Xtra Classes Privacy Policy
Vibration432 Inc. · Effective September 7, 2026
This notice covers the Xtra Classes website and Android and iOS apps operated by Vibration432 Inc. It describes our education service separately from the other Claudius England services. The website and mobile apps use the same account and learning records.
Homeschool families
An adult parent or legal guardian may create an educator account and a private teaching space. We record the educator type, adult confirmation, each learner’s age group, the guardian’s consent decision, and verification references. Giving consent in an account does not verify parental responsibility by itself; support completes that verification before the child’s login can be created. Guardian evidence is handled through the agreed secure verification process, not entered into ordinary account forms.
Parents manage and withdraw permission in My family. Withdrawal stops the linked learner’s access to that teaching space; request deletion separately through support. Adult learners give their own permission. Existing retention and deletion rights below apply to family records. Educator profiles are removed after permanent account deletion during permission-system cleanup.
Adult lesson preparation through SupaAI sends the educator’s chosen or typed lesson topic, subject, grade and class age range to its service provider, OpenAI. It sends no child names, student answers or document uploads. Educators check drafts before sharing. This feature does not enable under-13 student-work analysis or bypass any child-data retention gate.
Students, children and school authorization
Xtra Classes serves students, including children under 13, teachers and school administrators. Student accounts are created by a teacher or school. Public student self-registration is unavailable.
Before entering a child’s details or enabling access, the teacher or school must provide this notice, obtain the parent/guardian permission required for the child’s use, or establish valid school authorization for educational use. The school keeps the supporting record. Xtra Classes records the school, staff member, authorization basis, record reference and date. We do not ask children to upload consent documents or identification.
Teachers or school staff record a verified age group (under 13, 13–17, or 18 and over), without collecting a birth date through this setting. Unconfirmed students receive the same lesson restrictions as students under 13. Teachers set the intended age range when creating a subject and change it only in Manage Subjects. Every classroom, lesson and quiz inherits that range. Teachers must keep all material suitable for the subject’s audience; lessons about war or armed conflict belong in subjects for ages 13 and up. These access settings apply to the website and app. Xtra Classes retains a record of who changed a student age group or subject age range and when. Contact your teacher or school to correct an age group.
School authorization must be limited to the educational use the school can authorize. It does not authorize unrelated commercial use of children’s information. Parents or guardians can contact their school or support@claudiusengland.com to ask about their child’s account, review or correct information, withdraw permission, or request deletion. Withdrawal can prevent further access. An account without recorded authorization cannot access learning features.
Email requests for parent permission
For students under 18, teachers can request parent or guardian permission before creating the student login. A request initially stores the parent’s contact email, verified age group, school/teacher/class identifiers, a non-identifying school reference and email-delivery status. We email a direct notice and an expiring private link. No child account is created by sending the request.
A parent who agrees supplies their own name and the child’s name, confirms parental responsibility, and gives permission for the described educational use. We record the response, notice version and time, notify the teacher, and send the parent a confirmation with a private management link. The school must then verify the guardian using an appropriate completed method and retain the evidence securely at school. Xtra Classes stores the method, staff member and school record reference. An email click alone does not enable the account.
Request links expire after seven days and can be resent by authorized staff. Unused permission must be completed within 30 days of the parent response. Uncompleted requests and contact details are deleted after 30 days without further activity during the next permission-system cleanup. The cleanup runs when the permission system is used. Completed records are linked to the student account and removed when that account is permanently deleted. Email services and recipients may retain their own copies of messages.
The confirmation link lets the parent withdraw this permission. The school’s authorization is then withdrawn for the website and app. Withdrawal does not automatically delete learning records or withdraw an independent authorization at another school. Contact your school or support to request review, correction or deletion. Parents can decline a request without giving a child’s name.
Mobile store age settings
The mobile app checks Apple’s Declared Age Range service on supported iOS versions and Google Play Age Signals on Android. The store or device can provide an age range, a sharing or verification status, and relevant parental-control or approval settings. We use these signals only to apply age-appropriate access, respect parental settings and meet applicable requirements, never for advertising or analytics. We do not receive a birth date or an identity document through this check.
The app applies the stricter of the store age range and the school’s recorded age group. Optional non-sharing receives the same student content limits as an unconfirmed age. Required verification, pending or declined parental approval, and device communication limits can prevent classroom access. A school’s adult-only authorization does not authorize a store-reported child. Older iOS versions without the store service continue to use the school’s age and authorization records.
We store the resulting age band and control status with the signed-in mobile session, including a check time. If Google supplies an installation identifier for parental-approval revocation, we retain only its cryptographic hash for that purpose. These records are removed on app sign-out; inactive records older than 30 days are cleared during subsequent checks. Store settings must be corrected with Apple, Google or the supervising parent. Help and account-deletion instructions remain available when classroom access is blocked.
Information the service handles
- Account information: name, username, email, password hash, role, profile image if provided, school membership and classroom assignments.
- Learning records: assigned lessons, quiz and assignment responses, scores, feedback, progress, report cards, classroom comments and notifications.
- Content you or your school provide: documents, images, lesson media, submitted work and classroom communications.
- Live classes: your display name and audio/video when you choose to enable your microphone or camera. Other participants in the class can receive shared media.
- Authorization and privacy requests: the school’s authorization reference and staff confirmation, changes or withdrawals, and requests for account or data deletion.
- Technical information: IP address, browser/device information, session identifiers, request timing, security and server logs needed to operate and protect the service.
