Sorbit Ltd Privacy Notice
Last Updated: 21 April 2026
This privacy notice for Sorbit Ltd ("we," "us," or "our") describes how and why we collect, store, use, and share your information when you use our services ("Services"), including when you:
- Visit our website at www.sorbit.co.uk.
- Use our AI-powered learning platform (the "Sorbit App") as a Student, Parent, Teacher, School, Course Creator, Expert, Corporate customer, or Guest purchaser.
- Engage with us in other related ways, including sales, marketing, or events.
Questions or concerns? If you do not agree with our policies and practices, please do not use our Services. Contact us at enquiries@sorbit.co.uk.
Summary of Key Points
- What personal information do we process? It depends on how you interact with us. For Schools we act as a Data Processor; for all other contexts (Parents, Creators, Experts, Corporate customers and Guest purchasers) we are the Data Controller.
- Behavioural telemetry. To prevent cheating and impersonation we collect short-lived behavioural signals during learning sessions (paste events, tab switches, typing cadence and speed anomalies) and derive a per-user integrity score. A human reviews every score before any enforcement action.
- Skill ratings and learning memory. We keep a persistent skill rating per subject and a short AI-generated memory note per course to personalise tutoring.
- Public profiles are private by default. Your profile page and certificates are not indexed by search engines, and your profile is not viewable at all until you opt in from Settings.
- Payouts and tax. Creators and Experts receive earnings through Stripe Connect. Stripe holds the identity and bank data; we see status and amounts only.
- Sharing. We share data only with a short list of sub-processors listed in §5.
- Your rights. As a UK resident you have rights under UK GDPR; how you exercise them depends on your role (§11).
- Children. Sorbit is not directed at children under 13 outside a School Context. Accounts discovered to belong to a child under 13 without verified parental involvement will be closed (§15).
1. Our Legal Role: Processor and Controller
We act in different legal roles depending on how you use the Service.
- School Context (B2B): The School is the Data Controller for student and teacher data. Sorbit is the Data Processor, acting only on the School's instructions under a Data Processing Agreement (DPA).
- Parent / Consumer Context (B2C): Sorbit is the Data Controller for the Parent's account and billing data, and for any child personal data the Parent has given explicit consent for us to process.
- Creator Context: Sorbit is the Data Controller. Where a Creator uploads or imports content containing third-party personal data (for example, names in worked examples), the Creator is responsible for their own lawful basis for including it.
- Expert Context: Sorbit is the Data Controller for Expert account, calibration and payout data.
- Corporate Context: Sorbit is the Data Processor on the Corporate customer's instructions for their end-user data, and the Data Controller for the Corporate administrator's own account data.
- Guest Purchaser Context: Sorbit is the Data Controller for the guest's email and purchase record.
2. What Information Do We Collect?
Provided by Schools
- Student Data: names, email addresses, dates of birth.
- Teacher Data: names, email addresses.
Provided by Parents (Consumer Context)
- Parent Data: name, email, password, and billing information (processed by Stripe; we do not store full card numbers).
- Child Data: the child's name, date of birth, and email address (optional).
Provided by Creators
- Name, email, password, course content (including any media you upload), and Stripe Connect onboarding data (held by Stripe — we see status only).
Provided by Experts
- Name, email, password, profile biography (optional), and Stripe Connect onboarding data (held by Stripe — we see status only).
Provided by Corporate customers
- Administrator contact details, billing contact, and the end-user records the customer chooses to provision.
Provided by Guest Purchasers
- Email address at checkout and the course purchased.
Collected from all Users during use of the Service
- User content: chat conversations with our AI, submitted answers, and user-generated templates or course content.
- Authentication data: password or social-login provider identifiers.
- Integrity and behavioural signals: paste events, tab-switch events, typing cadence and speed anomalies recorded during learning sessions, plus derived suspicion scores and a rolling integrity profile. See §16.
- Skill ratings and learning memory: a persistent numerical rating per subject skill and an AI-generated short memory note per course, used to personalise tutoring.
- Usage metadata: session timestamps, token counts per message, and aggregate product-analytics events.
Social Login Data: If you sign in with Google or Microsoft, we receive your name, email, and profile picture.
