Collect less
BridgeBack needs to know which earlier ideas support the lesson. It does not need medical details, family circumstances, or the reason for absence.
BridgeBack minimises data, separates responsibilities, and keeps educational decisions with the teacher.
The guiding principle
Use what the lesson needs. Leave everything else out.
A learning route should not require a detailed account of a child's life or reason for absence.
Pupils may have limited choice over technology selected by a school. Privacy, agency, transparency, and human support must therefore be product requirements.
BridgeBack needs to know which earlier ideas support the lesson. It does not need medical details, family circumstances, or the reason for absence.
Generated structures begin as drafts. A teacher approves the graph before it can shape a diagnostic.
The system does not infer emotion, motivation, disability, behaviour, or safeguarding risk from responses.
Lesson analysis uses curriculum material without pupil names, attendance histories, Clerk details, or absence reasons.
The AI gets only the information it needs for that job. It does not receive pupil identity, decide marks, or choose the learning route.
Needed
Upcoming lesson, objectives, source text or supported lesson files
Excluded
Pupil name, absence record, reason for absence, diagnostic history
Result
Draft concept graph with source references
Needed
Teacher-approved concept graph and references
Excluded
Pupil identity, selected answers, attendance information
Result
Closed questions, options, and correct indexes
Needed
Approved concept map plus the correct or incorrect results
Excluded
An AI opinion about the pupil
Result
Up to three concepts chosen by BridgeBack code
Needed
Approved concept path, source context, concept key, and correctness
Excluded
Pupil name, selected option, reason for absence
Result
Explanation, example, and closed check
BridgeBack does not collect free-form pupil chat, precise location, contacts, biometrics, photographs, audio, health information, family information, safeguarding records, or absence reasons.
Hiding a page is not enough. BridgeBack checks a person's identity and school access again whenever protected data is read or changed.
Clerk handles sign-in. Convex then checks that the person belongs to the right school before protected work can continue.
Organisation-scoped access prevents a teacher or pupil from opening another school's classes, lessons, or pathways.
Clerk, Convex, and OpenAI keys stay on the server or inside the service settings. They are never sent to the browser.
Lesson files remain in managed private storage. Browser uploads are size and type checked and are never placed in the public directory.
Administrative actions create append-only events without copying tokens, request bodies, or lesson content into the audit record.
Production deployments require HTTPS. Clerk, Convex, OpenAI, and the hosting platform provide managed encryption controls.
Models help transform source material into inspectable drafts. They do not authorise access, grade responses, choose sanctions, or approve their own work.
The concept graph is saved as a draft and cannot drive a pupil diagnostic until a teacher approves it.
Zod Structured Outputs constrain fields. Application checks reject invalid references, cycles, and unsupported shapes.
BridgeBack compares each response with the correct answer saved by the teacher. The AI does not decide whether a pupil is right.
BridgeBack follows the approved concept map and shows no more than three next ideas.
Concepts and micro-lessons retain references so a teacher can compare generated content with lesson material.
BridgeBack cannot decide grades, sets, admissions, exclusions, sanctions, safeguarding referrals, or access to teaching.
BridgeBack reduces persistence, but it does not describe store false as Zero Data Retention.
OpenAI requests use store false, so the response is not kept as saved application history in the Responses API.
Lesson files are sent as request inputs rather than created as persistent OpenAI File objects.
A SHA-256 hash of the authenticated subject is used instead of sending the raw Clerk identifier.
OpenAI's standard safety-monitoring retention may still apply. Some personal data about under-18s requires approved Zero Data Retention controls first.
Responsible use starts with named owners, tested controls, clear information, and approval from the right people.
Complete a child-specific DPIA and establish the lawful basis for every purpose.
Write down who is responsible for each use of data across the school, BridgeBack, and its service providers.
Set clear time limits for keeping data, and build deletion, export, correction, and school offboarding tools.
Configure appropriate OpenAI retention controls for the pupil ages and data involved.
Run security reviews, penetration tests, software checks, and tests that prove one school cannot see another school's data.
Publish age-appropriate privacy information and a clear human help and reporting route.
Evaluate curriculum quality, accessibility, and unequal performance across pupil groups.
Obtain named safeguarding, privacy, security, and education approval.
This page explains our product choices. It is not legal advice, and a school rollout needs expert review.