Privacy Policy
TransparencED — Privacy Policy
Last Updated: June 6, 2026
1. Introduction
This Privacy Policy explains how TransparencED, Inc. ("TransparencED," "we," "us") collects, uses, discloses, and protects personal information when you use our tutoring platform (the "Service"). It is incorporated into our Terms of Service. For children's information, also read our Children's Privacy Notice.
Our roles. When an independent tutor or a tutoring company uses the Service to serve their own clients, that organization is generally the controller of its students' data and we act as a processor / service provider on its behalf. When we deal directly with a family (a solo tutor's or direct-to-parent account), we act as the controller. These roles affect how data-subject requests are handled (Section 10).
2. Information We Collect
Account & profile data: name, email, phone, role (admin, tutor, parent, student), organization membership, time zone, and — for students — grade level, school (where provided), and a tutoring goal. For students under 18, we collect a date of birth or age to apply age-appropriate protections and verify whether parental consent is required.
Session content: audio recordings of live tutoring sessions; transcripts generated from that session audio; whiteboard content; shared on-screen materials; and in-session chat messages. We do not make video recordings of sessions.
Uploaded documents: materials uploaded by tutors, students, or parents, which may include graded work, report cards, progress reports, and individualized education programs (IEPs).
Learning data and AI-derived inferences: mastery and skill estimates, practice outcomes, learning profiles, health cards, roadmaps, and affective/engagement signals derived from session content.
Communications: in-platform messages, email, and SMS we send or you send through the Service.
Billing data (where paid billing is enabled): if and when your account uses paid billing, we collect Stripe customer/account identifiers and transaction and payout metadata. We do not store full payment-card numbers; Stripe handles card data.
Usage and device data: product-analytics and learning-signals events about how the Service is used.
We do not intentionally collect precise geolocation; we collect time zone only.
3. How We Use Information
We use personal information to: create and manage accounts and authenticate users; deliver, schedule, secure, and support tutoring sessions; record, transcribe, and analyze sessions to produce learning insights and progress summaries for tutors, students, and parents; generate AI-assisted content and practice; process billing and tutor payouts; send transactional communications; maintain, debug, and improve the Service; ensure safety and prevent fraud and abuse; and comply with legal obligations. We do not use personal information for behavioral advertising, and we do not sell personal information for money. Cross-organization analytics is addressed in Section 6.
4. Automated Processing, AI, and Profiling
4.1 AI processing. We use AI (the "Iris" features, powered by Anthropic's Claude) to provide tutoring. This processes student messages, answers, uploaded documents, and session recordings (which we transcribe and analyze).
4.2 Automated inferences ("profiling"). We use automated processing to infer a student's mastery, skill levels, learning patterns, and engagement, and to infer affective signals (such as indicators of frustration or confidence) from session transcripts, to personalize the Service (for example, "Smart Paths" roadmaps and warm-up routing). These are automated estimates, not definitive measures, and are not clinical or psychological assessments. A human tutor remains involved.
4.3 Your rights regarding automated decisions. Where we use automated processing to make or substantially contribute to decisions about a student's educational path, you have the right to be notified (this is that notice), to request information about the logic and data used, and to request human review of, or to correct or appeal, an automated determination. Contact privacy@transparenced.com. A human tutor remains involved in the tutoring relationship at all times.
4.4 Affective analysis. Our automated session analysis may infer engagement and emotional tone from session transcripts to help tutors support the student. We do not use this for advertising, eligibility, or disciplinary decisions, and we do not use it to identify anyone biometrically. You may contact us at privacy@transparenced.com to request that we stop or review this affective processing for your account, and we will honor your request.
4.5 AI improvement. See Section 6 ("AI improvement"). You may ask us to stop using your data to improve our AI features by contacting privacy@transparenced.com. The Service is not offered to children under 13, so under-13 children's data is not used for this purpose.
