Skip to content

Acceptable Use Policy

Last updated

The small number of things you must not do with a ScholarDeck account.

Draft, not yet legally reviewed

This document is published for transparency while it is being reviewed by our legal advisers. It is not yet a binding agreement. If you are evaluating ScholarDeck for your school and need the final version, please ask us.

The rules

Do not use the service to:

  • Attempt to access data belonging to a school you are not a member of, or to escalate your own permissions.
  • Probe, scan or load-test the service without our prior written agreement. We welcome genuine security reports, see below.
  • Upload malware, or content that is unlawful, harassing, or harmful to a child.
  • Send bulk messages to parents or staff that are unrelated to the school's operation.
  • Resell or sublicense access, or use the service to build a competing product.

Reporting a security issue

If you believe you have found a vulnerability, email us through our contact page with enough detail to reproduce it. Please do not access, modify or retain anyone else's data while investigating, and give us a reasonable chance to fix the issue before disclosing it. We will not pursue action against anyone who reports in good faith and within these bounds.

Enforcement

We may suspend an account that breaches this policy. Where the breach threatens other schools' data or the stability of the service, we may act immediately and explain afterwards.

The other documents

If you would rather have this in plain language than legal language, the same ground is covered on is your data safe with us.