Short version: For the website, we collect the minimum we need to respond to school enquiries and send the newsletter. For the Cloak Check browser extension, we collect nothing at all — every check runs locally in your browser and no data is transmitted anywhere. For the Cloak for Schools student platform, your school is the data controller, we are the processor, and data is hosted in the UK — the full detail is in section 11. We don't sell data, we don't use trackers, and you can ask us to delete anything we hold about you at any time.
What this policy covers
Cloak is more than one thing, and the data story is different for each part. This policy covers all of them — use the split below to find the bit you care about:
| Product | Who it's for | Data position | Details |
|---|---|---|---|
| This website (getcloak.tech) | Anyone — teens, parents, school staff | We collect only what you hand us: school enquiries, newsletter sign-ups, direct emails, plus standard server logs. | Sections 1–9 |
| Cloak Check browser extension | Anyone who installs it | Transmits nothing. Every check runs locally in your browser; there is no backend and nothing to collect. | Section 10 |
| Cloak for Schools student platform | Licensed schools, their staff and students | Built for 2026/27; no student data processed yet. The school is the controller and Solid Code Solutions is the processor, under a data processing agreement signed before any student data is processed. | Section 11 |
The free interactive mini-games and activities on this site (Would You Click?, the Leak Simulator, and so on) need no login and ask for no personal data — they run entirely in your browser, so they aren't listed separately above.
1. Who we are
Cloak is a cyber safety education brand for teenagers. It's a product of Solid Code Solutions Ltd, an IT consultancy based in Leamington Spa, UK.
For the purposes of UK GDPR and the Data Protection Act 2018, the data controller for this website is:
- Solid Code Solutions Ltd
- Registered address: 20 - 22 Wenlock Road, London, England, N1 7GU
- Company number: 08750436
- ICO registration: ZC141966
- Privacy contact: info@solidcodesolutions.co.uk
2. What we collect
We only collect personal data when you choose to give it to us.
| When | What we collect | Why |
|---|---|---|
| You sign up as a pilot school, or contact us as a parent | Your name, email, school or organisation, role, and anything you choose to write in the optional "what would be most useful?" field | To follow up about Cloak's school programme as it takes shape |
| You subscribe to the newsletter | Your email address | To notify you when we publish new content |
| You email us directly | Your email address and anything you choose to put in the message | To reply to you |
| You visit any page | Standard server logs (IP address, browser type, pages viewed, timestamp) held by our hosting provider | Security, abuse prevention, basic operational diagnostics |
We do not currently use website analytics (e.g. Google Analytics), advertising trackers, or social media pixels. If we add any of these in future, we'll update this policy and add a cookie consent banner first.
The table above covers the website only. The Cloak Check browser extension is covered separately in section 10 — it transmits no data of any kind and is not represented in any row above because there is nothing to collect. Student data in the Cloak for Schools platform is covered in section 11.
3. Why we use it (lawful basis)
- School enquiries — legitimate interest, or taking steps at your request prior to entering a contract (UK GDPR Article 6(1)(b)) where you're actively exploring a licence or pilot. You've contacted us about a service for your school, and replying is the obvious thing to do.
- Newsletter — consent. You've opted in by submitting the form, and you can withdraw it at any time — every email carries an unsubscribe link, or you can just ask us to remove you.
- Server logs — legitimate interest in keeping the site secure and operational.
4. If you're under 18
Cloak is aimed at teenagers aged 13–18. We're aware that many of our visitors are minors, and we follow the ICO's Age Appropriate Design Code (the "Children's Code").
What that means in practice:
- We don't ask for personal information from anyone under 13. The pilot school sign-up form is intended for school staff and parents, not students.
- If you're under 18 and want to subscribe to the newsletter, we ask that you check with a parent or carer first.
- We don't profile you, target advertising at you, or share your data with anyone for marketing purposes.
- If a parent or guardian is concerned about data we hold about a young person, they can contact us at the address in section 13 and we'll act on it promptly.