Camera and microphone access is requested when needed for a feature. You can deny or withdraw these permissions in your device settings. Denying them prevents the relevant camera or audio feature from working.
Optional camera effects
Auto framing can keep people centred during a live class. Where the camera does not provide this feature, the app detects face positions and crops the video on your device. It does not identify people, save face positions or send frames to an AI analysis service. The resulting camera video is shared with participants through the live class as usual. You can turn framing off in Camera Effects. Software framing downloads its processing library and model from jsDelivr and Google; those download services receive ordinary connection information, not your camera frames. Background blur can be used with framing.
Optional app icon notifications
If you allow notifications, the app can show the number of unread class updates on its icon. Android uses Google Firebase Cloud Messaging and iOS uses Apple Push Notification service. These providers process a device delivery identifier and a generic unread count. Delivery also uses technical routing information, an opaque account binding and update timing. Push messages do not contain student names, lesson content, grades or teacher message text. We do not enable Firebase Analytics or use push identifiers for advertising.
We link the delivery identifier to the signed-in account to keep its unread count synchronized. Reading notifications updates the count; signing out clears the local badge and stops delivery for that session. Delivery depends on device settings and connectivity. You can turn notifications off in device settings and still use the in-app inbox. Delivery registrations are removed after 30 days without registration activity, or within seven days after being marked revoked. Google and Apple may retain their own operational records under their privacy policies.
How information is used and shared
We use information to authenticate accounts, deliver assigned learning material, conduct and review assessments, provide class communication, support teachers and school administration, respond to requests, and protect the service.
Teachers and authorized school staff can access the student records their roles and assignments permit. Class participants can see content shared with their class. Hosting, communications and other service providers process information needed to run the features they support. We do not sell student personal information or use it for targeted advertising.
SupaAI assistance and linked services
SupaAI is the name of Xtra Classes’ AI features. OpenAI provides the underlying AI processing. Chalkboard image generation sends the lesson text and image idea that the teacher reviews to that provider. Do not include student answers, children’s personal information or sensitive family information. Generated images are stored with classroom media and shared when the teacher saves and shares the lesson.
Subjects must state their intended age group. AI tools are available for subjects marked 13 and older or 18 and older; they remain paused for subjects that include under-13 students or have no confirmed audience.
For an eligible student aged 13 or older, a teacher may send written answers, the question, rubric and necessary lesson context to OpenAI for private marking suggestions. A current school or parent/student authorization must cover this use. Under-13 and unconfirmed-age students are excluded. Ages 13–17 also require verified provider child-data retention controls because the applicable digital-consent age varies by country. Existing permissions recorded while AI grading was paused are not silently reused for this processing. Students can submit work and teachers can grade manually when AI is unavailable.
Teachers review AI suggestions and approve final marks and feedback before students see them. Xtra Classes requests that API responses are not stored as application response objects; this setting alone is not a claim of Zero Data Retention. Provider retention approval is checked separately before eligible minor data is processed. The school keeps final learning records under the retention policy below.
Where enabled for staff, AI assistance can process lesson material to help draft teaching content using OpenAI’s API. Teachers must review AI output and must not include student answers, children’s personal information or sensitive family information in these prompts or uploads. Ask your school which AI-assisted teaching features it uses and how it obtains the necessary authorization.
Live classes may use LiveKit or links to Zoom, according to the teacher’s setup. YouTube players, thumbnails and YouTube links are disabled for student accounts recorded as under 13, and for students whose age group is unconfirmed. The restriction also applies when any active school records the student in either group. Teachers can provide another suitable resource. Older students and staff can access YouTube or other linked media. Opening or playing third-party content can transmit technical information and any content you choose to share to that provider. Those services have their own privacy practices. Teachers are responsible for selecting content and services appropriate for their students.
For older students and staff, when an embedded YouTube player loads or plays, Google can receive an IP address, approximate location derived from it, browser or device identifiers, playback activity, advertising impressions and technical diagnostics. Embedded players use YouTube’s privacy-enhanced mode. Videos may show non-personalized ads, and the provider may use cookies or similar storage for playback, security, measurement and advertising functions. See the Google Privacy Policy and YouTube Terms of Service for the provider’s practices and terms. Links that open another service are subject to that service’s policies.
Local storage, security and retention
The mobile app stores its sign-in credential in platform secure storage. Embedded classroom pages use session cookies and browser storage. Local chalkboard drafts stay on the device until removed or cleared; lessons saved or shared to the server are stored with the classroom records. Downloaded or exported files can remain wherever you save them.
Connections to the Xtra Classes mobile service use HTTPS. Access is limited by account role and classroom assignments. No service can guarantee absolute security.
Accounts and learning records are retained while needed to provide and administer the school’s service, and until removed through school management or a verified deletion request. Some records may need to be retained for legal obligations, school recordkeeping, security or resolving disputes. We review those reasons when handling a request; disabling an account alone does not delete its learning records.
Access, correction and deletion
You or an authorized parent/guardian can request access, correction, withdrawal of permission or deletion through your school or our support address. Signed-in users can initiate an account-deletion request from Account & privacy in the app. People who cannot sign in can use the instructions on our help and account-deletion page.
We may need to verify the requester’s identity or authority and coordinate with the school before fulfilling a request. A submitted request is not a confirmation that deletion is finished. The school or support team will explain any information that must be retained and confirm the outcome.
Contact and updates
Contact Vibration432 Inc. at support@claudiusengland.com for Xtra Classes privacy questions. We update this notice when our practices change and show its effective date above.