WholeRecord · Privacy notice
Last updated: [date] · If anything important changes, you'll see it at the top of this page.
Hello. I'm Joe, and WholeRecord is my business. You're thinking about trusting me with something personal: your school reports, or your child's if you're a parent. This page sets out exactly what happens to them, and how I've kept your privacy central to the design.
The short version
- You upload your school reports (or, as a parent, your 14–17-year-old child's). We read them and give you back a written "reading" of the patterns teachers described over the years.
- We don't keep your reports or your reading. They're processed, then deleted from our systems. (We do keep a few small records, like proof you agreed and your order details. Section 5 lists exactly what, and for how long.)
- It runs on AI, used to read and sort the words. The reading itself is built from fixed wording, not written by AI, and it can't diagnose.
- The AI reading of your reports happens in Europe. That matters, because it means your reports stay under European privacy law, some of the strictest rules in the world, for the whole time they are being read. They are never sent outside Europe to be read or stored. (The website itself runs on a worldwide network, and a few support services like payment and email are run by trusted companies outside Europe under standard data-protection contracts. Section 10 explains both.)
- You're in control: uploading is your choice, and you can change your mind and ask us to stop at any time (section 12 shows you how).
That is the overall summary. The rest explains it in full.
1. Who we are, and how to reach us
WholeRecord is run by me, Joseph Griffiths. I'm a sole trader (a one-person business) based in Spain, trading as WholeRecord (website: thewholerecord.com). Looking after your information is my responsibility, and I'm the person accountable for it (in legal terms, the "data controller").
- Email us about your privacy or your rights: privacy@thewholerecord.com
- Our UK representative (a contact point for people in the UK):
[UK REPRESENTATIVE: name + postal address to be inserted before launch]
2. Whose information this notice covers
- You, if you upload your own reports (you must be 18 or over).
- Your child (aged 14–17), if you're a parent uploading their reports (see section 8).
- Teachers and other staff whose words appear in the reports (see section 9).
- People on our waitlist (section 7), and people who email our support (section 13).
3. What we do with your reports, and why
You upload school reports; we produce a written reading of the patterns described across them. To do that we:
- read the words on the pages (using AI to turn the images into text),
- sort those words against a fixed list of patterns that research links to ADHD (using AI),
- build the reading from fixed wording we prepared in advance, with your teachers' words quoted in, as they appear in your uploaded reports.
The reading is not written by AI, and it can't diagnose you or anyone else. It describes what's in the records, nothing more. A teacher's comment can have many explanations (a hard year at home, a particular teacher, an off day), so a reading on its own can never tell you whether someone has ADHD. There's an always-on "Why this reading cannot diagnose" note in every reading.
The legal bases for this (the plain version first, the legal label after):
| What | Why | Our legal basis |
|---|---|---|
| Reading your reports to make your reading | You asked us to; it's the whole point of the service | Your explicit consent (Article 6(1)(a) + Article 9(2)(a)), given on the consent screen before you upload |
| Your account, payment and delivering your reading | To run the service you paid for | Contract (Article 6(1)(b)) |
| Keeping account & order records afterwards | To meet Spanish business and tax record-keeping rules | Legal obligation (Article 6(1)(c)) |
| Reading teachers' words inside your reports | Unavoidable: their words are part of the records | Legitimate interests (Article 6(1)(f)), see section 9 |
You can take back your consent at any time (section 12). Giving your permission and uploading your reports is entirely your choice. If you don't, or if you later change your mind, we simply can't make your reading. Nothing else happens, and there's no other consequence.
4. Sensitive information (health and similar)
School reports can mention sensitive things: special educational needs, a doctor's note, a teacher's comment about wellbeing. And the reading is about patterns that touch on health. We can't reliably know in advance which reports contain things like these, so we treat every uploaded report, and the reading we make from it, as sensitive, and protect it accordingly. That's why we ask for your clear, explicit permission before we read anything (Article 9(2)(a)).
5. What we keep, and what we don't
We're built to keep as little information about you as possible:
- Your reports: not kept on our computers after your reading is made.
- Your reading: not kept on our computers after it's delivered to you, so please save it. (We give you a download button, and we email you a recovery code. The code lets you upload your report photos again and make a fresh reading, without paying again. It can't bring back the old reading, because nothing you sent is kept.) The recovery-code note below has the full details.
- On your own device: while the reading is being made, your browser temporarily stores your files so it can finish if the page is interrupted (for example while you pay and come back). These are deleted when your reading is ready. Otherwise they expire after two hours and are cleared the next time one of our pages runs. If you close the page and don't come back, the files stay in your browser's storage until a later visit to one of our pages clears them, or until your browser clears them itself. You can also clear them yourself at any time.