5. Who we share data with
We don't sell your data. We share it only with the providers we use to actually run the site and respond to you:
- Netlify — hosts this website and processes our form submissions, including school enquiries and newsletter sign-ups, on our behalf. See Netlify's privacy policy.
- Google Fonts — serves the typefaces used on this site. Loading the page sends your IP address to Google so the fonts can be delivered. See Google's privacy policy.
- Our email provider — Microsoft 365 handles the inboxes we use to reply to you.
We don't currently use a third-party email-marketing platform: newsletter sign-ups are simply stored as form submissions with Netlify until we send an update. If we ever add a dedicated email provider, we'll update this policy first.
We may also disclose data where we're legally required to (for example, in response to a court order, or to protect someone from serious harm).
The providers above run the website. The Cloak for Schools student platform uses a separate, UK-hosted set of sub-processors that are kept entirely apart from our marketing tools — that list is in section 11.
6. Cookies and tracking
This website does not currently set any cookies on your device, and we don't use analytics or advertising trackers.
Third-party services we link to or embed (TikTok, YouTube, Instagram) will set their own cookies once you click through to them. Their cookie policies apply on their own sites.
7. How long we keep data
- School enquiries — kept for up to 3 years from last contact, then deleted, unless you become a paying customer (in which case standard business records apply).
- Newsletter subscribers — kept until you unsubscribe, then promptly removed.
- Email correspondence — kept for up to 2 years for reference, unless there's a reason to keep it longer (e.g. an ongoing project).
- Server logs — typically rotated and deleted by our host within 30 days.
Retention for the Cloak for Schools student platform works differently and is set out in section 11, with the definitive schedule confirmed in each school's data processing agreement.
8. International transfers
Some of the providers we use for the website are based in the United States and may process your data there:
- Netlify (US) — website hosting and form submissions.
- Google (US) — Google Fonts delivery.
- Microsoft 365 — support inboxes; the storage region depends on our tenancy configuration and may include the US.
Where a transfer leaves the UK, it's protected by the UK Extension to the EU–US Data Privacy Framework or by the UK's International Data Transfer Agreement / Standard Contractual Clauses, in line with UK GDPR requirements.
The Cloak for Schools student platform is different. Student data is resident in the United Kingdom (Microsoft Azure UK regions), with no routine transfer of student data outside the UK. See section 11 for the detail.
9. Your rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Correct anything that's inaccurate or out of date
- Delete your data ("right to be forgotten") in most circumstances
- Object to us processing your data, or restrict how we use it
- Take your data with you in a portable format
- Withdraw consent at any time (e.g. unsubscribe from the newsletter)
To exercise any of these, email us using the address in section 13. We'll respond within one month.
If you're unhappy with how we've handled your data, you have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator. We'd appreciate the chance to put things right first, but it's your call.
10. The Cloak Check browser extension
Cloak Check is a free, open-source browser extension we publish on the Chrome Web Store. It scans the page you're currently looking at for cyber security signals (HTTPS use, lookalike domain tricks, missing security headers, phishing patterns, and so on) and shows you a traffic-light verdict in plain English.
The extension is built around one promise: nothing about your browsing leaves your browser.
What the extension reads
To produce a verdict for the page you're on, the extension reads:
- The page's URL and the response headers Chrome received when loading it
- The page's HTML, the scripts it references, and any iframes embedded in it
- Cookie attributes (the Secure flag and similar metadata) for the current page — never the cookie values themselves
- The page's favicon URL
This inspection happens locally inside your browser. The extension does not record what you read, what you type, what you click, or which pages you visit over time.
What the extension stores
Scan results are written to chrome.storage.session, a per-session RAM-only area provided by Chrome that is wiped automatically when you close the browser. The extension does not use chrome.storage.local, IndexedDB, or any other persistent storage, and writes nothing about your browsing to disk.
What the extension transmits
Nothing. The extension makes no network requests to our servers or to anyone else's, because there is no server. Cloak Check has no backend, no telemetry, no analytics, no error reporting, no remote configuration, and no update channel beyond the Chrome Web Store's standard distribution. The source ships unminified, so any of this can be verified by inspecting the unpacked extension.
