Last updated: 20 April 2026
Rocket Learning is operated by Rocket Software Ltd, a company registered in the Isle of Man (company number 136537C), with its registered office at 9 Auldyn Walk, Ramsey, Isle of Man, IM8 2TN.
We are the data controller for the personal data processed through the Rocket Learning platform (web application and iPad app). Our ICO registration number is R990140. We are also registered with the Isle of Man Information Commissioner where required.
We are not required to appoint a statutory Data Protection Officer under UK GDPR Article 37. Our Data Protection Contact is Leon, founder of Rocket Software Ltd. For any data protection matter, contact [email protected]and mark your message “Data Protection”.
We process personal data in compliance with the Isle of Man Data Protection Act 2018, the UK General Data Protection Regulation (UK GDPR), and the EU GDPR where applicable.
Each processing purpose has a specific lawful basis:
| Purpose | Lawful basis |
|---|---|
| Creating and managing your account, delivering lessons, tracking progress | Contract performance (Art 6(1)(b)) |
| Processing subscription payments and billing | Contract performance (Art 6(1)(b)) |
| Sending weekly progress reports (where enabled) | Contract performance (Art 6(1)(b)) |
| Platform security, fraud prevention, abuse detection | Legitimate interests (Art 6(1)(f)) |
| Aggregated analytics for service improvement (anonymised) | Legitimate interests (Art 6(1)(f)) |
| AI tutoring | Consent (Art 6(1)(a)), revocable at any time |
| Marketing emails | Consent (Art 6(1)(a)), revocable at any time |
| Sharing data with third-party AI providers | Consent (Art 6(1)(a)), revocable at any time |
| Safeguarding monitoring and crisis response | Legal obligation / vital interests (Art 6(1)(c) and (d)) |
| Tax and accounting records | Legal obligation (Art 6(1)(c)) |
| Consent audit logs | Legal obligation (Art 6(1)(c)) |
For children's data, we additionally rely on Article 8 UK GDPR (parental consent for information society services where consent is the lawful basis, for children under 13).
Parent/Guardian accounts:
Student accounts:
Guest accounts:
Usage data (all users):
Payment data:
We do not store credit or debit card details. Card payments are processed by Trust Payments (SecureTrading) and Apple (for iPad In-App Purchases). We store only subscription status, billing dates, and transaction reference IDs for our records.
AI tutor data (where AI features are enabled):
Safeguarding and moderation data:
Device and technical data:
We share the minimum data necessary with the following third-party services. All processors below act on our instructions under written data processing agreements. Apple and Trust Payments are independent controllers for their specific processing (payment authorisation and fraud checks).
| Provider | Role | Purpose | Data Shared | Location |
|---|---|---|---|---|
| Anthropic (Claude) | Processor | AI tutoring | Student first name, lesson context, student messages | US (IDTA / DPF) |
| OpenAI | Processor | Content moderation | Message text for safety screening | US (IDTA / DPF) |
| Trust Payments | Controller | Web card payments | Card details (entered directly with provider) | UK |
| Apple | Controller | iPad subscriptions | Apple ID, transaction data | US / Ireland |
| DigitalOcean | Processor | Database and CDN hosting | All platform data | UK / EU |
| Mailchimp (Intuit) | Processor | Email delivery | Parent email, first name, subscription status | US (DPF) |
Provider privacy policies: Anthropic · OpenAI · Trust Payments · Apple · DigitalOcean · Mailchimp
Our AI processors (Anthropic and OpenAI) do not train their models on data submitted through their APIs under their standard API terms. We do not opt in to any data-sharing-for-training programmes.
We do not sell personal data. We do not use personal data for advertising. We do not share data with advertising networks or data brokers.
Rocket Learning is designed for use by children aged 5 to 16 under parental supervision. We process children's data in compliance with UK GDPR, the Isle of Man Data Protection Act 2018, and the ICO Age Appropriate Design Code (“the Children's Code”). We do not rely on COPPA (a US framework); we mention it only to note that our standards meet or exceed COPPA requirements for any US visitors.
Our Children's Code commitments:
Under-13 users: Guest accounts for children under 13 require a parent or guardian's email address and explicit consent before creation, in line with UK GDPR Article 8. Student accounts for under-13s are created and managed only via a parent account.
AI features: AI tutoring for any child requires separate parental consent, which can be granted or withdrawn at any time from the parent dashboard.
Concerns: If you have a concern about how we handle your child's data, please contact [email protected] marked “Children's Privacy”.
To personalise learning, our platform adjusts the difficulty and selection of lessons, puzzles, and questions based on a student's skill progress. Under UK GDPR Article 4(4), this is a form of profiling.
It is not automated decision-making with legal or similarly significant effects under Article 22. It does not affect your statutory rights, your access to education more broadly, your grades from exam boards, or any outcome outside the platform itself.
The profiling we carry out is limited to:
For children, in line with the ICO Children's Code, we do not use profiling for:
Parents may object to profiling by contacting [email protected]. If profiling is turned off for a student, lesson selection will revert to a standard curriculum sequence rather than adaptive selection.
We operate a granular consent system. Parents can manage the following consents for their children:
All consent actions (grants and withdrawals) are logged with a timestamp, IP address, and platform identifier for audit purposes.
Our safeguarding systems screen student messages sent to the AI tutor and other interactive features for indicators of harm (including self-harm, grooming, and other concerns). This screening uses automated content moderation (currently OpenAI) and is a separate process from AI tutoring.
When a concern is detected:
Lawful basis: We process safeguarding data on the basis of legal obligation and, where applicable, vital interests (UK GDPR Article 6(1)(c) and (d)). This processing cannot be disabled by withdrawing consent.
Who sees safeguarding data: Safeguarding records are accessible only to authorised personnel on a strict need-to-know basis.
