Privacy & GDPR statement
How we look after your data.
Last updated: 29 June 2026
Class Prayer is a prayer-planning tool for Catholic schools in the United Kingdom. We take the privacy of pupils, teachers, and school leaders seriously. This statement explains what personal data we collect, why we collect it, how we keep it safe, and the rights you have under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Who is the data controller?
Two roles apply, depending on the data in question. We separate them so that schools and Class Prayer each carry the right legal responsibility.
- Class Prayer Ltd is the Data Controller for staff account data (teacher and school-leader name, email, role) and school marketing and billing data (school contact details, invoices, support correspondence). For these categories, contact us at info@classprayer.app.
- The School is the Data Controller for all pupil accounts (pupil first names, class codes), pupil free-text (questions answered, prayers written, chat refinements) and safeguarding flags. For these categories Class Prayer acts strictly as the Data Processor on the school's documented instructions, under our school-facing Data Processing Agreement. Data-subject requests about pupils should be directed to the school's Data Protection Officer in the first instance; we will assist the school in responding.
What we collect
- Account data - name, email, role (teacher, school leader, pupil), and the school you belong to.
- School data - school name, address, motto and translation, mission statement, crest, brand colours, school type, form entry, pupils on roll, diocese, Catholic Multi-Academy Trust (CMAT), patron and house saints, feast day, founder(s) and founder's day - supplied by your school leader and used to personalise prayers and PDFs.
- Class & pupil data - class names, year group, pupil first names and login codes. We do not collect pupil surnames, dates of birth, or contact details.
- Prayer content - prayers you create, the questions you answer in the planner, and chat-style refinements.
- Safeguarding flags - where pupil input raises concern, the relevant excerpt and surrounding chat are stored so the school's Designated Safeguarding Lead can review and act.
- Technical data - minimal logs needed to keep the service running and secure (e.g. error logs, authentication events).
Why we collect it (lawful basis)
- Contract - to provide the service to teachers and schools that have signed up.
- Legitimate interests - for account, school, prayer and AI-generation processing, where we have completed a written Legitimate Interests Assessment covering purpose, necessity and the balance with your rights and freedoms.
- Legal obligation - for safeguarding flags. Where the system detects a potential safeguarding concern in pupil input, we record it and notify the school's Designated Safeguarding Lead. This processing rests on Article 6(1)(c) UK GDPR and Schedule 1 part 2 paragraph 18 of the Data Protection Act 2018, read with Keeping Children Safe in Education and section 11 of the Children Act 2004.
- Consent - for any optional communications. You can withdraw consent at any time.
Children's data
Pupils sign in with a first name and a class login code provided by their teacher. We deliberately collect the minimum needed to operate a class. Pupil chat content is stored only so it can be displayed back to the pupil and reviewed where a safeguarding concern is raised. We never use pupil data for advertising or to train third-party AI models.
How we use AI
Prayer drafts are generated by AI models hosted by trusted providers. Inputs are sent over encrypted connections, are not used to train the underlying models, and are not retained by the model provider beyond the time needed to return a response. A safeguarding classifier reviews pupil input on-the-fly and creates a flag for the school if it detects a potential concern.
Pastoral context in the Mass planner
School leaders may opt-in to a feature that summarises, in an aggregated and de-identified way, the themes a class or year group has been praying about recently. The summary is shown only to the celebrant in the Mass plan and is intended as a prompt for the celebrant's own prayer.
- Off by default. A school leader must enable it explicitly.
- Themes are only surfaced when at least three prayers share a topic, so individual pupils are not identifiable.
- Prayers from any pupil with an open safeguarding flag are never included.
- The summary never contains pupil names, quotes, or per-pupil counts.
- It is shown only to the celebrant - never to pupils, never on the assembly handout.
- The summary is computed on demand and is not stored. Only an audit log of who requested it, for which cohort, and when is retained for 90 days.
- Lawful basis: legitimate interests in the pastoral care of pupils through the school chaplaincy. School leaders can disable the feature at any time in Pastoral context settings.
RE Directory (RED) units in the Mass planner
When “RED-aware homily notes” is enabled, the celebrant brief mentions which units from the Religious Education Directory for Catholic Schools (England & Wales, 2023) the cohort is currently studying - e.g. Year 4 - To the Ends of the Earth. This is reference material about the curriculum, not personal data about any pupil.
- No pupil names, no per-pupil data - only the unit the year group is on.
- On by default; can be turned off in Pastoral context settings.
- School leaders can override the default RED sequence for their school.
- Lawful basis: legitimate interests in the catechetical formation of pupils through the school chaplaincy. The benefit is helping the celebrant echo familiar themes; the impact on data subjects is nil (no personal data is processed).
Children’s Masses (DMC adaptations)
When a Mass is planned for a class of children younger than pre-adolescence, the planner applies the adaptations of the Directory for Masses with Children(1973) - preferring sung acclamations, simpler Eucharistic Prayers, and explicit silence cues. These are presentation choices in the planning document only and do not collect or store any additional personal data.
