All-In
How this classroom tool uses what you type
If you are a student
- What you give it: a nickname (use a first name or a nickname, never your full name), the room code on the board, and your answers, votes, words or buzzes during the lesson.
- What it never asks for: your email, student number, password, date of birth or anything else about you. You never sign in.
- Where it goes: to your lecturer's page and the classroom screen, in that room only. Your lecturer can hide names on the screen.
- How long it is kept: the room forgets you when the session closes. If your lecturer saves the results, the file holds the nicknames and answers from that session and is deleted automatically after 90 days, or sooner if the lecturer deletes it. Your phone remembers your nickname and the last room code so you can rejoin; clearing the browser's site data removes that.
- If a lecturer removes you from a room: your phone is told, and your answers come off that activity. A lecturer may also block a phone from the rest of that session. The block is on that phone's own identity in this service, not on your network address, so it never shuts out a classmate sitting beside you. Opening a new room clears it.
- Word clouds: words go onto the board as they are typed, through a filter or after the lecturer approves each one. Do not type anything about another person.
- Tools for students, and files your lecturer shares with your class: pages you open without signing in (a class's files through its room code). Nothing about you is recorded when you open or download something. A link marked "Open link" leaves this service for another website with its own rules.
If you are a member of staff
- Account: your College email address, a password that only this service uses (stored as a hash, never in clear), when you last signed in, and a log of administrative actions taken on or by your account. The six-digit confirmation code is emailed once, when you register, and never stored in clear. Logging in on a new device: the first time you log in on a computer or phone the service has not seen, it asks for a code as well as your password, emailed to you or shown by an authenticator app if you set one up. For each device you confirm, a fingerprint of a random token (not the token itself, and nothing about the device) is kept for 90 days. If you use an authenticator app, its secret key is stored encrypted, and only whether it is on and when it was set up is shown to an administrator, who can remove it if you lose your phone.
- Your faculty and department: if the College has switched on the staged roll-out, you choose the area you belong to when you register, and an administrator can change it. It is used to decide who may sign in while the service is being opened up area by area, to filter lists, and for counting how many sessions each area runs. It never limits what you can see: every tool and every shared course is available across the whole College. You may choose "Other, or prefer not to say".
- Your saved results: kept in a folder that only your account can list, download or delete. An administrator removing your account erases that folder with it.
- Class lists for the name spinner: stay in your own browser only (names and groups, never emails), one list for each of your rooms, are cleared after 90 days or when the room is deleted, and can be cleared at any time with "Clear list". Groups made from them are kept the same way. They are never stored on the server. The one exception is your choice: if you switch on Show on projector in the spinner, the names on show pass through the server to your room's projector, are held in memory only while they are on show, and are never saved or logged.
- Course libraries: an activity you share to a course carries your College address as the person who shared it, so colleagues and administrators know who to ask. If your account is removed, that name becomes "former staff" and the item stays with the course.
- Your collection: files, links and web pages you add are kept in your own folder and nobody can open them until you share an item with one of your rooms. Anyone with that room's code can then open what it shares, for as long as the room exists; deleting the room ends that. Do not share anything personal or confidential this way. Students see no name against a shared item. An administrator can see what your collection holds and how much space it uses, and can remove an item.
- What an administrator can see: your address, role and status, the area you chose, when you last signed in, whether your host page is connected right now and when it was last active (never from where), what you shared to courses, what your collection holds and its size, and the audit log of administrative actions. Tools for lecturers are for signed-in staff only. Your page signs itself out after two hours without activity (a running activity keeps it signed in); an administrator can change that time.
- Backups: the whole data folder (staff accounts, libraries, collections, results, settings) is archived on the server each night and the last fourteen archives are kept; the College may copy them to a store it controls. An administrator can download an export; every export and every restore is written to the audit log. An export leaves out the mail password and the live-room files, so a copy on a laptop cannot be used to read mail or to join a lesson that was running.
- Emails from this service: contain a code to type or a plain notice, never a link, and it never asks for your College password.
Storage on your device (cookies)
This service sets no cookies at all. It keeps a few small values in your browser's own storage so the page works: on a phone, a random identifier so you keep your seat if the page reloads, your nickname and icon, the room code and your Calm, text-size and colour choices; on a lecturer's PC, the sign-in token for this browser, a random token saying this browser has been confirmed for logging in (kept when you sign out, so the code is not asked for again), the projector's room code and the same display choices. These are needed for the service to work as you asked, are never used to track you, never leave this service, and go when you clear the site's data in your browser (the sign-in token also goes when you sign out or after two hours without activity). Because they are strictly necessary, no consent banner is required under the UK's PECR rules; this notice tells you they exist.
What is not collected
No advertising, no analytics from third parties, no cookies for tracking, and nothing is sent to any other service. During the pilot, anyone can send feedback, a suggestion or an idea from the Pilot button. A student's message is kept with nothing about who sent it: no name, nickname, room or address. A member of staff's message carries their College address only if they tick the box to include it. Administrators read these messages and delete them once they have been dealt with. If you tick "You can show this on the welcome page", your words (and any stars you gave) may appear in the welcome page's reel once an administrator has checked them, labelled only "A student" or "A lecturer"; a staff address is never shown there. Pictures a lecturer adds to quiz questions are stored once on the server under a random-looking name made from the picture itself, and are shown to the phones and projector in that quiz; they are removed a week after no saved quiz uses them. Usage counts kept for the administrator are totals only and never identify a person: for example how many sessions ran, how many ran in each faculty, and how many times each tool or class file was opened, never by whom.
How this is checked
The service is audited against published standards, most recently on 7 September 2026: OWASP Top 10:2025 and the Cyber Essentials Plus controls for security, WCAG 2.2 AA for accessibility, ISO 9241-110 and ISO 9241-11 for how it is to use, and ISO/IEC 25010 for product quality. Every finding was fixed and then checked again by a separate pass. These are internal audits: the wording is audited against, never certified. The findings and what was done about them can be shown on request.
Who to ask
Edinburgh College runs All-In and is responsible for the information it holds. For questions about this notice, or to see, correct or erase your data, contact the administrator of this installation at your College.
Data-protection enquiries and complaints go to the College's Data Protection Officer. If you are not satisfied with the College's answer, you can complain to the Information Commissioner's Office (ico.org.uk).
For help with accessibility, or to ask for something in a different format, contact the administrator of this installation at your College.
Last reviewed 14 September 2026.