Short version: For the website, we collect the minimum we need to respond to school enquiries and send the newsletter. For the Cloak Check browser extension, we collect nothing at all — every check runs locally in your browser and no data is transmitted anywhere. For the Cloak for Schools student platform, your school is the data controller, we are the processor, and data is hosted in the UK — the full detail is in section 11. We don't sell data, we don't use trackers, and you can ask us to delete anything we hold about you at any time.

What this policy covers

Cloak is more than one thing, and the data story is different for each part. This policy covers all of them — use the split below to find the bit you care about:

Product Who it's for Data position Details
This website (getcloak.tech) Anyone — teens, parents, school staff We collect only what you hand us: school enquiries, newsletter sign-ups, direct emails, plus standard server logs. Sections 1–9
Cloak Check browser extension Anyone who installs it Transmits nothing. Every check runs locally in your browser; there is no backend and nothing to collect. Section 10
Cloak for Schools student platform Licensed schools, their staff and students Built for 2026/27; no student data processed yet. The school is the controller and Solid Code Solutions is the processor, under a data processing agreement signed before any student data is processed. Section 11

The free interactive mini-games and activities on this site (Would You Click?, the Leak Simulator, and so on) need no login and ask for no personal data — they run entirely in your browser, so they aren't listed separately above.

1. Who we are

Cloak is a cyber safety education brand for teenagers. It's a product of Solid Code Solutions Ltd, an IT consultancy based in Leamington Spa, UK.

For the purposes of UK GDPR and the Data Protection Act 2018, the data controller for this website is:

2. What we collect

We only collect personal data when you choose to give it to us.

When What we collect Why
You sign up as a pilot school, or contact us as a parent Your name, email, school or organisation, role, and anything you choose to write in the optional "what would be most useful?" field To follow up about Cloak's school programme as it takes shape
You subscribe to the newsletter Your email address To notify you when we publish new content
You email us directly Your email address and anything you choose to put in the message To reply to you
You visit any page Standard server logs (IP address, browser type, pages viewed, timestamp) held by our hosting provider Security, abuse prevention, basic operational diagnostics

We do not currently use website analytics (e.g. Google Analytics), advertising trackers, or social media pixels. If we add any of these in future, we'll update this policy and add a cookie consent banner first.

The table above covers the website only. The Cloak Check browser extension is covered separately in section 10 — it transmits no data of any kind and is not represented in any row above because there is nothing to collect. Student data in the Cloak for Schools platform is covered in section 11.

3. Why we use it (lawful basis)

4. If you're under 18

Cloak is aimed at teenagers aged 13–18. We're aware that many of our visitors are minors, and we follow the ICO's Age Appropriate Design Code (the "Children's Code").

What that means in practice:

5. Who we share data with

We don't sell your data. We share it only with the providers we use to actually run the site and respond to you:

We don't currently use a third-party email-marketing platform: newsletter sign-ups are simply stored as form submissions with Netlify until we send an update. If we ever add a dedicated email provider, we'll update this policy first.

We may also disclose data where we're legally required to (for example, in response to a court order, or to protect someone from serious harm).

The providers above run the website. The Cloak for Schools student platform uses a separate, UK-hosted set of sub-processors that are kept entirely apart from our marketing tools — that list is in section 11.

6. Cookies and tracking

This website does not currently set any cookies on your device, and we don't use analytics or advertising trackers.

Third-party services we link to or embed (TikTok, YouTube, Instagram) will set their own cookies once you click through to them. Their cookie policies apply on their own sites.

7. How long we keep data

Retention for the Cloak for Schools student platform works differently and is set out in section 11, with the definitive schedule confirmed in each school's data processing agreement.

8. International transfers

Some of the providers we use for the website are based in the United States and may process your data there:

Where a transfer leaves the UK, it's protected by the UK Extension to the EU–US Data Privacy Framework or by the UK's International Data Transfer Agreement / Standard Contractual Clauses, in line with UK GDPR requirements.

The Cloak for Schools student platform is different. Student data is resident in the United Kingdom (Microsoft Azure UK regions), with no routine transfer of student data outside the UK. See section 11 for the detail.

9. Your rights

Under UK GDPR, you have the right to:

To exercise any of these, email us using the address in section 13. We'll respond within one month.

If you're unhappy with how we've handled your data, you have the right to complain to the Information Commissioner's Office (ICO), the UK's data protection regulator. We'd appreciate the chance to put things right first, but it's your call.

10. The Cloak Check browser extension

Cloak Check is a free, open-source browser extension we publish on the Chrome Web Store. It scans the page you're currently looking at for cyber security signals (HTTPS use, lookalike domain tricks, missing security headers, phishing patterns, and so on) and shows you a traffic-light verdict in plain English.

The extension is built around one promise: nothing about your browsing leaves your browser.

What the extension reads

To produce a verdict for the page you're on, the extension reads:

This inspection happens locally inside your browser. The extension does not record what you read, what you type, what you click, or which pages you visit over time.

What the extension stores

Scan results are written to chrome.storage.session, a per-session RAM-only area provided by Chrome that is wiped automatically when you close the browser. The extension does not use chrome.storage.local, IndexedDB, or any other persistent storage, and writes nothing about your browsing to disk.

What the extension transmits

Nothing. The extension makes no network requests to our servers or to anyone else's, because there is no server. Cloak Check has no backend, no telemetry, no analytics, no error reporting, no remote configuration, and no update channel beyond the Chrome Web Store's standard distribution. The source ships unminified, so any of this can be verified by inspecting the unpacked extension.

