Legal
Privacy Policy
How Bates Math collects, uses, and retains account, learning, and AI-tutoring data.
Effective 14 September 2026. Operator: Bates Publishing. Questions: contact the developer at lagodaoleg1357@gmail.com.
Who we are
This Privacy Policy applies to Bates Math at batesmath.com, an online math practice product of Bates Publishing. Bates Math is a consumer education service: students sign in with Google, work a roadmap of textbook problems, keep a streak, and can ask an AI tutor for help.
The operator named in the product is Bates Publishing. Questions about this policy or Bates Math: contact the developer at lagodaoleg1357@gmail.com.
What this policy covers
It covers personal information processed when you visit the public site, create an account, or use lessons, practice, leagues, and Ask Bates. It does not cover Google's own services or other sites we link to. Those are governed by their own policies.
Staff tools (the Bates Agent, review queue, and admin analytics) are internal to Bates Publishing. Student accounts cannot reach them.
Information we collect
Account and profile
When you start an account we collect, and then store:
- First name, optional last name, and the subject tracks you pick on
/start(or on the short post-sign-in completion if those answers were not already saved). - Optional “how you heard about us” (teacher, friend, search, social, a Bates Publishing book, or a short note). This is stored on your profile for product understanding, not sold.
- Those pre-sign-in answers are held for up to one hour in a first-party httpOnly cookie named
bm_pending_profile, bound to that Google sign-in with a one-time nonce, so they survive the redirect and are not applied to a different account. After the profile is written — or when the cookie must not apply — it is cleared. - Email address, display name, and profile photo URL from Google, plus a unique user identifier created by our authentication provider (Supabase Auth).
- Time zone (default UTC, used to settle streaks against local midnight) and a daily XP goal (a default until you can edit it). School year may be stored if it is set on the profile.
- Role on the product (student, or staff if we have granted it).
Learning records
- Lesson sessions, answers you submit (including whether they were graded correct), time spent on an item, and review schedule.
- Progress, XP, hearts, gems, streak, freeze count, crowns, and achievements.
- Weekly league membership and XP for that week. Other students in your league see your rank and weekly XP; they do not see your name or photo. Only you see your own name on that table.
Technical data
- IP address, used only as a rate-limit key so a flood of requests can be slowed. IPv6 addresses are truncated to a /64 prefix. These counters are short-lived operational records, not a profile.
- Server logs (request path, status, a request id, and error diagnostics) generated by our host.
What we do not collect
- We do not run advertising or product-analytics pixels.
- We do not ask for a date of birth, phone number, or home address.
- We do not collect payment card details.
- We do not take a camera or microphone permission. The product does not record video of you studying.
- Students do not upload photos of homework to the tutor. Textbook scans in the catalogue are uploaded by Bates Publishing staff.
Google sign-in
Bates Math uses Google OAuth through Supabase Auth. There is no password on this site. The sign-in button sends you to Google, and Google returns an authorization code to /auth/callback, which is exchanged for a session stored in first-party cookies.
We request offline access so the authentication provider can refresh the session without sending you back to Google on every visit. Google shows its own consent screen. We receive the profile fields Google includes for a basic OAuth sign-in: name, email, profile photo, and account id.
We do not receive your Google password, Gmail contents, Drive files, or Classroom roster. You can revoke Bates Math's access in your Google account settings; you should also delete your Bates Math account if you want our copy of the profile removed.
AI tutoring and generated content
Ask Bates and in-lesson hints send text to an inference provider so the tutor can reply. A typical request includes:
- The message you just typed, after basic sanitisation.
- A short recent conversation history. That history is supplied by your browser (it lives in local storage on your device). The server does not keep a second copy of the thread after the reply is generated.
- A skill summary derived from your attempts and review queue only — not from anyone else.
Generated visual problems are created from a prompt about the topic you asked for. Fair-use limits may apply to tutor replies and generated visuals; when they do, the counters are stored on your account.
Model providers process that text to produce a reply. We do not use student tutor conversations to train a public Bates Math model. We cannot promise that a third-party inference host will never log a request on its side; we choose providers that offer an API for this kind of product use and we send only what is needed for the turn.
