Sessportal — Privacy Policy
Operator: Jadon Irwin trading as JP Irwin Academy (ABN 68 645 483 536) Contact: support@sesswise.com Last updated: 10 August 2026 Version: 2026-08-10
1. Who we are and what this covers
Sessportal ("the platform", "we", "us") is software operated by Jadon Irwin trading as JP Irwin Academy. Tutoring businesses ("organisations") use Sessportal to run their classes, attendance, billing and family communication.
This policy covers:
- personal information we collect about the people who run organisations — the account holders, administrators and tutors who sign up and log in; and
- personal information we hold on behalf of an organisation about its families — students, parents and guardians.
Those two roles are different and it matters which one applies:
| Who decides what is collected | Who to contact | |
|---|---|---|
| Account holders, admins, tutors | We do | support@sesswise.com |
| Students, parents, guardians | The tutoring business does | That business — its contact details appear in its portal |
When a family's information sits in Sessportal, the tutoring business decides what is collected and why. We hold and process it on their instructions. If you are a parent wanting your child's records changed or deleted, contact the tutoring business first; we will help them action it.
2. Information we collect
2.1 Account information (account holders, admins, tutors)
Name, email address, password (stored only as a salted hash — we never store or can recover the plaintext), organisation name, business number where supplied, timezone and currency, chosen plan and seat count, and records of logins and failed login attempts.
2.2 Family information (held for an organisation)
Depending on what the organisation chooses to collect and use:
- Student records — name, preferred name, school year level, birth month and year, school, and the classes they are enrolled in. We do not collect a student's full date of birth. Month and year is deliberately the most precise date we hold, because it is enough to place a student and recognise a birthday while being materially less useful to anyone attempting identity fraud.
- Guardian records — name, email address, phone number where supplied, preferred language for communication, and which students they are linked to.
- Attendance — presence, absence and makeup records per session.
- Billing — invoices, payments, ledger entries and outstanding balances.
- Class notes and teaching records — including lesson notes and, where the organisation uses the feature, notes drafted from a lesson transcript.
- Assessment results — subject, assessment type and period, a letter grade and/or NAPLAN proficiency level confirmed by a parent or administrator. We do not collect sensitive information. See section 4.
2.3 Technical information
IP address, browser type, and session cookies. Sessportal sets three cookies,
all strictly necessary for the service to function: sess_access and
sess_refresh (keeping you signed in) and csrf_token (protecting form
submissions against cross-site request forgery). We do not use advertising
cookies, tracking pixels, or third-party analytics on Sessportal.
3. Why we collect it and what we do with it
We use account information to provide the service, authenticate users, bill organisations for their subscription, and send service messages such as password resets and trial reminders.
We use family information only to deliver the features the organisation is using: recording attendance, generating invoices, showing parents their child's progress, and passing information between the organisation's connected products where the organisation has enabled them.
We do not sell personal information. We do not use family information to train machine-learning models, and we do not use it for advertising.
4. Sensitive information — we don't collect it
Some information carries a higher bar under Australian privacy law: health and medical information, and anything revealing racial or ethnic origin.
Sessportal does not collect any of it. There is no medical, allergy, behavioural, diagnosis or nationality field anywhere in the product, and organisations cannot add one — the registration form is assembled from a fixed catalogue we provide, and no sensitive component exists in it.
Two deliberate consequences:
- We record a student's birth month and year only. We never collect a full date of birth.
- Assessment results are recorded as structured fields — subject, type, period, grade or NAPLAN proficiency — rather than uploaded report documents or free-text comments. Medical, diagnosis, disability, NCCD/learning-adjustment, behavioural and nationality content is excluded and cannot be saved.
If a tutoring business needs to know something of this kind about a student, it arranges that outside Sessportal.
5. Who we share it with
We share personal information with the service providers we need to run the platform, and with no one else except as described here or as required by law.
| Provider | Purpose | Where it is processed |
|---|---|---|
| Neon | Database hosting (all application data) | Singapore |
| Render | Application hosting | United States |
| Postmark | Transactional email | United States |
| Cloudflare | DNS and network protection | Global |
| Stripe | Platform subscription billing (when enabled; not family tuition payments) | United States, Australia |
| Cloudflare R2 | File attachment storage (when enabled) | Global |
| Anthropic | Drafting lesson notes and extracting structured assessment fields from a transient report image/PDF (when enabled) | United States |
Because several of these operate outside Australia, using Sessportal involves disclosure of personal information overseas, principally to Singapore and the United States. We take reasonable steps to ensure overseas recipients handle it consistently with the Australian Privacy Principles.
Connected products. Where an organisation enables a connected product such as WriteTut, information moves between that product and Sessportal so a parent can see their child's work in one place. Those products are operated by the same entity and under this same policy.
Note on AI-drafted notes. If an organisation enables note drafting, the lesson transcript is sent to Anthropic's API to produce a draft. Anthropic says it does not use commercial API inputs or outputs to train its models by default. The feature is available only where the organisation has enabled it and submits a transcript for drafting.
Note on assessment extraction. A parent or administrator may choose to send a school-report photo or PDF to Anthropic's API so proposed structured fields can be extracted. The source file is held in memory only for that request: Sessportal does not write it to its database, disk, logs or file storage. The user sees and can correct every proposed field before anything is saved. Anthropic states that standard API inputs and outputs are automatically deleted from its backend within 30 days, subject to its stated exceptions (including usage-policy enforcement and legal requirements). Sessportal uses the Messages API directly, not Anthropic's longer-lived Files API. Anthropic's current commercial-product retention information is available in its Privacy Center.
6. Security
We hold personal information with the following protections: passwords stored as salted hashes; sign-in tokens stored only as SHA-256 hashes, single-use and short-lived; session cookies marked HttpOnly, Secure and SameSite=Strict; secrets encrypted at rest with AES-256-GCM; database access over TLS; account lockout after repeated failed sign-ins; and strict separation between organisations so one business can never read another's records.
No system is perfectly secure. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
7. How long we keep it
We keep information for as long as the organisation's account is active. After an account closes we generally retain financial records (invoices, payments and ledger entries) for at least five years from the relevant transaction or record, in line with the ATO's general business-record requirements. We may keep a record longer where another law, an audit, a dispute or an active claim requires it. We delete other personal information within 90 days of closure or of a valid deletion request, whichever comes first.
Where a family asks an organisation to delete a student's record, records tied to issued invoices are archived for the applicable record-keeping period rather than immediately destroyed, because a business must be able to substantiate money it has charged.
Structured assessment results are deleted when the student is archived as having left the tutoring business. They are not financial records and are not restored if the student later returns.
8. Your rights
You may ask us to give you a copy of the personal information we hold about you, correct it if it is wrong, delete it, or withdraw a consent you previously gave. You may also complain about how we have handled it.
Email support@sesswise.com. We will respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
If you are a parent asking about your child's records, contact the tutoring business first — they decide what is held and we act on their instruction.
9. Children
Sessportal holds information about children, provided by their parents or guardians and by the tutoring business teaching them.
Students under 15 do not create their own accounts unless their parent or guardian arranges it, and consents relating to a student under 15 are given by a parent or guardian. A student aged 15 or over may exercise their own privacy rights where they have the capacity to understand what they are agreeing to. We collect the minimum needed to run a class and, as noted above, deliberately do not hold full dates of birth.
10. Changes
We may update this policy. The version and date at the top change whenever the text does. Where a change materially affects how we handle personal information, we will tell affected account holders by email before it takes effect.