Privacy

What we hold, who else touches it, and what you can take back.

Every company named below was named because it genuinely processes data for this product — checked against the running system, not against a list of things we might use one day. Where a right is described, the thing that implements it exists and can be pressed. Where one does not exist, this page says so.

This notice has not been reviewed by a lawyer. It is the product’s own description of how it handles data, published because families and schools are entitled to a real answer now rather than a page that says “coming soon”.

Version of 11 August 2026. The date at the top is the version — there is no other numbering.

Four entries in this notice are outstanding

Each one is a fact only the company can state. None is guessed at here and none is filled in with an example — a made-up address or an invented contact in a privacy notice is not a placeholder, it is a wrong answer somebody may send a legal request to.

Who the controller is The legal name and legal form of the company that decides how this data is handled. Outstanding.
Registered address & registration The registered office as it appears on the register, and the registration and VAT numbers. Outstanding.
Where to send a data request The named contact for access, correction, objection and complaint. Until it is published, connect@audeciusofficial.com reaches a person who will answer. Outstanding.
The residency region, as published The region the database runs in, stated as a commitment to customers rather than as an implementation detail. The mechanism as it stands today is described in § 2 without it. Outstanding.

Until these are filled in, nothing here should be read as a statement about who the controller is or where a formal request should be addressed. Everything else on this page describes the software, and that part is checkable.

§ 1

What the product holds

An exchange programme runs on details about children, so this is a long list and shortening it would be dishonest. Organisations put the following into the product:

People. Names, dates of birth, contact details, languages, sign-in identities and devices. Students. The student record, preferences, home school and academic records, courses, health and medical detail, immunisations, insurance, legal status and compliance state. Guardians and households. Named guardians with their contact details, occupation, custody status and statements; host families and the schools attached to them. Placements. Matches, decisions, events, travel permissions and flight segments. Documents. Uploaded files — passports, contracts, medical forms — and their status and expiry. Communication. Conversations, messages, notifications and support requests. Care. Incidents, safety settings and the audit trail.

And billing: the organisation’s billing contact, its subscription state, and generated invitation codes once a person connects an account to them. An unused code is not charged. Card numbers are entered with Stripe and never reach Audecius.

§ 2

Where it lives

The database, the file storage and the sign-in system are all Supabase. Audecius Exchange runs on one Supabase project, so the region is a single value for the whole service and the same for every organisation on it.

Each organisation carries a recorded residency choice — eu or us — set when it was created. Today that value is recorded, not enforced: it does not move data to a second database, because there is no second database. Saying otherwise would be the easiest sentence on this page to write and the least true. The region that actually applies, published as a commitment, is the fourth outstanding entry above.

File storage is split, and the split is checkable. The buckets holding documents, workbooks and chat files are private — no public read path, at any address. The buckets holding avatars and organisation brand assets are public, because a profile picture and a logo are shown in places that have no signed-in reader. Nothing about a child’s file is in a public bucket.

§ 3

Who else processes it

The current core providers identified in the product are listed below. A final legal notice still requires the approved controller details, processing terms and sub-processor schedule named at the top of this page.

Sub-processorWhat it does, and what it sees
Supabase The database, the file storage and the sign-in system. It holds everything in § 1.
Vercel Hosts the console and the family and school surfaces. It sees requests — addresses, headers, IP — not the contents of the database.
Stripe Payments. It sees the organisation’s billing contact, subscription and billable quantity: generated invitation codes once a person connects an account to them. Card details are entered with Stripe directly and never reach Audecius.
Resend Transactional and notification email — sign-in codes, invitations, support and notification digests — sent from verified domains the Audecius platform controls. It sees the recipient’s address and the message.
Anthropic The model behind Ariadne. It sees only what the field guard in § 4 lets through, and only when somebody asks her something.
Apple Push notifications to iPhones, through Apple’s push service. It sees the device token and the title and body of the notification — see § 5.

If an organisation connects its own tools — a mailbox, a calendar, a spreadsheet — that connection is the organisation’s own and sends data to a provider it chose. Those are not our sub-processors and they are not on this list.

§ 4

What reaches the model

Ariadne chat requires an authenticated user and an active membership in the organisation named by the request. The server then applies the organisation’s AI capability and durable usage budget before contacting the model provider.

Actions are a separate boundary: each tool carries an explicit tenant scope, permission and consequence class. Writes require the approval prescribed for that class, and high-consequence operations can be paused or refused.

This page does not claim that every database field is automatically safe to place in a prompt. The approved production configuration must define and test the fields and sources Ariadne may receive before they are enabled for an organisation.

