Last updated: 27 August 2026
This one-page notice explains what SATs Superstars MAX does with pupils' information. It is written for teachers, headteachers, data protection officers and parents. If anything here isn't clear, please email the contact at the bottom.
SATs Superstars MAX is operated by NTA Ltd. For direct family accounts, NTA Ltd is the data controller because we decide how the family account service is run.
For school accounts, the school remains the data controller for its pupil deployment. NTA Ltd acts as the school's data processor for pupil learning data unless a signed school DPA or legal review says otherwise.
NTA Ltd is also an independent controller for limited platform security, billing, legal, and operational records that we must manage ourselves.
| Field | Why |
|---|---|
| Email address and authentication ID | So the account holder can sign in, reset passwords, and manage access. |
| Display name or first name | So the pupil sees a friendly name in the app. We encourage nicknames where possible. |
| School, class, role, year group, and school code where used | So teachers see only their own authorised class and dashboards can be filtered correctly. |
| Practice progress, answers, XP, streaks, weak topics, homework, bookmarks, notes, and generated papers | So pupils, parents, and authorised teachers can track learning and choose what to practise next. |
| AI tutor messages and safeguarding flags where the feature is used | So SATs Superstars MAX can reply, abuse can be prevented, and safeguarding concerns can be reviewed. |
| Practice reminder push subscription where reminders are switched on (the browser push address, its keys, and the device type) | So opt-in practice reminders can be sent to that device. This is only stored if reminders are turned on, and is deleted when they are turned off or the account is closed. |
| Bursary / free-place application details where you apply (your name, email, child's year group, and what you tell us about your circumstances) | So we can review and respond to a request for a free or reduced place. Stored securely in our own database, never shared or sold, and used only to handle your application. |
| Technical and security logs | So we can keep the service secure, fix faults, and prevent abuse. |
| Stripe billing identifiers for paid accounts | So subscriptions, invoices, and the billing portal work. Card details are entered into Stripe; we do not see full card numbers. |
We do not collect home addresses, phone numbers, photos, camera or microphone access, live location, contacts, or third-party advertising identifiers. No advertising cookies, social-media pixels, or marketing trackers are used.
AI tutor (SATs Superstars MAX): When a pupil uses the AI tutor, the relevant question context and the pupil's message may be sent to OpenAI to generate a response. AI chat history may be retained for continuity, abuse prevention, and safeguarding review. Pupils should not type private information into the AI tutor.
Bursary / free-place applications: If you apply for a free or reduced place, NTA Ltd is the controller for that application. We collect the applying adult's name and email, the child's year group, an eligibility category (for example free school meals or a means-tested benefit), and anything you choose to write in the free-text box. Our lawful basis is your consent (given by submitting the form) together with our legitimate interest in offering places to lower-income families; you can withdraw at any time by emailing us. Please do not include health, medical, or other special-category details in the free-text box - it is not needed to assess a place. This data is stored only in our own database, is never sold or shared for marketing, and is used only to review and respond to your request.
We use carefully selected service providers to run the app. This includes Supabase for authentication/database, Cloudflare for hosting and security, OpenAI for AI tutor responses, Stripe for paid subscriptions, and Sentry for production error reporting. Depending on the provider, data may be processed in the UK, EEA, or other jurisdictions covered by that provider's contractual safeguards. We keep a processor register and review it for school/DPO handoff.
Account and learning data is kept while the account is active, plus up to 12 months after last sign-in unless a school contract, safeguarding hold, legal obligation, or billing rule requires a different period. Deletion/export requests are reviewed and actioned within 30 days where possible. Backups and third-party systems follow their processor retention windows.
Bursary / free-place applications are kept only as long as needed to handle your request: unsuccessful applications are deleted within 6 months of the decision, and successful ones are tied to the resulting account. You can ask us to delete a bursary application at any time by emailing the address below.
Under UK GDPR, pupils, parents/guardians, and account holders can ask to access, correct, export, restrict, object to, or delete personal data. Direct family account holders can use the in-app export/delete request tools or email us. For school accounts, the school is normally the controller, so we may need to coordinate with the school before completing the request.
Children have their own UK GDPR rights. Depending on age, understanding, and account context, a child may be able to exercise those rights directly, or a parent/guardian or school may help them.
This site does not set advertising cookies or marketing pixels. It uses necessary browser storage such as localStorage and sessionStorage for sign-in, settings, accessibility preferences, learning continuity, service-worker refresh state, checkout handoff, and security/support diagnostics.
Our current storage inventory treats these items as strictly necessary for the service requested by the user. The consent choice itself may be stored so the site remembers whether optional error reports were allowed or refused. Optional analytics, performance tracing, advertising, social plugins, cross-site tracking, or similar non-essential storage must stay disabled unless it is clearly disclosed, consented where required, tested, and legally reviewed. Clearing browser storage removes local copies, though server-side account data may still exist until export/deletion workflows complete.
In the unlikely event of a personal data breach, we will notify every affected school within 72 hours of discovery, with a description of what happened, what data was affected, and what we are doing about it - as required by UK GDPR Article 33.
If you believe we have handled personal data incorrectly, you have the right to complain. Here is how:
For any question about this notice, a data access/export request, or to request deletion review:
Email: [email protected]
This notice is written in plain English deliberately. It is ready for school, solicitor, and DPO review; it should not be treated as a legal guarantee.