Tutor replies can be wrong. They are study aids, not official marks or a replacement for a teacher. See the Terms of Service and the Acceptable Use Policy.
How we use information
- To create and keep your account, and to sign you in.
- To run lessons, grade answers, schedule review, and show progress.
- To operate Ask Bates and generated visual problems.
- To prevent abuse (rate limits, same-origin checks, session verification).
- To fix incidents and keep the service running.
- To communicate about the account you opened when we must — not to send marketing mail, which this product does not send.
Legal bases
If you are in the UK, EEA, or another jurisdiction that requires a lawful basis:
- Contract. Providing the service you asked for: account, lessons, and tutor.
- Legitimate interests. Securing the service, rate limiting, debugging, and understanding aggregate load. League rankings that hide other students' names are part of the product you chose to use.
- Legal obligation. Responding to a binding request from a competent authority, or keeping records the law requires us to keep.
- Consent. Not used for cookies today, because we only set strictly necessary cookies. See the Cookie Policy.
Retention
- Account and learning records are kept until you delete the account. Deletion removes the auth user; related rows (profile, attempts, progress, achievements, league membership) cascade with it.
- Ask Bates threads live in the browser until you clear site data or delete the threads in the tutor UI. They are not a server-side archive.
- Rate-limit counters are short-lived keys that are meant to be pruned on the order of a day, not kept as a history of your IP.
- Host logs follow the hosting provider's default retention. They are operational, not a second student database.
Security
Access to student data in the application database is scoped by row-level security: a signed-in student's client can only read their own rows. Privileged server paths use a service role and are limited to the operations the product needs (grading, deletion). Sessions are revalidated with the authentication provider rather than trusted from cookie contents alone.
No method of transmission or storage is perfectly secure. If you find a vulnerability, contact the developer at lagodaoleg1357@gmail.com (also listed in /.well-known/security.txt).
Children and education
Bates Math is built for secondary-school mathematics, typically high school. You must be at least 13 years old to create an account. We do not knowingly collect personal information from children under 13. If you believe we have, contact the developer at lagodaoleg1357@gmail.com and we will delete the account.
The product is a consumer service, not a school-administered student information system. We are not a “school official” under FERPA unless a school has a written agreement with us that says so. A student may use a school-issued Google account to sign in; that does not by itself make Bates Math a school service.
If you are a parent or guardian in a region that requires parental consent for teenagers, you are responsible for that consent before the student uses the service. We do not currently offer a teacher roster, class period, or school dashboard.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict, or object to certain processing, and to data portability. California residents also have the right to know the categories of personal information we collect and to direct us not to sell or share it. We do not sell or share personal information as those terms are used in the CCPA/CPRA.
To exercise these rights, contact the developer at lagodaoleg1357@gmail.com from the address on the account. We will need to verify that the request comes from that account. You can also delete the account yourself in Settings, which is the fastest erasure path we offer. We do not currently provide a self-serve data-export file; ask the developer at lagodaoleg1357@gmail.com if you need a copy of what we hold.
You may complain to a data protection authority in your country. Questions about these rights: contact the developer at lagodaoleg1357@gmail.com.
Deleting your account
Settings → General includes a delete-account flow. You type a confirmation phrase and complete a slide-to-delete control. The server only deletes the signed-in user (never an id supplied in the request). Deletion removes the account and learning data.
Deletion cannot be undone. Local tutor threads on a device are not part of the server database; clear this site's data in the browser if you want those gone too.
International transfers
Bates Math is hosted on infrastructure that may process data in the United States and other countries where our processors operate (including authentication, database, hosting, and inference). If you use the service from elsewhere, you understand that your information may be transferred to those countries. Where a transfer law requires safeguards, we rely on the processor's published mechanisms (for example standard contractual clauses) as offered in their customer terms.
Changes
If we change this policy in a material way, we will update the effective date on this page. Continued use after the new date means you accept the revised policy. If a change requires consent we cannot infer from continued use, we will ask for it.
Contact
Questions about privacy, this policy, or your data: contact the developer at lagodaoleg1357@gmail.com.