External disclosure: We do not routinely share safeguarding data with any external party. In rare cases, we may disclose information to emergency services, safeguarding authorities, or law enforcement where we reasonably believe this is necessary to protect life or prevent serious harm, and where such disclosure is lawful.
Retention: Safeguarding records are retained for 7 years, as set out in §12.
Your data is stored on servers operated by DigitalOcean, primarily in UK and EU data centres.
Our security measures include:
The iPad app caches lesson content locally using Apple's standard on-device storage (SwiftData, Keychain, and UserDefaults). Cached data is removed when you delete the app.
Despite our measures, no online service can be guaranteed completely secure. If a personal data breach occurs that is likely to result in risk to your rights or freedoms, we will notify the Isle of Man Information Commissioner and/or the UK Information Commissioner's Office within 72 hours as required by law, and we will notify affected users without undue delay where the breach is likely to result in a high risk to their rights or freedoms.
Your data is primarily stored in the UK and EU. Some of our processors are based outside the UK/EU (principally in the United States). Where transfers to third countries occur, we rely on one or more of the following safeguards:
We carry out transfer risk assessments where required, and we rely on the data processing agreements in place with each provider. You can request details of the safeguards in place for any specific transfer by emailing [email protected].
We retain personal data only for as long as necessary for the purposes set out in this policy. Our retention schedule is:
| Data category | Retention period |
|---|---|
| Account profile data (name, email, credentials) | While the account is active |
| Lesson progress, scores, attempt history, RocketFuel, avatar, badges | While the account is active |
| AI tutor conversation metadata (message lengths, lesson context; message text is not stored) | While the account is active |
| Moderation flags and safeguarding records | 7 years (legal obligation and vital interests) |
| Payment and subscription records | 7 years from end of tax year (HMRC / IoM tax law) |
| Consent audit logs (grants, withdrawals, IP, timestamp) | 7 years |
| Support correspondence | 3 years from last contact |
| Marketing preferences and unsubscribe records | Indefinitely, or until account deletion |
| Crash and diagnostic data | 90 days |
Inactive accounts: We periodically review inactive accounts. If an account has had no activity for an extended period, we may contact the parent account holder to check whether they wish to keep the account open. We will not delete an account without giving the account holder reasonable notice and an opportunity to log in or respond. Parent email addresses may be retained for account recovery and essential service communications for as long as the account exists.
You may request deletion of your account at any time by contacting us at [email protected] or using the in-app deletion feature.
When a parent account is deleted, all associated child profiles and their data are deleted in the same operation.
Deleted immediately on account closure:
Retained for the periods set out in §12 (Data Retention):
Retained records are minimised and access is restricted. They are permanently deleted at the end of the applicable retention period.
For users who signed in via Apple, we also revoke Apple Sign-In tokens on account deletion. If you have an active Apple subscription, you must cancel it separately via your Apple ID settings.
Under UK GDPR and Isle of Man data protection law, you have the right to:
To exercise any of these rights, contact us at [email protected]. We will respond to requests within one calendar month of receipt. For complex or numerous requests, we may extend this by up to two further months and will tell you within the first month if we need to do so. Most requests are free; we may charge a reasonable fee or refuse to act on a request that is manifestly unfounded or excessive, in line with UK GDPR Article 12(5).
Parents/guardians: A parent or guardian of a child under 16 may exercise any of the rights in §14 on behalf of the child.
Children under 13: Rights are exercised by the parent or guardian who holds the account.
Children aged 13 to 17: The child may exercise their own rights where they have the capacity to understand what is being asked. We will consider each request on its merits and may, where appropriate, consult with the parent or guardian. If there is disagreement between a child and parent about how rights are exercised, we will act consistently with UK GDPR and ICO guidance.
Verification: Before acting on any rights request, we will take reasonable steps to verify the identity of the person making the request and, where relevant, their authority to act on behalf of a child.
The Rocket Learning web application uses only strictly necessary cookies. We do not use tracking cookies, advertising cookies, or third-party analytics cookies. Because all our cookies are strictly necessary, we do not require a cookie consent banner under the Privacy and Electronic Communications Regulations.
The cookies we use are:
| Name | Purpose | Duration |
|---|---|---|
| auth_token | Authentication (access token) | 1 hour |
| refresh_token | Session continuity (token refresh) | 30 days |
| rl_user_id, rl_username, rl_usertype | Keeping you logged in across page loads | 30 days |
| active_learner_id, active_learner_name | Remembering which child profile is selected (parents only) | 30 days |
We use browser local storage to persist session state and UI preferences. No personally identifiable information is stored in local storage beyond what is necessary for the application to function.
The iPad app does not use cookies. Session data is stored securely using iOS Keychain and UserDefaults.
You can clear cookies at any time through your browser settings. Clearing the session cookie will log you out but will not delete your account data.
If you have opted in to marketing communications, we may send you emails about new features, content updates, and promotional offers via Mailchimp. You can unsubscribe at any time using the link in any marketing email, or by updating your preferences in your account settings.
Weekly progress reports are sent to parents who have enabled them. These are a platform feature, not marketing, and are managed separately from marketing preferences.
We may update this privacy policy from time to time. Material changes will be communicated via email or in-platform notification at least 30 days before they take effect, to give you time to review and, if you disagree, exercise your rights. Minor changes (such as typographical corrections) will take effect on posting. The “Last updated” date at the top of this page indicates the most recent revision.
If you are unhappy with how we handle your data, please contact us first at [email protected].
You also have the right to lodge a complaint with a supervisory authority. For Isle of Man residents, this is the Isle of Man Information Commissioner (inforights.im). For UK residents, this is the Information Commissioner's Office (ico.org.uk).
For any questions about this privacy policy or your personal data: