Learning without
pupil profiles.
Spellwell does not ask children for a name, email address or account. There are no adverts or advertising trackers.
Last updated: 15 September 2026.
Who runs Spellwell
Spellwell is operated by Mark Brackenborough, an independent parent and developer. Mark is responsible for the personal information described in this notice. For privacy questions or requests about your information, email support@spellwell.uk.
What stays on your device
Practice history and effort stars are stored in this browser using IndexedDB. They are not sent to our servers or to the teacher. Handwriting stays on the current screen. Temporary practice does not save the session. You can clear saved progress from the practice page.
Teacher information
Teacher sign-in uses an email address, expiring sign-in links and a necessary session cookie. The shared database stores teacher-managed school labels, class labels, spelling lists and access settings. Account deletion removes the teacher’s account and content from the active database.
Shared links
Anyone with a class or weekly link can read the published content it opens. Never include pupil names or sensitive information in a spelling list. Shared practice pages ask search engines not to index them, but that is not an access restriction.
Connections, email and sound
Cloudflare hosts the website and database and processes connection information such as IP addresses to deliver requests. Spellwell does not enable Cloudflare Workers Logs, create application request logs or export database backups. Short-lived hashed rate-limit identifiers help prevent misuse; practice answers are not stored on the server. Resend processes teacher email addresses and sign-in messages to deliver sign-in links. Sound uses a local British English speech voice where the browser identifies one as available.
When you contact us
If you email for help or to share feedback, we will receive your email address and the information in your message and use them to respond. Cloudflare Email Routing forwards support messages to our working mailbox. Please don’t include children’s names or other sensitive pupil information.
How long information is kept
Sign-in links expire after 15 minutes and sessions after 14 days. Expired authentication and rate-limit records are removed by a daily cleanup. Teacher accounts and spelling content remain until the teacher deletes the account.
Cloudflare D1 automatically keeps short recovery history for up to seven days on the current plan, so deleted database information can remain in that recovery history until it expires. Resend retains transactional email data for 30 days. Support messages are kept only as long as needed to respond and manage the request.