5. Session Recordings, Transcripts, and AI Analysis
When you participate in a live tutoring session, we make an audio recording of it, transcribe the audio using automated speech-to-text (Amazon Transcribe), analyze it using AI (Anthropic's Claude) to generate summaries, learning signals, and recommendations, and store the recording, transcript, and resulting insights. We do not make video recordings of sessions today; if we introduce session video or session playback in the future, we will update this Policy and our in-session disclosures before doing so. Recording begins when you join a session; by accepting our Terms and joining a session, you consent to it, as described in Section 8 of our Terms. We do not sell recordings, transcripts, or insights, and do not use them for advertising. For how we separate speakers in a transcript and our position on biometric data, see Section 8.7 of the Terms. Retention is described in Section 14.
6. How We Share Information
6.1 Service providers (subprocessors). We disclose personal information to vendors who process it only on our instructions to provide the Service, under written contracts restricting other use. A current, named list of our sub-processors and their purposes — including our cloud provider (AWS, which also provides session audio recording storage and automated speech-to-text transcription), our AI provider (Anthropic, which does not train its models on your data), Google (as an optional "Sign in with Google" identity provider, used only when you choose it), and — where paid billing is enabled — our payment processor (Stripe) — is maintained at /legal/subprocessors.
We require these providers to maintain safeguards appropriate to the data and, where applicable, to not use the data to train their own general-purpose models.
6.2 Within organizations. Within a tutoring organization, data is shared among the tutor, the relevant parent/guardian, the student, and authorized organization administrators, subject to access controls.
6.3 Legal and safety. We may disclose information to comply with law, enforce our Terms, protect the rights, safety, or property of any person, including reporting apparent CSAM to NCMEC as required by 18 U.S.C. § 2258A.
6.4 Business transfers. In a merger, acquisition, financing, or sale of assets, information may be transferred subject to this Policy.
6.5 Our position on "selling" and "sharing." We do not sell personal information for money, do not use student, parent, or family personal information for advertising, and do not allow third parties to use it for cross-context behavioral advertising.
We do operate, or may operate, a Cross-Organization Benchmarking Program ("macro analytics"), in which tutoring organizations that affirmatively opt in contribute learning and outcome data that we combine into aggregated, organization-pseudonymized benchmarks. Direct identifiers of students, parents, and families (names, emails, phone numbers, addresses, dates of birth) are blocked at the database boundary and never enter this Program. Because some privacy laws define "sale" and "sharing" broadly, we treat contributions to this Program as a "sale" and "share" under those laws out of caution, and we give you the right to opt out using the "Do Not Sell or Share My Personal Information" control (Section 11) or a Global Privacy Control signal. The Program is off by default for any organization that has not opted in, and no data sourced under a school data-protection agreement is ever included (Section 8). We do not include the personal information of children under 13 in this Program; the Service is not offered to children under 13.
6.6 AI improvement. To make our AI features more accurate, we may use certain platform data — including AI conversations, student answers, and tutor reviews/corrections — to evaluate, debug, and improve our own AI features. We do not sell this data, and our AI provider does not train its models on it. Because the Service is not offered to children under 13, we do not use under-13 children's data for this purpose. If you do not want your data used to improve our AI features, contact privacy@transparenced.com and we will honor your request; this does not affect your tutoring service.
7. Children's and Student Information
The Service is intended for students age 13 and older, and we treat all student information as sensitive, limiting our use of it to providing the requested tutoring service. The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. We ask for a date of birth at signup so that we can apply age-appropriate protections. If we learn that we have collected personal information from a child under 13, we delete it. Students who are 13 to 17 may create their own account and accept our Terms; we encourage guardian awareness and support, and a parent or guardian may exercise the rights in Section 10 on a minor's behalf.
We do not knowingly create accounts for, or collect personal information directly from, a child under 13. If we learn that we have collected personal information from a child under 13, we delete it promptly.
8. FERPA and Student Data
The Family Educational Rights and Privacy Act (FERPA) applies to schools and educational agencies that receive U.S. Department of Education funding — not directly to tutors, families, or independent tutoring businesses. When you use TransparencED directly as a tutor, tutoring business, or family, FERPA generally does not apply to your data, and we make no representation that this use is governed by FERPA.
When TransparencED is engaged by a school or school district, we act as a "school official" with a legitimate educational interest under FERPA's school-official exception (34 C.F.R. § 99.31(a)(1)(i)(B)) only under a signed Data Protection Agreement with that school or district. Under that agreement we remain under the school's direct control with respect to education records, use those records only for authorized purposes, do not redisclose them, and do not use them for AI training or cross-organization analytics. Our School Data Protection Agreement is available on request from legal@transparenced.com.
