Draft, published for transparency during the private beta.
It will be replaced with a finalised version before public launch.
Privacy Policy
Last updated: 30 August 2026
1. Who we are and what this policy covers
Daily Work Pad is a privacy-first, local-first planning application built for Australian teachers. It is developed and operated by the Daily Work Pad team, referred to in this policy as “we”, “us”, or “Daily Work Pad”.
This policy explains what information the app handles, where it is stored, how it is protected, and what choices you have as a teacher using the app. It is written with reference to the Privacy Act 1988 (Cth) and applicable state and territory privacy laws. Because this is a draft document, it should not be treated as a complete legal compliance statement. Our lawyers will review and finalise it before the app moves beyond private beta.
If you have a question about this policy or a privacy concern, contact us at support@dailyworkpad.com.
2. Your data lives on your device, not our servers
Daily Work Pad is designed to work entirely offline. All of your teaching data, including lesson plans, timetables, student records, assessment marks and award logs, is stored in your browser’s IndexedDB, which is a private database on your own device. The app does not require an internet connection for any core function.
This “local-first” design is a deliberate architectural choice, not an afterthought. Under normal use with cloud sync disabled, we have no way to access your teaching records because they never leave your device. The practical consequence is that if you lose your device or clear your browser storage, your local data may be unrecoverable unless you have exported a backup. See section 9.
3. The Student Identity Vault: how student names are protected
This is the most important privacy property of the app. Student real names are stored only in a dedicated “Identity Vault”, a separate, isolated table in the on-device database. Everywhere else in the app, including work pads, lesson plans, exports and AI features, students are referenced by opaque codes such as STUDENT_004. Section 4 sets out the one place that is not automatic — a name you type yourself that is also an ordinary word — because it is the exception that decides what is safe to write in a free-text box.
This technique is called pseudonymisation. It is important to understand that this is not anonymisation. Under Australian privacy law, a code combined with other information (for example, a class timetable, grade level, or school name) can still constitute personal information about a child. We use the pseudonymisation framing deliberately and honestly: the Identity Vault provides meaningful protection by separating names from operational data, but it does not create anonymity.
The vault is never transmitted to our servers, to AI providers, or included in exports unless you explicitly choose a name-inclusive export format for your own local use.
Being precise about how the vault is stored: names in the vault are held in your browser’s local database in ordinary readable form. They are not encrypted at rest on your device. What protects them is that no readable copy ever leaves it, and your device’s own security: your account password, screen lock and disk encryption. Anyone with access to your unlocked device and browser can read them. If you use a shared staffroom computer, sign out and treat the device as you would a paper roll left on a desk.
The one copy that does leave, and why you want it to: a browser can throw its own database away. Clearing your history does it, and some phones do it on their own after a few weeks. Without a backup that means every name gone, and a class of “STUDENT_04”. So once you set a vault PIN, Daily Work Pad keeps a single encrypted copy of the vault for you, and updates it automatically whenever the list changes. This is not a one-off action you take; it runs quietly from then on.
What is stored is ciphertext and nothing else. No names, and not your PIN. The key is built from your PIN combined with a secret held on our server, and your PIN is never transmitted, so neither half is enough on its own and we are never holding both. We cannot read that backup, and nor could anyone who obtained a complete copy of our database. The trade is the honest one: if you forget your PIN, the backup cannot be recovered, and you would re-enter the class list.
4. Optional cloud sync (beta feature)
Cloud sync is on while you are signed in, and you can turn it off at any time in Settings under “Connections and privacy”. When it is on, planning data such as lesson plans, timetables, calendars, marks and the evidence you attach to them, marking rubrics, your professional-learning record, and student UID codes is backed up to a cloud database linked to your account. The following data is never uploaded:
- Student real names (the Identity Vault stays on-device only)
- Your school’s name
- Any data you have not explicitly entered or synced
Before any record leaves your device, student names in it are replaced with the student’s code; when the record comes back to your device, the names are put back for you to read. The Identity Vault itself is never uploaded in readable form under any circumstances.
Where that replacement stops, and why. A full name is always replaced, and so is an unusual first name or surname. Some names are deliberately left alone: ones that are also ordinary English words, ones shorter than three letters, and ones shared by two children in the same class. If a child is called Will, May, Grace or Jack, replacing that word everywhere would rewrite “Mark the roll” and “we will start Monday” into nonsense, and a planning document that has been mangled is one a teacher stops trusting.
