The platform
Everything that is in it, on one page.
One page rather than six thin ones, because six pages about one product is a way of looking bigger than you are. Where a thing is designed and not yet running, the sentence that describes it says so — and none of it is deployed anywhere yet, because there are no customers to deploy it for.
What it is
An empty study app that becomes yours when your material goes into it.
Your students study on their phones, from your book, under your name. Your staff work in a console holding your material, your drafts and your published versions. Both halves belong to one school and cannot see another: the database itself refuses a query that has not said which school is asking. The detail is on security and data.
We have no course of our own to sell you, and we will never sell your students anything — not a subscription, not an upgrade, not a course, not anything at all.
Page citations
Every claim carries the page it came from. Every paragraph says who wrote it.
- From your material
Your own words, lifted from your book and not rewritten.
source_extracted
- Written from your material
Written from a section of your material, with the page it came from underneath it.
ai_generated_from_source
- Written without a source
Written with nothing behind it. Nothing in the product can produce one today.
ai_generated
- Written by a person
Somebody put their name to it — one of your people, or one of ours.
human_authored
The label sits on the paragraph, in the lesson, not in a settings page nobody opens. It is applied by the renderer to every block rather than block by block, because “everything is labelled” is only true if it cannot be forgotten.
A citation is a page range and the quoted sentence, and it becomes a verified citation only once that sentence has been matched against the text of the page it names — the two are stored separately so the difference is queryable rather than a matter of opinion. Until then it is shown marked unverified. The matching is deterministic and is explicitly not a model judging whether a model cited correctly: normalise, collapse the whitespace, re-join words broken across lines, match against the cited page, then a fuzzy fallback above a fixed threshold. That checker is specified and not yet written, so today a person does it with the pages in front of them.
We will not generate a question we cannot point at a page for, and we will not show a citation we have not checked as though we had.
Your question bank
Your past papers go in as you wrote them, and the system records that they are yours.
- Word for word
- A question taken from your material is stored with its source recorded as extracted verbatim — a distinct value from a question somebody wrote later, so “these are our own past papers” is a fact the database holds rather than a claim on a page.
- Your official bank
- A bank can be marked as your own official one. A mock exam assembled from your official bank is a materially different thing from one assembled from questions we wrote, and the difference has to survive being asked about by a regulator.
- Four question types
- Single choice, multiple choice, true or false, and free text. That list is closed on purpose: adding to it is a decision, not a configuration screen.
- Four states
- Draft, approved, rejected, retired. A retired question is kept rather than deleted, because next year somebody will want to know what it used to say.
- Every attempt kept
- One row per answer, appended rather than overwritten, so a retry is a new row and the first attempt survives. That is what makes “which question does everyone get wrong” answerable a year from now.
- Nothing invented
- The vocabulary has a value for a machine-written question and nothing in the product can currently produce one, because nothing here calls a model. When that changes, the label on the screen changes with it.
We will not improve your questions. They go in as you wrote them or they do not go in.
What your students see
Your name at the top. Nothing on the screen names a supplier.
- 1
Your colours, from the first paint
The branding is written into the page during the server render, so the first thing that appears is already yours. There is no moment where it is visibly the wrong colour and then corrects itself, which is the tell that a supplier has skinned somebody else’s product. - 2
The whole course in one request
A student’s course arrives in a single call and is rendered on the server. No spinners, no half-loaded lesson, and it behaves on the connection your students actually have rather than on the one in our office. - 3
Pinned to the version they started
A student stays on the version they enrolled on. Publishing a correction does not move somebody who is three lessons in, and a published version cannot be edited underneath them at all — a correction is a new version. - 4
A draft is never mistaken for the real thing
Your staff can preview an unpublished version and it carries a banner saying so. A student cannot see one at all: the permission that unlocks a draft is not one the student role holds. - 5
Progress, and every answer
Which lessons are done, how long they took, and every question attempt with its result. Enough to see who has stopped, without a surveillance product attached to it. - 6
How they get in
An owner or an administrator generates an access link and hands it over. Nothing is emailed, because nothing in this product sends email; the link is shown once, is stored only as a hash, and expires after fourteen days.
Two things this does not do yet. Your students sign in — no download and no app store, but an account, and we are not going to call that no account. And your address on the web is a name we hold for you rather than a route that resolves: it is stored and checked against a reserved list, and served today under your school’s own path.
