Effective Date: May 1, 2026
Last Updated: September 29, 2026 — Section 4.3 and Section 6 now disclose Plio's math engine, which runs on Fly.io and processes the math expression your child types transiently (not stored, not logged; B-1334); previous update September 25, 2026 — Section 3.1 added the child's-state-of-residence disclosure (asked on the guardian dashboard, optional, used only to route a mandated report to the right state's child-protection authority — B-1218); previous update September 24, 2026 narrowed Section 6's third-party DPA sentence from an unverified blanket claim ("Each third-party service is bound by...") to a requirement statement plus the one substantiated instance (Anthropic, by incorporation into the Commercial Terms); prior update September 15, 2026 added to Section 4.3 (human tutors as a recipient of your child's live tutoring session content) and Section 6 (Human tutors disclosure row); earlier update August 5, 2026 added Section 4.3 (what happens to text your child types)
1. Overview
Plio Academy, Inc. ("we," "our," "us," or "Plio") is a Nevada nonprofit corporation providing free, self-paced AI and technology education to children ages 5–17 nationwide. This Privacy Policy explains what information we collect, how we use it, and what rights you have regarding your data.
Privacy is fundamental to our mission. As a nonprofit serving children and families, we are held to the highest standards of data protection. We comply with:
- The Children's Online Privacy Protection Act (COPPA)
- The California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
- General Data Protection Regulation (GDPR) where applicable
- State data privacy laws and best practices
2. Who This Policy Covers
This Privacy Policy applies to:
- Visitors to plio.academy (our public marketing website)
- Parents, guardians, and legal representatives who create accounts
- Students who access our learning platform at learn.plio.academy
- Instructors and administrators at partner schools or organizations
- Donors and supporters who contribute to our nonprofit
3. Information We Collect
3.1 Information You Provide
Guardian Account Registration
- Full name (legal name used for identity verification)
- Email address (primary contact for account and family communication)
- Password (hashed, never stored in plaintext)
- Phone number (optional, for SMS notifications)
- Address (optional, for mailing communications)
- Preferred language (English or Spanish)
- The U.S. state (or country) your child lives in — optional, asked on your dashboard, used only so the right child-protection authority can be contacted if a safety concern ever arises. Never your address, never shown to your child or to tutors.
Student Profile (Created by Guardian)
- First or display name (e.g., "Alex," "Dino") — not a legal name
- Age or age range (e.g., "8-10 years") — not exact date of birth
- Avatar emoji (chosen from a curated set of 20 emojis)
- Avatar background color (chosen from 8 approved hex colors)
- Learning preferences or accessibility settings
Waitlist and Contact Forms
- Name
- Email address
- Optional: phone number, message content, school or organization affiliation
Donations
- Name and email (provided by donor)
- Donation amount
- Payment method type (Visa, Mastercard, etc.) — we do NOT store full card numbers, CVC, or expiration dates. Stripe handles PCI-compliant payment processing.
Feedback and Support
- Any messages, feedback, or support requests you send via email, contact form, or support channels
- Name and email address
- Description of issue or suggestion
3.2 Information Collected Automatically
Learning Activity Data
- Lessons accessed and completion status (started, in-progress, completed)
- Time spent on each lesson (session duration)
- Quiz and assessment responses (answers and scores)
- Game/challenge participation and performance
- Streak data (consecutive days of engagement)
- Badges and achievement milestones earned
Usage Analytics
- Pages visited within the Platform
- Features accessed (e.g., dashboard, progress reports, cohort forums)
- Clicks and interactions with UI elements
- Session duration and frequency
- Referrer information (how you found the Platform)
We use Plausible, a cookieless privacy-friendly analytics tool, on our public marketing site (plio.academy) only. Plausible sets no cookie, stores no data in your browser, and does not fingerprint your device — because it collects no personal data at all, it runs without requiring a consent choice, the same way our server logs do. Plausible is never loaded on the learning platform (learn.plio.academy) or on any page a student uses, and we do not use session recording anywhere.
