Last updated 15 September 2026. This covers two things: the public
waitlist, and the department console at /dashboard.html that signed-in
teachers use.
Phloem is run by one person, Alaa Abbadi. There is no analytics vendor, no ad network, no tracking pixel and no third party buying anything about you.
A department account exists once a head of department is given sign-in details. From then on the following is held in the Phloem database, hosted by Supabase:
Row level security decides what each account can reach: a teacher sees their own department and nothing else, and a student sees only their own work. This is enforced by the database, not by the page you are looking at.
For student work and marks, the school is the data controller and Phloem is a processor acting on its instructions. Phloem does not use student work to train any model, does not sell it, and does not share it with anyone outside the processors listed below.
Written answers are sent to Anthropic's API to be marked against the Cambridge mark scheme, one criterion at a time. Anthropic does not train on data sent through the API. No student name is sent with an answer — a script is identified by an internal reference only. A teacher can overrule any mark, and their decision is what stands.
A head of department can delete their department from Settings. A school can ask for everything held about it — accounts, classes, scans, marks — to be deleted by emailing hello@usephloem.com; it is done within 30 days. Scans and marks are otherwise kept for as long as the school's account is open.
?ref= value on the link you arrived
through, or the hostname of the referring site. It records that "someone came
from TikTok", never who.No name, no school, no phone number, no raw IP address, no cookies, no device or browser fingerprint, no advertising identifier. The page sets no cookies of its own.
Submitting the form does not put you on the list. It sends one email asking you to confirm the address really is yours. If you never click the link, you receive nothing further and the pending row is deleted within 30 days. This exists so that nobody can sign somebody else up.
That is the entire list. No newsletter, no drip sequence, no "just checking in". Every email carries a one-click unsubscribe, and unsubscribing is honoured immediately.
They are processors — they handle the data to provide the service and for no purpose of their own. Nobody else receives it, and nothing is ever sold.
Confirmed addresses are kept until launch plus 12 months, or until you unsubscribe. Unconfirmed rows are deleted after 30 days. Rate-limit records are deleted after 24 hours. Unsubscribed addresses are kept as a suppression record only — so that nobody can add you back — and hold nothing but the address and the opt-out date.
If the GDPR or UK GDPR applies to you, you can ask for a copy of what is held, ask for it to be corrected, ask for it to be deleted, or withdraw consent at any time. Withdrawing consent is what the unsubscribe link does. For anything else, email hello@usephloem.com and I'll deal with it within 30 days. You can also complain to your national data protection authority.
Phloem is built for IGCSE students, so most people whose work it marks are under 18. Where a school uses the console, the school obtains whatever consent its own policy requires before adding a student; Phloem holds that work on the school's instructions. The waitlist collects an email address and nothing more, and sends two emails. If you are under 13, please ask a parent or guardian before joining. If you're a parent and want an address removed, email hello@usephloem.com and it will be gone the same day, no questions.
Questions: hello@usephloem.com · Back to usephloem.com