Privacy
Last updated: 30 September 2026
senco is designed for sensitive school SEND information. Observation text, student profiles, reasoning outputs, interventions, and escalation tasks are scoped to the signed-in user’s organisation.
The system is non-diagnostic. Stored reports are intended to support professional review, school SEND pathways, and accountable intervention planning.
Production deployments should use approved data-processing agreements, role-based access, secure email delivery, and school/trust retention policies before live pupil data is entered.
Who we share data with
senco uses the services below to run. Each receives only what is listed here, and only to do the job described.
- OpenAI — AI behaviour extraction, when a signed-in member of staff asks senco to pick out the behaviours in an observation with an AI model. It receives the observation text exactly as it was written — which can include a pupil's name and details of their needs, behaviour and wellbeing — with senco's fixed instructions. It is not sent the pupil's profile, year group or school, or anyone's account details. A connection check an owner or SENCO can run from Settings sends a made-up observation, never a real one.
- Brevo — delivering the emails senco sends. It receives the recipient's email address and the email itself: sign-in, password-reset and verification links, email-change confirmations (with the new address), team invitations (the school's name and the role offered), and escalation, pathway and review notifications and reminders — which name the person they are for and the pupil concerned (display name and year group), with the risk level, the review action or meeting pack, and any message a colleague added.
- PostHog — product analytics — understanding which parts of senco are used. It receives senco's internal reference for the signed-in person (never their name or email address), what they did — for example saving an observation or raising an escalation — and the internal references, counts, roles and risk levels that go with it. Never a pupil's name or the text of an observation.
- Vercel — running the application. It receives every request to senco and every response it sends, which is everything described on this page.
- Neon — storing senco's database. It receives everything senco keeps: accounts, schools, pupil profiles, observations, reports, reviews, escalations and the audit trail.
AI behaviour extraction
senco’s reasoning — the behaviour domains, possible needs, interventions and escalation it suggests — runs inside senco without AI. Picking out the behaviours in an observation can be done by senco’s own ontology or, when a signed-in member of staff asks for it, by an AI model from OpenAI.
When AI extraction is used, senco sends OpenAI the observation text as written, and nothing else about the pupil, the school or the person asking. Because an observation can name a pupil and describe their needs, write observations with that in mind. Nothing is sent to OpenAI from the public demo, which uses the ontology only.