The consequence is worth stating plainly, because it is the one that affects what you type: if you write a note such as “Jack needs his inhaler” about a child whose name is an ordinary word, that sentence can be backed up with the name still in it. Only you can read your own rows, and the Identity Vault that links codes to names is never there — but the sentence is. If you would rather it were not, use the student’s code instead of their name in that note, which is what the reminders beside the free-text boxes are for. Where a name is shared by two children, the backup pauses and tells you instead, because the app cannot tell which child you meant.
A limitation we want you to know about during the private beta. The design separates your login identity (email address and authentication credentials) from your planning data so that a breach of one could not readily be used to re-identify people from the other. During the private beta those two sets of data are held in one database rather than two, to keep the system small enough to operate and audit properly at this stage. They remain logically separated, and student names are not in either. The physical separation described above is not yet in place, so a single compromise would reach both your email address and your planning records. We will separate them before the app leaves private beta, and will say so here when we do.
You can disable cloud sync at any time in Settings, and delete your cloud data yourself from the same page. No request to us required. See section 9.
The pilot waitlist. If you join the waitlist on our public pages, we store your email address and the date you joined, and nothing else. It is used for one purpose: a single email letting you know when the pilot opens. We do not use it for anything else and we do not share it with anyone. You can ask us to remove it at any time by writing to the contact address in section 1.
5. AI assistant and cross-border processing
Daily Work Pad includes an optional AI assistant to help you draft lesson content and summaries. When you use it:
- Only UID-masked context is sent to an AI provider. The same replacement described in section 3 applies here, including where it stops: a name that is an ordinary word, very short, or shared by two children is not replaced automatically.
- A guard on your device catches what the replacement does not. Before anything is sent, your text is checked against your own class list, and a request carrying a name from it is stopped and shown to you rather than sent. You can look at what was found and send it anyway if you meant to — that decision is yours, and it is the last gate, so nothing reaches an AI provider without either being masked or being something you chose to send.
- The check knows your class, not the world. It compares against the children on your roll, so it will not stop you sending a parent’s, a colleague’s, or another class’s child’s name. Before you have imported a class list it is broader, and treats any unfamiliar name-like word as worth stopping for. You remain responsible for what you type into a free-text box.
- If a name you type could mean more than one child in your class, such as two students who both go by “Bec”, the assistant asks which one you mean before sending anything. It has to: replacing the name with either child’s code would file your note against the wrong student. Your answer is remembered for that conversation only, is held in memory on your device, and is never saved or uploaded.
- Raw prompts are not stored by the app or serialised for any other outbound purpose.
- Every AI feature uses Google Gemini: the assistant, the onboarding questions and the documents Pip drafts. It is the only AI provider this app sends anything to. Refer to Google’s privacy policy for their data-handling practices. We use a paid Google project, on which prompts are not used to train Google’s models.
- Video suggestions, where they are switched on. If your deployment has them enabled, asking for videos on a topic sends that topic, the subject and the year level to YouTube (also Google) to run a search — the same words you would have typed into YouTube yourself. No student data, no code, and nothing from your pad beyond the lesson topic goes with it. Results are filtered to YouTube’s strictest safety setting, and nothing plays automatically: the app suggests and you choose.
- During onboarding, the interview performs a one-off web lookup of your school (its name, suburb and state, all information you supplied) via Google Search grounding, to confirm its sector and curriculum authority with you. This lookup contains no student data. If the interview discusses pupils needing support, they are recorded by opaque codes (S1, S2 …) only, never by name. Real names are added later in the Students page and stay in your device’s vault.
- Notes you write beside a student are sent to the AI during setup, with the name removed. If you write “needs movement breaks” beside a child on your class list, that phrase is sent so the assistant can ask a useful question about how you record adjustments, attached to a code such as
SETUP_STUDENT_001, never to a name. A note we cannot safely strip a name from is not sent at all. We are calling this out rather than leaving it to be inferred: it means information about a child’s needs leaves your device, unattached to who they are. Nothing about it is stored by the AI provider on our behalf, and the note itself stays in your device’s database as the record of it. - AI inference may be performed on infrastructure located outside Australia. This is a cross-border disclosure of the masked (pseudonymised) context data. Because the request contains no student real names, the information disclosed is limited; however, UID codes combined with lesson content may still constitute personal information under Australian law depending on context.
