Trust, governance and data protection
Privacy-First by Design
ChalkboardAI is designed to help schools use AI tools while reducing unnecessary exposure of pupil data. Its pilot workflows are built around local-first processing, pseudonymisation, data minimisation, human review and privacy-by-design principles.
ChalkboardAI supports teacher-controlled workflows where pupil information may be used to create draft planning or documentation support. The product is designed to reduce unnecessary exposure by replacing direct identifiers locally, sending only tool-specific pseudonymised educational context, and keeping professional judgement with the teacher.
How ChalkboardAI Protects Pupil Data
- Teacher uploads a class record on their own device.
- The selected tool extracts only the information required.
- Direct identifiers are pseudonymised locally.
- The backend and external AI services receive pseudonymised educational context for the selected tool.
- AI returns a pseudonymised response.
- Reidentification occurs locally on the teacher's device.
- Teacher reviews and approves the final output.
The identity mapping between real names and pseudonyms is retained locally in the browser workflow and is not transmitted to the backend or external AI services.
What Data Leaves the Device?
ChalkboardAI is designed so that directly identifiable pupil information, such as pupil names, is not included in requests sent to external AI services. Depending on the tool, pseudonymised educational information may be transmitted, such as:
- Year group
- Subject information
- Attainment information
- Learning targets
- Intervention information
- Relevant educational context
Uploaded CCR files are processed in the browser workflow. ChalkboardAI does not store uploaded CCR files as backend file uploads. Pilot access and usage telemetry may be stored separately, limited to access code, selected role, tool, event timing, browser-session id and small non-sensitive metadata.
What Stays Local?
The current pilot architecture keeps the following information on the teacher's device or within the local browser workflow:
- Pupil names
- Real-name to pseudonym mapping
- Full class records
- Data not required by the selected tool
- Teacher review and decision-making processes
Defence in Depth
ChalkboardAI does not rely on a single safeguard. Its pilot workflows combine several privacy layers that are intended to reduce the risk of exposing identifiable pupil information.
- Pseudonym shuffle and pseudonymisation: pupil names are replaced locally with temporary pupil pseudonyms before tool workflows continue.
- Name and red-flag detection: the dashboard and tool workflows include checks intended to identify names or other identifying details before AI requests are sent.
- Data minimisation through Required Data Profiles: each tool requests a defined subset of fields rather than the whole class record.
- Synthetic profile shielding: Reports and Individual Support Planner requests mix the selected pseudonymised profile with plausible synthetic shield profiles. This reduces attribution risk and increases ambiguity around profile ownership, but it is not the same as anonymisation.
- Local-only reidentification: AI outputs are returned with pseudonyms and can be reidentified locally for teacher use.
- Human review: teachers review, edit and approve outputs before use.
Use of AI
ChalkboardAI uses third-party AI services to generate draft suggestions and planning support.
AI outputs are treated as draft support only. A teacher remains responsible for reviewing, editing and approving outputs before they are used in school documentation, planning or decision-making.
Professional judgement remains with the teacher. ChalkboardAI is not designed to replace safeguarding procedures, SEND processes, school policies or statutory responsibilities.
Data Controller and School Responsibility
Schools remain responsible for determining whether use of ChalkboardAI is appropriate within their own governance, data protection and safeguarding frameworks.
ChalkboardAI is designed to support safer AI-assisted workflows by reducing unnecessary exposure of identifiable pupil data. Schools should complete their own review, approval and governance processes before use.
Security and Governance Measures
The following safeguards are visible in the current codebase and pilot implementation:
- HTTPS delivery through the hosted Netlify deployment.
- Local pseudonymisation before AI processing.
- Tool-specific data minimisation through Required Data Profiles and handoff allowlists.
- Session-based or in-memory identity mapping used for local reidentification.
- Pupil names and stable pupil identifiers are excluded from AI request payloads through local pseudonymisation, request construction controls and backend identifier guards.
- Pilot bearer tokens, accepted pilot terms and selected role are stored locally for convenience until expiry or sign-out; uploaded pupil data and generated working outputs are not stored in persistent browser storage.
- Human review before final use.
- Privacy-first product design with restrictive site headers and limited function routing.
Pilot Status
ChalkboardAI is currently being prepared for small-scale pilot evaluation within education settings.
The pilot is intended to gather evidence relating to:
- Workload reduction
- Consistency of documentation
- Usability
- Data protection suitability
- Wider applicability within schools
Contact
For questions about ChalkboardAI, privacy or pilot access, please use the contact link below.
Send a privacy or pilot access enquiry