Device and Browser Information
- Device type (mobile, tablet, desktop)
- Operating system (iOS, Android, Windows, macOS, Linux)
- Browser type and version
- Screen resolution
- Language and timezone settings
Server Logs
- IP address
- HTTP method and request path
- HTTP status code
- Response size
- Referrer and user agent
- Access timestamp
Server logs are retained for up to 30 days for security and debugging, then deleted.
4. Children Under 13 — COPPA Compliance
4.1 No Direct Collection from Children
Plio Academy does not knowingly collect personal information directly from children under 13. Children do not create their own accounts or email addresses. All account creation and data management is performed by a parent, guardian, or school administrator.
4.2 Information Collected from Children (via Guardian Accounts)
When a guardian enrolls a child under 13, we collect only:
- Display name (e.g., "Alex") — not a legal name, not linked to any government ID
- Age range (e.g., "8-10 years") — not exact date of birth or SSN
- Avatar preferences (emoji and color) — no photo, no biometric data
- Learning activity within Plio Academy (lessons completed, quiz scores, time spent) — used only to show progress to the guardian and improve our curriculum
- Written responses your child types into a lesson activity or into a conversation with Lio, our AI learning assistant — see Section 4.3 below, which explains exactly what happens to this text
We never collect from a child under 13:
- Email address
- Phone number
- Physical address
- Social media handles
- Precise location (GPS)
- Biometric data (fingerprints, face recognition)
- Health information
- Behavioral or psychological profiles for marketing
4.3 What Happens to Text Your Child Types
Some parts of Plio Academy let a child type in their own words — a written answer to a lesson question, or a message to Lio, our AI learning assistant. This section explains exactly what we do with that text, because it is the one place where a child could type something we did not ask for.
Every message is checked automatically for signs that a child may be in danger. This check runs on our servers, by software, the moment the text is submitted. It looks for indicators of abuse, neglect, self-harm, or a child being unsafe. No person reads a child's writing as part of this check.
If nothing concerning is found, which is the overwhelming majority of the time:
- For a written lesson answer: the text is discarded. We do not store it.
- For a conversation with Lio: the message is stored so that your child's learning
history is available to you, and so we can review the assistant's behaviour for safety and quality. Before it is stored, we automatically remove any email address, phone number, street address, or personal web link it may contain.
If the check does find something concerning, we follow our child-safety procedure. A trained member of our team is alerted so a person can decide what help is needed. We do not store the child's original words as part of that alert — only the category of concern and a short fragment of the matching phrase, which is what allows a human to assess the situation responsibly.
Math problems are solved by software Plio runs. When your child types a math expression into a math activity, the expression and your child's learning tier (nothing else: no name, no account identifier) are sent to Plio's own math engine, which runs on rented Fly.io servers. It is processed only long enough to return the answer, and it is not stored or written to logs. No other company receives it, and it is not sold or used for anything else.
Lio's replies are generated by Anthropic. To answer your child, the message is sent to Anthropic, the company that provides the underlying AI model. They are contractually prohibited from using it to train their models — Section B of Anthropic's Commercial Terms states "Anthropic may not train models on Customer Content from Services." Anthropic and every other company that processes data for us is listed in Section 6, together with what each one receives.
What we never do with this text: we do not sell it, we do not use it for advertising, we do not use it to build a profile of your child, and we do not use it to train artificial-intelligence models.
You can turn this off. If you would prefer your child not use the AI assistant or the written-response activities, contact us at hello@plio.academy and we will disable those features on your child's account. Your child can still complete every lesson; activities that require typing will be skipped.
Human tutors can see what your child does live in a tutoring session — not what they type elsewhere. The check described above is about text your child types into a lesson answer or to Lio. It is separate from live 1:1 video tutoring, which some families choose to book. If your family books a live tutoring session, a background-checked adult volunteer tutor your family chose and consented to, for that specific session, can see:
- Your child's display name, age band, and the subjects you approved for tutoring
- What your child says and shows on the live video call, for the length of that session
- What your child draws or types on the shared whiteboard, if your family also turns that on, during
that session
The tutor cannot record, screenshot, download, or keep any of it. We do not record the audio or video of a tutoring session. The tutor also cannot see your child's full legal name, contact details, location, or detailed progress data. Before a session, the tutor sees only: your child's display name, the number of lessons your child has completed in the relevant subject, and the title of the most recently completed lesson — never a score, a grade, or anything your child has written.