Our K-12 student commitments (binding regardless of whether FERPA applies). Because students use the Service for school-related learning, for all information we collect about a K-12 student we will: (1) not use or disclose it for targeted advertising; (2) not sell or rent it; (3) not use it to amass a profile of a student except in furtherance of that student's own tutoring; (4) use it only to provide and improve this Service for the account that submitted it, and as authorized or required by law; (5) maintain reasonable security; (6) delete it on the responsible account holder's request, subject to legal retention; and (7) not combine identifiable K-12 student information across unrelated customer organizations. (These commitments reflect California SOPIPA and similar state student-privacy laws and apply even with no school contract.)
9. Aggregate and De-Identified Data
We may create de-identified or aggregated data that cannot reasonably be used to identify any individual or organization, and use it for product improvement and research. We do not attempt to re-identify it. De-identified data is not subject to the rights in Section 10.
10. Your Privacy Rights and How to Exercise Them
Subject to applicable law and the exceptions below, you may: access the personal information we hold about you; correct inaccurate information; delete your personal information; export / port a copy of personal information you provided; opt out of sale/sharing and targeted advertising (Section 11); limit the use of sensitive personal information; and opt out of profiling / automated decision-making that produces significant effects. You also have a right to non-discrimination for exercising these rights, and, in some states (VA, CO, CT, and others), a right to appeal.
For students who are minors, these rights are exercised by the parent or guardian (or by the educational organization acting on the family's behalf, consistent with FERPA). We verify parental/guardian authorization before acting.
How to make a request. Submit a request to privacy@transparenced.com. We will verify your identity (typically by confirming control of the email on file and matching information) and respond within the time required by law (generally 45 days for U.S. state-law requests, extendable as permitted; one month for EU/UK, extendable to three). Authorized agents may submit requests with proof of authorization. If we decline a request, you may appeal by replying to our decision or emailing privacy@transparenced.com with "Appeal" in the subject line; we will respond to an appeal within 45 days and, if we deny it, tell you how to raise a concern with your state attorney general.
Exceptions. We may decline or limit a request where law permits or requires us to retain information — for example, to comply with a legal obligation, tax/accounting/audit requirement, or legal hold; to complete a transaction or service you requested; for security and fraud prevention; where the information resides only in routine backups (purged on our backup-rotation cycle); or to protect another user's rights or data (such as shared session content). We will tell you if an exception applies.
11. California Notice; Do Not Sell or Share
This Section supplements the above for California residents and informs all users of opt-out rights.
Categories collected. In the preceding 12 months we collected the categories of personal information in Section 2 (identifiers; customer records; commercial information; financial information; internet/usage activity; audio/visual recordings; professional/education information; inferences; sensitive personal information; and consent records), from the sources, for the purposes, and shared with the categories of recipients described throughout this Policy (see Sections 2, 3, 6, and 14).
Sensitive personal information. The sensitive personal information we collect may include account login credentials, audio and video recordings of sessions (which contain your voice and, where video is enabled, your image), the contents of in-session messages, engagement and emotional-tone inferences drawn from session content, and information relating to minors. We use sensitive personal information only to provide, personalize, and secure the Service, and not to infer characteristics about you for unrelated purposes. You may direct us to limit its use by contacting privacy@transparenced.com.
Sale/Sharing and minors. As described in Section 6.5, we treat contributions to our Cross-Organization Benchmarking Program as a sale/share and offer an opt-out. We do not knowingly sell or share the personal information of consumers under 16 without the required opt-in consent (from a consumer who is 13–15). The Service is not offered to children under 13.
Do Not Sell or Share My Personal Information. To opt out: (1) contact us at privacy@transparenced.com to opt out of any sale or share of your personal information; or (2) enable a Global Privacy Control (GPC) signal in your browser. We honor GPC signals; where our automated detection is unavailable, you may confirm your opt-out by contacting privacy@transparenced.com. We do not require you to verify your identity to honor an opt-out of sale/sharing, and we process opt-outs within 15 business days.
Retention and metrics. We retain each category for the period in Section 14.
