Trust
Data & safeguarding
Last updated 7 August 2026
This note is written for the person in a school who has to sign Lantern off — a head of department, a DSL, a data protection lead — and for parents who want to know what happens to their child's work. It describes how the product is built. It is a plain-English summary, not a contract; the formal data processing agreement is issued with a pilot.
The one-line version. A school's student work stays attached to that school's account and is not pooled across schools or used to train models. A child's home tutoring stays with the family unless a parent explicitly connects it — and disconnecting deletes the school's copy rather than just stopping the updates.
What Lantern holds
In Lantern · Teach (the school product)
- Teacher accounts — name, school email, the classes and stages they teach.
- Class rosters — the learner names and school-issued student IDs a teacher enters.
- Generated material — the lesson plans, worksheets and answer keys a teacher creates.
- Scanned scripts and marks — the pages a teacher uploads for marking, the transcribed answers, and the marks (proposed and published).
In the Lantern tutor (the family product)
- The child's profile — first name, board and grade.
- Learning activity — questions asked, pages read, quizzes taken, and the mastery estimate derived from them.
Who can see what
- A teacher sees their own classes only. Nothing is shared between schools.
- Student work is not used to train models, ours or anyone else's.
- Parents see their own child's progress. They do not see other children.
- Lantern staff do not browse school content routinely. Access for support or debugging is on request and time-limited.
The line between home and school
Lantern Link is the only route by which tutoring data reaches a school, and it is deliberately narrow.
- The parent starts it. A teacher shares a class join code; the parent enters that code plus their child's school student ID. A teacher cannot pull a child's home data, and a class code on its own identifies nothing about a child.
- Only a summary crosses. Objective bands, how confident the estimate is, how recent the evidence is, and misunderstandings that have recurred at least twice.
- These never cross: chat transcripts, practice counts, streaks, per-question detail, or anything from before the connection was made.
- Revocation deletes. When a parent disconnects, the school-side cached copy is removed — not merely frozen.
- It is shown separately. Home practice appears as its own card on a learner report and is never merged into marked attainment, because a tutor's reading of home work is different evidence from work a teacher marked.
How the tutor is kept safe for a child
- Closed content. Answers are retrieved from the child's own grade-level coursebook material. There is no open-web browsing and no content feed.
- Homework guard. Worksheets and answer keys are held so the tutor can recognise homework and switch to hints rather than supply answers.
- Age bounding. Questions well beyond the child's year get a kind deferral rather than an out-of-level answer.
- Constrained visuals. Generated diagrams come from a fixed set of templates with validated data, falling back to plain text rather than risking a bad image.
- No child-to-child contact. There is no messaging, no social layer, no user-generated content between children.
Retention and deletion
- Generated plans and papers persist in a teacher's library until they delete them.
- Scanned scripts and marks persist for the school's record until the school asks for removal.
- A school may request export or deletion of its data at any time.
- A parent may request deletion of their child's tutoring history at any time.
TODO before publishing: state your concrete retention periods (e.g. "scripts deleted 24 months after the academic year ends"), the hosting region, your named sub-processors (model and infrastructure providers), your legal entity and registered address, and your DPO / data contact. Those are commitments only you can make — I have deliberately not invented them.
Sub-processors
Lantern uses third-party model and infrastructure providers to generate content and host the service. Content sent to model providers is covered by their zero-retention or no-training-on-customer-data terms where offered.
TODO: list each provider by name and role, and link their DPAs. Schools will ask for this by name in procurement.
Reporting a concern
If you believe a child's data has been exposed, or you see output from Lantern that worries you, tell us and we will investigate. Email hello@lantern.school.
Not affiliated with Cambridge. Cambridge Primary is a curriculum of Cambridge Assessment International Education. Lantern generates material aligned to that published framework; it is not endorsed by, affiliated with, or a product of Cambridge.