Nex2School

Privacy

What we know about your family, and what we do with it.

Written to be read, not to be survived. Every number below is the real one.

Last updated 14 September 2026

Who we are

Nex2School runs live online classes for children aged 6 to 16. A parent or guardian holds the account; children do not sign in independently and cannot create an account of their own.

For anything in this policy — a question, a correction, a copy of your data, or a deletion request — write to hello@nex2school.com or use the contact page. A person reads that address.

What we collect

Three kinds of thing, and nothing else.

From the parent

  • Your name and email address.
  • Your password — stored only as a one-way hash. We cannot read it, and neither can anyone who obtained a copy of the database.
  • Your country, currency, language and time zone, so prices and class times are shown in your own money and on your own clock.
  • Which classes you booked, when, and what you paid.

About your child

  • Their first name or nickname — whatever you choose to enter.
  • Their date of birth. Used to check a class is age-appropriate and to determine whether parental consent is legally required.
  • Optionally: their pronouns, the subjects they are interested in, and any note you leave for teachers. All three are yours to leave blank, and you can delete them at any time.

Automatically

  • The country your connection appears to come from, used to choose a currency before you have told us one. It is not stored against your account.
  • Sign-in records — when, and from what address — kept briefly so we can detect somebody attacking your account.
  • Ordinary server logs. We do not use advertising trackers.
  • On our public pages only (the ones you can read without signing in), Microsoft Clarity records how visitors use the page: clicks, scrolling and a replay of the visit, with anything typed into a form masked. We use it to find pages that confuse people. It is never loaded anywhere a child uses the service, or on any page you reach by signing in.

Children under 13

Where the law requires verifiable parental consent before a child under 13 can use the service — the Children’s Online Privacy Protection Act in the United States, and comparable rules elsewhere — we ask for it before the child attends anything, and we record that we did.

A child has no login. Everything about them is entered and controlled by you, visible to you, and deletable by you. They are never asked for personal information directly, and there is no profile, no messaging between children, and no public presence of any kind.

You can withdraw consent at any time by writing to us. Doing so removes your child’s details and ends their classes.

Who your data reaches

We use other companies to run the service. Each one receives only what it needs, and this is the complete list.

CompanyWhat it doesWhat it receives
CloudflareRuns the website and protects it from attacksYour IP address and the pages you request
NeonHosts the databaseEverything in the sections above, encrypted at rest
ZoomRuns the live video classesThe course name and time, and the display name whoever joins is shown under. Never a child’s name in the meeting title.
Google CalendarPuts booked classes in our private staff calendarYour child’s name, the course, the time and the joining link. This calendar is not shared with instructors — only the two people who run Nex2School can open it.
ResendSends email — verification, reminders, password resetsYour email address and the contents of that email
Google Sign-InOptional way to sign in without a passwordOnly used if you choose it; Google tells us your name and email
GroqAnswers questions in the help chat when our own answers do not matchWhat you type into the chat box. Do not put personal details there.
Microsoft ClarityShows us how visitors use our public pages, so we can fix confusing onesOn public pages only: clicks, scrolling, a replay of the visit with form text masked, and your browser, device and approximate location. Never loaded where a child uses the service or after you sign in.

One detail worth stating plainly, because it is unusual: a Zoom meeting created by us is titled with the course and the time and never your child’s name. That is enforced in the code and covered by an automated test, so it cannot quietly stop being true.

What we never do

  • We do not sell your data, or your child’s, to anybody, in any form, ever.
  • We do not show advertising and we do not share anything with advertising networks.
  • We do not build profiles of children for any purpose beyond matching them to a suitable class.
  • We do not track you across other websites. There are no advertising pixels on this site. The one analytics tool we use, Microsoft Clarity on our public pages, only shows us how people use this site.

How long we keep it

  • Your account — for as long as it exists. Ask us to close it and we remove it.
  • Your child’s learning records — the classes they booked, the work they submitted and the grades they were given — for as long as the account exists, so a parent can look back over a year of progress.
  • Operational records — sign-in attempts, expired sessions and notifications you have already read — for as long as we need them to run the service securely. We do not currently delete these on a fixed schedule.

One deliberate exception. Records of parental consent are kept even after a child’s details are removed. They are the evidence that we asked permission before teaching your child, which is exactly the thing a regulator or a parent might later need to check — so the consent record survives, while the personal details it refers to do not.

Your rights

Whatever country you are in, you can ask us to:

  • show you everything we hold about you and your child;
  • correct anything wrong;
  • delete it;
  • send you a copy in a portable format;
  • stop processing it.

Much of this you can already do yourself: your own details are on your account settings page and your child’s are under Learner Profiles. For anything else, write to us and we will act within 30 days. We do not charge for this and we will not ask you why.

How it is protected

  • Everything travels over an encrypted connection, and is encrypted at rest.
  • Passwords are stored as one-way hashes and are never recoverable.
  • Staff accounts with access to family data require two-factor authentication, and every administrative action against a family record is logged.
  • Teachers see only the children they teach. Nobody sees a family they have no reason to see.

Where your data is

Nex2School is operated from India and teaches families in the United States, Australia and elsewhere, so your data is processed across borders — including by the companies listed above, which operate internationally. We rely on the standard contractual protections those providers offer. If you would like the detail for a particular provider, ask and we will tell you.

Changes to this policy

If we change how we handle your data in a way that matters, we will email you before it takes effect rather than quietly editing this page. The date at the top always reflects the current version.

Anything here you disagree with?

Tell us. A policy that nobody has ever pushed back on is usually one nobody has read. hello@nex2school.com

See also our child safety commitments, which cover what happens inside a lesson rather than what happens to data.