bandwise.
PrivacyTermsSign in

Privacy Policy

Last updated 26 September 2026

Bandwise is an online workspace that helps IELTS teachers assess their students’ practice work. This policy explains what personal data Bandwise handles, why, and the choices you have.

1. Who is responsible

Bandwise is operated by Panagiotis Chatzigiannakis (“we”, “us”). Contact: hello@bandwiseapp.com.

We are the controller of teachers’ account data. For information about students that teachers add to Bandwise, the teacher (or their school) is the controller and we act as their processor: we handle it only to provide the service to that teacher and on their instructions.

2. What we collect

  • Account data: your email address and, if you sign in with Google, your name and profile picture from your Google account.
  • Sign-in and security data: session records, one-time sign-in codes (kept for 10 minutes), and the IP address and browser type of each session, used to keep accounts secure and to limit abuse.
  • Content you add: students’ names, email addresses, target bands and test types; essays, photos, PDFs and speaking recordings; transcripts, scores, feedback and your notes.
  • Settings: AI provider keys and email (SMTP) passwords you choose to save, which we encrypt before storing; your report branding, including any logo you upload.
  • Usage records: for each AI request, the provider, model, number of tokens used and an estimated cost.

3. Information from Google

If you choose “Continue with Google”, we ask Google only for your basic profile: your name, email address and profile picture (the openid, email and profile scopes). We use it solely to create your Bandwise account, sign you in and show your name in the app. We do not request access to your Gmail, Google Drive, contacts or any other Google data.

We do not sell Google user data, use it for advertising, or transfer it to others except as needed to run Bandwise (see section 5), for security, or where the law requires. Bandwise’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to train AI models.

4. How we use data

  • To provide Bandwise: store your workspace, run the assessments you ask for, produce reports and send them when you choose.
  • To run your account: sign-in codes, approval of new accounts, and messages about your account.
  • To keep the service secure and working, and to understand costs so we can price it fairly.

Our legal bases are performing our contract with you, our legitimate interest in running a secure and reliable service, and complying with legal obligations. We do not sell personal data, do not show advertising, and do not use your content to train AI models.

5. Who else handles data

  • Cloudflare hosts Bandwise and stores its database and files, and delivers Bandwise’s own emails (sign-in codes, account approval).
  • Google provides “Continue with Google” sign-in.
  • The AI provider you choose (OpenAI, Google Gemini, Anthropic Claude or Alibaba Qwen) receives the student work, prompt and rubric needed for a transcription or assessment, only when you request one. With your own API key, that provider processes it under your agreement with them. With the built-in “Bandwise AI” option, it is processed by Google Gemini under our account. While that option is in test mode it may run on Google’s free tier, where Google can use submitted content to improve its products, so it is limited to named testers using sample work.
  • Your own email provider sends the progress reports you email to students, through the mailbox you connect.

Some of these providers may process data outside the European Economic Area. Where they do, they rely on safeguards recognised under EU law, such as the European Commission’s Standard Contractual Clauses.

6. Where data is stored and how long we keep it

Bandwise’s database and files are stored with Cloudflare, currently in Eastern Europe. We keep account data while your account exists. Your content stays until you delete it or ask us to delete your account. Sign-in sessions expire after 30 days of inactivity, and sign-in codes after 10 minutes. After you ask us to close your account, we delete its data within 30 days, except where the law requires us to keep something.

7. Students and children

Bandwise is for teachers, not for students to use directly. Teachers are responsible for having a lawful basis to add their students’ information and work, including consent from a parent or guardian where a student is a child and the law requires it. Teachers should add only what they need, and can edit or delete a student’s information at any time.

8. Security

All traffic is encrypted in transit. Saved AI keys and email passwords are encrypted at rest. Each teacher’s workspace is separate, and uploaded files are only served to their signed-in owner. The exceptions are report logos, which are publicly readable so that emailed reports can show them. No system is perfectly secure, but we work to protect your data and will tell you about any breach that affects you as the law requires.

9. Cookies

We use only the cookies needed to keep you signed in. We do not use advertising or cross-site tracking cookies.

10. Your rights

You can ask to access, correct, export or delete your personal data, to restrict or object to how we use it, and to withdraw any consent. Email hello@bandwiseapp.com. Students whose information a teacher added should contact that teacher first; we will help the teacher respond. You can also complain to your data protection authority. In Greece, that is the Hellenic Data Protection Authority (dpa.gr).

11. Changes

If we change this policy, we will update the date above and, for significant changes, tell signed-up teachers by email before they take effect.

See also our Terms of Service.

Questions? Email hello@bandwiseapp.com.