Privacy Policy

Last Updated: 30 June 2026

At LibraryAid, we take student privacy seriously. This Privacy Policy explains clearly and plainly how we collect, use, store, and protect information when schools and students use our platform. We have written this policy to be easy for parents, teachers, and school administrators to understand.

Key facts about student privacy on LibraryAid:

Table of Contents

1. Who We Are

LibraryAid is an AI-powered school library management platform built by David Webb, a primary school teacher. LibraryAid is operated globally, serving schools in the UK, US, and internationally. Our platform is designed specifically for use in educational settings — by school librarians, teachers, and students.

References to "LibraryAid", "we", "us", or "our" in this policy refer to the LibraryAid service and its operator, David Webb (davidwebb@libraryaid.net).

2. Information We Collect

2.1 School Administrator Information

When a school registers for LibraryAid, we collect:

2.2 Student Information

Student accounts are created by school administrators or teachers — not by students directly. For each student we collect:

We do not collect student email addresses. Students log in using a school-issued code. No personal contact information is required from students.

2.3 Teacher Information

Teachers and librarians log in using an email address and password. We store their name, email, school association, and activity within the platform (classes created, recommendations made, reviews approved).

2.4 Parent Information

Parents who access the parent portal are invited by the school. We collect the parent's name and email address to create their account. Parents can view their child's reading progress and recommendations.

2.5 Information Collected Automatically

When you use LibraryAid we automatically collect:

3. How We Use Your Information

3.1 Student Data

Student data is used exclusively for educational purposes:

Student data is never used for advertising, marketing profiling, or any commercial purpose.

3.2 School and Teacher Data

3.3 Analytics Data

We use Google Analytics GA4 to understand how our marketing website (libraryaid.net) is used. GA4 data is anonymised and aggregated. We use this data to improve our website and understand which pages are most useful to schools evaluating our platform.

4. Information Sharing and Disclosure

We never sell student data. We never share student data with advertisers or commercial third parties.

We may share information in the following limited circumstances:

4.1 Service Providers

We use the following third-party services to operate LibraryAid:

Each of these providers is contractually bound to protect data and use it only for the purposes we specify.

4.2 Schools and Administrators

Student data is accessible to the student's class teacher and school librarian within the same school. Student profiles and progress data are not visible to other students. District administrators can view aggregated school-level metrics through the District Dashboard (see Section 13) but do not have access to individual student profiles.

4.3 Legal Requirements

We may disclose information if required to do so by law, or if we believe in good faith that disclosure is necessary to comply with a legal obligation, protect the safety of students, or protect the rights and property of LibraryAid.

4.4 Business Transfers

If LibraryAid is involved in a merger, acquisition, or sale of assets, we will notify affected schools before any student data is transferred and give schools the opportunity to request deletion of their data.

5. Cookies and Tracking Technologies

5.1 On Our Marketing Website (libraryaid.net)

We use the following cookies on our public marketing website:

We do not use advertising cookies or allow third-party advertisers to set cookies on our website.

5.2 Within the LibraryAid App

Within the student-facing application, we use only essential cookies required for authentication and session management. No third-party tracking cookies are used within the student application.

For full details see our Cookie Policy.

6. Data Security

We take the security of student data seriously. Security measures include:

No system is completely secure. If we become aware of a security breach affecting student data, we will notify affected schools promptly in accordance with applicable law.

7. AI-Generated Data

7.1 Book Recommendations

LibraryAid uses AI to generate personalised book recommendations for each student. The recommendation engine analyses over 30 factors including reading level, interests, favourite authors, genre history, curriculum topics, series progression, and peer reviews within the school community. Recommendations are drawn exclusively from books in the school's own library catalogue — we do not recommend books the school does not own.

7.2 Reading Level Assessment

LibraryAid includes an adaptive reading age assessment spanning 13 bands from 6.0 to 12.0 years. Results are used to inform recommendations and are visible to teachers. Assessment results are clearly labelled as estimates within the platform and are intended as a guide for teachers, not as a replacement for formal educational assessment.

