Privacy
Privacy policy
This policy explains how PurpleScone handles personal data under the UK GDPR and the EU GDPR. It applies wherever the deck is used. Questions go to info@purplescone.com. Last updated 23 September 2026.
Who is responsible
For the email address and password of a PurpleScone account, PurpleScone is the controller. For school data pulled from a learning portal, the organisation that connects the portal is the controller and PurpleScone is the processor. The processor acts on that organisation's instructions so the deck can be shown to the people it invites. Write to info@purplescone.com.
What we collect
- Account data: email address, a one-way password hash and whether the account is on a free trial, a paid plan or a trial that has ended.
- Deck data: the deck name, the Moodle site URL and the API token. The token is encrypted at rest and is not shown back in full.
- School snapshots: courses, categories, groups, cohorts, enrolments, attendance, lessons, assignments, quizzes and the messages a person has chosen to send. These can include pupils' and staff names.
- A session cookie so you stay signed in. It is HttpOnly and SameSite Lax. It is marked Secure when the page is served over HTTPS.
Why and the legal basis
Account data is used to provide the deck you asked for. The basis is contract. Session data and access checks are used to keep the deck from being misused. The basis is legitimate interests in running a secure service. School and pupil data is processed because the school, as controller, has instructed that processing. PurpleScone does not sell personal data and does not use it for advertising. The deck does not make a solely automated decision that has a legal or similarly significant effect. A person sends each message.
Children and schools
The deck is for staff. Pupils' names, attendance and work appear because the school has connected its portal. PurpleScone is not a service aimed at children. The school remains responsible for its lawful basis for pupils, including any public-task or consent basis it relies on, and for telling pupils and parents what the portal is used for.
Security
PurpleScone follows ordinary safeguards and is not responsible for security beyond them. You must use a safe connection and a secure password.
What PurpleScone does:
- Passwords are stored only as a one-way hash. The plain password is not kept.
- The Moodle API token is encrypted with AES-256-GCM and is not displayed in full.
- The sign-in cookie is HttpOnly so a page script cannot read it, and it is sent as Secure on an HTTPS connection.
- Forms that change data carry a one-time check so another site cannot submit them for you.
- Each person opens only the sections the main account has ticked. Any other address sends them away.
What PurpleScone does not do, and does not accept responsibility for:
- The security of your device, browser, network, email account or the learning portal you connect.
- A loss that follows from an unsafe connection, a weak or reused password, a shared sign-in, a token copied out of the deck, or a portal that is left open.
- Checking that your password is unique or that your staff have locked their screens.
You must open the deck over HTTPS, choose a long password you do not use elsewhere, keep sign-in details to yourself and leave the API token inside the deck. An invited person is given a starter password and must replace it before the deck opens. Do not keep that starter password.
How long we keep it
Account and deck data stay while the trial or the subscription is active. Snapshots are replaced when the deck is refreshed. If the organisation closes the deck, the snapshots and the token are deleted with it. Message logs are kept so the school can see what was sent. You can ask for account data to be deleted by writing to info@purplescone.com. A request about pupil data should go to the school first, and we will help the school carry it out.
Where it goes
Data is stored on the server that hosts the PurpleScone installation. The token is used only to call the portal you named. If that portal or the host is outside the UK or the EEA, a transfer needs a lawful tool under the UK GDPR or the EU GDPR, such as an adequacy decision or standard contractual clauses. The organisation that connects the portal is responsible for that transfer. No one else is given the token or the snapshots for their own purposes.
Subprocessors
The host that runs the server and the database is a subprocessor. Moodle, or the other learning portal you connect, receives the messages you choose to send. PurpleScone does not pass the data to an advertiser or a data broker.
Cookies
Under the UK PECR and the EU ePrivacy rules, a session cookie is strictly necessary to keep you signed in. It is not used for advertising or analytics. The notice asks you to accept before any further choice is stored in this browser. Until you accept, only that necessary cookie is used. Accepting stores a local flag so the notice stays hidden.
Your rights
Under the UK GDPR and the EU GDPR you may ask to see your data, correct it, delete it, restrict it, receive a portable copy or object to processing based on legitimate interests. Staff should ask their school first about portal data, because the school is the controller of it. Write to info@purplescone.com. You may complain to the Information Commissioner's Office in the UK or to the supervisory authority in your EU country. Those rights do not depend on where you open the deck.