Privacy statement

What we process, why, for how long, and what you can do about it. In plain language, because a privacy statement you do not understand is no statement at all.

This is an English translation for convenience. If the English and the Dutch version differ, the Dutch version applies.

If you are looking for the readable answer rather than the legal text, see Safety and privacy. It says the same thing in plain language, for each question a school asks. This page is the formal statement and is consistent with the data processing agreement.

1. Who is responsible for what

Two lines run through each other here, and keeping them apart saves a lot of confusion.

The school is responsible for student data. The school decides that GoYou is used and for what; GoYou processes that data solely on the school’s instructions and does nothing else with it. In legal terms: the school is the controller, GoYou is the processor. That arrangement is set out in the data processing agreement, which is part of the terms and conditions. A teacher who creates an account and invites students accepts that agreement on behalf of the school.

GoYou is responsible for the teacher’s own data. Your account, your profile and your use of the service: that is a relationship between you and us, and this statement applies to it directly.

The controller for your teacher account is GoYou B.V. Questions about privacy go to privacy@goyou.io. Our full company details are on the contact page.

2. Which data we process

As little as possible, and only what is needed to be able to teach.

From teachers
Email address, first name and an encrypted password to log in. In addition, your school type, your subjects and levels, the classes you create and your teaching preferences, because they make the material fit your way of working.
From students
First name, surname and an encrypted password, plus, for identification, an email address or a username that we create. An email address is not required. Also a chosen avatar and whatever the student fills in about interests, and the work itself: completed tasks, progress and the conversations with the AI tutor. In addition, we record which method someone uses to log in, when a teacher has had a recovery code or a recovery email created, when a teacher has changed a student’s recovery address, and when two profiles of the same student have been merged.
From everyone
Login times, timestamps and technical log files. We need these for security, troubleshooting and countering misuse.
When you sign up
If you sign up for the beta, we keep your email address, your name, your type of education and what you signed up for, until you unsubscribe.

With themes such as citizenship or personal development, a student may share something sensitive of their own accord. We never probe for that, and it is not used to categorise or assess anyone. If such a message points to a concern, GoYou automatically places a signal about it in the class overview of the student’s own teacher, with the excerpt included. GoYou itself does not draw any conclusions and takes no further action: the teacher knows the student and decides what is needed.

3. For what purpose, and on what basis

To create teaching material, to guide students through it, and to show the class’s own teacher how the class is doing. Nothing else: not for advertising, not to build profiles that claim something about someone, and not to train AI models.

For teachers’ data, the basis is the agreement you enter into with us: without that data we cannot provide the service. For students’ data, the school determines the basis; schools usually do so on the grounds of their statutory educational task. The school informs parents and students about this, because the school has that relationship and we do not.

4. How long we keep data

Two years after the last activity. That applies to everything: accounts, profiles, teaching material, completed tasks, tutor conversations and log files. One period for everything is easier to explain and easier to comply with than a table of exceptions.

Two things outside that: we delete sooner at the request of the school or of you, and a beta sign-up is removed as soon as you unsubscribe.

In all honesty: automatic clean-up after two years has not been set up yet. The first period expires in the course of 2028, so there is time for that. We would rather write that down than make a promise the system does not keep today.

5. Who we bring in

To make GoYou work, we bring in a number of parties: a database supplier that stores the data, a hosting supplier that runs the application, a European language model supplier that carries out all tasks involving student data, an American language model supplier that creates the teaching material and receives no student data in doing so, an email sending service, and the code host where our software is kept and where a sample of generated lessons is measured for quality every week. Who they are, what we use them for and where they process data is set out by name in the data processing agreement. We send it to any school that asks for it, even if you are not a customer yet.

What goes to a language model is what the task needs: when creating a lesson, your request and the lesson content; for a tutor conversation, the conversation itself plus the interests entered and how far that student has got in the lesson. Where the student’s name belongs in a text, a placeholder is sent and the real name is only filled in on the student’s own screen. What does not go there: names, email addresses, usernames, passwords, class lists and your school’s administrative data.

6. What happens outside the European Union

The database and the file storage are in Frankfurt, and since 21 August 2026 the application itself runs there too: the servers that handle your requests are in Germany, no longer in the United States. Email goes through a French provider. All student data is processed within the European Union. Two links in the chain process data outside the European Union, and no student data goes to them.

Creating teaching material runs through an American language model supplier. Your lesson request and the lesson content go there, and no student data. Our code host is in the United States and measures a sample of generated lessons for quality there every week. For both, the transfer takes place under the standard contractual clauses of the European Commission, which form part of those suppliers’ terms. Our hosting supplier is an American company; processing takes place in Frankfurt, but for management and support that supplier may access data from the United States, under the same clauses.

The tasks involving student data were moved to a European language model supplier on 27 August 2026. That supplier does not store or log input and output for longer than is needed to produce the answer, and does not use them to train models. If anything changes in the division above, we will report it here and to the schools we work with.

7. Your rights

You have the right to know which data we hold about you, to have it corrected, to have it deleted, and to object to processing.

If it concerns a student, such a request goes through the school: the school is the controller, and we help the school comply with it within the statutory time limit. In GoYou itself, a student sees which profile the tutor uses and can change it. If it concerns your own teacher account, you can contact us directly via privacy@goyou.io. We respond within one month.

8. Complaints

If you disagree with something, let us know first; most things are resolved faster that way than through a procedure. If you cannot resolve it with us, you can file a complaint with the Autoriteit Persoonsgegevens, the Dutch Data Protection Authority. If it concerns student data, that route goes through the school, because the school is responsible for that data.

If you suspect a breach or a vulnerability in our environment, report it to security@goyou.io. In the event of a data breach, we report it to the school concerned without undue delay, with what happened, which data is involved and what we are doing about it.

9. Changes

If something fundamental changes, for example because we replace a supplier or introduce a new feature that uses different data, we will update this statement and put a new date on it. Schools we work with will be notified.

Updated on 28 August 2026.