Permissions, in plain English

Chrome asks you to approve the following permissions when you install the extension. Each one is used for the specific purpose described below and nothing else:

Children and the extension

Because the extension transmits no data of any kind, it does not collect personal information from anyone, including under-18s. Nothing about the analysis or the storage changes based on who's using it. A parent or guardian who wants to verify the extension's behaviour can inspect the source or contact us at the address in section 13.

If this ever changes

If a future version of the extension changes any of the above — for example, if we were ever to add an opt-in feature that transmitted data — we would update this policy first, update the Chrome Web Store listing, and ask for explicit consent within the extension before any new data flow began.

Reporting an issue

Bugs, wrong verdicts, or anything else about the extension can be reported on the Cloak Check support page.

11. The Cloak for Schools platform

Cloak for Schools is a student-facing online safety learning platform, licensed to schools, where students work through interactive lessons and teachers assign tasks and see progress on a dashboard. It is launching in September 2026, for the 2026/27 academic year, with free pilots during that year.

Status: the platform is launching in September 2026 and has not processed any student data yet — the first pilot schools start then. This section describes how it handles student data. The binding, school-specific detail — including the data schema, retention periods and sub-processor list — is set out in a Data Processing Agreement (DPA) that is signed before any student data is processed, including for pilots. Where this section and a signed DPA differ, the DPA wins.

Controller and processor

For the student platform, your school (or trust) is the data controller and Solid Code Solutions Ltd is the data processor. We process student data only on your documented instructions, for the purpose of delivering the lessons and reporting progress back to you — never for our own marketing, and never to train AI models. We provide a DPA (UK GDPR Article 28), a sub-processor list, a retention schedule, and support for your Data Protection Impact Assessment (DPIA) as part of onboarding.

What data the platform collects

The platform is built around data minimisation: it collects only what students need to complete lessons and what teachers need to see progress. Where a school prefers, students can be identified by a pseudonymous ID rather than a full name. The data model is:

Data Example Why
Student identity First name and last name (or a pseudonymous ID / display name, at the school's choice) So students can log in and teachers can see whose work is whose
Class / cohort Year group, class or teaching group To assign work and group progress for a class or year
Account / sign-in School email address or username, and an authentication identifier used to sign in securely To authenticate students and staff securely
Learning activity Lesson and activity completion status, scores/answers to fixed-choice questions, time spent, last-active date To show teachers progress and let students resume where they left off
Staff accounts Teacher / DSL / admin name, work email, role and permissions To give the right staff the right access and produce reports

What the platform deliberately does not collect. In line with the safeguarding design set out on the For schools page, there are no free-text boxes asking students to describe things that have happened to them or to other people, and no student-to-student messaging. The platform does not seek special-category data (such as health, religion or ethnicity), does not track students' browsing outside the platform, and does not build advertising or behavioural profiles. Answers are to scenario-based, fixed-choice questions — not disclosures.

How students and staff sign in

Student and class accounts are provisioned from the data a school shares through the MIS sync or CSV described below — students don't self-register, and no student enters personal data to create an account. Cloak issues the sign-in credentials, so no third party is involved in authentication and no student account is linked to a personal email address.

Passwords are never stored in plain text. They are hashed with Argon2 and cannot be recovered by us — not by support, not by an engineer, not by anyone. If someone forgets their password, an authorised member of school staff can issue a reset for any student or staff account at any time.

MIS integration — and why it's kept separate from marketing

To create student and class accounts, a school can either sync from its Management Information System (MIS) through an approved connector such as Wonde, or upload a CSV — whichever the school prefers. Only the fields listed above are taken; the sync does not pull contact details, safeguarding flags, SEN, attendance, medical or other sensitive MIS fields.

Student data and marketing are fully partitioned. The student platform runs on separate, UK-hosted infrastructure with its own database. Student records are never added to the newsletter list or any marketing tool, and are never used to contact students or their families for marketing. The providers that run the website (section 5) have no access to platform data, and vice versa.

Access controls, roles and audit logs

Access is role-based and least-privilege — staff see only the data their role needs:

Solid Code Solutions staff access to school data is restricted to the minimum needed to run and support the service, and significant actions (such as account changes, exports and deletions) are recorded in audit logs. A school can request the audit log relating to its own data.

Where it's hosted and how it's secured

Sub-processors

These are the only sub-processors that may handle student or school data:

Sub-processor What it does Location
Microsoft Azure Cloud hosting, database and backups for the platform United Kingdom
Wonde (only if your school chooses MIS sync) Secure one-way sync of the agreed fields from your MIS United Kingdom

The definitive, contractual sub-processor list is provided with your DPA, and we give schools advance notice of any new or replacement sub-processor so you can object before it takes effect.

Keeping, exporting and deleting student data

The exact retention periods are confirmed in your DPA. Because your school is the controller, requests from students or parents to access, correct or delete data are handled through the school; we support the school in responding to them.

For your procurement and DPO

Before any pilot goes live, we provide the documents a school's data protection review needs: a signed DPA, the sub-processor list, a retention schedule, and support for your DPIA. To request these, contact us using the details in section 13.

12. Changes to this policy

If we change this policy in a way that materially affects you (for example, if we add analytics or change who processes your data), we'll update the "last updated" date at the top of this page and, where appropriate, notify you by email or with a banner on the site.

13. Contact us

For anything privacy-related — data requests, questions, complaints, or concerns about a young person's data — get in touch: