Skip to main content
tech futures.

Privacy Policy

Last updated: 27 August 2026

This policy at a glance

For teachers, principals and parents deciding whether our platform is right for their students:

  • Students are anonymous to TFA by design. We do not offer student accounts, sign-ins or access codes, and we do not ask students for names, email addresses or contact details. Like any website, ours processes limited technical information when someone visits, and embedded content may process information when it is used. The policy explains both.
  • Course progress stays on their device. Progress is stored in the student's own browser, not sent to us. Nothing entered into a certificate is transmitted to or stored by us.
  • Teachers can't add student data to their accounts. Accounts have no fields for student names or class lists.
  • We do not track anonymous visitors across visits. We use no advertising or profiling technologies, and our cookieless analytics do not join an anonymous visitor's activity across visits or devices. Students are always in this group — they have no accounts, and nothing is ever linked to them. Signed-in teachers and educators are the one exception: we associate your own platform use with your account in our analytics, using a random identifier, so we can understand how educators use our resources over time — and you can ask us to unlink it at any time.
  • AI activities are privacy-protective by design. Students choose from pre-approved options rather than typing freely. We do not store conversations or chat history. Students only work with files we provide, and the AI providers we use do not train on what is sent, which never includes anything that identifies a student.
  • The only accounts are teacher and educator accounts. We collect the account holder's name, email, school and role, together with their sign-in details. Accounts do not store learning records. We share this only with the service providers who run our platform (or where the law requires it, or in the limited circumstances set out in this policy), and never sell personal information.
  • Your rights and choices. Ask for access or correction at any time, and you can ask us to delete your information too, subject to records we have to keep — we respond within 30 days.

This summary is for convenience. The full policy below is what applies.

Tech Futures Australia Ltd (ABN 97 662 365 120) ("Tech Futures", "we", "us" or "our") is committed to protecting your privacy. This policy explains what personal information we collect through our programs website, techfutures.org.au (including our online learning platform), and through our AI learning environment, Lumen, at lumenlearn.ai, how we use it, and the rights and choices you have. We handle personal information in line with the Australian Privacy Principles (APPs). We adopt the APPs as our privacy standard by choice — as a small charity, TFA is not currently required by the Privacy Act 1988 (Cth) to comply with them — and we stand by every commitment in this policy. We will also comply with any privacy laws that otherwise apply to us.

Who we are

Tech Futures Australia is a not-for-profit digital technology education charity. This website hosts our online courses, lessons, careers resources and learning platform for students and teachers. Our AI learning environment, Lumen, at lumenlearn.ai, is part of the same platform and is covered by this policy; references in this policy to our site include Lumen. Our organisational website, tfa.org.au, has its own privacy policy, available at tfa.org.au/privacy. If you have any questions about this policy or your personal information, contact us at support@tfa.org.au.

Information we collect

Accounts on our learning platform are for teachers and other educators only. We do not invite or knowingly permit students to register for an account — students do not need one, and are not asked for names, email addresses, contact details or other identifying details (see "Students and children's privacy" below). We only collect information we need to run our site, deliver our programs and stay in touch with the people who ask to hear from us. Depending on how you use our site, this may include:

Account information — when you create a teacher or educator account or log in, we collect your name, email address and the encrypted credentials used to authenticate you. Accounts and sign-in are managed using Google Firebase Authentication.

School and role information — when registering, educators may select their school from a list of Australian schools (sourced from ACARA) and their role (for example teacher, principal or deputy/assistant principal).

Learning activity — we do not collect learning progress. For everyone who uses our courses, with or without an account, progress is stored locally in the browser on their own device and is not sent to or stored by us. Signing in to a teacher or educator account unlocks access to additional teaching resources; it does not create a record of your progress, quiz responses or anything similar.

Newsletter and updates — if you subscribe to our newsletter or updates, we collect the details you provide (such as your name and email address) so we can send them to you.

Event registrations — if you register for one of our events (for example a careers day), we collect the details you provide to manage your attendance and follow up afterwards.

Surveys — if you take part in one of our surveys, we collect your responses, along with any contact details you choose to give.

Program waitlists — if you join a waitlist for one of our programs (for example the National AI in Schools Program), we collect the details you provide so we can contact you about it.

Technical and usage data — technical information such as browser type and version, device information, and the pages you visit and how you interact with our site. We use this to keep our site secure and to understand and improve how it is used. Like any website, ours needs your device's IP address to deliver pages and keep the site secure. The providers that host and protect our site may keep it, or information derived from it, in technical logs for security and operational purposes. Umami, our analytics service, does not log or store your IP address (see "Cookies, analytics and similar technologies"). If you are signed in to a teacher or educator account, we also link this usage information to your account in our analytics, using a random identifier, so we can understand how educators use our resources over time; you can ask us to unlink it at any time (see "Cookies, analytics and similar technologies" and "Your rights and choices").

Communications — if you contact us or subscribe to updates, we keep a record of that correspondence.

Students and children's privacy

Our learning content is used by students in schools, and protecting student privacy is a priority. Our site is free and open, and students use it as anonymous visitors. In practice this means:

  • Students do not need accounts, sign-ins or access codes, and we do not invite or knowingly permit students to register for one. They use our learning content in the same way as any visitor to a public website.
  • We do not collect identifying information about students, such as names, email addresses or contact details, through our site.
  • Where a student works through a course, any progress is stored locally in their own browser, on their own device, and is not sent to or stored by us.
  • Certificates a student generates are produced in their own browser. Nothing entered into a certificate is transmitted to or stored by us.
  • Teachers do not enter student names, class lists or other student details into their accounts. There is no function for doing so — teacher and educator accounts hold only the teacher's own account details, and no learning records of anyone, teacher or student.
  • We do not use student information for advertising, profiling or any commercial purpose, and we do not sell any personal information.

Because our site is open, the same privacy-protective analytics that run across our site also run on the pages students use. They run without cookies, so for anyone using our courses and learning content without an account — which always includes students — each visit is treated as anonymous and is not recognised or tracked from one visit to the next. The random identifier we use to understand how signed-in educators use the platform is never created for a student: students have no accounts, so nothing is tied to a student's identity, because there is no student identity to tie it to. Security tools such as reCAPTCHA run only on our sign-up, waitlist and newsletter subscription forms, and so do not run on our courses and learning content.

Some of our courses include AI-powered learning activities. How we protect student privacy in those activities is described in "AI learning activities" below.

If you have any questions about student privacy, please contact us at support@tfa.org.au. If we become aware that a student has provided personal information to us, we will assess whether we could have collected it consistently with this policy and our APP-based privacy standard. If not, we will take reasonable steps to delete or de-identify it as soon as practicable, unless we are required or authorised by law to retain it. If we learn that a student has created an account, we will close the account and delete or de-identify the associated information in the same way.

AI learning activities

Some of our courses include AI-powered learning activities, delivered through our AI learning environment, Lumen, at lumenlearn.ai. Students reach Lumen through our courses at techfutures.org.au, or by a direct link from learning materials provided by one of our partner organisations. However a student arrives, the same protections in this section apply. Here students can explore how artificial intelligence works, for example by generating text or images within a guided activity. We have designed these activities to protect student privacy by default.

  • Students do not need an account or sign-in to use them, and they are not asked to type in free text. Students work within a guided activity and choose from pre-approved options, and cannot use these activities to access the open internet.
  • Some activities involve a file, such as an image or a document. Students only ever work with files we provide: the platform checks every uploaded file against the approved file for that activity, and anything that was not supplied by us is refused and not stored. This means students cannot introduce their own content.
  • Where an activity uses a file in this way, it is held only briefly, in storage located in Australia, and is automatically deleted within 24 hours.
  • We do not store conversations or chat history from these activities.

To produce a response, these activities send pre-approved prompts and approved activity files to established commercial AI providers (currently Google, OpenAI and Anthropic). Requests are routed through Vercel's AI Gateway, which does not retain the prompts, files or outputs, and passed on to the relevant provider. We do not send anything that identifies a student. These providers do not use what is sent to train their AI models and, with one exception, do not retain it at all, including for image generation and editing. The exception is one older OpenAI text model, kept so students can compare older and newer AI, where OpenAI retains what is sent for up to 30 days solely to detect and prevent misuse. Because these providers are based overseas, please also see "Overseas disclosure" below.

Cookies, analytics and similar technologies

We take a deliberately minimal approach. We do not use cookies or similar technologies to track you or to build profiles of individuals, and we do not use any advertising, remarketing or ad-targeting technologies. Anonymous visitors are not recognised from one visit to the next; if you sign in to a teacher or educator account, your browser keeps you signed in so that we recognise your account when you return (see "Staying signed in" below). Because we do not track you in this way, our site does not display a cookie-consent banner.

  • Analytics. We use Umami, a privacy-focused analytics service, to understand how our site is used, such as which pages and resources are viewed. It runs without cookies and does not collect or store personal information; anonymous visitors are not recognised from one visit to the next, and Umami does not log or store your IP address. If you sign in to a teacher or educator account, we associate your use of the platform with your account in our analytics using a random identifier, so we can understand how educators use our resources over time — you can ask us to unlink this at any time (see "Your rights and choices"). This is never done for students, who have no accounts.
  • Staying signed in. If you have a teacher or educator account, secure sign-in information stored in your browser keeps you signed in — including if you close your browser — until you sign out. It is used only to keep you signed in, not to track you, and it is cleared when you sign out.
  • Security (Google reCAPTCHA Enterprise). We use reCAPTCHA to detect and prevent automated abuse such as spam sign-ups. It runs only on our sign-up, waitlist and newsletter subscription forms, not across the rest of our site. To do its job on those forms it may set its own security cookie; this is not used to track you. Use of reCAPTCHA is subject to Google's Privacy Policy and Terms of Service.

Where a third-party security or embedded-content provider sets a cookie, you can control or delete it through your browser settings.

Embedded content from other websites

Pages on our site may include embedded content (for example videos, images or interactive activities) from other websites. Where we embed video, we use privacy-enhanced (no-cookie) mode where the provider offers it, so that the provider does not set cookies unless you play the video. Embedded content otherwise behaves as though you had visited the other website directly, and those third-party sites may collect data about you, use cookies and monitor your interaction with that content.

How we use your information

We use personal information to:

  • create and manage teacher and educator accounts and provide access to courses and resources;
  • operate, secure, maintain and improve our site and platform;
  • understand how our courses and resources are used — including, for signed-in educators, how they are used over time — so we can improve them;
  • respond to your enquiries and provide support;
  • manage event registrations and surveys;
  • send you newsletters, program updates and other information where you have asked to receive them or where permitted by law; and
  • meet our legal, administrative and reporting obligations as a registered charity.

Who we share your information with

We do not sell your personal information. We share it only with trusted service providers who help us run our site and programs, and only as needed to provide their services. These include:

  • Google LLC (Firebase Authentication and reCAPTCHA Enterprise) — sign-in and security. Google is based in the United States; its privacy policy is at policies.google.com/privacy.
  • Umami Software — privacy-focused website analytics. Data is limited to anonymous usage information (pages viewed, approximate location, device type) and, for signed-in educators, a random identifier linked to their account only in our own systems. Umami is hosted in the European Union.
  • Sanity — content management for our website content;
  • Vercel — hosting and delivery of our website; routing of requests in our AI learning activities through its AI Gateway, which does not retain the content of those requests; and brief storage of approved activity files in its Sydney, Australia region, automatically deleted within 24 hours;
  • Airtable — program administration and records;
  • Mailchimp (Intuit) — sending newsletters and program updates to subscribers;
  • AI providers for our learning activities (Google, OpenAI and Anthropic) — providing the AI models used in our Lumen learning activities. We send only pre-approved prompts and approved activity files, never information that identifies a student, and these providers do not use it to train their models.

