Privacy Policy
Last updated: 5 September 2026
This policy explains what personal data StoryJar processes, why, on whose behalf, and the rights people have. A short plain-English version for families is also available.
1. Who is responsible for your data
StoryJar is a service provided by Storyjar Limited, a company registered in England and Wales (company number 17404945), trading as “StoryJar”, of 2 Peel Court, 24 St Cuthberts Way, Darlington, DL1 1GB (“StoryJar”, “we”). We are registered with the Information Commissioner's Office (ICO) under C2015410.
StoryJar is a small business and does not have a Data Protection Officer. The ICO's own assessment confirmed that one is not required here: we do not monitor people's behaviour at scale, and children's schoolwork is not special category data. There is instead a named person responsible for data protection, and you can reach them at hello@storyjar.co.uk. A school that needs that person named in a contract or a due-diligence return should ask, and we will give the name.
For the data of children, parents and staff, the school is the data controller and StoryJar is a data processor acting only on the school's documented instructions. The school decides why children's data is collected; we only handle it to provide the service. For a small amount of data about the account holder (e.g. a teacher's login email), we act as controller.
2. What we process
| Who | What | Why |
|---|---|---|
| Children (3–11) | First name only; the “moments” they create (photos, drawings, typed words); optional teacher-added skill tags and dates | To build the child's class journal / portfolio for the school |
| Teachers / staff | Name, title, school email, hashed password, role, class assignment | To create and secure staff accounts and moderate content |
| Parents / carers | Name, email, family code, link to their child(ren) | To give a read-only family view of approved moments, and, where the school has switched it on, to let a family write to their child's class teacher |
| Children (as the subject), written by parents/carers and school staff | Messages between a child's family and their class teacher — text only, about that child, delivered only inside office hours the school sets, and readable only by that family and the school staff the school allows | To let the family and the school talk about the child, with the school governing the hours and who may read. Never emailed; never shown to the child; kept with the child's record |
We deliberately do not collect: children's surnames, dates of birth, addresses, contact details, or any behavioural/analytics profiling data. Children never have logins, emails or passwords.
3. Lawful basis
The school determines and documents the lawful basis for processing children's data — typically public task (UK GDPR Art. 6(1)(e)) for state schools carrying out their educational function, with appropriate conditions for any special-category data (e.g. images). StoryJar processes this data solely as the school's processor under Art. 28. For account-holder data we rely on legitimate interests / contract to operate the service. Photographs of children are handled under the school's own photography consent arrangements.
4. How moments are controlled
Every moment a child creates is held privately in a teacher approval queue and is not visible to anyone else until a teacher approves it. Approved moments are visible only to the child's teacher(s), school admins who teach that class, and the child's linked parent/carer (read-only). Content is never public.
5. Where data is stored
The database and uploaded media are stored and processed in the EU — Amsterdam, the Netherlands, confirmed with our hosting provider on 15 August 2026. Transfers from the UK to the EEA are covered by the UK's adequacy regulations.
Backups. Backups of that data are taken by our hosting provider and are held in the same region as the service itself — EU West, Amsterdam, in the Netherlands, confirmed with the provider in writing on 5 September 2026. No copy of a child's work leaves the EEA, in a backup or otherwise.
Support access from outside the EEA. Our hosting provider is incorporated in the United States, so its personnel may access the systems holding this data for support purposes from outside the EEA. We have not yet obtained and recorded that provider's data processing agreement or its onward-transfer terms. Children's data is not stored outside the EEA, but support access is a transfer and we describe it rather than leave it out.
Our current infrastructure and sub-processors are listed in the Sub-processors page.
6. How long we keep it
We keep a child's data for as long as the school's subscription and the school's own retention rules require, and then delete it. A school can export or delete a class's data at any time; deletion removes both the database records and the underlying media files. Full details are set out in the Data Processing Agreement.
Deletion and backups. Deleting data removes it from the live service straight away. Copies of it remain in our hosting provider's backups until those backups age out on their normal rotation: daily backups are kept for 6 days, weekly backups for 1 month, and monthly backups for 3 months. Those copies are not used to restore deleted work, and they are held in the same EU region as the service.
7. Security
We apply technical and organisational measures appropriate to children's data (UK GDPR Art. 32), including server-side access control scoped to who may see a child's work, access-controlled media, HTTPS, hashed passwords, security headers, least-privilege staff roles, and no third-party trackers. Our internal engineering rules are set out in our safeguarding & security governance.
8. Who we share data with
We do not sell data and we do not share it for advertising. We share it only with the limited sub-processors needed to run the service (see Sub-processors), each under a data-processing agreement, or where required by law.
9. Rights
Because the school is the controller for children's data, requests to access, correct, delete or export a child's data are made to the school, and we support the school in fulfilling them. Parents and pupils can raise requests with the school; the school can also contact us. For account-holder data you can contact us directly at hello@storyjar.co.uk. You may complain to the ICO (ico.org.uk).
10. Children's Code
StoryJar is designed to meet the ICO's Age Appropriate Design Code: high-privacy defaults, data minimisation, no profiling of children, no nudge techniques, and transparency in language families can understand (see the plain-English version).
11. Changes
We will tell schools about material changes to this policy before they take effect. This version is effective from 5 September 2026, and the date it was last updated is shown at the top of the page.