Made to Teach respects the privacy of teachers and school staff who use our websites, mobile app, timetable import tools, and related services. This Privacy Policy explains how we collect, use, store, and disclose personal information when you use Made to Teach.
We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply.
1. Who this policy covers
This policy applies to:
- Made to Teach websites and support channels,
- the Made to Teach mobile app on supported iOS and Android devices,
- the timetable import site at import.madetoteach.com.au, including the one-time code flow that connects the site to the app,
- teacher accounts, timetable drafts, synced app data, and related support or operational activity.
2. What information we collect
We collect information that is reasonably necessary to operate the service, keep it secure, and support the app.
2.1 Account and profile information
- name or display name, email address, and sign-in provider details,
- timezone, school country or state, teaching focus, and onboarding preferences,
- account status, product entitlement, or subscription status connected to your Made to Teach account.
2.2 App content and service data
- classes, timetable entries, reminders, assessments, notes, and other planning content you create in the app,
- shared-class content, invitations, collaborator activity, and device push tokens if you enable collaboration notifications,
- the one-time import code generated inside the app,
- timetable files and images you upload, such as recurring grid
.pdffiles,.icsexports, photos, or screenshots, - calendar event details needed to build a timetable draft, including titles, times, recurrence details, and locations,
- draft timetable rows and review outcomes created through the import flow, including whether you tell us that a PDF or image timetable did not extract correctly,
- teaching program documents, extracted program content, annotations, and registration records if you use Program Register when that feature is available,
- requests, previous answers, class labels, timetable anchors, work-window timing, calendar context, and generated suggestions when you choose to use a Pro AI planning feature,
- support messages or emails you send to us.
2.3 Images, voice memos, and attachments
- photos or images you take or attach inside the app,
- voice memos you choose to record and attach to a loose end,
- media metadata and storage references needed to display those attachments across your devices where cloud sync is enabled.
Photos and voice memos remain on your device in local-only mode. If you sign in and enable cloud sync, selected media may be uploaded to private cloud storage and linked to your account so it can sync across devices.
2.4 Technical and device information
- IP address, browser type, app or device metadata, and request timestamps,
- scrubbed crash reports, performance measurements, route names, session activity, and other technical diagnostics used for security, support, and operational debugging,
- mobile app launches, sessions, screen views, coarse geography derived from masked network addresses, app and device metadata, in-app purchase events, pseudonymous app-instance or device identifiers, and high-level account-state properties such as whether sign-in, Pro, or sync is enabled when mobile Firebase Analytics is configured,
- cookies required to keep a claimed import session attached to the current browser, plus analytics cookies or similar browser storage when Google Analytics is configured for website measurement,
- website usage and search performance information from Google Analytics and Google Search Console,
- device identifiers, local storage entries, and secure device tokens needed to keep sign-in, import access, sync, settings, push notifications, purchase entitlements, or similar app features working.
We configure the mobile apps not to collect advertising identifiers: the iOS app does not include advertising identifier support, and the Android app blocks permission to access the Google Advertising ID. Advertising-related storage, user-data, and personalisation collection are disabled in the mobile Firebase Analytics configuration. Made to Teach does not send your account ID to Firebase Analytics, and configures Sentry not to send default personal information. Diagnostic events are scrubbed for common secrets and identifiers before they are sent, although an unexpected error can still contain technical context.
2.5 Notifications and widgets
- notification preferences and locally scheduled reminder data if you enable reminders,
- limited upcoming schedule or planning information written to device widget storage if you enable home screen widgets.
3. How app data is stored and synced
Some parts of Made to Teach can be used in a local-only mode. In that mode, core app data is stored on your device rather than in our cloud backend, unless you separately use a cloud-connected feature such as timetable import.
If you sign in to a cloud account, we may sync profile and planning data through our backend so that it is available across supported devices and sessions.
Authentication tokens and temporary import access tokens may be stored using secure device storage where available. Depending on your account mode, images and voice memos may remain on-device or be uploaded to private cloud storage so they can be retrieved later.
