Skip to main content

Safeguarding

Information for designated safeguarding leads, headteachers and computing leads

This page describes how Zippylang works in practice, so that a designated safeguarding lead (DSL) can assess it against the school's own policies and its duties under Keeping Children Safe in Education (KCSIE).

We have tried to describe what the product actually does today, including its limitations. Where a control does not exist, we say so rather than implying it does.

Zippylang is not a filtering or monitoring system. It does not replace the appropriate filtering and monitoring your school is required to have in place under KCSIE. Zippylang should be used alongside your existing provision, with the usual supervision you apply to any online classroom activity.

Pupil accounts and access

  • A class join code is required. A pupil cannot create an account without the join code for a specific class. Teachers control who is given that code.
  • No pupil email addresses. Pupils do not have an email address on the platform, are never asked for one, and cannot receive email from us.
  • No pupil passwords. Pupils sign in with their name. A teacher may optionally set a 4-digit PIN for a pupil to use when returning to their account.
  • Teachers can remove pupils. Staff can delete a pupil account from the teacher dashboard, which also removes that pupil's progress records.
  • Staff accounts are separate. Teacher and administrator accounts use an email address and password, and the teacher and administration areas are not reachable without signing in.

Please note: pupil sign-in is designed for shared classroom devices and is deliberately lightweight — it is a convenience measure, not a strong authentication control. We recommend that pupils use Zippylang under normal classroom supervision, and that staff sign pupils out at the end of a session on shared devices.

What we hold about a pupil

We deliberately keep pupil records minimal. For each pupil we store:

  • Their first name and surname, used to tell classmates apart and to let a pupil find their own account when they return
  • The class they belong to, and its year group
  • Learning progress — lessons started and completed, scores, time spent, and experience points
  • An optional 4-digit PIN, if their teacher has set one

We do not ask for or store pupil email addresses, dates of birth, home addresses, phone numbers, photographs, or any special category data. We do not show advertising to pupils and we do not use pupil data for marketing.

AI tutor safety

"Zippy" is an AI tutor powered by Anthropic's Claude models. The following controls are built into the product:

  • A fixed role. Zippy operates under a system instruction that defines it as a language tutor for children aged 5–11, requires age-appropriate language, and instructs it not to discuss inappropriate topics, not to share personal information, and to steer off-topic conversations back to the language being learned.
  • Deferral to staff. Zippy's instructions tell it to keep the conversation on the language lesson and steer anything else back to it, and that if a child tells it something upsetting or worrying it must not investigate, must not promise to keep anything secret, and must tell them to speak to their teacher or a grown-up at home. Separately, and not left to the model at all, the most serious phrases are answered with fixed wording and the conversation is closed — see below.
  • Short, bounded replies. Responses are capped in length and only the most recent part of a conversation is sent to the model.
  • The browser cannot instruct the tutor. Zippy's instructions are assembled on our servers from the lesson your teacher assigned. The pupil's own words are passed to the model clearly labelled as something to reply to, never as an instruction to follow, and special characters in them are escaped so that text which looks like an instruction stays part of the message.
  • The conversation is ours, not the browser's. What the tutor has already said is carried between messages in a signed, expiring token that only our servers can create. A browser cannot invent an earlier Zippy reply, and a token that has been altered or has expired is refused before the model is asked anything.
  • Message limits. Each pupil message is capped at 500 characters and only the last few turns of a conversation are sent to the model.
  • Rate limiting. Requests to the AI tutor are rate limited to reduce misuse.
  • Access is tied to the school. AI features are only available while the school has an active trial or subscription, and the school is identified from the signed-in account rather than from anything the browser sends.

Concern flagging, and what it does not do

When a pupil's own message to Zippy matches an explicit, defined list of phrases a primary school would want to see — for example a disclosure of harm, or signs of real distress — we record a flag for staff in your school. Teachers and admins review these under Zippy flags in the teacher dashboard, and can mark each one reviewed with a note, which is kept as an audit trail.

For the most serious phrases, Zippy does not attempt to answer at all. It replies with fixed wording telling the child to speak to a trusted adult straight away. It does not ask what happened, does not offer advice and never promises to keep anything secret. That conversation is then closed: the child cannot send anything else in it, and nothing from it — including what they disclosed — is sent to the AI model at any later point.

What this is not. It is a defined list of phrases, not a monitoring or filtering system. The list itself is not published — we will share the current version with a school on request, and every flag records which version of it produced the flag. It will miss a concern worded differently from anything on the list, and it will sometimes flag something innocent. It does not replace your safeguarding procedures or your designated safeguarding lead.

Nobody is emailed or texted automatically. Flags are seen when a member of your staff opens the review page. If you need automated alerting to a named person, tell us before you start a trial — we do not have it yet and will not pretend otherwise.

If a pupil leaves. When you remove a pupil, everything else about them is deleted — their progress, their XP, their account. Their safeguarding flags and your reviews of them stay, as your school's record, with the direct pupil-account link removed. The bounded message excerpt is retained and may itself contain identifying information. The flags appear in the review queue as “Former pupil”. If your retention policy requires them to be removed as well, tell us and we will delete them for you.

We do not keep transcripts. Full conversations between a pupil and Zippy are not stored. Where a flag is raised we keep at most 200 characters of the message that raised it, which is the minimum a designated safeguarding lead needs in order to act. Retaining whole conversations is a separate decision that we will not take without a data protection impact assessment and a published retention period agreed with schools. AI tutor sessions should still be treated as supervised classroom activity.

A school admin can switch the AI tutor off entirely, from School settings in the teacher dashboard. When it is off, the chat and the roleplay adventures are removed from the pupil interface and every request is refused by our servers, including a request made directly. We can also switch it off across the whole platform. If either switch cannot be read, the tutor is off: a setting we cannot confirm is treated as off rather than on.

Where data is stored

The Zippylang application is deployed to a London (UK) hosting region. Our database and staff authentication are provided by Supabase, and the AI tutor is provided by Anthropic.

For the current storage location of pupil data and the list of processors we use, please see our Privacy Policy, or contact us and we will confirm it in writing for your records.

Your responsibilities as a school

Zippylang is provided to schools, and the school remains the data controller for its pupils. We recommend that you:

  • Treat class join codes as you would any other classroom credential, and refresh them if one is shared outside the class
  • Include Zippylang in your existing online safety and acceptable use arrangements
  • Supervise pupil use of the AI tutor as you would any other online activity
  • Tell parents what you are using, and what is held about their child — our information for parents page is written in plain English for this purpose
  • Remove pupil accounts when a pupil leaves the school

Raising a concern or a question

If you have a safeguarding question about Zippylang, need documentation for a procurement or data protection impact assessment, or want to report something you have seen in the product, please contact us. We will respond to safeguarding enquiries as a priority.

Drakon Systems Ltd

Email: support@drakonsystems.com

Or use our contact form

If a child is at immediate risk of harm, contact your local children's social care service or the police. Do not use this page to report an emergency.