A trained Plio staff member may join any tutoring session live, the same way you can, to help keep the session safe.
You choose the tutor, every time. Saying yes to one tutor does not carry over to a different one — if your child works with a different tutor later, we ask you again, and you can decline. Plio staff may join any session; the tutor cannot bring in anyone else.
You can end a session or stop a tutor at any time. From your parent dashboard, you can end a session that is happening right now, or withdraw your consent for a specific tutor going forward. Doing so ends the live connection for everyone immediately.
4.4 Parental Rights and Consent
By creating a guardian account and enrolling a child under 13, you give us consent to collect, use, and disclose the information described above. You may withdraw this consent at any time by:
- Emailing hello@plio.academy with your request
- Deleting your child's profile through the dashboard
- Requesting full account deletion
Upon withdrawal of consent, we will delete your child's information within 30 days, except where retention is required by law or for legitimate educational research (in which case data will be anonymized).
4.5 COPPA-Related Inquiries
If you believe Plio Academy has violated COPPA or your child's privacy, you may contact:
Federal Trade Commission (FTC)
Bureau of Consumer Protection
https://www.ftc.gov/about-ftc/bureaus/bureau-consumer-protection
Or file a complaint at reportfraud.ftc.gov
Plio Academy
hello@plio.academy
5. How We Use Your Information
5.1 Service Delivery and Improvement
- Provide access to lessons, activities, and games
- Show progress reports to guardians and students
- Send transactional emails (enrollment confirmations, password resets, progress reports)
- Respond to support requests and technical issues
- Analyze learning patterns to improve curriculum design and personalization
5.2 Communication
- Send email updates about new features, resources, or opportunities (guardians can opt out)
- Send policy update notifications and legal notices
- Conduct surveys or feedback collection to improve the Platform
5.3 Research and Analytics
- Aggregate, anonymized learning data to measure educational outcomes
- Identify trends in student engagement, completion rates, and learning pathways
- Publish research on learning effectiveness (always anonymized and aggregated)
- Evaluate program impact for grant reporting to nonprofit funders
5.4 Legal and Safety
- Comply with subpoenas, court orders, or legal process
- Investigate fraud, security breaches, or terms of service violations
- Protect the rights, property, and safety of Plio Academy, our users, or the public
- Enforce our agreements and policies
5.5 What We Do NOT Do
We do NOT:
- Sell or rent personal information to third parties
- Share student data with advertisers, marketers, or data brokers
- Use children's learning data to create behavioral profiles for targeting
- Engage in price discrimination or algorithmic profiling
- Share data with political campaigns, religious organizations, or non-educational entities
- Create or use shadow profiles (inferred data not directly collected)
6. Third-Party Service Providers
We use the following third-party services to operate the Platform:
| Service | Purpose | Data Shared | Policy |
|---|---|---|---|
| Clerk | User authentication and account management | Guardian email, Guardian name, User ID, Password hash | https://clerk.com/privacy |
| Neon | Serverless PostgreSQL database hosting | All platform data (encrypted at rest and in transit) | https://neon.tech/privacy |
| Vercel | Application hosting, edge network, and CDN | Web traffic, Standard access logs | https://vercel.com/privacy |
| Resend | Transactional email delivery | Guardian email address, Guardian name, Email subject/body content | https://resend.com/privacy |
| Anthropic | AI tutoring — generates Lio's replies to what a student writes or draws. Not used to train AI models. | Student-authored messages, Whiteboard drawings, Associated lesson/slide context | https://www.anthropic.com/legal/privacy |
| LiveKit Cloud | Real-time video/audio for live 1:1 tutoring sessions | Session metadata, Audio/video streams | https://livekit.io/privacy |
| Stripe | Payment processing for donations | Donor name, Donor email, Donation amount, Payment method type | https://stripe.com/privacy |