4. How we use information
- to operate the website, mobile app, timetable import flow, and related support services,
- to authenticate users, keep sessions secure, and connect a browser upload to the correct teacher account,
- to parse calendar files, PDFs, and timetable images and create drafts for review in the app,
- to investigate failed or inaccurate timetable imports and improve the parser using the review outcome you submit; a reported PDF issue may also include a temporarily retained parser sample,
- to save, sync, restore, and display the planning data you choose to keep with Made to Teach,
- to schedule reminders or support widget features on your device where you enable those features,
- to process or restore subscription entitlements and account status,
- to generate optional AI-assisted planning suggestions from the context you submit,
- to secure the service, prevent misuse, investigate errors, and improve the product,
- to understand mobile feature usage, website traffic, landing pages, and search visibility so we can improve the app, website, and import flow,
- to comply with legal obligations and respond to lawful requests.
5. Device permissions
The app may request access to certain device features so that optional functionality can work.
- Notifications: to schedule local reminder alerts if you turn them on.
- Camera or photo library: to let you take or attach timetable images, reminders, notes, or other app content.
- Microphone: to let you record and attach an optional voice memo to a loose end.
- File picker access: to let you select timetable, teaching program, or image files from your device.
You can usually decline these permissions, but the related feature may not work properly until access is granted.
6. AI features
Pro AI planning is optional. When you invoke it, Made to Teach sends the request and only the planning context needed for that request through our Supabase backend to OpenAI. Depending on the action, this can include your typed request, previous answers, planning date and timezone, class labels and internal class identifiers, work-window timing, timetable anchors, and school-calendar context. We do not intentionally include your email address, display name, or Made to Teach account ID in the model request.
The app asks for your permission before the first Pro AI planning request is sent. You can decline and keep using non-AI planning features, or reset that permission from Profile > Help, privacy & safety so the app asks again before a later request.
Made to Teach does not intentionally save AI prompt or response text in the planner database after returning the result, and our OpenAI request asks the provider not to store the generated response. We do retain account-linked usage counters needed to enforce Pro access, rate limits, and daily AI budgets, and limited technical logs may be retained for security and fault investigation. OpenAI processes submitted content under our service configuration and applicable provider terms. Do not include student names, health information, or other sensitive information that is not necessary for the planning request.
AI-checked PDF and photo import is also optional. When you use it, Made to Teach sends the validated PDF, or validates and re-encodes an image to remove embedded metadata before sending it, through our Vercel-hosted import service to OpenAI so timetable details can be extracted into a structured draft. We do not intentionally include your email address, display name, or Made to Teach account ID in that model request. The source file is not kept by Made to Teach after the request finishes, although the extracted draft, review outcome, rate-limit records, and limited technical logs may be retained as described in this policy.
OpenAI processes AI feature content under our service configuration and applicable provider terms. Provider systems may retain submitted content temporarily for safety, abuse monitoring, legal, or operational purposes according to those settings and terms. AI extraction can be inaccurate, so timetable PDF and image drafts must be reviewed before use.
7. Calendar content, student privacy, and sensitive information
Calendar exports can sometimes include more than timetable structure. Depending on the system used by a school or teacher, an uploaded file may contain class names, room names, teacher-entered notes, or in some cases student names embedded in event titles or descriptions.
Made to Teach does not want or require formal student records for timetable import. We ask users to upload the narrowest timetable file available and to avoid uploading unnecessary student-identifying or sensitive information.
Photos, voice memos, shared-class content, and teaching program documents can also contain personal information. Only capture or upload material you are authorised to handle, obtain any consent required by your school or law, and avoid including student-identifying or sensitive information when it is not necessary.
We do not create a student record system from imported files. The import flow is intended only to turn timetable structure into a draft recurring timetable inside the app.
8. When we may disclose information
We may disclose information to trusted service providers that help us operate Made to Teach, such as:
- Supabase for database, authentication, storage, and backend services,
- Vercel for web hosting and deployment infrastructure,
- Google for Firebase Analytics in the mobile app, website analytics, search performance reporting, and Google sign-in where you choose it, and Google Play for Android app distribution and billing,
- Sentry for scrubbed crash, performance, and operational diagnostics,
- OpenAI for optional AI-assisted planning requests and timetable PDF or image extraction,
- RevenueCat for subscription entitlement and purchase support; the app uses your Made to Teach account ID as the RevenueCat customer identifier so purchase status can follow the correct signed-in account,
- Cloudflare for Turnstile abuse prevention during email sign-in, which may process network, browser, device, and challenge-result information,
- Expo for app and push-notification infrastructure, including collaboration alerts you enable and silent device-security events,
- Apple for Sign in with Apple, app distribution, notifications, and in-app purchase services,
- email delivery providers for support messages, suggestions, and service notices such as inactivity warnings,
- professional advisers, security providers, or regulators where reasonably necessary.
