Australian company
Operated by Ten Labs Pty Ltd (ABN 15 696 155 192), incorporated in Australia.
Encrypted everywhere
TLS in transit and encryption at rest, on every plan, with no exceptions for schools.
No ads, no data sale
Student data is never sold, never used for advertising, never used to train AI models.
School-mediated consent
Students access SwiftsReader Schools through accounts their school creates and manages โ not open self-signup.
Who's responsible for your data
SwiftsReader is built and operated by Ten Labs Pty Ltd, an Australian company. We are the ones accountable for how student data is collected, used, and protected โ not a subsidiary of a larger platform, not a reseller.
How SwiftsReader Schools handles student consent
SwiftsReader Schools is supplied to schools for use by their enrolled students in Year 4 and above. Students access it through an account their school creates and manages, not through open self-signup.
- The school is responsible for obtaining any consent required under its own enrolment processes and applicable law before giving students access.
- We process student information โ reading progress, assignment submissions, AI Tutor conversations, and reward-profile selections โ solely to provide the educational service the school has contracted, for as long as the school's licence is active.
- Parents and guardians with questions about their child's data should contact their school first, since the school controls enrolment and account access. We assist schools in responding to these requests.
Full detail: Privacy Policy, Section 11.
Where data is stored, and how it's protected
Data is currently stored on infrastructure located primarily in the United States (Vercel for hosting, Neon/Prisma for the database), protected with TLS in transit and encryption at rest, with access restricted to authorised personnel. We disclose this location openly rather than leaving it implicit โ see our Privacy Policy for the full subprocessor list. Australian data residency is on our roadmap as we scale within Australia and New Zealand.
Security practices
- Dependency hygiene: in August 2026 we ran a full audit of every software dependency across the platform and patched all known vulnerabilities flagged by GitHub's security scanning โ this is now part of our ongoing release process, not a one-off.
- Authentication: account sign-in is handled by Clerk, a dedicated identity provider, rather than a custom-built auth system.
- Payments: handled entirely by Stripe โ we never see or store full card details.
- Least-privilege access: access to student data is restricted to what each service needs to function, not broadly shared across our systems.
Third-party services we use
We use a small number of specialist providers to deliver the service โ for authentication, payments, AI features, hosting, and email. Every one is named, with what it's used for and where it's based, in our Privacy Policy, Section 4. None of them are permitted to use student data for advertising or to train their own models on it.
Data retention & deletion
Account data and uploaded documents are retained for as long as an account is active. If an account is deleted, personal data is removed within 30 days, except where we're required by law to retain it longer.
Where we're heading on compliance
We're a young company โ SwiftsReader launched in 2026 โ and we'd rather be upfront about what's in place versus what's in progress than overstate either:
| Area | Status | Notes |
|---|---|---|
| Australian Privacy Principles | Built in | Our privacy policy and Schools consent model are designed around the APPs under the Privacy Act 1988 (Cth). |
| OAIC Children's Online Privacy Code | Building ahead of it | The Code is due to be registered by 10 December 2026. We're designing our Schools consent and data-handling model in line with its direction now, ahead of the deadline. |
| NSW Online Learning Tools Panel | In progress | Required before NSW public schools can purchase directly. We're working through this process; independent and Catholic NSW schools are not gated by it. |
| VIC / QLD / WA school-level adoption | Ready today | No state-wide panel applies to a curriculum tool like SwiftsReader in these states โ adoption happens at the school level, which our privacy and security documentation is built to support. |
| Formal certification (e.g. ISO 27001 / SOC 2) | Roadmap | Not yet undertaken โ realistic for a company at our stage. Planned as we scale beyond our first cohort of schools. |
Questions from a school or IT reviewer?
Happy to walk through any of this directly, or provide more detail than fits on this page.