Permissions, in plain English
Chrome asks you to approve the following permissions when you install the extension. Each one is used for the specific purpose described below and nothing else:
- activeTab — lets the popup talk to the page currently in focus when you click the icon.
- storage — used only for the RAM-only chrome.storage.session area described above.
- webRequest — read-only access to the response headers (CSP, X-Frame-Options, HSTS, and so on) of pages as they load. The extension never blocks, redirects, or modifies any request.
- cookies — read-only inspection of cookie attributes (Secure flag, SameSite, and so on) on the current page. Cookie values are not read.
- webNavigation — lets the extension re-run its checks automatically when a tab finishes loading, so the verdict is ready by the time you click.
- host_permissions: <all_urls> — required so the above can happen on whichever page you're visiting. The permission is broad by necessity but the use is narrow: read-only inspection, with no transmission of data anywhere.
Children and the extension
Because the extension transmits no data of any kind, it does not collect personal information from anyone, including under-18s. Nothing about the analysis or the storage changes based on who's using it. A parent or guardian who wants to verify the extension's behaviour can inspect the source or contact us at the address in section 13.
If this ever changes
If a future version of the extension changes any of the above — for example, if we were ever to add an opt-in feature that transmitted data — we would update this policy first, update the Chrome Web Store listing, and ask for explicit consent within the extension before any new data flow began.
Reporting an issue
Bugs, wrong verdicts, or anything else about the extension can be reported on the Cloak Check support page.
11. The Cloak for Schools platform
Cloak for Schools is a student-facing online safety learning platform, licensed to schools, where students work through interactive lessons and teachers assign tasks and see progress on a dashboard. It is launching in September 2026, for the 2026/27 academic year, with free pilots during that year.
Status: the platform is launching in September 2026 and has not processed any student data yet — the first pilot schools start then. This section describes how it handles student data. The binding, school-specific detail — including the data schema, retention periods and sub-processor list — is set out in a Data Processing Agreement (DPA) that is signed before any student data is processed, including for pilots. Where this section and a signed DPA differ, the DPA wins.
Controller and processor
For the student platform, your school (or trust) is the data controller and Solid Code Solutions Ltd is the data processor. We process student data only on your documented instructions, for the purpose of delivering the lessons and reporting progress back to you — never for our own marketing, and never to train AI models. We provide a DPA (UK GDPR Article 28), a sub-processor list, a retention schedule, and support for your Data Protection Impact Assessment (DPIA) as part of onboarding.
What data the platform collects
The platform is built around data minimisation: it collects only what students need to complete lessons and what teachers need to see progress. Where a school prefers, students can be identified by a pseudonymous ID rather than a full name. The data model is:
| Data | Example | Why |
|---|---|---|
| Student identity | First name and last name (or a pseudonymous ID / display name, at the school's choice) | So students can log in and teachers can see whose work is whose |
| Class / cohort | Year group, class or teaching group | To assign work and group progress for a class or year |
| Account / sign-in | School email address or username, and an authentication identifier used to sign in securely | To authenticate students and staff securely |
| Learning activity | Lesson and activity completion status, scores/answers to fixed-choice questions, time spent, last-active date | To show teachers progress and let students resume where they left off |
| Staff accounts | Teacher / DSL / admin name, work email, role and permissions | To give the right staff the right access and produce reports |
What the platform deliberately does not collect. In line with the safeguarding design set out on the For schools page, there are no free-text boxes asking students to describe things that have happened to them or to other people, and no student-to-student messaging. The platform does not seek special-category data (such as health, religion or ethnicity), does not track students' browsing outside the platform, and does not build advertising or behavioural profiles. Answers are to scenario-based, fixed-choice questions — not disclosures.
How students and staff sign in
Student and class accounts are provisioned from the data a school shares through the MIS sync or CSV described below — students don't self-register, and no student enters personal data to create an account. Cloak issues the sign-in credentials, so no third party is involved in authentication and no student account is linked to a personal email address.
