Privacy notice
BugBotLab Ltd · last updated 11 September 2026
This notice covers the BugBot websites (bugbotlab.com and its lessons, competitions, simulator and documentation pages) and the teacher tools at teach.bugbotlab.com. It is written for teachers, school IT and data protection staff, parents, and students.
The short version
- Students do not need an account, an email address, or a real name. They join a class with a code and a nickname.
- We store what a student does in the lessons (which tasks they tried and passed, the code they last ran) so their teacher can see it. Nothing else.
- Teachers sign in with a school Google or Microsoft account, or an email address and password.
- Data is stored in Google Cloud in London. We do not sell data and there are no adverts, ever.
- Analytics run only if you accept them on the cookie bar.
Who is responsible
For the class features (class codes, student progress, hints, assignments) the school is the data controller and BugBotLab Ltd is the data processor, acting on the school's instructions under the terms of the School or Teacher plan. For teacher accounts and for visitors to the websites, BugBotLab Ltd is the controller.
Contact: info@bugbotlab.com, BugBotLab Ltd, registered in England and Wales.
What we collect
| Who | What | Why | Kept |
|---|---|---|---|
| Students in a class | Nickname (chosen by the student), a random identifier the browser creates, the class code, the lesson they are on, each task's result and number of tries, the code of the last program they ran (up to 4000 characters), the last error message, timestamps | So the teacher can see who is stuck, who has finished, and what they wrote; to show the student their own progress on any page | Until the teacher deletes the class, or 12 months after the class was last used |
| Students not in a class | Progress is saved only in their own browser (local storage). Nothing is sent to us. | To remember where they got to | Until they clear their browser |
| Teachers | Email address, display name and sign-in provider (from Google, Microsoft or the email sign-up), the classes they make, the messages and hints they send | To run the account and the classes | Until the account is deleted, or 24 months after the last sign-in |
| Anyone leaving feedback or reporting a problem | The text they type, the page they were on, and for signed-in teachers the email address | To fix the problem and reply | 12 months |
| Visitors (with consent) | Google Analytics 4: pages viewed, buttons pressed, lessons and tasks run, a cookie identifier. IP addresses are truncated by Google. | To see which lessons work and which do not | 14 months (Google's default), or until you withdraw consent |
| Waitlist subscribers | Email address, via MailerLite | To send launch news; unsubscribe in any email | Until you unsubscribe |
We do not collect dates of birth, photographs, addresses, or any special category data. We ask students to choose a nickname their teacher will recognise; teachers should not let students use full names if the school's policy prefers otherwise.
Lawful basis
For class data, the school's lawful basis is normally public task (state schools) or legitimate interests (independent schools) in delivering education; BugBotLab processes it under the school's instructions. Teacher accounts and feedback are processed under contract and legitimate interests (running the service, replying to you). Analytics cookies are set only with your consent.
Where the data goes
| Processor | Used for | Location |
|---|---|---|
| Google Cloud Firestore (Firebase) | Classes, student progress, teacher accounts, feedback | London (europe-west2) |
| Firebase Authentication (Google) | Teacher sign-in and the students' anonymous identifiers | Google service; data may be processed in the United States under Google's UK Addendum and Standard Contractual Clauses |
| Firebase Hosting (Google) | Serving the websites | Global edge network |
| Google Analytics 4 | Usage statistics, with consent only | Google; EU/UK data controls enabled |
| Google Workspace | Email, including feedback emails | |
| MailerLite | Waitlist emails on bugbotlab.com | EU (Lithuania) |
| Cloudflare cdnjs, jsDelivr | Loading open-source libraries (the code editor, the 3D view, the Python runtime). They see the request, no personal data is sent. | Global |
No other third parties receive the data. We never sell it, share it for advertising, or use it to train AI models.
Cookies and local storage
- Essential: the sign-in session (Firebase Authentication) and the class you joined, in the browser's local storage. No consent needed.
- Progress: which tasks you passed and the code in each editor, in local storage, so the pages remember you. No consent needed.
- Analytics (optional): Google Analytics cookies, only after you press Accept on the bar at the bottom of the page. Your choice is shared across all bugbotlab.com pages and can be changed by clearing site data.
Security
All traffic is encrypted (HTTPS). Database rules mean a student can only write their own record, a teacher can only read the classes they made, and nobody can read feedback from the websites. Teacher sign-in uses Google, Microsoft or Firebase Authentication with passwords hashed by Google. Access to the underlying project is limited to BugBotLab Ltd staff with two-factor authentication.
Your rights
You can ask for a copy of the data we hold, ask us to correct or delete it, or object to processing. Teachers can delete a student's record or a whole class from BugBot Teach; students can leave a class from the lessons page, which stops any further data being sent. For anything else, email info@bugbotlab.com and we will reply within 30 days. If you are a student, ask your teacher first, who can act for the school. You can also complain to the Information Commissioner's Office at ico.org.uk.
Changes
We will post changes here with a new date at the top, and email teachers about any change that affects student data.
