educator Yes Yes No No No
Org admin Yes Yes Yes No No
Thadus staff Yes Yes Yes Yes Yes

🚫 07 — What we never sell

Some things are simply not for sale.

The following will never be sold, licensed, shared, or disclosed to any external party for any commercial purpose, ever.

🚫 Names
🚫 Email addresses
🚫 Phone numbers
🚫 Physical addresses
🚫 Individual learning records
🚫 Personal identities
🚫 Student profiles
🚫 Educator records
🚫 Organisation contact lists
🚫 Private communications
🚫 Passwords or credentials
🚫 Any identifiable record
⚠️

This commitment is unconditional. It does not have carve-outs for "trusted third parties," "service providers," or "business transfers." If we ever faced a situation that required us to reconsider this, we would contact affected partners directly and seek explicit consent first.

🔗 08 — Third-party services

Services that receive data in order to operate the platform.

Four external services handle data as part of running Thadus. We name them here with exactly what each receives.

Service What it receives Why
Supabase All portal data — user accounts, survey responses, session data from the app, support conversations, and login records. This is our primary database and login provider. Hosting and securing the database and user authentication
Render Standard server connection logs — request times and response codes. No user content. Hosting the portal server
ip-api.com / ipinfo.io IP addresses from app connections only, to convert them to a city and country. Approximate device location for admin visibility
Email provider (SendGrid) Name and email address of the recipient only. Sending login credentials and programme notifications

We do not share data with advertising networks, analytics platforms, or data brokers.

🔐 09 — Data security

How we protect what you share with us.

We take security seriously, especially given the communities we serve.

🗄️

Secure hosting

All portal data is stored on Supabase. Data is encrypted at rest and in transit — meaning it cannot be read by anyone who intercepts it.

🔑

Access controls

Users only see the data their role allows. Admin access to production data is limited and logged.

⏱️

Data retention

Personal data is retained for the duration of your active partnership and up to 24 months after. You can request deletion at any time.

🌐

No tracking scripts

The Partner Portal does not include advertising trackers, social media pixels, or any third-party behavioural tracking.

📤

Anonymisation before sharing

Programme data is anonymised and aggregated by our internal team before it is compiled into any report. Raw records are never shared.

🔔

Breach notification

In the unlikely event of a data breach, we will notify affected partners within 72 hours and report to relevant authorities.

✊ 10 — Your rights

You are in control of your data.

We honour these rights for all users of the Partner Portal, regardless of where you are located.

👀

Right to access

Request a copy of all personal data we hold about you at any time.

✏️

Right to correct

Ask us to correct any inaccurate or incomplete information we hold.

🗑️

Right to deletion

Request that we delete your personal data. We will act within 30 days.

📦

Right to portability

Request your data in a machine-readable format (JSON or CSV).

🚫

Right to object

Object to specific uses of your data, including use in anonymised regional reporting.

✉️

How to exercise your rights

Email neth@thaduscodelabs.com. We respond within 5 business days.

❓ 11 — Frequently asked questions

Questions we hear most often.

From partner organisations, educators, and parents.

🖥️ What does the desktop app actually send?
It sends a device identifier, the centre's licence key, and session information — which event type occurred, how long the session lasted, which course and activity is active, and how far through the course the student is. It also sends the app version and whether the device is licensed. It does not send student names, what students type, or any personal information about the person using the app.
📷 The app has a photo feature. Does it use the webcam?
No. The avatar photo feature captures a portion of the app window on-screen — it is a screenshot of the app itself, not a webcam capture. The image is saved locally on the device only and is never sent to Thadus.
💬 Are chatbot conversations stored?
Yes. Every message sent to and from the in-portal AI assistant is stored and linked to your account. These conversations may be reviewed by Thadus staff for support and quality purposes. Please do not share passwords or sensitive personal information through the chatbot.
🗑️ What happens to our data when our partnership ends?
Personal information — names, emails, login records — is retained for up to 24 months after your partnership ends, then deleted. Anonymised programme data may be retained in de-identified regional datasets, where it cannot be traced back to your organisation or students. You can request full deletion of personal data at any time by emailing us.
🔒 Can students or parents object to data collection?
Yes. Students or parents can contact us at neth@thaduscodelabs.com to request that a student's data is excluded from anonymised reporting datasets. The student can continue using the programme. Exclusion only affects whether their data contributes to anonymised reporting.

📬 12 — Contact

Get in touch.

Have a question about this policy, want to exercise a data right, or just want to speak to a human? We respond within 5 business days.

✉️

Email us

For all privacy, data, and policy enquiries:
neth@thaduscodelabs.com

🏢

Organisation

Thadus Group
Thadus CodeLabs operates under Thadus Group
Brisbane, Australia

Need the full formal policy?

Download the complete document for your records, compliance team, or funding requirements.

Download Full Policy (PDF)