Privacy and data

Privacy & data handling

Last updated: 31 August 2026

The short version

Students never create accounts on Tensile, and they never enter any personal information. They join a class with a code and pick a team from a preset list (Team Alpha, Team Bravo, and so on). There is nothing for a student to type that could identify them: no name, email, password, or profile. There is no advertising and no tracking of individuals on this site. We use Vercel Web Analytics, a cookieless service that counts page visits in aggregate only. It does not identify or profile visitors.

What we collect from teachers

Teachers create an account with an email address, a password, their name, their school, the school's county, and the school's type (for example community school, ETB, or voluntary secondary). The county and school type are used only to understand which kinds of school are using Tensile. They are not shared and are not used for advertising.

Passwords are stored only in hashed form by our authentication provider, so we never see or store them in plain text.

A teacher can have their account and everything in it deleted at any time by emailing hello@tensile.ie.

What we collect from students

Students don't type or provide any personal information. When they join, they choose a team from a preset list. The only data recorded against that team is:

  • Their challenge result: two numbers (load held and structure mass, in grams) and the time it was submitted.

The leaderboard shows the preset team name and its score, never a student's name. If a teacher wants to know which students are on which team, they keep that record in their own notes, off the platform.

Who can see what

  • The class leaderboard (preset team names and scores) is visible to anyone who has that class's join code, which in practice is the class and their teacher.
  • Teachers can see the participants and results of their own classes only.
  • Class data is not published anywhere else and is not indexed by search engines.

Where data is stored

Tensile runs on Supabase (database and authentication), Vercel (website hosting), Resend (account emails such as confirmations and password resets), and Cloudflare (the security check on the sign-in page), all operating as data processors. The database is hosted in the European Union, and data is transferred over HTTPS.

Your browser's local storage holds a signed-in teacher's session and, for students, the preset team they picked for a class, on that device only. We do not use advertising or tracking cookies. Page-visit counts are measured by Vercel Web Analytics without cookies and without identifying visitors.

Abuse prevention

To stop automated guessing of class codes, we briefly record the IP address of failed join attempts and count them for a short period. This is used only to rate-limit abuse, is not linked to any student or class, and is discarded automatically.

The teacher sign-in and sign-up pages carry a Cloudflare Turnstile check, which looks at browser and network signals to tell a person from a script. It runs on those pages only, never on any student page, and we do not receive a profile of the visitor from it.

Deletion and retention

When a teacher deletes a class, its submissions and team records are deleted with it. Teachers can also remove individual submissions during a session.

Schools, parents, or students can ask us to remove any data at any time. Email hello@tensile.ie and we will action it promptly.

Questions

If your school needs more detail for approval (data processing terms, infrastructure specifics, or anything else), contact hello@tensile.ie.