Mammath.study (“we”, “us”, “our”, "Mammath") is committed to protecting the privacy of teachers and students who use our service (“the Service”). This Privacy Policy explains what information we collect, why we collect it, and how it is used.
By using the Service, you agree to the practices described in this Policy.
1. Information We Collect
1.1 Teacher Account Information
When a teacher creates an account, we collect:
- Email address
- Password (stored securely)
- Optional: a display name to present to students in the lobby (e.g. teacher: Mr Smith)
1.2 Class and Alias Information
In using our service, it is expected that teachers will create:
- Classes with names (e.g., “7A”, “8-1”, etc.)
- Student aliases for each class.
Class names and aliases are only visible to the teacher account. Aliases are limited to a maximum of 3 characters, thus minimising collection of any personally identifiable information (PII).
1.3 Assessment Data
Results for quizzes and activities are stored against aliases only. This data is available to the teacher for educational use until it is deleted by the teacher.
1.4 System Logs
For operational reasons, our hosting and infrastructure providers may temporarily record:
- IP addresses
- Browser or system metadata included in standard access logs
We do not routinely access, export, or analyse these logs, except where required for service integrity or security investigations.
2. Information We Do Not Collect
We do not collect:
- Student names
- Student emails
- Dates of birth
- Personal identifiers
- Any information that directly links aliases to identifiable individuals
- Other sensitive information
Students do not create accounts.
3. How We Use the Information
We use the information we collect only to:
- Provide login and authentication
- Deliver and improve quiz and reporting features
- Store and display alias-based results to teachers
- Maintain platform security and stability
- Communicate essential updates to teacher accounts
3.1 Aggregated, Anonymised Data
We may review aggregated, anonymised data (such as overall question performance statistics) to:
- Improve the quality, accuracy, and fairness of assessments
- Guide refinement of quizzes and curriculum materials
No individual teacher, class, alias, or school can be identified in this aggregated data.
We do not use any data for advertising, profiling, or commercial resale.
4. Cookies
We use only essential, first-party cookies:
- Session cookies for secure login
- Functional cookies to protect the “Contact Us” page and quiz pages by rate-limiting access (for example)
We do not use analytics cookies or third-party tracking cookies.
5. Data Disclosure
We do not share any user or educational data with third parties.
This does not include technical processing by infrastructure and service providers, as described in Section 8.
6. Data Storage and Hosting
Data may be processed outside Australia as part of normal service operation.
The Service is hosted by Render, using servers located in Singapore.
Data stored may include:
- Teacher account information
- Class names and aliases
- Alias-based assessment results
Render may temporarily retain server logs that include IP addresses (see Section 1.4).
7. Data Retention
- Teachers can delete classes, aliases, and results at any time.
- Deleted data may temporarily persist in system backups.
- Limits on active classes and quizzes discourage long-term data archiving.
- Stale data older than two years may be automatically purged.
- Teachers are encouraged to export required records for institutional storage.
8. External Service Providers
The following external service providers are used for roles outlined below. * Render is used as the website and database server host. * Sentry is used for error and bug tracking to fix software issues. * Cloudflare is used for DNS, DDoS protection, bot & abuse protection and CDN edge caching. * Google Sign-in is optionally used for user authentication.
Teachers may choose to authenticate using Google. When this option is used, we receive the teacher’s name and email address from Google for account creation and authentication only. We do not receive Google passwords and do not access Google Drive, contacts, calendars, or other Google services. You may disconnect third-party accounts through our Accounts page if you have verified an email address and set a secure password.
Mammath’s use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
These services may process IP addresses and metadata (e.g. browser, operating system) as part of normal operation for the purposes of providing their stated functions.
These providers do not receive any PII of students (as we do not collect and use such data). We configure services to minimise the collection of personal data wherever possible.
9. Account Deletion
Teachers may request account deletion via the contact us page. They must be logged-in when making this request. When a request is received:
- The account will be permanently removed
- All associated classes, aliases, and results will also be deleted
- Backup copies (if present) will be removed automatically during normal archive cycling
10. Security
We implement reasonable technical and organisational measures, including:
- Secure hosting
- Password hashing and salting
- Restricted internal access
- Design choices that prevent collection and storage of PII (risk minimisation).
- Security measures implemented by our External Service Providers (see Section 8)
No online service can guarantee absolute security.
11. User Responsibility
Teachers must ensure that:
- The Service aligns with their institution’s privacy and data requirements
- Required assessment records are exported for long-term retention
We can provide additional information to support institutional review if needed.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Significant changes will be communicated via email to registered teacher accounts.
Continued use of the Service constitutes acceptance of updated terms.
13. Contact Us
For privacy questions, account deletion requests, or compliance inquiries, please contact us.