Mount Carmel School
Class LogMount Carmel School

Privacy Policy

Last updated: 5 August 2026

Class Log is a staff application operated for Mount Carmel School. It records lesson coverage, plans, remarks, timetables, duties, absences and substitutions, and can optionally synchronise a teacher’s selected schedule with Google Calendar. This policy explains how Class Log accesses, uses, stores and shares information, including information received from Google APIs.

Who may use Class Log

Google sign-in does not by itself grant access. A school administrator must first approve a staff email and assign its branch, department and role. Unapproved accounts cannot access school application data.

Information Class Log accesses

Google identity information

  • Name, email address, profile image and Google account identifier are used to verify sign-in, match the account to an approved staff record, display the signed-in user and protect role-based access.
  • The Google ID token is sent to the Class Log server for verification with Google. Class Log then creates its own session; the Google ID token is not used as the application database.

Google Calendar information — optional

  • Calendar access is requested separately only after a signed-in teacher selects Sync to Calendar or Remove from Calendar.
  • Class Log requests the calendar.events permission to create, update and delete Class Log schedule, duty and substitution events in the user’s primary calendar.
  • For removal, Class Log lists events carrying its private Class Log tag within the selected week. It is not designed to read or analyse unrelated calendar events.
  • A short-lived Calendar access token is kept in that browser so the chosen operation can finish. It is not stored in the Class Log server database and is cleared on sign-out or expiry.

School operational information

Teacher names, departments, timetables, class topics, plans and remarks are operational school information. Approved teachers can view entries within their department for lesson continuity; editing is restricted by role. Leaders and administrators may have wider access.

How information is used

  • Authenticate staff, approve access and enforce branch, department and role permissions.
  • Provide class logging, lesson continuity, dashboards, substitutions, absences, school calendars and exports.
  • Create or remove Calendar events only when a user requests a sync operation.
  • Protect the service, diagnose failures and prevent misuse.

Storage, retention and security

  • Class Log application data and sessions are stored in Cloudflare infrastructure. Traffic is served over HTTPS.
  • The browser stores the Class Log session identifier and local preferences. Server sessions expire after 30 days and are invalidated when the user signs out.
  • School records are retained for the period required by the school’s operational and record-keeping needs, then removed or anonymised under school direction.
  • Class Log uses access controls and limited permissions, but no online service can guarantee absolute security.

Sharing and service providers

  • Within the school: approved staff see information allowed by their department and role.
  • Google: Google Identity Services verifies sign-in and Google Calendar processes user-requested calendar operations.
  • Cloudflare: hosts the application and key-value storage.
  • Ask AI: only when an authorised staff member submits a question, the permitted recent class-log context and question are sent to the configured AI provider, currently OpenRouter and its selected model, to generate an answer. AI answers may be inaccurate and should be checked.

Class Log does not sell personal data and does not use it for advertising.

Student information

Class Log is intended for staff use and is not intended to collect personal data directly from students. Staff should not enter sensitive student personal information in topic or remark fields.

Your choices and deletion requests

  • You may decline Calendar access and continue using the core class-log features.
  • You may revoke Google access from your Google Account permissions.
  • You may ask the school to correct or delete account information and associated records by contacting the address below. Requests may be subject to school record-keeping obligations.

Google API Limited Use

Class Log’s use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

Changes and contact

This policy will be updated when Class Log’s data practices change. Questions, access requests and deletion requests may be sent to desmondperis@gmail.com.