1. Data we process
- Teacher account data — name, email, school, and curricula you teach, provided when you sign in with Google.
- Student data — the name and login username your school creates for each student, plus quiz, worksheet and practice records. Short classroom-support features also store a student’s response so it can be updated or counted once. Teachers receive only combined class totals for Learning Reset and Quiet Signal responses, not the individual response attached to a student. Students sign in with a username, not an email. If a teacher chooses the limited Snap-and-Mark beta, student data also includes the private single-page answer-sheet capture, transcription suggestions, the teacher’s corrections and the normal assessment record created after approval.
- Lesson and source content — topics, prompts, uploaded teaching material, source-use choices, generated lessons and edits.
- Family Digest contact and communication data — in the feature-flagged beta, a teacher may enter a guardian’s display name, email address, preferred language and time zone and link that contact to a current student and class. We also keep the opt-in, unsubscribe or suppression state, teacher-approved digest, delivery status and limited consent and delivery evidence needed to operate and audit the feature. Guardians are contacts for email delivery, not student or teacher login accounts.
- Operational data — basic logs needed to run and secure the service.
2. How we use data
We process personal data to provide the service (generate lessons, run live quizzes, save scores), to keep it secure, and to support you. We do not sell personal data, and we do not use student data for advertising.
Family Digest email is disabled by default and available only in an enabled beta. A teacher can request an invitation, but no learning digest is sent until the guardian confirms the opt-in link. Every digest must then be reviewed and approved by the teacher. The guardian can unsubscribe using the private link in the email, and the teacher can also stop future messages. Withdrawal stops future delivery but does not automatically erase historical consent or delivery evidence that may be needed for school instructions or legal records.
3. AI processing
User-requested generation is performed server-side using configured AI subprocessors, currently Anthropic Claude and, when hybrid routing is enabled, Alibaba Cloud Model Studio Qwen. The requested task is sent to one provider at a time and may move to the other only if a bounded availability fallback is needed. Under Anthropic’s commercial API terms, submitted inputs and outputs are not used to train their models by default, and Alibaba Cloud’s Model Studio documentation states that transmitted customer data is not used for model training. Roster names are not automatically added to ordinary lesson-generation prompts. For the optional report-card comment drafter, marks are sent only to Anthropic with the student name replaced by a placeholder, and the name is restored on our server afterwards. Lesson topics, instructions and excerpts from sources a teacher selects are sent to the selected provider to perform generation; teachers must remove personal student data before entering or uploading that material. Schools can review the compliance schedule in our Data Processing Agreement.
Snap-and-Mark is a limited, teacher-requested paper-answer-sheet beta. Its generated sheet uses a cryptographically random, opaque page code instead of a student name or other roster identity. For transcription, Anthropic receives the de-identified single-page image or PDF and a narrow list of answer-region aliases and capture types. We do not send roster identity or the server-side answer key with that request. The model transcribes and suggests only: the teacher selects and confirms the student and page match, then reviews, corrects or confirms every value and score before approval can create a normal worksheet assessment record.
For a Family Digest draft, Anthropic receives de-identified verified skill descriptions and official standard codes, the reporting period and requested language. The prompt excludes the learner and guardian names, email address, database identifiers, raw answers, scores, rankings, diagnoses and confidence values. The student display name is added on our server only after generation. The teacher can edit the draft and must approve the exact content before it can be delivered. Under Anthropic’s commercial API default, submitted inputs and outputs are not used for provider model training unless the customer explicitly opts in or submits qualifying feedback.
4. Sub-processors
We rely on these named sub-processors: Supabase, Anthropic, Alibaba Cloud Model Studio, Vercel, Google, Vercel Analytics and Speed Insights, Resend, Unsplash, PostHog, Stripe, Opinly. Our security page explains the public-facing service boundaries; schools and authorized reviewers can request the current detailed schedule.
Resend processes the destination email address, delivery metadata and email content needed to deliver transactional messages. For Family Digest this can include the guardian’s address, an opt-in or unsubscribe link and the exact teacher-approved digest, including the student display name and learning summary. We do not describe this as teacher-address-only processing.
5. Children’s data
EdulabsAI is designed for schools. Student accounts are created and controlled by educators, acting as the school’s agent, consistent with FERPA and COPPA’s school-consent model and GDPR protections for children. See our Children’s Privacy notice.
6. Data retention
We keep account and lesson data while the account is active and as needed to provide the service, meet school instructions, resolve security or support issues, and comply with applicable law. A school may request export or deletion of student records.
Snap-and-Mark raw originals stay in private storage and have a bounded deletion deadline. An original awaiting teacher review is retained for no more than 30 days; after approval, the deadline is no more than seven days from approval, and deletion may happen sooner. Permanent teacher-account or student erasure detaches the raw upload, removes access and advances its deletion deadline. A teacher-approved assessment is handled under the normal school-record retention, anonymisation and deletion rules rather than kept as a raw image.
Family Digest is a feature-flagged beta pending counsel review. Its final retention schedule for guardian contact details, consent evidence, approved digests and delivery records will be set in the applicable school agreement before broad release. In an enabled beta, we retain those records while the family-school communication relationship is active and as needed to document consent, withdrawal, delivery, school instructions and applicable legal obligations. Optional five-question home-practice links expire within 14 days. They return immediate feedback only and do not write answers, grades, practice progress or mastery into the student’s school record. A school may request deletion or anonymisation, subject to any required consent or security record.
Closing a teacher account does not delete student work. Scores, worksheets and report cards belong to the student and their school, so they survive a teacher leaving. Closing an account signs that teacher out and blocks further sign-in, but the account and its content may be retained so the school relationship and shared records are not damaged. Contact support for restoration, export or erasure options.
If you want an account and its contents permanently erased rather than closed, say so explicitly when you contact us. We will erase it, and student scores are detached or anonymized where it belongs to a school or learner rather than destroyed as a side effect of an adult’s request. The school may separately request student-record deletion. You may request export at any time.
7. Security
Data is encrypted in transit (TLS) and at rest. Access to production data is restricted. Read the specifics on our security page.
8. Your rights
Depending on your jurisdiction (including under GDPR and similar laws), you may have rights to access, correct, export, or delete personal data. To exercise them, email support@edulabsai.com.
9. International transfers
Our providers may process data in regions outside your own. Where required, transfers are made under appropriate safeguards such as standard contractual clauses.
10. Contact
Privacy questions or requests: support@edulabsai.com.