Teach

Privacy notice

BugBotLab Ltd · last updated 11 September 2026

This notice covers the BugBot websites (bugbotlab.com and its lessons, competitions, simulator and documentation pages) and the teacher tools at teach.bugbotlab.com. It is written for teachers, school IT and data protection staff, parents, and students.

The short version

Who is responsible

For the class features (class codes, student progress, hints, assignments) the school is the data controller and BugBotLab Ltd is the data processor, acting on the school's instructions under the terms of the School or Teacher plan. For teacher accounts and for visitors to the websites, BugBotLab Ltd is the controller.

Contact: info@bugbotlab.com, BugBotLab Ltd, registered in England and Wales.

What we collect

WhoWhatWhyKept
Students in a classNickname (chosen by the student), a random identifier the browser creates, the class code, the lesson they are on, each task's result and number of tries, the code of the last program they ran (up to 4000 characters), the last error message, timestampsSo the teacher can see who is stuck, who has finished, and what they wrote; to show the student their own progress on any pageUntil the teacher deletes the class, or 12 months after the class was last used
Students not in a classProgress is saved only in their own browser (local storage). Nothing is sent to us.To remember where they got toUntil they clear their browser
TeachersEmail address, display name and sign-in provider (from Google, Microsoft or the email sign-up), the classes they make, the messages and hints they sendTo run the account and the classesUntil the account is deleted, or 24 months after the last sign-in
Anyone leaving feedback or reporting a problemThe text they type, the page they were on, and for signed-in teachers the email addressTo fix the problem and reply12 months
Visitors (with consent)Google Analytics 4: pages viewed, buttons pressed, lessons and tasks run, a cookie identifier. IP addresses are truncated by Google.To see which lessons work and which do not14 months (Google's default), or until you withdraw consent
Waitlist subscribersEmail address, via MailerLiteTo send launch news; unsubscribe in any emailUntil you unsubscribe

We do not collect dates of birth, photographs, addresses, or any special category data. We ask students to choose a nickname their teacher will recognise; teachers should not let students use full names if the school's policy prefers otherwise.

Lawful basis

For class data, the school's lawful basis is normally public task (state schools) or legitimate interests (independent schools) in delivering education; BugBotLab processes it under the school's instructions. Teacher accounts and feedback are processed under contract and legitimate interests (running the service, replying to you). Analytics cookies are set only with your consent.

Where the data goes

ProcessorUsed forLocation
Google Cloud Firestore (Firebase)Classes, student progress, teacher accounts, feedbackLondon (europe-west2)
Firebase Authentication (Google)Teacher sign-in and the students' anonymous identifiersGoogle service; data may be processed in the United States under Google's UK Addendum and Standard Contractual Clauses
Firebase Hosting (Google)Serving the websitesGlobal edge network
Google Analytics 4Usage statistics, with consent onlyGoogle; EU/UK data controls enabled
Google WorkspaceEmail, including feedback emailsGoogle
MailerLiteWaitlist emails on bugbotlab.comEU (Lithuania)
Cloudflare cdnjs, jsDelivrLoading open-source libraries (the code editor, the 3D view, the Python runtime). They see the request, no personal data is sent.Global

No other third parties receive the data. We never sell it, share it for advertising, or use it to train AI models.

Cookies and local storage

Security

All traffic is encrypted (HTTPS). Database rules mean a student can only write their own record, a teacher can only read the classes they made, and nobody can read feedback from the websites. Teacher sign-in uses Google, Microsoft or Firebase Authentication with passwords hashed by Google. Access to the underlying project is limited to BugBotLab Ltd staff with two-factor authentication.

Your rights

You can ask for a copy of the data we hold, ask us to correct or delete it, or object to processing. Teachers can delete a student's record or a whole class from BugBot Teach; students can leave a class from the lessons page, which stops any further data being sent. For anything else, email info@bugbotlab.com and we will reply within 30 days. If you are a student, ask your teacher first, who can act for the school. You can also complain to the Information Commissioner's Office at ico.org.uk.

Changes

We will post changes here with a new date at the top, and email teachers about any change that affects student data.