Skip to main content
← Back to Student Retainer

Student Retainer — Privacy Notice

Effective date: 31 August 2026
Last updated: 3 September 2026

This notice covers the free Student Retention Scan. You send us two exports from your Thinkific site; we read them, produce a report naming students who may be worth contacting, and email it to you. That is the whole service, and this notice describes exactly what happens to the data involved.

It does not cover any connected Thinkific application. There isn't one. There are no accounts, no logins, no passwords, no billing, and no connection to your Thinkific site.


1. Who we are

Student Retainer is a service of ABB Residential Limited (New Zealand company number 9297136), operated by Alex Bellis-Boag in New Zealand.

For privacy questions, or to ask us to delete your data, email alex@studentretainer.com. We aim to answer a question within 30 days, and in practice much sooner. A deletion request is faster and has its own clock: see section 6.

2. The two kinds of data, and our role in each

Your data — we are the controller. Your name, your email address, your Thinkific site address, your plan, your answers about your courses, and anything you tell us on a call. We decide how this is used, and we use it to deliver your report and talk to you about it.

Under the New Zealand Privacy Act 2020 this makes us an "agency". Under the GDPR it makes us a "controller".

Your students' data — we are your processor. Everything inside the two export files. We only handle it to produce your report, on your instructions, and for nothing else.

You remain responsible for that data. You are the controller; we act on your behalf. That means you are responsible for having a lawful basis to share it with us, and for whatever your own privacy policy tells your students about how their information is used.

Our obligations to you for your students' data are set out in full in our Data Processing Agreement, which forms part of our terms.

3. What is actually in the exports

We want you to know this before you upload, because most of it is not obvious.

You send the complete exports, and we use part of them. Each Thinkific Analytics export is a zip holding a whole dashboard — several files, not one — and Thinkific offers no smaller version. So we receive everything in those two zips, including files our analysis never opens. What follows is what is in them today, by category. Thinkific changes its exports from time to time; anything new that appears will arrive with them, and it is covered by everything this notice says.

Who your students are. First name, last name, email address, Thinkific user ID, and the date their account was created.

What they are enrolled in. Which courses, bundles and product types, when they enrolled, when access expires, and counts of enrolments by kind — courses, communities, coaching and webinars, and digital downloads.

How far they have got. Percentage viewed and percentage completed for each course, which individual lessons they have completed and when, how long they spent on each lesson and on the course as a whole, whether a certificate was earned and when it expires, and whether Thinkific counts them as new or returning.

How they have done on assessments. Quiz scores, how many attempts they started, completed and passed, and how long a typical attempt took.

When they were last around. When they last signed in, and when they were last active in each course.

Groups, and anything you have defined yourself. Any group a student belongs to, and whatever custom fields you have set up on your own Thinkific site. On a typical site those are things like company, job title and timezone, but they are yours to define and we have no control over what is in them.

What our analysis actually opens. Five of the files: the enrolment list, the student list, course engagement, lesson engagement, and enrolments over time — plus one count we use to detect an export that was downloaded with a filter left on. From those it uses enrolment and expiry dates, progress figures, lesson completion and timing, last sign-in and last activity, course names, and each student's name and email address, so your report can name them and you can contact them. The quiz file is never opened. Your custom field values also appear inside one of the files we do open, and nothing in the analysis uses them.

One thing to check before you upload. If you collect anything sensitive in a custom field, it will be in the file you send us — and we will hold it for the fourteen days in section 6 whether or not our analysis reads it. Take a look before you upload, and if you are unsure, email us first.

What is not in them. No payment details, no physical addresses, no dates of birth. We do not ask you for any of those separately either.

4. What we do with it

We read the exports, apply the same rules to every student, and produce a report listing up to 20 students in detail who may be worth your attention, with what was observed about each one and a draft message you can adapt.

A person reads that report before it is sent to you. That is deliberate: it is how we catch cases where the data has been misread. It also means one human being sees your students' names.

We never contact your students. Not by email, not in any other way. The report gives you a draft message; sending it is your decision and your action.

We do not put your data, or your students' data, into any AI system. The analysis is ordinary software following fixed rules, and the person who reviews your report reads it himself. Nothing you send us is used to train a model, ours or anyone else's. This is a commitment in our Data Processing Agreement, not just a description of current practice.

We do not build a profile of any individual across creators. We never sell your data or your students' data, we never share it for any purpose other than producing your report, and your finished report is sent only to you.

We may use anonymous, aggregated information — for example, how often a particular pattern occurs across all reports — to improve how the analysis works. Nothing in that can identify a student or a creator.

5. Where the data goes

Your files and your report go to four places, and no others:

WhoWhat they holdWhere
Tally (Tally BV)The form you fill in, and the two export files you uploadEuropean Union
Our own computerA downloaded copy of the exports, and your report while it is produced and for the 30 days afterNew Zealand
Google Workspace (Google LLC)The email carrying your report, which contains student names and email addressesUnited States
Google Workspace, our Sent folderOur own copy of that same email, for the same 30 daysUnited States

About Tally, and what we can and cannot tell you. Tally BV is a company under Belgian law with its registered office in Gent, and Tally states that its product is made and hosted in the European Union. We rely on Tally's own statement for that; we have not independently verified where the files sit. Tally's data processing agreement is published at tally.so/help/data-processing-agreement. It names the categories of subprocessor Tally uses — hosting, payments and communications — rather than the individual companies, and states that Tally is not required to disclose their identities. So we can tell you the categories behind Tally. We cannot tell you the names, because we do not know them either.

Nothing at Tally deletes itself. Tally keeps a response for as long as the form and the account exist, and removes it when the response, the form or the account is deleted. The fourteen days in section 6 is therefore something we do by hand, in two places — the response at Tally, and the copy on our computer — and not a setting that expires on its own.

The computer holding the working copies is not backed up to any cloud service and is not synced to one, so your students' data does not travel anywhere beyond the four places above.

Our website is hosted on Cloudflare. It is a set of plain pages with no forms, no scripts and no cookies. Like any web host, Cloudflare receives the ordinary request information your browser sends when you view a page: your IP address, your browser, which page, and when. It never receives an export file, a report, or anything about your students, and it does not carry our email — that runs on Google Workspace.

Encryption, and the one leg we do not control. Your files travel over encrypted connections when you upload them to Tally and when we download them, and Tally stores them encrypted. Your report leaves our mail server over an encrypted connection, but whether it stays encrypted the rest of the way depends on your own mail provider, which is not something we can promise on your behalf.

6. How long we keep it

  • The export files: deleted from Tally and from our computer within 14 days of your report being sent.
  • Your report: kept for 30 days, so it is still available if you want to talk it through with us, then deleted from our computer and from our Sent folder.
  • Your contact details and your answers about your courses: kept until you ask us to delete them.

One clock for deletion. Ask us to delete anything, at any time, by emailing the address in section 1, and we will complete it within two business days and confirm in writing when it is done. If you stop using the service without asking us for anything, everything we still hold is deleted within 14 days.

We delete by hand rather than automatically. We mention that because it is the truth, and because it means the timings above are commitments we keep rather than settings a system enforces. Every deletion is two actions, not one: the response at Tally, and the copy on our computer.

Two things that do not vanish the moment we delete them. Tally keeps backups of its systems and publishes no retention window for them, so a deleted response may persist in Tally's backups for a period we cannot tell you. An email we delete in Google Workspace goes to Trash, where Google removes it permanently after 30 days. Neither is a copy we can reach, read or use, and neither is something we can speed up. We would rather name them than let you assume deletion is instant everywhere.

7. Security

We are a small operation and we would rather describe what we actually do than list reassuring words.

  • Files travel over encrypted connections between you, Tally and us, and Tally stores them encrypted. The last leg — your report travelling from our mail server to yours — is encrypted where your own mail provider supports it, which is not in our control.
  • The computer holding the working copies is password-protected with full-disk encryption.
  • One person, and the software on his machine. Only one person handles your files, and nobody else has an account on that computer. What we will not claim is that a file is invisible to the programs on the machine holding it: ordinary software with access to that folder can read it. We keep your files away from any tool that would send them elsewhere, and the commitment in section 4 about AI systems is part of how we do that. "One person" describes who we let near your data. It is not a technical lock.
  • The working copies are not synced to any cloud service and not backed up to one. There is no second machine and no cloud folder.
  • If your data were ever exposed, we would tell you and the Office of the Privacy Commissioner as the Privacy Act requires, and we would tell you what happened rather than the minimum we could get away with.

8. Your rights

You can ask us to show you what we hold about you, correct it, or delete it. Email the address in section 1.

If your students want to exercise their own rights — to see, correct or delete their information — those requests go to you, because you are their controller. Tell us and we will correct or delete our copies within two business days and confirm it. If you need a copy of exactly what we hold about a particular student, ask and we will send it.

If you are in New Zealand and unhappy with how we have handled your information, you can complain to the Office of the Privacy Commissioner. If you are in Australia, you can complain to the Office of the Australian Information Commissioner. If you or your students are in the EU or UK, you can complain to your local supervisory authority.

9. Courses we cannot accept

Please do not upload exports from either of the following. If you do, we will delete the files and tell you why rather than produce a report.

Courses with students under 18. Several countries apply additional rules to children's data, and the exports give us no way to tell a student's age. We are not set up to handle this properly, so we would rather not receive it at all.

Courses whose subject matter makes the enrolment list itself sensitive. If knowing that someone is enrolled would reveal something private about them — a health condition, a recovery or support programme, a legal or financial difficulty, anything of that kind — then the list of names is sensitive information regardless of what the other fields contain. Please keep those sites out of this.

If you are unsure whether a course falls into either category, email us before you upload rather than after.

10. Changes

If we change this notice we will update the date at the top. If a change is significant, we will email anyone whose data we still hold.

← Back to Student Retainer

Student Retainer · New Zealand

Privacy Notice · Terms of Service · Data Processing Agreement · Contact Alex