We do not sell personal information, use Made to Teach data for targeted advertising, or operate third-party ads in the app.
9. Cross-border processing
Some of our service providers may process or store information outside Australia, including in the United States or other jurisdictions where their infrastructure operates. Where that happens, we take reasonable steps to work with providers that offer appropriate security and privacy protections.
10. Retention
Local-only app data generally stays on your device until you delete it, clear app storage, or uninstall the app.
Account-linked data is retained while your account remains active and for as long as reasonably necessary to support the service, security, backups, support, legal compliance, or operational needs. Cloud-synced photos, voice memos, and push tokens are retained while their related content or account remains active, then removed or queued for deletion. Limited residual copies may remain temporarily in backups, security logs, or processor systems until their ordinary retention periods expire.
If someone reports shared-class content or conduct, we keep a restricted moderation record containing the report, relevant account and class identifiers, and a snapshot of the reported content and membership context. These records are not visible to class members and are available only to authorised service-side reviewers. We retain them only for as long as reasonably necessary to investigate the concern, prevent repeated contact or re-entry, protect users and the service, resolve disputes, and meet legal obligations. A narrowly retained safety record may remain after the reported content, class, or account is deleted when those purposes still apply.
If you do not open and sign in to the app for 365 days, we may automatically remove inactive app data such as classes, timetable entries, imports, attachments, and in-service backups. We send a warning email about 30 days beforehand, and signing in resets the inactivity period. This cleanup does not itself delete your login identity. Accounts with active or payment-recovery subscription access are excluded while that access continues.
One-time import sessions are temporary. Pending or unused sessions may expire automatically. Parsed timetable draft rows are retained only as long as reasonably necessary to support the import and associated support, security, or operational needs.
We aim not to keep raw uploaded files longer than necessary for processing. Where feasible, we parse the file to the required timetable draft data and avoid treating the raw file as a long-term store of record. If you tell us that a PDF timetable did not extract correctly, we may keep that PDF and related review outcome for a short period, usually up to 14 days, so we can inspect the parser issue and improve PDF import accuracy. We then delete the retained PDF sample once it is no longer needed for that work.
Timetable PDFs are validated before AI processing. Photos and screenshots are also re-encoded to remove embedded metadata. The AI source file is discarded by Made to Teach after the extraction request, except for a PDF retained temporarily when you report a parser issue as described above. Extracted timetable rows and review outcomes remain part of the temporary import session. A processor may retain submitted content temporarily under its own configured safety, security, legal, and operational retention practices.
If Program Register is enabled, active source documents and derived records are retained while needed to provide the feature. Abandoned uploads, expired exports, and deletion requests are handled by scheduled storage-cleanup workflows. Analytics, diagnostics, purchase records, security records, and support correspondence are kept only for as long as reasonably necessary for their stated purpose, subject to provider settings and legal requirements.
11. Data security
We use reasonable technical and organisational measures to protect information against unauthorised access, misuse, loss, or disclosure.
- restricted backend access,
- secure account and token storage where supported on the device,
- short-lived import codes and session expiry,
- signed session cookies,
- role-based database access and infrastructure controls.
No online system can be guaranteed perfectly secure, but we aim to keep the risk proportionate and well managed.
12. Access, correction, deletion, and complaints
Signed-in app users can initiate account deletion from Profile > Manage account. Account deletion removes the Made to Teach account and associated cloud data, subject to narrow legal, safety, security, backup, moderation, and transaction-record retention described above. Deleting an account does not itself cancel an Apple, Google, or web subscription; subscriptions remain managed through the store or provider that billed you. Local-only data can be removed by clearing the local workspace or uninstalling the app.
If you want to request access to, correction of, or deletion of personal information we hold about you, contact us at privacy@madetoteach.com.au.
If you believe we have mishandled your information, contact us first so we can investigate. If you are not satisfied with the outcome, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.
13. Changes to this policy
We may update this Privacy Policy from time to time as the product evolves. The latest version will be published on this site with a revised effective date.