Passwords are never stored in plain text. They are hashed with Argon2 and cannot be recovered by us — not by support, not by an engineer, not by anyone. If someone forgets their password, an authorised member of school staff can issue a reset for any student or staff account at any time.
MIS integration — and why it's kept separate from marketing
To create student and class accounts, a school can either sync from its Management Information System (MIS) through an approved connector such as Wonde, or upload a CSV — whichever the school prefers. Only the fields listed above are taken; the sync does not pull contact details, safeguarding flags, SEN, attendance, medical or other sensitive MIS fields.
Student data and marketing are fully partitioned. The student platform runs on separate, UK-hosted infrastructure with its own database. Student records are never added to the newsletter list or any marketing tool, and are never used to contact students or their families for marketing. The providers that run the website (section 5) have no access to platform data, and vice versa.
Access controls, roles and audit logs
Access is role-based and least-privilege — staff see only the data their role needs:
- Teacher — the progress of their own assigned classes.
- DSL / safeguarding lead — the school-configured view appropriate to their role.
- School admin — accounts and settings for their own school.
- MAT / trust admin — an aggregate view across the trust's schools, where a trust licence applies.
Solid Code Solutions staff access to school data is restricted to the minimum needed to run and support the service, and significant actions (such as account changes, exports and deletions) are recorded in audit logs. A school can request the audit log relating to its own data.
Where it's hosted and how it's secured
- UK data residency. Student and school data is hosted on Microsoft Azure in UK regions (UK South / UK West). There is no routine transfer of student data outside the UK.
- Encryption. Data is encrypted in transit (TLS) and at rest.
- Separation. Each school's data is logically separated so one school cannot see another's.
- Backups. Backups are held within the UK region and are subject to the same retention and deletion rules as live data.
- Certification. Solid Code Solutions holds Cyber Essentials and is registered with the ICO. The platform is designed to meet the ICO's Children's Code.
- AI. AI is used behind the scenes to spot emerging scams so lessons stay current; a human reviews and approves everything before it reaches a classroom, and AI never touches student data.
Sub-processors
These are the only sub-processors that may handle student or school data:
| Sub-processor | What it does | Location |
|---|---|---|
| Microsoft Azure | Cloud hosting, database and backups for the platform | United Kingdom |
| Wonde (only if your school chooses MIS sync) | Secure one-way sync of the agreed fields from your MIS | United Kingdom |
The definitive, contractual sub-processor list is provided with your DPA, and we give schools advance notice of any new or replacement sub-processor so you can object before it takes effect.
Keeping, exporting and deleting student data
- During your subscription or pilot — we keep student records for as long as they're needed to deliver the service to your school.
- Export. Your school can export its student records and progress data (for example as CSV) at any time, so the data is portable and stays yours.
- Deletion. At the end of a subscription or pilot, we delete your school's student data — including from backups on their normal cycle — no later than 30 days after it ends, unless you ask us to delete it sooner or the law requires us to keep it. A school can also request deletion of an individual student's record at any time.
- At the end of a free pilot — the same applies: you can export first, then everything is deleted on the schedule above. Pilots carry no obligation to continue.
The exact retention periods are confirmed in your DPA. Because your school is the controller, requests from students or parents to access, correct or delete data are handled through the school; we support the school in responding to them.
For your procurement and DPO
Before any pilot goes live, we provide the documents a school's data protection review needs: a signed DPA, the sub-processor list, a retention schedule, and support for your DPIA. To request these, contact us using the details in section 13.
12. Changes to this policy
If we change this policy in a way that materially affects you (for example, if we add analytics or change who processes your data), we'll update the "last updated" date at the top of this page and, where appropriate, notify you by email or with a banner on the site.
13. Contact us
For anything privacy-related — data requests, questions, complaints, or concerns about a young person's data — get in touch:
- Email: info@solidcodesolutions.co.uk
- Post: Solid Code Solutions Ltd, 20 - 22 Wenlock Road, London, England, N1 7GU