§ 5

Email, push, and what is on the wire

Platform email such as sign-in codes, invitations and notification delivery goes through Resend from verified Audecius-controlled domains. When an authorised user deliberately sends through a connected Gmail or Outlook mailbox, the approval names that sender and the provider keeps the message in that mailbox’s Sent folder.

Push reaches a phone only when the person’s own preference for that category is push, or when the notification is an emergency. What travels to Apple is the device’s push token and the title and body of the notification — the same words that appear on the screen. A device that has been signed out is not sent to.

§ 6

Cookies, storage, and what we do not do

This site sets no analytics cookies, no advertising cookies and no tracking pixels. There is no analytics script on any page of it, which is a thing you can check in your own browser rather than take our word for.

Two things are kept. A short-lived au_role cookie remembers which seat you are in, so an active person is not bounced mid-task; it is a routing hint and grants nothing on its own. And the sign-in session itself is held by the browser, the way any signed-in site holds one.

A sign-in code typed into the landing page before signing in is held in memory for the length of the tab and written to storage nowhere — a code off a printed letter is exactly the kind of thing that should not be lying around afterwards.

§ 7

What you can actually do

Each action below has a real product control or a named, audited server operation behind it.

Get a copy of everything. One press, any time. The document is assembled from the database with your own permissions and written straight to your disk as JSON — not emailed, not queued, not copied to a bucket you cannot see. It is JSON rather than a PDF because portable means a machine has to be able to read it; a person moving to another programme should be able to hand this to whoever takes over. Rows about other people are not in it.

Correct what is wrong. Names, dates of birth and the primary email are locked, because they come off a passport and are the basis of guardian consent, insurance and a visa. So there is a request instead of an edit — it carries the value you are asking for and lands with the organisation you actually belong to.

See who did what. The audit log records the actor, the action, the entity, the time, and where from. It is append-only, enforced in the database: two triggers refuse every update and every delete, and no policy grants anyone insert, update or delete through the API. It is written by one internal function and read by an organisation’s administrators. A log you can edit is a log nobody should have trusted.

Control the fields. Visibility is per field, per role, saved against the organisation, and read back under the token of the person asking.

Consent. A consent is recorded for a subject, by a grantor, for a kind, in a jurisdiction, timestamped, with one live consent per combination, and the grant writes a line into the audit log. The kinds are data processing, media, location fallback, social, Ariadne’s memory, sharing medical detail, and a named partner-organisation share.

The subject or the person who gave a consent can withdraw it in the product. The server locks the consent, records who acted, the time and the stated reason, keeps the original grant as part of the legal history, and notifies the programme for follow-up. If a minor’s data-processing consent is withdrawn, their programme access is paused immediately. An organisation administrator can delegate the follow-up operation to a named staff seat; ordinary staff do not receive it from their role.

§ 8

Children, and who is allowed to answer for them

Most of the people in this product are under eighteen, and the mechanism is worth describing exactly rather than summarising as “we comply”.

Guardianship is a recorded link, not an assumption. A guardian is joined to a student by an explicit row that carries the relationship and how the link was established, and by the guardian’s own entry on the student’s file — including whether they have custody. The question why may this adult read this child’s file always has an answer written down somewhere.

A consent carries the jurisdiction it was given under, because the age at which a young person can answer for themselves is not the same everywhere and is not ours to decide. The record stores which rule applied; it does not assert what that rule is.

Health, medical, legal and safeguarding detail are separate parts of a student’s file, each visible to a different set of people, and the safeguarding lock is not a setting an organisation can switch off for the assistant.

This section describes what the software does. It is not a claim about which legal standard applies to a given organisation, in a given country, for a given child — that depends on facts this page does not know, and the outstanding block at the top is why.

§ 9

Keeping and deleting

Authorised staff can remove a document through a guarded operation. It deletes the database record first and then its private stored bytes; if the second step is interrupted, a cleanup worker can remove the leftover private object. Consent withdrawal is a separate legal-history action and does not silently rewrite that history.

An organisation administrator can schedule closure in the console after taking an uncapped data-table archive and clearing every live programme, safety, support, connected-app and billing blocker. The server checks those facts again after the 30-day cooling-off period. Closure ends seats and removes connected-app credentials; it does not delete people, accounts, programme history, invitations or the audit trail. The exact mechanics and the archive’s scope are set out in § 8 of the terms.

A person can end their own seat at an organisation themselves. That is a real action, and it does not touch the account.

A published retention schedule — how long each category is kept after a programme ends — is not written yet, and this page does not pretend to one.

Ask us the hard question

If a specific clause, contact or region decides whether you can use this, ask before you sign. You will get the real answer, including when the answer is “not yet”.