- The AI step: runs with no copy kept by the AI provider, and your reports are not used to train any AI model.
- What we do hold (small and necessary):
- Proof you agreed (your consent): kept for 6 years, so we can show consent was given if it's ever questioned, then deleted.
- If a child says no on their own screen: we keep a scrambled (one-way hashed) record of that refusal, so a parent can't simply ask again. The record holds no name and no report content. It's kept for up to 4 years (until the child is an adult), then deleted.
- Your recovery code: we keep only a scrambled version we can never read, so you can make your reading again without paying. It's kept for 30 days from purchase (and for up to three re-runs), then deleted. A re-run means uploading your reports again from scratch; it does not bring back a saved reading, because we don't save one.
- Your account and order details: kept for 6 years to meet Spanish business and tax record-keeping rules (a legal obligation, Article 6(1)(c)), then deleted.
Because we keep so little: if you ask us for a copy of your data after your reading is delivered, there usually won't be one to give. We'll instead explain what we did, when, and on what basis. (This is your "right of access", section 12, working as best it can with a no-keep design.)
6. The AI, in a bit more detail
- The AI reads the words on your pages and sorts them. It does not write your reading. The reading's wording is fixed and prepared in advance. The only words from your reports that appear in it are the things your teachers wrote, quoted as they appear in your uploaded reports. Anything the system can't read with certainty is held back, never guessed.
- All of this runs on Amazon Web Services in Europe. The AI models are made by Anthropic and run inside Amazon's own European service (Amazon's "Bedrock"). Under Amazon's terms, Anthropic the company is not given the words from your reports at all. Your text is processed by the model inside Amazon's systems for only the moment it takes to do the reading, and no copy is kept. Anthropic receives only technical usage information that includes nothing from your reports: never the words from your reports or your reading.
- About the quoted words: every quote is your teachers' own words, copied from your reports. The system is built so the AI never guesses:
- if it can't read a word, it marks it instead of inventing one;
- each page is read twice and the two results are compared;
- anything it's unsure of is set aside and flagged, rather than guessed at.
No automatic reader can prove every word against the original page, so anything flagged is held back rather than shown as certain.
- More on how it works is on our methodology page [link].
7. Marketing and our waitlist
If you join our waitlist or opt in to updates, we'll email you about the launch and occasional product news (the basis is your consent). Every email has an unsubscribe link, and you can opt out at any time. If you never engage and we never launch to you, we clear your details after 24 months. We don't tag or sort you by anything sensitive.
8. Children aged 14–17, and their parents
If you're the 14–17-year-old whose reports these are: this is about your choice. A parent can start the upload, but nothing is read unless you say yes on your own screen. You can change your mind, or contact us yourself at privacy@thewholerecord.com, without involving your parent. There's a plain-English "your rights" page for you [link].
If you're a parent uploading a 14–17-year-old's reports:
- Your child decides. Before anything is read, your child is asked on their own screen to confirm, and nothing happens unless they do. If they say no, we don't process anything, and a parent can't override that.
- Your child is the person the data is about, and they have all the rights in section 12. They can ask us things, or ask us to stop, directly and without involving you, at privacy@thewholerecord.com.
- The service is for children aged 14–17 only (not younger).
9. Teachers named in the reports
The reports you upload were written by teachers, so their words pass through our systems when we read your reports. Their words reach us only because they're written inside the reports you upload. That is the only source. The teacher information involved is limited to the words written in the report; we hold no names, contact details or identifiers for teachers. The system doesn't pick out or store who wrote what; it only reads the words.
One honest exception: if a teacher's name was written inside a sentence in your report, and that exact sentence is quoted, the name stays inside the quote exactly as the teacher wrote it: text you already have in your own report. We never add a teacher's name to a quote, label who wrote what, or keep it as a record.
We rely on legitimate interests for this (Article 6(1)(f), a lawful basis that lets us handle information where it's necessary and fair). The teachers' words are an unavoidable part of your records, and we've weighed it up to make sure it's fair to teachers (we don't profile them, score them, or keep their data). There's a separate page explaining this to teachers, and how they can get in touch: thewholerecord.com/for-teachers (the "For teachers and school staff" page). Because we use this legitimate-interests basis, any teacher also has the right to object to it at any time. They can email us at privacy@thewholerecord.com and we'll act on it.