| Plausible | Cookieless, privacy-friendly web analytics on the marketing site | Aggregate usage events, Page views (no personal data, no cookie) | https://plausible.io/privacy-focused-web-analytics |
| Checkr | Background checks for volunteer tutors | Tutor name, Tutor identity information for background screening — not active in production yet | https://checkr.com/privacy-policy |
| Twilio | Mandated-reporter SMS alerts for safety incidents requiring review | Staff phone number, Incident id and category (no child identifier in the message body — see packages/core/src/safety/sms.ts:95-97) | https://www.twilio.com/en-us/legal/privacy |
| Sanity | CMS for curriculum content — no learner data | Lesson content authored by staff (no student/guardian data) | https://www.sanity.io/privacy |
| ImprovMX | Mail forwarding for hello@, support@, privacy@, safety@, legal@, and security@plio.academy | Guardian correspondence, which may name a child | https://improvmx.com/privacy-policy/ |
| Cloudflare R2 (Cloudflare, Inc.) | Video file storage for tutor interview recordings | Tutor video recordings (not student data) | https://www.cloudflare.com/privacypolicy/ |
| Fly.io, Inc. — first-party hosting, not a sub-processor | Runs two pieces of Plio's own self-hosted code: the shared-whiteboard sync server (San Jose, US region) and Plio's math engine, which checks and solves the math your child types — same category as Vercel/Neon below: rented compute, not a third party receiving content, and not a sale or third-party use | Whiteboard: redacted board content transits this server in the clear so Plio's own moderation runs; only a REDACTED snapshot is ever stored. Math engine: receives only the typed math expression and your child's learning tier, processes it while answering, and stores nothing (it is not saved and not written to logs). Fly.io itself has no visibility into either beyond hosting the container | https://fly.io/legal/privacy-policy/ |
| Human tutors — a person, not a service provider | A background-checked adult volunteer tutor, for a live 1:1 tutoring session your family booked and consented to for that specific tutor | What your child says and shows on the live video call and draws or types on the shared whiteboard, during that session only; your child's display name, age band, and approved subjects; before the session, completion counts and the last completed lesson title (never a score) | See Section 4.3 — the tutor cannot record, screenshot, or keep any of it, and this consent is per-tutor, not platform-wide |
We require every third-party service that processes personal data for us to be bound by a Data Processing Agreement (DPA) restricting use of that data to the services they provide to us, and we prohibit them from using it for any other purpose. For Anthropic, our AI provider, that agreement is Anthropic's Data Processing Addendum, which is incorporated by reference into the Commercial Terms we accepted.
6.1 Data Residency
- Primary database hosted in the United States (Neon PostgreSQL, us-west-2 AWS region)
- Email processing via Resend (distributed, compliant with GDPR/CCPA)
- Backups retained up to 7 days (7 nightly snapshots) in the same US region; our database provider's point-in-time recovery window may hold a copy for up to 30 days
7. Cookies and Tracking
7.1 Student-Facing Pages (learn.plio.academy)
Student-facing pages do NOT use:
- Third-party tracking cookies
- Advertising pixels or beacons
- Behavioral profiling pixels
- Session tracking for marketing purposes
Essential cookies may be used for:
- Maintaining login session
- CSRF token security
- Language preference persistence
7.2 Guardian-Facing Pages (plio.academy)
Guardian-facing pages use minimal, essential cookies for:
- Session management
- Security (CSRF tokens)
- Language preference
- Cookie preference choice (does not gate Plausible, which is cookieless and always runs)
No third-party marketing cookies are used on guardian pages.
7.3 Cookie Consent and Preferences
When you visit plio.academy, you will see a cookie consent banner. You may:
- Accept all essential and analytical cookies
- Decline non-essential cookies and use the Platform (with reduced analytics)
You can manage cookie preferences anytime via the footer link "Cookie Settings."