12. International Users (EEA, UK, and Switzerland)
The Service is offered to users in the United States only at launch. We operate from the United States and process and store personal information on AWS infrastructure in the United States (region us-east-1). The provisions below apply only if your personal information is nonetheless processed in connection with access from the EEA, the UK, or Switzerland. If you access the Service from the EEA, the UK, or Switzerland, your personal information will be transferred to the United States and to our subprocessors. Where we transfer such data, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with supplementary technical measures, or, where applicable, a subprocessor's EU-US Data Privacy Framework certification.
Legal bases (EEA/UK). We process: account/session/billing data on the basis of contract; session recording, transcription, and AI analysis on the basis of contract where integral, otherwise consent; security and fraud prevention on legitimate interests; AI improvement on legitimate interests subject to your right to object (and we do not train AI on children's data on a legitimate-interests basis); cross-organization benchmarking on the consent of the contributing organization; and legal-compliance processing on legal obligation. Where we process special-category data, we rely on your explicit consent or another applicable condition. For a child below the applicable age of digital consent (13–16 by country), we obtain authorization from a holder of parental responsibility.
You have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with your supervisory authority. Our Data Protection contact can be reached at privacy@transparenced.com.
13. Data Security
We maintain administrative, technical, and physical safeguards designed to protect personal information using commercially reasonable measures consistent with industry standards and the sensitivity of the data. These include: encryption in transit using current industry-standard transport-layer encryption (TLS); encryption at rest using strong encryption (AES-256 or equivalent) managed through our cloud provider; access controls based on user role and least privilege, with logging of access to sensitive records; and multi-factor authentication that account holders may enable. Because we handle children's data and education records, we maintain a written information security program governing that data and review our safeguards periodically. No method of transmitting or storing data is 100% secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials.
14. Data Retention
We retain personal information only as long as reasonably necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements, then delete, de-identify, or archive it. Retention may vary where a longer period is required by law or a legal hold applies.
| Data category | Retention (target) |
|---|---|
| Account & profile data | Life of the account; deleted within 30 days of a verified deletion request or closure, subject to exceptions |
| Session audio recordings | Retained for as long as reasonably necessary to provide the Service and its learning insights, then deleted or de-identified |
| Session transcripts | Retained for as long as reasonably necessary to provide the Service, then deleted or de-identified |
| AI-derived inferences & learning records | While the tutoring relationship is active and for as long as reasonably necessary thereafter to provide the Service; deleted or de-identified on a verified account-deletion request, subject to exceptions |
| Uploaded documents & messages | While the account is active; deleted on a verified deletion request, subject to exceptions |
| Product/usage analytics | 90 days (auto-expired); limited de-identified/aggregated data retained longer |
| Billing records | As required for tax/accounting/audit (typically 7 years); no card data stored by us |
| Children's (under 13) personal data | Not knowingly collected or retained; if we discover personal information from a child under 13, we delete it promptly |
| Backups | Cycled out on our standard backup-rotation schedule (within 30 days) |
15. Data Breach
We maintain an incident-response plan and monitor for security incidents. In the event of a breach affecting your personal information, we will investigate, contain, and remediate, and notify affected individuals and the appropriate regulators as, and within the timeframes, required by applicable law. Notification obligations vary by jurisdiction; we will comply with those that apply.
16. Cookies
We use only essential cookies and similar local-storage mechanisms required for authentication and core functionality. We do not use third-party advertising, marketing, or cross-site tracking cookies, and we do not embed third-party analytics SDKs in the Service; our product analytics are collected server-side. We honor Global Privacy Control signals as described in Section 11.
17. Changes to This Policy
We may update this Policy by posting the revised version with a new "Last Updated" date and, for material changes, providing reasonable notice. Where a material change affects how we process children's information under a prior parental consent, we will notify the parent and obtain new consent where the law requires.
18. Contact
TransparencED, Inc., 2622 Little Kate Road, Park City, UT. Privacy: privacy@transparenced.com. Data requests: privacy@transparenced.com or the email above.
Privacy Policy · Terms of Service · Children's Privacy Notice · Sub-Processors
TransparencED, Inc., 2622 Little Kate Road, Park City, UT · privacy@transparenced.com