Trust

Data & safeguarding

Last updated 7 August 2026

This note is written for the person in a school who has to sign Lantern off — a head of department, a DSL, a data protection lead — and for parents who want to know what happens to their child's work. It describes how the product is built. It is a plain-English summary, not a contract; the formal data processing agreement is issued with a pilot.

The one-line version. A school's student work stays attached to that school's account and is not pooled across schools or used to train models. A child's home tutoring stays with the family unless a parent explicitly connects it — and disconnecting deletes the school's copy rather than just stopping the updates.

What Lantern holds

In Lantern · Teach (the school product)

  • Teacher accounts — name, school email, the classes and stages they teach.
  • Class rosters — the learner names and school-issued student IDs a teacher enters.
  • Generated material — the lesson plans, worksheets and answer keys a teacher creates.
  • Scanned scripts and marks — the pages a teacher uploads for marking, the transcribed answers, and the marks (proposed and published).

In the Lantern tutor (the family product)

  • The child's profile — first name, board and grade.
  • Learning activity — questions asked, pages read, quizzes taken, and the mastery estimate derived from them.

Who can see what

  • A teacher sees their own classes only. Nothing is shared between schools.
  • Student work is not used to train models, ours or anyone else's.
  • Parents see their own child's progress. They do not see other children.
  • Lantern staff do not browse school content routinely. Access for support or debugging is on request and time-limited.

The line between home and school

Lantern Link is the only route by which tutoring data reaches a school, and it is deliberately narrow.

  • The parent starts it. A teacher shares a class join code; the parent enters that code plus their child's school student ID. A teacher cannot pull a child's home data, and a class code on its own identifies nothing about a child.
  • Only a summary crosses. Objective bands, how confident the estimate is, how recent the evidence is, and misunderstandings that have recurred at least twice.
  • These never cross: chat transcripts, practice counts, streaks, per-question detail, or anything from before the connection was made.
  • Revocation deletes. When a parent disconnects, the school-side cached copy is removed — not merely frozen.
  • It is shown separately. Home practice appears as its own card on a learner report and is never merged into marked attainment, because a tutor's reading of home work is different evidence from work a teacher marked.

How the tutor is kept safe for a child

  • Closed content. Answers are retrieved from the child's own grade-level coursebook material. There is no open-web browsing and no content feed.
  • Homework guard. Worksheets and answer keys are held so the tutor can recognise homework and switch to hints rather than supply answers.
  • Age bounding. Questions well beyond the child's year get a kind deferral rather than an out-of-level answer.
  • Constrained visuals. Generated diagrams come from a fixed set of templates with validated data, falling back to plain text rather than risking a bad image.
  • No child-to-child contact. There is no messaging, no social layer, no user-generated content between children.

Retention and deletion

  • Generated plans and papers persist in a teacher's library until they delete them.
  • Scanned scripts and marks persist for the school's record until the school asks for removal.
  • A school may request export or deletion of its data at any time.
  • A parent may request deletion of their child's tutoring history at any time.

TODO before publishing: state your concrete retention periods (e.g. "scripts deleted 24 months after the academic year ends"), the hosting region, your named sub-processors (model and infrastructure providers), your legal entity and registered address, and your DPO / data contact. Those are commitments only you can make — I have deliberately not invented them.

Sub-processors

Lantern uses third-party model and infrastructure providers to generate content and host the service. Content sent to model providers is covered by their zero-retention or no-training-on-customer-data terms where offered.

TODO: list each provider by name and role, and link their DPAs. Schools will ask for this by name in procurement.

Reporting a concern

If you believe a child's data has been exposed, or you see output from Lantern that worries you, tell us and we will investigate. Email hello@lantern.school.

Not affiliated with Cambridge. Cambridge Primary is a curriculum of Cambridge Assessment International Education. Lantern generates material aligned to that published framework; it is not endorsed by, affiliated with, or a product of Cambridge.

← Back to Lantern · Teach  ·  The Lantern tutor →