8. Data Retention
We retain personal information only as long as necessary to provide services or comply with law:
| Data Type | Retention Period | Reason |
|---|---|---|
| Account information (email, name) | While your account is active, or until 24 months of inactivity across all your children's profiles. When you delete your account, your Clerk sign-in record is deleted by Clerk immediately; any child profile it leaves behind is permanently erased within 30 days. | Account recovery, legal holds |
| Student learning activity (lesson progress, quizzes, exit tickets; mastery/skill-tracking state if enabled; what your child types or says to Lio) | Lesson progress and quizzes: until guardian deletion, or 24 months of profile inactivity. Mastery/skill-tracking state, if enabled: until guardian deletion, or 12 months of profile inactivity. What your child types or says to Lio: 30 days, then deleted, regardless of profile activity. | Educational record, progress tracking |
| Waitlist submissions | Until you ask us to remove you, or until you enrol. We review waitlist entries at least quarterly and remove entries older than 24 months; this review is manual, not an automatic timer. Write to privacy@plio.academy to be removed at any time. | Enrollment notification |
| Tutoring session chat (text between you and a tutor about your child's session) | 24 months after the chat session ends, then automatically deleted; immediately if you delete your child's profile. The retention period matches other guardian-account data and is confirmed by counsel. | Coordinating a specific tutoring session; safety review if needed |
| Donation records | 7 years | Nonprofit financial regulations (Form 990) |
| Server logs | 30 days | Security, debugging, incident response |
| Backup data | Up to 7 days. We keep 7 nightly database snapshots and prune older ones; a deletion becomes permanent in every snapshot within 7 days. Our database provider's own point-in-time recovery window (up to 30 days, plan-dependent) may hold a copy for the same period. | Disaster recovery |
| Analytics data (aggregate, no cookies, no identifiers) | Aggregate counts are kept indefinitely. There is no individual record to retain or delete: our analytics provider (Plausible) stores no cookies, no IP addresses, and no per-visitor identifier, and analytics are not loaded at all on pages your child uses. | Program evaluation, research |
| Tutor interview video recordings (adult applicants only — never a child) | Kept while the tutor application is open and for as long as the tutor is active with Plio. Deleted on request to privacy@plio.academy, reviewed at least quarterly by staff; there is no automatic timer today. Stored in Vercel Blob. | Vetting record for an adult who may work with children |
| Whiteboard drafts (in-progress drawings) | 30 days after last edit, then permanently deleted | Lets your child continue the same drawing on another device; keeps AI tutoring consistent across devices |
| Skill-lab projects (child-written code) | Kept until you delete your child's profile, or your child resets that lab from within the editor | Lets your child resume the code project they're building in a Skill Lab, on any device, without losing their work |
Whiteboard drafts are working copies, not saved artwork. We keep them only so your child can pick up where they left off on another device, and so Lio's help stays consistent no matter which device they use. They are deleted automatically 30 days after the last edit, and immediately if you delete your child's profile. We do not use them to build a profile of your child, and we do not share them with anyone outside the providers listed above.
Skill-lab projects work the same way, but are kept longer because they are your child's own build, not scratch work: we do not delete them on a timer, only when you delete your child's profile or your child chooses to start that lab over. If your child adds notes to a project's README, or names the project, we automatically remove any email address, phone number, street address, or personal link from that text before saving — the same protection described in Section 4.3 for a message to Lio. The code itself (the blocks your child arranges and the program they generate) is saved exactly as written; we do not scan or alter your child's own code.
9. Your Privacy Rights
9.1 Right to Access
You have the right to request and receive a copy of all personal information we hold about you or your child. We will provide this in a portable, human-readable format within 10 business days of verification.
9.2 Right to Correction
You may request correction of inaccurate information. We will update our records and correct any downstream copies with service providers.
9.3 Right to Deletion
You may request deletion of your account and associated personal information at any time. We will delete within 45 days (with one 45-day extension available for complex cases with notice), except where:
- Retention is required by law (tax records, legal holds)
- Deletion would harm other users or the Platform's operation
Anonymized, aggregated data is retained for research.
9.4 Right to Opt-Out of Communication
You may opt out of non-essential emails (newsletters, feature announcements) by:
- Clicking the unsubscribe link in any email
- Changing email preferences in your dashboard
- Emailing hello@plio.academy
Transactional emails (password resets, enrollment confirmations) cannot be opted out of while your account is active.
