Privacy Policy
Classy AI ("we", "us") operates the Socrates tutoring service. This policy describes what information we collect, why we collect it, who processes it on our behalf, how long we keep it, and the controls you have. We hold ourselves to two commitments up front: we do not sell your data, and we do not train AI models on student data.
1. Information we collect
- Account information. Your email address, an optional display name, a securely hashed password (we never store the password itself), your chosen role (student or educator), and subscription status.
- Tutoring conversations. The full text of your chat sessions with the tutor — your messages and the tutor's replies.
- Uploaded documents. Files you upload (such as lecture notes or textbook chapters), including the extracted text and filenames.
- Quiz and learning records. Quiz questions, your answers and scores, per-section proficiency estimates, study streaks, badges, and class enrollment records.
- Model-inferred learning signals. Classifications our AI systems make about your learning activity (for example, which cognitive level a quiz result reflects), including short model-written rationales that may paraphrase your work.
- Logs and security records. An audit log of significant account actions including IP addresses and timestamps, kept for security and academic-records integrity; standard server logs.
- Billing identifiers. Stripe customer and subscription identifiers. Card details are collected and held by Stripe, never by us.
- Roster information from educators. If an educator rosters a class, they may provide student email addresses to invite those students.
- Contact messages. If you use the contact form on our marketing site, the email address and message you submit.
2. How we use it
- Providing Socratic tutoring grounded in course materials.
- Adapting quiz difficulty and review recommendations to your measured performance.
- Giving educators privacy-scoped insight into their own classes: educators see progress and concept-level evidence, not students' full chat transcripts.
- Account security, fraud prevention, and audit integrity.
- Billing and subscription management.
- Service emails: welcome messages and password resets. We do not send marketing email to student accounts.
- Aggregate usage analytics and error monitoring (see section 4).
3. Service providers (subprocessors)
We use a small set of service providers to run the product. Each receives only what its function requires:
| Provider | Purpose | Data processed |
|---|---|---|
| Anthropic | AI tutoring, quiz generation, and learning classification | Conversation text and course-document text and page images. We do not include names, emails, or account identifiers in these requests. |
| Voyage AI | Text embeddings for document search | Uploaded-document text and study-question text. |
| Stripe | Billing | Email, subscription state, payment details (held by Stripe). |
| Google (Gmail SMTP) | Transactional email (welcome, password reset) | Recipient email addresses and reset links. |
| Google Analytics 4 | Usage analytics | Event names and limited parameters (see section 4). No chat text, quiz text, or document content; no account identifiers. |
| Sentry | Error monitoring (backend) | Error reports and stack traces, configured to exclude personal information. |
| Render | Hosting and storage infrastructure | All service data at rest and in transit. |
| Cloudflare | Network and content delivery | Traffic metadata, including client IP addresses. |
| Backup storage provider | Off-site database backups, when enabled | Database snapshots. |
We do not sell personal information to anyone, and none of these providers is permitted to use student data to train AI models on our behalf.
4. Analytics and your opt-out
We use Google Analytics 4 to understand aggregate product usage. The events we send carry names and limited parameters — never chat content, quiz content, or document text, and never your account identifier or email. You can turn analytics off for your browser at any time with the "Usage analytics" toggle in the app under Settings → Privacy. The setting applies per browser.
5. Retention
We keep your data while your account is active. When you delete your account, your conversations, documents, quiz history, learning records, and inferred learning signals are deleted from the live system in one transaction. Copies in system backups expire on the backup rotation window (approximately seven days). Certain audit records are retained for security and integrity purposes. A formal, per-category retention schedule is under development; this policy will be updated when it is adopted.
6. Your controls: export and deletion
- Export. You can download your chat history and your learning data (documents metadata, quiz attempts, proficiency, engagement, badges, classes) as JSON from Settings at any time.
- Deletion. You can delete your account yourself from Settings. Deletion is immediate in the live system for your conversational, assessment, and inference records. We are expanding deletion coverage to residual records (for example, class-invite entries created by an educator and historical audit entries), and backup copies expire on the backup rotation window rather than instantly.
7. Children
The service is designed for higher education. It is not directed to children under 13, and we do not offer accounts to children under 13.
8. Institutional use and FERPA
When Classy AI is deployed by a school, college, or university, student learning records created in that deployment can constitute education records under FERPA. Classy AI supports institutions in meeting their FERPA obligations under contract — including contractual limits on use and disclosure and the export and deletion controls described above. Institutions can contact us to put a data-processing agreement in place.
9. Security
Passwords are stored as salted hashes; traffic is encrypted in transit; educator dashboards are scoped so educators can access only their own classes; and significant account actions are recorded in an audit log. No system is perfectly secure, and we do not claim certification against any specific security standard.
10. Changes to this policy
We will post any changes to this page and update the "Last updated" date and version above. Material changes will be flagged in the product.
11. Contact
Privacy questions and requests: kt@stayclassy.ai.