Privacy policy
Last updated: 28 July 2026
This policy explains how PublishSentry ("we", "us") handles personal data when you use our websites and services (including publishsentry.com and schools.publishsentry.com). It is written for school staff and other adult users in a B2B context. It is practical information about our product — not formal legal advice for your organisation.
Who we are
PublishSentry provides automated checks of publicly available school website content and published documents. For privacy questions, contact hello@publishsentry.com.
Who this policy covers
We mainly deal with work or school email addresses belonging to staff (for example headteachers, business managers, or governors) who request a check or create an account. We do not offer accounts to children, and we do not ask schools to upload pupil registers or private pupil records to PublishSentry.
When we scan a school website, we may process text and file content that is already published on the public web. That content is treated as part of providing the monitoring service. If a public page happens to include personal data, we process it only as needed to run and report the check.
Data we collect
- Account data — name (if provided), email address, password hash, organisation membership, and sign-in session details.
- School / organisation details — organisation name, website URL, country/region, and school profile settings you choose.
- Prospect / free-check data — email address and school website URL when you request a published policy check without (or before) a full paid subscription, plus related unsubscribe and monitoring preferences.
- Scan results and reports — crawl/job status, findings, evidence URLs or excerpts from public pages, compliance summaries, and report tokens used to access private reports.
- Billing data — subscription status, plan details, and Stripe customer/subscription identifiers. Card payments are handled by Stripe; we do not store full card numbers on PublishSentry servers.
- Technical and security data — essential cookies and similar storage needed for secure sign-in (see our cookie notice), and limited server logs needed to operate and protect the service.
- Communications — messages you send to us (for example to hello@publishsentry.com) and service emails we send you (password reset, check results, monitoring reminders where enabled).
Why we use the data (purposes)
- Provide accounts, dashboards, scans, and reports
- Send check results, security notices, and monitoring emails you enable
- Process payments and invoices via Stripe
- Respond to support and contact requests
- Keep the service secure, reliable, and abuse-resistant
- Improve scanning quality and product features using operational data
Legal bases (UK GDPR)
Depending on the activity, we rely on:
- Contract — to create and run your account, perform scans you request, and deliver paid features.
- Legitimate interests — to operate free/prospect checks for school staff who request them, send related service reminders (with unsubscribe), protect the platform, and improve the product in ways that do not override your rights.
- Legal obligation — where we must keep records for tax, accounting, or other legal requirements.
- Consent — where UK law requires it for a specific optional use (you can withdraw consent at any time without affecting prior lawful processing).
Processors and service providers
We use specialist providers to run PublishSentry. They process data only on our instructions for the purposes above:
- Vercel — application hosting and related infrastructure (and Vercel Blob when used for scan artefacts).
- Neon (or equivalent Postgres host) — database storage for accounts, organisations, and scan records.
- Resend — transactional and service email delivery.
- Stripe — payment processing and billing.
- Browserless (when configured) — real-browser fetching of public pages that block simple HTTP clients.
- Baidu Cloud OCR (when configured) — extracting text from scanned/image PDFs already published on a school site, so we can read review dates and similar content.
- OpenAI (when configured) — optional assistance for certain compliance-matching features on public page content.
Some providers may process data outside the UK. Where that happens, we use appropriate transfer safeguards required under UK GDPR (for example the provider's UK/EU-approved mechanisms or standard contractual clauses as applicable).
Retention
We keep personal data only as long as needed for the purposes above:
- Account and organisation data — while your account is active, then for a reasonable period afterwards so we can close the account cleanly, resolve disputes, or meet legal record-keeping duties.
- Scan jobs, findings, and reports — while needed to provide the service and history in your dashboard; older material may be archived or deleted when no longer required.
- Prospect / free-check records — while monitoring or follow-up is relevant, or until you unsubscribe / ask us to stop.
- Billing records — for the period required for tax and accounting.
- Security logs — for a limited operational period unless needed longer to investigate an incident.
Your rights
Under UK GDPR you may have the right to access, rectify, erase, restrict, or object to certain processing, and to data portability where it applies. You may also complain to the UK Information Commissioner's Office (ICO). To exercise a right, email hello@publishsentry.com. We may need to verify your identity before acting on a request.
Children and school contexts
PublishSentry is aimed at schools and adult staff users, not at children. We do not knowingly create accounts for under-13s. If you believe we hold a child's personal data in an account context that should not be there, contact us and we will delete it promptly.
Schools remain controllers of their own websites and of any personal data they publish. Our role is to check what is already public when you (or your organisation) ask us to monitor a site.
Cookies
We use essential cookies for security and signed-in sessions. We do not currently use advertising cookies. Full details are in our cookie notice.
Security
We take practical steps to protect accounts and reports (including HTTPS, hashed passwords, and unguessable report tokens). More detail is on our security page.
Related documents
See also our terms and conditions, cookie notice, and security page.
Changes
We may update this policy from time to time. The "Last updated" date at the top will change when we do. If a change is material, we will take reasonable steps to highlight it.
Contact
Privacy requests and questions: hello@publishsentry.com.