Dialogue-homily helper (staff only)
For Masses with children, staff may ask Class Prayer to suggest three to five short questions the celebrant could use during a dialogue-style homily. The helper is staff-only (teachers, chaplains, school leaders); pupils cannot reach it. It pins every question to the day’s Gospel and the cohort’s Religious Education units - never personal pupil data. The suggested questions are not stored; we only log a single audit row recording who asked, for which year group, and how many questions were returned. Class Prayer never writes the homily; the celebrant accepts, edits, or discards the suggestions in line with Magnifica Humanitas §§128, 137, 147.
Lesson-prayer theme suggester
When a pupil or teacher chooses “Lesson prayer”, Class Prayer can suggest three Scripture themes tailored to the lesson. We send the subject, topic, the pupil’s own short answer to “why is it important to pray about this?”, the year group, and the titles of any currently active Religious Education units for that year group. We do not send pupil names, chat history, prayer history, or any other personal data, and the model provider is contractually prohibited from training on this input. We log a single audit row recording who asked and for which year group; the suggestions themselves are not stored centrally.
Where data is stored
Personal data is stored in our managed backend (Lovable Cloud, powered by Supabase) in data centres located in the Republic of Ireland (AWS eu-west-1). The Republic of Ireland is recognised by the UK Government as providing an adequate level of data protection, so no additional safeguards are required for routine UK-to-EU storage. The only routine transfer outside the United Kingdom and EEA is to Crossway in the United States for Scripture text lookups (the ESV API), where the request body is a Scripture reference such as John 3:16 and contains no personal data; that transfer relies on the UK International Data Transfer Addendum.
Accounts are scoped to one school
Each Class Prayer staff account belongs to a single school. When a teacher tries to join a school using a school code or invite link, we check that the teacher's email domain matches the School Leader's school-email domain (for example @stmarys.sch.uk) - if it doesn't, the join is refused. This keeps each school's prayers, classes, pastoral context and safeguarding flags cleanly separated, and is part of how we meet our data-minimisation obligation under UK GDPR. If you work across multiple schools, please create a separate account for each using that school's email address. Schools whose leader signed up with a personal email (Gmail, Outlook, etc.) cannot use auto-matching; every join in those schools is approved manually by the School Leader.
How long we keep it
- Account & school data: for as long as the account is active. Soft-deleted accounts are permanently purged by a nightly database job 30 days after deletion.
- Prayers: until you or your school deletes them.
- Safeguarding flags: for the period required by your school's safeguarding policy, capped at 7 years from creation. Flags past that date are automatically purged by the nightly database job.
- Pastoral-context audit log: 90 days.
- Email send log: 12 months.
- Account deletion: when you delete your own account it is marked as deleted and you are signed out immediately. Pupils' deleted accounts are visible to their class teacher; staff deleted accounts are visible to their school leader. A class teacher or school leader can either restore your account or permanently delete it. Once permanently deleted, personal data is removed within 30 days, except where law requires us to retain it.
The full retention schedule and the database job that enforces it are at /legal/retention.
Your rights
Under the UK GDPR you have the right to:
- Access the personal data we hold about you.
- Ask us to correct data that is inaccurate or incomplete.
- Ask us to delete your data ("right to be forgotten").
- Restrict or object to certain processing.
- Receive a copy of your data in a portable format.
- Withdraw consent at any time, where consent is the lawful basis.
- Lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
You can exercise the rights of access, portability, and erasure directly from your Profile page:
- Download my data returns a single JSON file containing every record we hold against your account.
- Delete my account immediately signs you out, blocks future sign-ins, and queues your data for permanent deletion within 30 days (automated nightly purge).
For any other request - correction, restriction, objection, or to raise a concern - email info@classprayer.app. We respond within one calendar month. Our full Subject Access Request procedure sets out exactly what to expect.
How we keep data safe
All traffic is encrypted in transit (TLS) and data at rest is encrypted by our backend provider. Access is protected by row-level security so users can only see data they are entitled to. Staff access to production systems is logged and limited to those who need it. We review our security posture regularly.
Cookies
We use a small number of strictly necessary cookies (and equivalent local storage) to keep you signed in and to remember your preferences. We do not use advertising or cross-site tracking cookies. The full list is at classprayer.app/cookies.
Data Processing Agreement & sub-processors
Every school using Class Prayer signs a Data Processing Agreement covering UK GDPR Article 28. The current sub-processor list is at classprayer.app/subprocessors and our security posture is at classprayer.app/security. School DPOs can find the DPA, DPIA, retention schedule, breach procedure, SAR procedure, Legitimate Interests Assessments and Children's Code self-assessment in the Compliance library, or download them all as one PDF via the DPO Bundle.
Changes to this statement
We will update this page when our practices change. Material changes will be communicated to school leaders by email.