Privacy Policy
Effective date: [EFFECTIVE DATE] · Last updated: [DATE]
Notavo is operated by [LEGAL ENTITY NAME] ("Notavo," "we," "us"). This policy explains how we handle information when a school or district uses Notavo, a K-12 STEMM learning platform (Science, Technology, Engineering, Math, and Music).
1. Our role
When a school or district adopts Notavo, the school is the controller of student information and Notavo acts as a service provider, or processor, on the school's behalf and on its instructions. We collect and use student personal information only to provide the educational service to the school, consistent with FERPA, COPPA, and applicable state student-data-privacy laws including New Jersey's. Where the law requires parental consent for students under 13, the school provides or obtains that consent as the parent's agent under COPPA's school-consent provision.
2. Information we collect
For students, we collect only what the service needs: first name or display name, grade level, class assignment, and learning activity such as tutoring sessions, practice attempts and scores, and the topics or lyrics a student writes in the Music Studio. For teachers and staff, we collect account and contact details. We also process limited technical metadata, such as sign-in and standard web request data, to operate and secure the service.
We do not collect student email addresses for students under 13, who join a class with a class code. We do not collect student photos or videos, as any media is AI-generated output. We do not collect Social Security or government ID numbers, or demographic data such as date of birth, race, ethnicity, or gender.
3. How we use information
We use information only to provide and improve the educational service: to power the AI tutor, generate practice, track progress, and report progress to the student's teacher, school, and, where enabled, the student's parent. We do not sell student data. We do not use student data for advertising, and we do not allow advertising in the product. Our AI provider does not use data submitted through its API to train its models.
4. Sub-processors
We use a small number of service providers to deliver Notavo. Each receives only the data needed for its function, acts on our instructions, and is bound by a data protection agreement.
- Anthropic (Claude): AI tutoring and content generation. Receives tutor prompt text with direct identifiers removed first, and does not train on the data.
- Google Firebase: authentication, database, and file storage. Stores account and learning-activity data, encrypted at rest.
- ElevenLabs: read-aloud voice and Music Studio audio. Receives tutor reply text and student-entered song notes.
- Vercel: application hosting and delivery. Processes standard web request traffic.
5. Data retention and deletion
We retain student work and activity logs for up to twelve months, after which they are deleted automatically. We delete student data sooner on the school's request, and we delete or return student data at the end of the school's agreement with us.
6. Security
We protect information with encryption in transit and at rest, school-level data isolation so one school cannot access another's records, and role-based access controls. Special-education information, including IEP and accommodation data, carries our strictest access controls and audit logging.
7. Children's privacy
Notavo is used in schools with children. We follow COPPA's school-consent framework, collect only what is needed for the educational purpose, and never use children's data for advertising or to build advertising profiles.
8. Parent and school rights
Parents may request access to, correction of, or deletion of their child's information through the child's school, which directs us as the controller. Schools may exercise these rights at any time under their agreement with us.
9. Changes to this policy
We may update this policy. We will post the new effective date here and, for material changes that affect schools, notify the school.
10. Contact
Questions about this policy or a data request: admin@notavo.org.