If you are subject to specific school or departmental policies restricting cloud AI tools, it is your responsibility to ensure your use of the AI assistant complies with those policies.
6. Product analytics
During the beta period, we use PostHog (an open-source product analytics platform) to understand how teachers use the app so we can improve it. Analytics are optional. You can opt out in Settings.
We apply the following protections to analytics:
- Session recording is off everywhere inside the app. It runs only on the public pages, meaning the home page, sign-in, sign-up and these legal pages, which contain no teaching or student information. It was previously disabled on a named list of screens; that has been inverted, so a screen added in future is private by default rather than recorded until somebody remembers to add it to the list.
- Form inputs are masked so their content is not captured in session recordings.
- Analytics events never include student real names or student UID codes. Events describe actions (“user opened work pad”) not content.
- PostHog may process analytics data on servers outside Australia. Refer to PostHog’s Privacy Policy for details.
7. What we do not collect, and what we never sell
To be direct about what Daily Work Pad does not do:
- We never sell personal information to third parties.
- We do not use your teaching content for advertising purposes.
- We do not build advertising profiles from your usage.
- We do not transmit student names, school names, or identifiable student records to our servers (with the pseudonymisation caveat in section 3 noted).
- We do not use third-party tracking pixels or advertising SDKs in the app.
For completeness, we keep two pieces of operational data. A count of how many assistant requests your account has made in the current hour, so no single account can run up an unbounded AI bill. It records how often, never what was asked, and is discarded shortly after the hour it covers. And, when an invite code is entered at sign-up, the attempted code, the outcome, the requesting IP address and the browser user-agent string, kept for 30 days. That record is what stops the invite gate being brute-forced; it is written before any account exists and is never linked to your planning.
8. Children’s information and sensitive data
Daily Work Pad is a tool for teachers, not a service used directly by children. Children’s information (names, year levels, assessment results) is entered by the teacher. Under the Privacy Act 1988, the teacher and their school are likely to be the data controllers for that information. Daily Work Pad acts as a processing tool on the teacher’s device.
The app is designed to minimise the personal information it requires. Student year levels and class assignments are needed for curriculum-alignment features; real names are used only locally in the Identity Vault. We do not require (and strongly discourage) entering other sensitive information about students, such as health records, home addresses or family details, into the app.
Teachers in government schools, Catholic schools, and independent schools may be subject to additional information-handling obligations under their employer’s policies, applicable state education department guidelines, and the Australian Privacy Principles. Daily Work Pad’s design supports compliance with those obligations, but does not guarantee it.
9. Your choices and rights
You have the following controls:
- Export your data. The app provides export tools to download your lesson plans and records to your local device.
- Remove one student. On the Students page you can remove a student and everything recorded about them: marks, IEP goals, awards, and their name in the vault. Their name is also removed from any notes you had written it into, so nothing about them is left behind unmasked. This reaches your other devices at the next sync.
- Delete everything. Settings has a “Delete everything” action that removes your planning, marks, IEP goals, awards and student vault from this device and from the cloud. You do not need to ask us. It is done immediately and cannot be undone. If any part of it fails, you are told which part, rather than being told it worked. Your sign-in account itself remains; contact us to close it.
- Disable analytics. You can opt out of PostHog analytics in Settings at any time.
- Turn off cloud sync. Settings → Connections and privacy → “Back up planning to the cloud”. With it off nothing is uploaded and your planning stays on this device only.
- Turn off the online AI. Settings → Connections and privacy → “Online AI (Pip)”. Pip keeps working with it off. It answers from what is already on your device, without a network call.
Under the Privacy Act 1988 you may have rights to access, correct, or complain about the handling of your personal information. To exercise these rights, contact us at support@dailyworkpad.com.
10. Changes to this policy
We may update this policy as the app evolves. When we make material changes, we will post the updated policy at this URL and update the “last updated” date at the top. For significant changes affecting how student data is handled, we will notify you in the app with enough notice to review the changes before they take effect.
11. Contact
Privacy questions, complaints, and access requests:
- Email: support@dailyworkpad.com
- Postal: not published, please use email
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.