1. Information We Collect
When you create a Schoolarise account, we collect the following personal information:
- Account information: name, email address, date of birth, and password (stored as a secure hash).
- Study data: chat sessions with the AI tutor, quiz scores, flashcard decks, saved notes, teach-back results, and assignment data.
- Profile data: optional avatar image and grade level preference.
- Optional analytics data: for consenting adult users, account identifiers and profile name, page usage, and feature events such as study topics, quiz results, course activity, and flashcard activity. Analytics is disabled for minors.
2. How We Use Your Information
- To provide and personalize the AI tutoring experience based on your grade level and study history.
- To enable features such as flashcards, quizzes, notes, and knowledge mapping.
- To send account-related emails (password resets, parental consent requests, announcements).
- For consenting adult users, to understand product usage and improve the platform through optional analytics. Analytics is default-off and never enabled for minor accounts.
3. Third-Party Services
We share data with the following third-party services only as necessary to operate the platform:
- Groq — provides the AI inference used for tutoring and generation features. The prompts, conversation messages, uploaded study context, or assessment content needed for a request are sent to Groq to generate the response.
- Resend — email delivery for password resets, parental consent, and announcements.
- Stripe — payment processing for subscription plans. We do not store credit card numbers.
- PostHog — optional product analytics for consenting adult users, including the account identifier and profile name supplied at identification plus feature-event properties such as study topics and course activity. PostHog is not initialized for minors or before acceptance.
- Vercel Analytics — optional site usage analytics for consenting adult users. Its analytics component is not loaded for minors or before acceptance.
- Vercel — application hosting and content delivery.
- Neon / PostgreSQL — cloud database storage for user and study data.
We do not sell personal data to any third party. We do not use personal data for advertising purposes.
4. Children's Privacy (COPPA) & Minor User Policy
Schoolarise complies with the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. § 6501–6506. We go beyond COPPA's minimum requirement and require verifiable parental or guardian consent for all users under 18 years old, not only those under 13.
- Age gate — under 18: If a user indicates they are under 18, their account is placed in a pending state. We send a consent request to the parent or guardian email provided. The account is activated only after the parent clicks the confirmation link. After the consent request expires, the disabled pending account is quarantined as a cleanup candidate. The current cleanup job reports aggregate candidate counts only; it does not delete these records.
- Parent account verification: Parent and guardian accounts are subject to email verification before activation, preventing minors from creating fraudulent parent accounts to bypass the consent requirement.
- COPPA — under 13: For users under 13 years old specifically, we comply fully with COPPA. We collect only the minimum data necessary — name, email address, date of birth, and study data (chat sessions, quiz scores, flashcards, notes). We do not collect phone numbers, precise geolocation, photos, or other sensitive personal information from children under 13.
- No sale or sharing for advertising: We do not sell, rent, or share personal information of users under 18 with any third party for marketing or advertising purposes. Users under 18 are never shown targeted or behaviorally-based advertisements.
- Third-party processors: We share minor users' data with third-party service providers (Groq for AI tutoring, Resend for email, Vercel for hosting, Neon for database) solely to deliver the Service. These providers are contractually prohibited from using this data for any other purpose. PostHog and Vercel Analytics are disabled for minors.
- Parental rights — review: A parent or guardian may request a copy of all personal information we hold about their child by contacting us at support@schoolarise.ai. We will respond within 30 days.
- Parental rights — correction & deletion: A parent or guardian may at any time request correction of inaccurate information, revoke consent, or request permanent deletion of their child's account and all associated data. They may do so via the Parent Dashboard, the management link in the consent email, or by contacting us directly. We will confirm the request and explain the deletion status and any records that must be retained for legal, security, billing, or dispute-resolution purposes.
- Parental rights — refuse further collection: A parent may revoke consent at any time, which disables the child's access. Limited processing may continue where needed to secure the account, honor the request, or meet legal and recordkeeping obligations.
If you believe we have inadvertently collected personal information from a child under 13 without parental consent, please contact us immediately at support@schoolarise.ai so we can investigate, restrict access where appropriate, and process an authorized deletion request.
5. Data Retention
- Active accounts: Your data (name, email, study sessions, quiz scores, flashcards, notes) is retained for as long as your account is active.
- Account-deletion requests: When an authorized account-deletion workflow completes, the account and the records covered by its database deletion are removed. Some minimized records may be retained where required for billing, legal compliance, security, fraud prevention, or resolving a dispute. We do not promise that every copy or every category is deleted within a fixed period unless the request response expressly confirms that result.
- Expired parental consent (minors): If a parent or guardian does not approve a child's account after the consent request expires, the disabled pending account is quarantined and counted by a report-only cleanup job. Automatic deletion is disabled. These records remain pending a separately authorized retention-and-deletion process.
- Revoked consent (minors): If a parent or guardian revokes consent, the child's account is disabled. A formal deletion request is then handled through the authorized account-deletion workflow, subject to the limited retention described above.
- Payment records: Billing records (transaction IDs, amounts, dates) may be retained for up to 7 years as required by law. We do not store full payment card numbers.
- Security, administrative, and billing-operation logs: The codebase contains a retention worker that removes certain chat-abuse counters after 7 days, administrative and audit records after 365 days, and completed billing/webhook records after 400 days. That worker is part of the new billing lifecycle, is default-off, and remains migration-gated; these periods are not currently a blanket active-production deletion guarantee. Other server or provider logs follow their actual system or provider settings until a separately verified retention job applies.
- Optional analytics: Analytics for consenting adult users is processed by PostHog and Vercel Analytics under their applicable retention settings. Minor accounts are excluded.
6. Security
We take reasonable measures to protect your personal information:
- Passwords are hashed using bcrypt (never stored in plaintext).
- API endpoints are rate-limited to prevent abuse.
- Browser API mutations use same-origin checks where applicable; signed webhooks and installed authentication actions use their own request-validation mechanisms.
- HTTPS is required for all connections.
- Account lockout is triggered after multiple failed login attempts.
7. Your Rights
You have the right to:
- Access your personal data through your account profile.
- Update or correct your personal information at any time.
- Request account deletion and receive information about its status and any limited records that must be retained.
- Request information about what data we hold about you.
8. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or an in-app announcement. Continued use of the platform after changes constitutes acceptance of the updated policy.
9. Contact Us
If you have questions about this Privacy Policy, your data, or your child's account, please contact us at:
support@schoolarise.ai