× Times Table HazeBack to practice
YOUR INFORMATION

Privacy

Last updated: 7 October 2026

Times Table Haze helps learners practise maths facts and return to facts that need more practice. This page explains the information the current beta handles.

A small amount of information, not anonymous accounts

Learners join a teacher's class using a class code or QR link, choose one to three initials and create a PIN. Duplicate initials receive a number. We do not ask learners for an email address, full name, date of birth, photograph, home address or school identifier.

Initials are pseudonyms, not a guarantee of anonymity. A teacher who knows the class may identify a learner from their initials, class and practice history. Treat learner progress as private information. Do not put children's full names or sensitive details in class names or other fields.

What is stored and why

Information stored and its purpose
InformationPurpose
Teacher name, email, account identifier and creation dateSign-in, managing classes and password recovery.
Class name, code, enrolment status, creation date and practice settingsJoining the correct class and applying the teacher's tables and session window.
Learner initials, account identifier, class association and creation dateKeeping each learner's practice separate and allowing return visits.
Password/PIN verification valuesChecking credentials without storing the original password or PIN as readable database fields.
Questions attempted, submitted answers, timestamps, answer and first-input timing, correction/interruption flagsSaving practice and deciding which facts to review.
Per-fact progress, review dates, evidence, active question queues and practice allocationsContinuing across sessions and devices, applying the daily limit and preventing conflicting saves.
Hashed session/reset tokens, expiry times and login-limit countersMaintaining sign-in, recovering accounts and limiting repeated guesses or requests.

The app receives network addresses to apply request limits. Its limit records use derived identifiers rather than a dedicated plain IP address field. Cloudflare also handles network addresses and other request metadata to deliver and protect the website; hashing a limit record does not make the whole service anonymous.

Answer timing guides practice selection. It does not prove recall or measure intelligence. Input method, interruptions and accessibility can affect timing.

Who can access it

A signed-in learner can access their own practice. A teacher can access their own classes and learner roster, including the last-practised information currently displayed. Other classes are restricted by server-side ownership checks. The service operator can access the database when supporting or maintaining the service.

Cloudflare hosts the website, application and D1 database. Resend delivers teacher password-reset and password-change messages, and messages submitted through the private request form. Resend receives the recipient email, message contents and delivery metadata, including the temporary reset link. Learner progress is not included in account emails. The request form collects your reply email, request type and message and sends them to the operator. Do not include student names, passwords, PINs or class lists. Request contents are not saved in the app database, but are processed by Resend and retained in the operator’s email inbox. There is currently no automatic deletion schedule for this correspondence.

There are no advertising features, public learner profiles, chat or marketing analytics integrations in the application. Practice questions and feedback are generated by the application's rules; answers are not sent to a generative AI service for marking.

In browsers that support it, the app exposes a read-only browser tool containing fact progress and review dates. A browser assistant with access to the page may read that information. This integration does not automatically send progress to an AI service. Schools can use an ordinary browser without that capability.

Where processing occurs

Cloudflare operates globally. We do not promise Australian-only processing or storage. Recent database requests have been served in Oceania, but that observation is not a contractual data residency guarantee.

Resend is configured to send from Tokyo. Its documentation states that account data, including email metadata, logs and API records, is stored in the United States regardless of sending region. Schools should assess overseas processing before using the service with students.

Cookies and shared devices

The app uses a secure, browser-inaccessible sign-in cookie with a seven-day lifetime and a one-day device cookie for login protection. These support accounts and security. Signing out removes the active sign-in. A browser's own security features and Cloudflare may also use technical cookies under their policies.

Sign out when finished on a shared device. Closing a tab does not necessarily sign out. Keep PINs private and ask the teacher for a temporary reset PIN if needed. A learner must choose a new PIN after redeeming the temporary PIN.

Retention, access and deletion

There is currently no automatic removal of inactive teacher accounts, classes or learner progress, and no self-service account/class deletion button. Information remains stored until it is removed through maintenance. Expired credentials stop working at expiry; expiry does not mean every associated database record is immediately deleted.

Contact the service operator through the private request form on this page to request access, correction or deletion, or to report a privacy concern. Parents and carers should begin with their child's teacher so the correct class and learner can be identified. Do not send passwords, PINs or full class lists by email. The operator will need to verify that a request is authorised before disclosing or changing information.

A retention schedule, deletion workflow and tested backup/restore procedure are later readiness steps. We do not yet promise a fixed deletion turnaround or that information immediately disappears from providers' recovery copies. Requests must be checked against the current provider arrangements.

Security and changes

HTTPS, protected session cookies, teacher ownership checks, credential hashing and request limits are in place. The beta has not undergone an independent security audit. The stronger teacher password-hashing upgrade remains deferred on the current free hosting configuration. Use a unique teacher password.

If the service's data handling changes, update this page before introducing the change. If you suspect a privacy or security problem, contact the operator without including other learners' data or account secrets.

Contact and information requests

Send a request privately to the operator. Parents and carers should start with their child’s teacher. Requests are checked before information is disclosed or changed.

Do not include student names, class lists, passwords or PINs. Your reply email and message will be emailed using Resend and kept in the operator’s inbox.