School Resource Manager

Privacy Policy

Last updated: 10 October 2026

This policy describes the intended data handling for the privately operated School Resource Manager (“the application”). The application is designed for use by its operator to organise educational resources.

Information processed

The application may process educational files that the operator places in its configured incoming folder. It may also store file hashes, file paths, classification results, processing status, timestamps, and error logs to prevent duplicate processing and support troubleshooting.

Google Drive access

If the operator enables the Google Drive integration, the application will request Google authorisation and use the granted permission to create folders and upload eligible educational resources to the operator’s Drive. It is intended to use the minimum required Drive permission. The application does not use this website to collect Google passwords.

Google data accessed by the application is intended to be used only to provide the resource organisation and upload functionality requested by the operator. It is not sold, rented, or used for advertising. The operator can revoke the application’s access through their Google Account security settings.

Private and uncertain resources

The application is designed to keep memorandums, marking guides, answer keys, worked solutions, and resources requiring review out of learner-facing publishing destinations. Uncertain resources are intended to remain in a separate review or unclassified location. The operator is responsible for checking the destination configuration and access permissions before enabling uploads.

Storage and security

Files and processing records are stored on the operator’s own server and, where enabled, in the operator’s Google Drive. The operator is responsible for securing the server, backups, Google account, and Drive sharing settings. OAuth credentials and tokens should be stored separately from this public website and protected with operating-system access controls and encryption where available.

Sharing and disclosure

The application is not intended to sell or share personal information with advertisers. Data may be processed by Google when Google Drive functionality is enabled, under Google’s own terms and privacy policy. The operator may disclose information where required by law or to protect system security.

Retention and deletion

Files and processing records may be retained to support organisation, duplicate detection, auditing, and recovery. The operator controls the server and Drive copies and is responsible for deleting data when it is no longer needed.

Children’s information

The application is intended to organise educational materials, not to collect student profiles or student account information. The operator should not upload student personal information unless there is a lawful basis and appropriate safeguards.

Changes and contact

This policy may be updated as the application changes. For privacy questions, contact the operator using the contact details provided directly by the operator.

Return to the homepage

Before OAuth review: Confirm this policy accurately describes the final deployment, actual OAuth scopes, storage locations, retention practices, and contact method. Add a working contact address before submitting the OAuth app for review.