Skip to content

EdulabsAI / Security

How we protect your data

A plain-language summary of how EdulabsAI keeps teacher and student data safe.

Security at a glance

  • All data is encrypted in transit (HTTPS/TLS) and at rest.
  • Secret keys stay on our servers — never in your browser.
  • Each teacher's and school's data is isolated at the database layer.
  • The report-card drafter removes the student's name before sending marks to the AI provider and restores it on our server.
  • Teacher prompts and source excerpts selected for generation are sent to the AI provider, so teachers are warned to remove personal student data before upload.
  • Optional Snap-and-Mark originals are private, single-page uploads linked by an opaque non-PII page code.
  • Snap-and-Mark sends a de-identified page and answer-region aliases for transcription, never roster identity or the answer key.
  • Family Digest sends the AI provider only de-identified verified skills and official standard codes, never names, email addresses, raw answers, scores, rankings, diagnoses or confidence values.
  • Guardian email requires double opt-in, every digest requires teacher approval, and every message includes a private unsubscribe path.
  • EdulabsAI does not run its own student-data model-training programme; the AI service's commercial terms do not use submitted content for model training by default.
  • We never sell, rent, or advertise against any personal data.
  • No payment details are collected (free during beta).

Data-flow map

What happens at each boundary

1. A user chooses an action

A teacher enters a lesson brief, selects a source or, in the feature-flagged Family Digest beta, enters a guardian contact; a student signs in, joins a class activity or submits an answer.

2. The server checks authority

Authentication, role, ownership, roster membership, input validation and rate limits are applied before protected work runs.

3. Records stay access-scoped

Accounts, private files, lessons and outcomes are stored through database and storage rules plus server-side ownership checks.

4. AI receives only task content

Generation sends the brief and selected excerpts. Report drafting removes the student name before marks are sent. Family Digest drafting sends de-identified verified skills and standard codes. Snap-and-Mark sends a de-identified page plus answer-region aliases. Output returns for teacher review.

Feature-flagged family beta

The Family Digest trust boundary

A teacher may enter a guardian display name, email address, language and time zone and link that contact to a current student and class. The invitation is only the first half of double opt-in: no learning digest is delivered until the guardian confirms. The guardian can unsubscribe through a purpose-bound private link, and the teacher can stop future messages.

The AI service receives only de-identified verified skill descriptions, official standard codes, the reporting period and requested language. It does not receive the learner or guardian name, email address, raw answers, scores, rankings, diagnoses or confidence values. The learner display name is added on our server, and the email-delivery service receives only the exact digest the teacher reviewed and approved for delivery, together with the destination address and delivery metadata.

Optional home practice contains exactly five read-only questions behind an expiring link. It gives immediate feedback but cannot write answers, grades, practice progress or mastery into a school record. Family Digest remains a feature-flagged beta pending counsel review; its final retention schedule for guardian contact, consent, digest and delivery records will be agreed before broad release.

Limited paper beta

The Snap-and-Mark trust boundary

Snap-and-Mark runs only when a teacher chooses it for an EdulabsAI-generated paper answer sheet and uploads one private page. The printed marker is a cryptographically random opaque code, not a student name, username or login credential. The teacher selects the student and page; a missing or mismatched marker needs explicit teacher confirmation.

The recognition service receives the de-identified page image or PDF and only the expected answer- region aliases and capture types. It does not receive roster identity or the server- side answer key. The model is instructed to transcribe, not identify a person, infer missing work or grade. Server-side comparisons can produce suggestions, but the teacher must review, correct or confirm every value and score before a normal worksheet assessment is saved.

Raw originals remain private. Review-ready originals have a maximum 30-day retention window; approval shortens that window to no more than seven days after approval, and deletion may happen sooner. Permanent teacher-account or student erasure detaches the original, removes access and advances its deletion deadline. This beta cannot promise perfect handwriting recognition and does not automatically grade essays.

A small, controlled service stack

EdulabsAI uses established services to host the app, store protected records and complete actions a user asks for. Optional services stay off until their related feature is used, and student pages do not load product-analytics tools.

Keep the app running

Secure hosting, sign-in, database and private file storage support the core product.

Complete requested actions

AI, email and imagery services run only when the related generation or delivery action needs them.

Keep student use separate

Student dashboards, quizzes and worksheets stay outside product-analytics scripts.

School compliance information

We keep a current subprocessor schedule covering service purpose, data categories, safeguards and feature-specific use. Schools and authorized reviewers can request that schedule for privacy, procurement or compliance review.

Need a signed Data Processing Agreement for your school? Generate one on our DPA page. See live system health on our status page.