Template: fill in the bracketed details and have it reviewed before launch.
[Business or trading name], [address], contact [email]. We are the data controller for Timetable Creator.
Your email address and a securely hashed password; the timetable sessions you upload or type in (titles, times, rooms, groups, staff names); your term dates; any assignment deadlines and exam dates you add; any placement shifts you log (dates, times, breaks, placement names, notes and whether you missed the shift), teaching sessions you mark as missed, and the hours target and earlier hours you enter; any feedback you send us (a rating from 1 to 10 and optional comments); payment records from Stripe (we never see card details); the country your connection comes from, which Cloudflare works out from your IP address so we can show prices in your currency (we don’t store it, although Stripe records the country and currency of any payment); and basic server logs.
Files you upload are read in memory to find your sessions and are then discarded. We don’t store the original files.
When a file is read by the smart reader, we keep what was read from it (the sessions, not the file) together with a fingerprint of the file, for up to 180 days after it was last uploaded. If anyone uploads exactly the same file again, for example another student on the same course, we reuse that reading instead of sending the file to Anthropic again. This copy isn’t linked to your account, and it can only be matched by someone who uploads an identical file.
Shifts you log and sessions you mark as missed are used to count your hours, to show your shifts next to your teaching, and to fill your private shifts calendar. We only record whether a shift was missed, not why, so you don’t need to give us any health details. Notes are stored exactly as you type them.
Your shifts calendar has its own private link. Anyone who has the link can see your shifts, and you can replace it at any time from the Hours page. Deleting a timetable doesn’t delete your shifts; deleting your account does.
When you send feedback from your Account page, only our team can see it unless you tick the box to share it. If you tick the box, your rating and comment may appear on our home page. They are shown with your nursing field (for example “Adult nursing student”) and the month you sent it. Your name, email address and account details are never shown. We show up to 12 of the most recent shared comments and may choose not to show, or later remove, any comment.
You can stop sharing a comment at any time. Go to Account, open “Feedback you’ve sent” and choose “Stop sharing”. It is taken off the website straight away. Deleting your account deletes all your feedback.
To provide the service you’ve paid for (contract), to keep the service secure (legitimate interests), to read your feedback and improve the service (legitimate interests), to show comments you chose to share on our website (consent, which you can withdraw at any time), and to meet tax and accounting duties (legal obligation).
Stripe (payments), Cloudflare (which carries all traffic to the site), our hosting provider [name], and, if smart reading is switched on, Anthropic, which processes the text of uploaded timetables to extract sessions under its commercial terms.
Your account, timetables, shifts and feedback until you delete your account. A shared comment stays on the website until you stop sharing it, we remove it, or you delete your account. Payment records for 6 years for tax purposes.
You can access, correct or delete your data. Delete your account at any time from the Account page. You can complain to the Information Commissioner’s Office (ico.org.uk).