3. How Do We Process Your Information?
- To create and authenticate accounts.
- To deliver the tutoring Service, including AI feedback, skill ratings and personalised memory.
- To generate integrity signals and route flagged sessions to human reviewers.
- To match learner work with Expert reviewers (with the learner's identity removed — see §17).
- To bill subscriptions and transact course purchases.
- To pay out Creator and Expert earnings via Stripe Connect.
- To respond to support inquiries.
- To send administrative information (changes to these policies, security notices).
- To send marketing to opted-in Parents and Schools; you may opt out at any time.
- To evaluate, debug and improve the Service.
- To record and verify your acceptance of the Terms of Service.
4. What Legal Bases Do We Rely On?
- As a Data Processor (Schools, Corporate end-user data): we process on the Controller's instructions.
- As a Data Controller:
- Parent account data, Creator/Expert account data, Guest purchases: Performance of a Contract.
- Child data in the Consumer Context: the Parent's explicit Consent.
- Integrity and behavioural telemetry: Legitimate Interest — preventing cheating and impersonation is necessary to the pedagogical and commercial integrity of the Service, and enforcement is human-reviewed rather than automated (§16). You may object; see §11.
- Public profile publication: explicit Consent (opt-in from Settings).
- Creator/Expert payouts: Performance of a Contract.
- Record of Terms acceptance: Legal Obligation and Performance of a Contract.
- Marketing to Parents and Schools: Legitimate Interest with an opt-out; or Consent where required.
5. When and With Whom Do We Share Your Personal Information?
We share data with the sub-processors below. Each is bound by a contract that limits their use to providing the service we instruct.
| Third Party | Purpose | Location |
|---|---|---|
| Google Cloud / Firebase | Cloud hosting and user authentication | United Kingdom & United States |
| Anthropic (Claude models) | AI tutoring models | United States |
| Groq | AI model hosting (open-source models) | United States |
| Voyage AI | Text embeddings for adaptive assessment | United States |
| Stripe (including Stripe Connect) | Payments, subscriptions and Creator / Expert payouts | United States |
| SendGrid | Transactional email | United States |
| Ionos | Domain registration and email forwarding | UK / EEA |
| Google / Microsoft | Social-login account identification | United States |
| Google Analytics | Anonymised web and mobile analytics | United States |
| Linkup | Search-tool calls from AI | France |
In addition, the Sorbit platform may route your conversation excerpts to other Sorbit users acting as Experts for quality review. Before an Expert sees any content, we remove identifiers (name, school, user ID). See §17.
6. Do We Use Cookies?
We use strictly necessary cookies to operate the Service — principally to keep you signed in. See our Cookie Policy for detail.
7. How Do We Handle Your Social Logins?
If you sign in with a third-party provider (Google or Microsoft), we receive your name, email and profile picture from that provider. We use this information only for the purposes described in this notice.
8. How Long Do We Keep Your Information?
- School accounts: when the School's subscription ends, we delete all associated personal data from live systems within 30 days and from backups within 90 days, subject to any student/parent request to retain data for personal use.
- Parent and Consumer accounts: we keep your data for as long as your subscription is active. On cancellation, the 30 / 90-day cycle applies.
- Creator and Expert accounts: account data follows the 30 / 90-day cycle after closure, but financial records (invoices, payout statements, tax references) are retained for 7 years to meet UK tax and accounting requirements.
- Corporate customers: retention is governed by the individual contract with the Corporate customer. In the absence of specific contract terms, we apply the same 30 / 90-day cycle.
- Guest purchasers: purchase records are retained for 7 years for the same tax reason. Other guest data (e.g. abandoned-checkout email, if never converted) is deleted within 90 days.
- Anonymised data may be retained indefinitely for AI training and Service improvement.
9. How Do We Keep Your Information Safe?
We use strong organisational and technical measures, including encryption in transit, access controls, and a least-privilege deployment model on Google Cloud. No system is perfectly secure; see §13 for how we respond if a breach does occur.