We may also use or disclose personal information where required or authorised by law, or in the limited circumstances permitted under the APPs, which we apply as our standard — including where it is unreasonable or impracticable to obtain consent and we reasonably believe the use or disclosure is necessary to lessen or prevent a serious threat to the life, health or safety of any individual, or to public health or safety; where we reasonably believe it is necessary to take appropriate action in relation to suspected unlawful activity or serious misconduct connected with our activities; or where it is reasonably necessary to establish, exercise or defend a legal or equitable claim.

Overseas disclosure

Some of our service providers store and process data outside Australia, mainly in the United States and, in the European Union, for our content management system (Belgium) and our website analytics. These include Google, Vercel (a United States company, which hosts our website in the United States and routes requests in our AI learning activities through its AI Gateway), Airtable and Mailchimp (United States), Sanity (Belgium), Umami (European Union), and the commercial AI providers used in our Lumen learning activities (Google, OpenAI and Anthropic — United States). When our learning activities use these AI providers, we send only pre-approved prompts and approved activity files, and nothing that identifies a student. A temporary copy of an approved activity file is held in Vercel's Australian-based storage, in Sydney, and automatically deleted within 24 hours; to produce the requested output, a copy is also transmitted to the relevant overseas AI provider and handled under the arrangements described above. Where we disclose personal information overseas, we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles.

How long we keep your information

We keep personal information only for as long as it is needed for the purposes described in this policy, and to meet our legal and administrative obligations. In particular:

  • you can ask us to delete your personal information at any time, and we will do so, subject to any records we are required to keep for legal, administrative or security reasons;
  • where you have a teacher or educator account, the random identifier that links your usage to your account in our analytics is kept while your account is active, or until you ask us to unlink it;
  • we keep newsletter and updates subscription data until you unsubscribe;
  • we de-identify event and survey responses once the relevant reporting cycle is complete; and
  • any files used in our AI learning activities are held only briefly and automatically deleted within 24 hours (see "AI learning activities").

When information is no longer needed, we take reasonable steps to delete or de-identify it.

Your rights and choices

You can:

  • request a copy of the personal information we hold about you;
  • ask us to correct information that is inaccurate or out of date;
  • ask us to delete your personal information, subject to any records we are required to keep for legal, administrative or security reasons;
  • if you have a teacher or educator account, ask us to unlink your platform usage from your account in our analytics at any time; and
  • unsubscribe from our emails at any time using the link in the email or by contacting us.

To make a request, email us at support@tfa.org.au. We will respond within 30 days.

How we protect your information

We take reasonable technical and organisational measures to protect personal information against loss, misuse and unauthorised access, including encrypted authentication, access controls and reputable service providers. No method of transmission or storage is completely secure, but we work to safeguard your information.

We use the Notifiable Data Breaches (NDB) scheme as our data-breach response standard, even though it does not currently bind TFA as a legal requirement. If we suspect a data breach that may meet the scheme's serious-harm threshold, we will promptly assess it in line with the scheme. Where we have reasonable grounds to believe that threshold is met, we will inform the Office of the Australian Information Commissioner (OAIC) and notify affected individuals where practicable. If direct notification is not practicable, we will publish a notice on our site and take reasonable steps to publicise it, in line with the scheme.

Changes to this policy

We may update this policy from time to time. When we do, we will revise the "Last updated" date at the top of this page.

Contact us

If you have any questions, concerns or complaints about how we handle your personal information, please contact us at support@tfa.org.au. We will acknowledge your complaint, investigate the circumstances, ask for any further information we reasonably need, and give you our response and reasons in writing. We aim to complete this within 30 days; if we need more time, we will tell you why and when we expect to respond. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au for information about your privacy options and whether it can consider your complaint. Because we follow the APPs by choice rather than as a legal requirement, the OAIC may not have the power to investigate our handling of your information.