7.3 VIPERS Comprehension Questions

Comprehension quiz questions are AI-generated based on the books in our catalogue. Questions are aligned to the VIPERS comprehension framework (Vocabulary, Inference, Prediction, Explanation, Retrieval, Summarise). AI-generated questions are provided as educational tools and should be reviewed by teachers where used for formal assessment purposes.

7.4 Book Metadata

Reading level estimates for books (where not available from official sources) may be AI-generated. These are clearly labelled within the platform and should not be used as definitive educational measurements.

8. Children's Privacy (COPPA)

LibraryAid is designed for use in schools with students of all ages, including children under 13. We comply with the Children's Online Privacy Protection Act (COPPA) in the United States and equivalent regulations in other jurisdictions.

8.1 How We Comply with COPPA

8.2 Parental Rights

Parents may request to review the personal information collected about their child, request deletion of their child's personal information, or refuse further collection of their child's information by contacting their school administrator. Schools can delete student accounts and all associated data at any time through the teacher dashboard.

8.3 Age-Appropriate Content

LibraryAid applies content age-rating filters to all book recommendations. A gifted young reader with a high reading level will never be recommended books with age-inappropriate content for their actual age. Reading ability and content appropriateness are managed separately.

9. Data Retention

We retain data for as long as a school maintains an active LibraryAid account. Specifically:

Schools can request deletion of all their data at any time by contacting davidwebb@libraryaid.net. We will confirm deletion within 30 days.

10. Your Rights

10.1 Rights for All Users

10.2 GDPR Rights (UK and EU Users)

If you are located in the UK, European Economic Area, or Switzerland, you have rights under the UK GDPR and EU GDPR including all rights listed above plus the right to lodge a complaint with your local data protection authority. In the UK this is the Information Commissioner's Office (ICO) at ico.org.uk.

10.3 CCPA Rights (California Residents)

California residents have rights under the California Consumer Privacy Act (CCPA) including the right to know what personal information is collected, the right to delete personal information, and the right to opt out of the sale of personal information. We do not sell personal information.

10.4 Exercising Your Rights

To exercise any of these rights, please contact us at davidwebb@libraryaid.net. We will respond within the timeframe required by applicable law (typically 30 days).

11. International Data Transfers

LibraryAid is operated globally and our data infrastructure uses Google Firebase, with servers located in us-central1 (United States). This means that data submitted by users in the UK, EU, and other countries may be transferred to and stored in the United States.

For transfers of personal data from the UK and European Economic Area to the United States, we rely on Google's standard contractual clauses and Google Cloud's Data Processing Addendum, which provides appropriate safeguards for international data transfers in accordance with UK GDPR and EU GDPR requirements.

Google Firebase is compliant with GDPR, and Google's data processing terms are available at cloud.google.com/terms/data-processing-addendum.

12. Clever Single Sign-On

LibraryAid supports Clever Single Sign-On (SSO) for US schools and districts. When a school uses Clever SSO:

For information about Clever's data practices, see Clever's privacy policy at clever.com/trust/privacy/policy.

13. District Dashboard

LibraryAid offers a District Dashboard for school district administrators managing multiple schools. District administrators can:

District administrators do not have access to individual student profiles, individual student reading history, or any personally identifiable student information. All district-level data is aggregated at the school level.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will:

We encourage schools to review this policy periodically. Continued use of LibraryAid after changes are posted constitutes acceptance of the updated policy.

15. Contact Us

If you have any questions about this Privacy Policy, want to exercise your data rights, or have concerns about how we handle student data, please contact us:

LibraryAid
David Webb
Email: davidwebb@libraryaid.net
Website: libraryaid.net

We aim to respond to all privacy enquiries within 5 business days and to resolve requests within 30 days.

If you are a UK or EU resident and are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. In the UK: ico.org.uk. In the EU: your national data protection authority.