10. Who helps us run the service
A small number of trusted companies process some data on our instructions:
| Company | What they do | Where | Protection |
|---|---|---|---|
| Amazon Web Services | Runs the AI that reads and sorts your reports | Europe only | Data not kept; contract + EU processing |
| Anthropic (inside Amazon's service, as Amazon's onward sub-processor) | Provides the AI models | Europe (within AWS) | Gets only usage info, never your reports or reading |
| Cloudflare | Hosts the website, handles security, and provides our cookieless visitor analytics (basic, anonymous numbers; no cookies; not used to identify you) | Global network | Standard data-processing contract; analytics data is aggregate and cookie-free |
| Resend | Sends you emails (your receipt with your recovery code, and the child-confirmation link) | United States | No report content in any email; transfer covered by standard contracts (section 11) |
| Paddle | Takes your payment. Paddle is the seller of record for the payment, so it handles VAT and sends your receipt | United Kingdom (with group companies in the United States) | We never see or store your card number; any transfer covered by adequacy or standard contracts (section 11) |
| Proton | Our support email inbox | Switzerland | Encrypted; Switzerland recognised as having equally strong protection |
| Kit (formerly ConvertKit) | Sends waitlist/marketing emails (if you opt in) | United States | Marketing only; opt-in; unsubscribe any time; transfer covered by standard contracts (section 11) |
We keep written contracts with each of these and check how they handle data.
11. Where your information goes (transfers outside the UK/Europe)
Your reports are read for the AI step in Europe (the EU/EEA), and are not sent outside Europe for that reading or for storage. The website itself, and the handling of each request, run on a global hosting network (Cloudflare). While your reading is produced, your report text may pass through that network only momentarily, in memory. It is never stored there. Separately, a little of your information (for example payment, some service emails, and marketing emails if you opt in) is handled by companies based outside the UK and Europe, marked "United States" in the table above. When that happens, we use legal contracts that require those companies to protect your data to the same standard it has here (these are called "Standard Contractual Clauses"). Switzerland is officially recognised as having equally strong protection, so no extra contract is needed there. You can ask us for a copy of these contractual protections by emailing privacy@thewholerecord.com.
12. Your rights, and how to use them
You can ask us to:
- see what we hold about you (remembering section 5: there's usually very little);
- correct anything wrong;
- delete your information;
- stop using it, or object to a particular use;
- take back your consent at any time (this stops any further processing);
- get a copy of your account information in a portable form.
To do any of these, email privacy@thewholerecord.com. We'll respond within a month. Using these rights is free.
To take back your consent while your reading is being made, or from the reading screen, you can also press the Stop & delete button. It stops processing, cancels your recovery code so nothing can be re-run, and clears the copies on your device straight away, no email needed. At any other time, just email us.
If you're unhappy with how we've handled your information, you can make a data-protection complaint to us at privacy@thewholerecord.com. We'll acknowledge it within 30 days, look into it, and tell you the outcome. You can also complain to a data-protection regulator: our lead regulator is the AEPD in Spain (aepd.es); if you're in the UK, you can also complain to the ICO (ico.org.uk). If you're in Ireland, you can also contact the Data Protection Commission (dataprotection.ie). We'd appreciate the chance to put things right first.
13. When you contact us (support)
When you email us, whether for help, a question, or to use any of your rights, what we hold is your email address, whatever you write, and our reply. That's all we need, and please don't send us your reports: support doesn't require them.
- Why we're allowed to (the legal basis): if it's about a reading you've paid for, handling it is part of providing the service you bought (contract, Article 6(1)(b)); for general or pre-sale questions, it's our legitimate interest in answering you (Article 6(1)(f)).
- How long we keep it: routine support emails are kept for about 60 days by default, then deleted. But if your message is a rights request, a withdrawal of consent, or a data-protection complaint, we keep a record of what you asked and how and when we handled it, so we can show it was handled properly. That record is kept for longer, in line with the consent-record period in section 5. It's a record of the request, not the whole email kept indefinitely. If you ever attach a report by mistake, we delete that attachment within 72 hours.
- Where it's handled: our support inbox is provided by Proton (in Switzerland, see sections 10 and 11), and I'm the only person who reads it.
This is, in practice, the one place we might hold something about you, and only because you chose to write to us.
14. Cookies and tracking
We don't use tracking cookies or advertising tools, so there's no cookie banner. We do use privacy-first website analytics (Cloudflare) to see basic, anonymous visitor numbers (like how many people visit a page). It sets no cookies, stores nothing on your device, and we don't use it to identify you or follow you across other websites. Our legal basis for keeping the site secure and seeing these basic, anonymous visitor numbers is our legitimate interest in a secure, working website (Article 6(1)(f)).
15. Automated decisions (the reading is for you to interpret)
The reading is information for you to interpret. We don't make any automatic decision about you that has a legal or similarly significant effect. You decide what, if anything, the reading means and what to do next.
16. Changes to this notice
If we change anything important, we'll update the date at the top and, where it matters, tell you directly.
If anything here isn't clear, or you'd just like to ask something before you upload a single page, email privacy@thewholerecord.com. It comes to me.
WholeRecord · privacy@thewholerecord.com