10. How Do We Handle International Transfers?
Several sub-processors are outside the UK (primarily the United States). Transfers are governed by the UK Addendum to the EU Standard Contractual Clauses (SCCs), a legally binding contract requiring the recipient to protect the data to UK standards.
11. What Are Your Privacy Rights?
Under UK GDPR you have the right to request access, correction, deletion, restriction, and portability of your data, and to object to certain processing (including integrity telemetry under §16).
- Students or Teachers in a School Context: contact your School first, as the School is the Data Controller. We will assist.
- Parents, Consumer users, Creators, Experts, and Guests: contact us directly at enquiries@sorbit.co.uk.
If you are not satisfied with our response, you have the right to complain to the UK Information Commissioner's Office (ICO).
12. Controls for Do-Not-Track Features
No uniform DNT standard exists, so we do not currently respond to DNT signals.
13. How Do We Respond to Security Incidents?
- For Schools and Corporate customers: we will notify the affected Controller(s) without undue delay, and in any case within 72 hours of becoming aware of the breach.
- For users in a Controller relationship with us (Parents, Consumers, Creators, Experts, Guests): we will notify you directly if the breach is likely to result in a high risk to your rights and freedoms, and will notify the ICO where legally required.
14. How Do We Define and Use Student Data?
We use student data only for educational purposes. Student data will not be sold and will not be used to build a personal profile for non-educational purposes. We do build educational profiles (skill ratings, learning memory, integrity signals) to deliver and protect the Service; these are described elsewhere in this notice and stay within the platform.
- For School Users: we act as Data Processor and process data on the School's instructions.
- For Parent / Consumer Users: we act as Data Controller; Parents provide explicit consent for children (including those under 13) to use the Service.
15. Children Under 13
Sorbit is not directed at children under the age of 13 outside a School Context. We do not knowingly permit children under 13 to register without parental or guardian involvement in the Consumer Context. If we become aware that a child under 13 has registered without appropriate consent, we will close the account and delete the associated data. Parents or guardians who believe their child has used the Service without their consent should contact enquiries@sorbit.co.uk and we will act promptly.
In a School Context, the School warrants that it has obtained appropriate consent from parents or guardians for student use, consistent with its own safeguarding and data-protection obligations.
16. Automated Decisions and Integrity Scoring
To prevent cheating and impersonation we record short-lived behavioural signals from your learning sessions: when content is pasted into the chat, when the browser tab loses focus during a session, typing cadence, and anomalous response speeds. Those signals are aggregated into a per-session suspicion score and a rolling integrity profile on your account.
A high score does not automatically suspend your account, invalidate a session, or notify a School. All enforcement actions require human review by a Sorbit administrator. You have the right to object to this processing under UK GDPR; if you do, we will either stop processing your telemetry or demonstrate a compelling legitimate interest that overrides your objection.
Behavioural telemetry is kept for up to 12 months (integrity profiles for as long as your account is active). Under UK GDPR you may request access to, or deletion of, this data at any time.
17. Expert Review of Learner Work
Sorbit uses a panel of trained Expert users to evaluate samples of learner work and help calibrate scoring. Before an Expert sees any conversation, we remove your identifying information — name, school, user ID, email — so the Expert sees the content of the exchange without knowing who wrote it. Experts are bound by confidentiality terms in their Expert Services Agreement.
If you do not want your work to be sampled for Expert review, contact us at enquiries@sorbit.co.uk.
18. Public Profiles, Certificates and Shareable Content
Profiles are private by default. Every account is assigned a profile link, but the page only renders content if you have turned on "Public Profile" in Settings → Privacy & Analytics. A private profile returns "not found" to anyone who visits it. All profile pages are sent to search engines with a noindex directive so they will not appear in search results; discovery is link-only.
Certificates (e.g. /certificate/<code>) and completion pages (/completion/<share-token>) are always accessible by direct link, because the point of a certificate is that you can share it with an employer or on social media. They show your name, the course title, date and grade. They are not indexed by search engines.
19. Do We Make Updates to This Notice?
Yes. The "Last Updated" date at the top of this notice will reflect the most recent revision. If we make material changes, we will notify you by posting a notice in the app or by email.
20. How Can You Contact Us?
Email enquiries@sorbit.co.uk.