Privacy Policy
Last updated: 21 July 2026
1. Who we are
STRETCH is operated by Stretch Study Ltd, a company registered in England & Wales under company number 17346479, whose registered office is at 2 Wolseley Gardens, London, W4 3LP (“STRETCH”, “we”, “us”), in the United Kingdom.
The data controller is Stretch Study Ltd (company number 17346479), whose registered office is at 2 Wolseley Gardens, London, W4 3LP.
Children: there is a shorter version of this policy written for children to read — see STRETCH and you. Schools: our data processing agreement is at Schools & data.
For questions about this policy, or about your data, email studiokingelin@gmail.com. We answer every one.
The law that applies. This policy is governed by the UK GDPR and the Data Protection Act 2018.
2. Who controls the data — this depends on how you use STRETCH
This matters, and it is different for families and for schools.
If you are a family, you sign up directly, you add your own children, and you decide whether they use STRETCH. We are the data controller for that information and this Privacy Policy governs it.
If you are a school, the school decides which pupils are entered, for what purpose, and for how long. The school is the data controller and STRETCH is the data processor, acting on the school’s documented instructions. Our Data Processing Agreement governs that relationship and takes precedence over this policy where the two differ. LINK TO DPA
If you are a tutor, you can only see a child’s progress after a parent has explicitly approved the link. You cannot add children, and you cannot change their data.
3. What we collect
From adults (parents, teachers, tutors)
- Email address and password (the password is stored only as a secure hash — we never see it)
- Your name, or your school’s name, and account type
- For schools: the school’s name, URN and postcode, verified against the published register of schools
- Any colleagues you invite to your school account, by email address
- Billing information, when paid plans go live (handled by our payment provider — we do not store card details)
About children
- First name and surname
- Year group, and for schools, the class they are in
- A username we generate for them, and a password
- Their learning progress: which words they have attempted, how many times, how many they answered correctly, which they have mastered, coins earned, rank, and the dates and times they practised
- Whether they have asked a parent to reactivate their access
Technical information
- Your IP address and browser type, transiently, when you use the site
- Anonymous page-visit counts (see Part 3)
We do not collect, and have never collected: photographs of children, dates of birth, home addresses, phone numbers, health information, free-text written by children, or any special category data. There is no chat, no messaging between users, and no way for a child to publish anything.
4. Why we use it, and our lawful basis
| What we do | Why | Lawful basis (UK GDPR) |
|---|---|---|
| Create and run your account | To provide the service you asked for | Performance of a contract |
| Give a child a login and record their progress | It is the entire purpose of the product | Performance of a contract (families); the school’s instructions under Article 6(1)(e) or (f) (schools) |
| Show progress to a parent or teacher | So an adult responsible for the child can support them | Performance of a contract / legitimate interests |
| Show progress to a tutor | Only where a parent has approved it | Consent |
| Keep the service secure and working | To prevent misuse and fix faults | Legitimate interests |
| Take payment | To be paid | Performance of a contract |
| Count page visits anonymously | To know whether the site works | Legitimate interests |
We do not use children’s data for marketing. We do not profile children for advertising. We do not sell data. We have never done so and we will not.
5. Children’s data — our commitments
STRETCH is used by children, most of them under 13. We follow the ICO’s Age Appropriate Design Code (the Children’s Code).
- A child cannot create an account. Only a parent or a school can, and only they can add a child.
- A child cannot see other children’s progress. They see only their own. The one exception is within a family: a parent can see all of their own children’s progress side by side on the Family Dashboard, and may choose to show it to them. A child never has access to that view themselves, and never sees the progress of any child outside their own family.
- A child sees no advertising, no third-party marketing, and no “nudge” techniques designed to extend use.
- A child’s data is used only to teach them vocabulary and to show their progress to the adults responsible for them.
- A class or family code shows first names. When a child signs in, they type a code and tap their own name from a list of their class or family. This means a child can see the first names and usernames of others in that same class or family. It does not reveal surnames, progress, or passwords. Confirm you are content with this. It is a deliberate design choice made so that young children do not have to type a username.
6. Where your data is held, and who processes it
| Processor | What they do |
|---|---|
| Supabase | Stores all account and learner data, and handles logins |
| Netlify | Hosts the website |
| jsDelivr | Delivers a software library to your browser. Receives your IP address as a technical necessity |
| GoatCounter | Counts page visits. Sets no cookies and collects no personal data |
These are the only companies that touch your data. There are no advertising networks, no analytics trackers, and no data brokers.
If any of your data is stored outside the United Kingdom, we rely on the safeguards required by UK data protection law. If you want to know exactly where your data is held, email us and we will tell you.
If any processor stores data outside the UK, name the transfer mechanism — International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses. This is a question a school’s data protection officer will ask.
7. How long we keep it
- Family accounts: for as long as the account is open. If you delete a child, their data is deleted with them. If you close your account, we delete it within 30 days.
- School accounts: for the duration of the agreement with the school, and then deleted within 30 days of the school asking, or of the agreement ending.
- A child who leaves: the school or parent can remove them at any time, and their record and progress are deleted.
- Backups: deleted data may persist in encrypted backups for up to 30 days before being overwritten.
- Anonymised statistics: we keep counts and averages that identify nobody — for example how many classes a school ran, how many teachers were assigned, how many pupils took part, and average progress across a cohort. We delete the personal data that identifies a child or a teacher — names, usernames, PINs, email addresses, and progress records tied to a named individual. What remains carries no identifiers and cannot be traced back to any person. We keep these figures indefinitely to understand how STRETCH is used and to improve it.
- Business records: invoices, contracts and accounting records are kept for six years, as UK tax law requires. These concern the school or the bill-payer, not children.
8. Your rights
You can ask us to: give you a copy of your data; correct it; delete it; restrict what we do with it; or object to it. You can withdraw consent where we relied on it. A parent may exercise these rights on behalf of their child. Where a school is the controller, ask the school first — but we will always help.
Email privacy@stretch.study and we will respond within one month.
If you are unhappy, you can complain to the Information Commissioner’s Office (ico.org.uk, 0303 123 1113). We would rather you told us first.
9. Security — stated honestly
- All traffic is encrypted in transit (HTTPS).
- Data is separated at the database level so that one family or school cannot read another’s records.
- Adults’ passwords are stored as secure hashes and cannot be read by us.
- Children’s passwords are deliberately retrievable by the
adult who manages their account, and we say so openly. A
child’s password is generated by us (for example,
42quietfalcon) — a child never chooses it, and it is not a password they use anywhere else. Parents and teachers can see and print it, because that is how a login actually reaches a child. A child’s login gives access to their own vocabulary progress and nothing else — no payments, no messages, no personal content, and no other child’s record. Any adult managing the account can reset a child’s password instantly if it is ever misused. Adults’ own passwords are never stored this way — they are stored as secure hashes that we cannot read. - We do not claim our security is perfect. If we ever suffer a breach that puts anyone at risk, we will report it to the ICO within 72 hours and tell those affected.
10. Changes
If we change this policy materially, we will show a notice inside Stretch, on the dashboard, before the change takes effect. You will see it the next time you sign in. We do not email you about policy changes: an email that nobody reads is not consent, and we would rather tell you where you are actually looking.
The date at the top of this page always tells you when it last changed.