There is also no QR code. The database reserves the words for one — a code per branch, a code per instructor — and nothing reads them, because no such feature is built. It goes on this page the day it exists, not before.
We will not put our name on your students’ screens, and we will not contact them about anything, ever.
Your staff and their roles
Five roles for your people, and the useful question is what each one cannot do.
| Can | Owner | Admin | Editor | Instructor | Analyst | Student |
|---|---|---|---|---|---|---|
| Change the school itself | yes | yes | no | no | no | no |
| Add and remove people | yes | yes | no | no | no | no |
| Publish to your students | yes | yes | no | no | no | no |
| Write and edit lessons | yes | yes | yes | no | no | no |
| Edit the question bank | yes | yes | yes | no | no | no |
| Upload your material | yes | yes | yes | no | no | no |
| Hand out access links | yes | yes | no | yes | no | no |
| See every student’s progress | yes | yes | no | yes | yes | no |
| Read the audit log | yes | yes | no | no | no | no |
- Owner
- Everything. The one thing the system protects is that there is always one: the change that would leave your school with no active owner is refused, whoever makes it, including the owner making it to themselves.
- Admin
- Runs your people, your branding and your courses, and can publish. Cannot promote anybody to owner and cannot mint an invitation link that hands out an admin role to whoever finds it — a link that privileged has to be addressed to a named person.
- Editor
- Writes and edits lessons, uploads your material, edits questions, builds a draft version — and cannot publish it. Making a version live needs an owner or an admin. Cannot touch your people or the school itself.
- Instructor
- Sees how students are getting on, and holds the permission to hand out access links — though the route behind that one is not built yet, so today the links come from an owner or an admin. Cannot edit a lesson, a question or a person.
- Analyst
- Reads results and reporting and changes nothing at all — not one write permission in the matrix.
- The student
- Studies the published course and sees their own progress. Not a staff role, and the reason the code has six values where this page has five.
Suspending somebody signs them out everywhere, immediately: their tokens are revoked and a revocation time is stamped on the account that every later request is checked against, so an open session stops working on its next click rather than whenever the cookie expires. It is the thing everybody assumes already works, and usually it does not. Every change to who can do what, and every publish, is written to an audit log that deleting the person does not erase.
Formats we accept
What the reader reads, and what it refuses.
| PDF with a text layer | Read end to end. This is the one to send. |
|---|---|
| PDF that is a scan | Routed to optical character recognition in batches of 200 pages, up to 1,000 pages per document |
| Plain text | Read directly |
| Word (.docx) | Accepted by the upload, refused by the reader as an unsupported type |
| PowerPoint (.pptx) | The same |
| PNG or JPEG | The same |
| Largest single file | 250 MB |
| Longest single document | 3,000 pages |
| Text extraction, per job | 400 pages |
| Password-protected PDF | Refused, and told to you as that rather than as a failure |
| Encrypted, corrupt or empty file | Reported as a result rather than a crash |
Word, PowerPoint and image uploads are stored and then reported by the reader as an unsupported type — an actionable answer rather than a crash. Each is a separate library and a separate way of finding the headings in a document, and we would rather have two formats that work all the way through than five that work as far as the first table.
A document that fails does so by name: eleven named failures, each ending with what to do about it. “Page 47 could not be read — the scan resolution is 96 DPI, below the 150 DPI needed for reliable text extraction. Re-scan that page at 300 DPI and upload again.” The page number and both figures are measured rather than adjectives.
Reading a scan costs real money per page, so it is off by default and cannot be switched on outside a deployed environment at all — and there is no deployed environment. Nothing on this page is running anywhere yet. The first place any of it runs is on the chapter you send us.
We will not quietly retry a document that cannot be read. A file that fails stops, once, and somebody tells you why.
All of it is built on your book being yours. Who owns the converted course, what we check before we convert a page, and what you get on the day you leave: Your material
Send one chapter.
Not a demo of somebody else’s course. A chapter of yours, converted properly, so you can look at your own questions and your own page numbers and decide whether it is any good. Pick the chapter you know best. If it is no good, you have lost an email.
We will ask who owns the copyright before we convert anything. If you do not hold the rights to the material, we will say so rather than take the work.