9.5 Right to Data Portability
You may request a copy of your data in a portable format (CSV, JSON) for transfer to another service.
9.6 Right to Know About and Limit Use
California residents (and residents of other privacy-law states) have the right to know:
- What categories of data we collect
- How data is used
- Who data is shared with
You may request limitation of use to service delivery only.
9.7 Exercising Your Rights
To exercise any privacy right, email:
Plio Academy Privacy Office
Email: hello@plio.academy
Subject: "[YOUR_RIGHT] Request — [Your Name]"
Include:
- Your full name
- Email address
- Account ID (if applicable)
- Specific request (access, correction, deletion, etc.)
- Proof of identity or guardianship
We will respond within 10 business days. Identity verification may be required for sensitive requests.
10. CCPA/CPRA — California Residents
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you specific rights:
As a nonprofit organization, Plio Academy may be exempt from certain CCPA provisions. However, we voluntarily extend these privacy rights to all California residents as a matter of practice.
10.1 Categories of Personal Information Collected
- Identifiers (name, email, phone, account ID)
- Commercial information (donation amounts, tier enrollment)
- Education information (learning activity, quiz responses, progress)
- Geolocation data (not collected for students)
- Device information (browser, OS, device type)
- Usage data (pages visited, time on page, clicks)
10.2 Sources of Information
- Directly from you (account registration, forms)
- Automatically (usage analytics, cookies)
- Not from data brokers or third parties (we do not purchase data)
10.3 Business or Commercial Purpose
We use your information to:
- Provide and improve educational services
- Comply with law and regulations
- Ensure platform security and prevent fraud
- Conduct research on learning outcomes (anonymized)
10.4 Disclosure of Personal Information
We disclose information only to service providers (listed in Section 6) under contract restricting their use to our purposes.
10.5 Right to Delete
California residents may request deletion of personal information. Submit requests to hello@plio.academy with "CCPA Request — Delete" in the subject line.
10.6 Right to Opt-Out of "Sale" or "Sharing"
Plio Academy does not sell or share personal information in the manner described by CCPA. We do not permit third parties to collect our data for their own use.
10.7 "Do Not Sell or Share My Personal Information"
Plio Academy does not sell or share personal information as defined by CCPA/CPRA. No action is required. If you have questions, contact hello@plio.academy.
10.8 Right to Limit Use of Sensitive Personal Information
Plio Academy does not use sensitive personal information (as defined by CPRA) for purposes beyond providing the services you requested. We do not use sensitive PI for advertising, profiling, or secondary commercial purposes.
10.9 Right to Limit Use and Disclosure
You may request that we limit use of your personal information to the purposes necessary to fulfill the services you request. Submit requests to hello@plio.academy with "CCPA Request — Limit Use" in the subject line.
10.10 Right to Know and Access
You have the right to know what categories of personal information we collect and how we use it. Request this information via hello@plio.academy with "CCPA Request — Know" in the subject line.
10.11 Non-Discrimination
Plio Academy does not discriminate against you for exercising your privacy rights. We will not:
- Deny services or charge different prices
- Provide a degraded level of service
- Suggest we treat you differently
11. European Users — GDPR Compliance
If you are located in the European Union, United Kingdom, or other GDPR-applicable jurisdiction:
11.1 Legal Basis for Processing
We process personal information on the following legal bases:
- Performance of Contract: Data needed to provide Platform services (account, learning activity)
- Legitimate Interest: Service improvement, security, fraud prevention
- Consent: Marketing communications (you can withdraw anytime)
- Legal Obligation: Compliance with subpoenas, court orders, data protection laws
- Children's data (Art. 8): For users under 16 (or the applicable age threshold in their EU/UK member state — e.g., 13 in Ireland and UK, 16 in Germany), we rely on verifiable parental/guardian consent under GDPR Article 8. We collect the minimum data necessary and do not use children's data for any purpose beyond providing the educational services.
11.2 Data Protection Officer
Plio Academy does not currently have a designated Data Protection Officer. Questions about GDPR compliance may be directed to:
Plio Academy Privacy Office
hello@plio.academy
11.3 International Data Transfer
Your data is processed in the United States. Plio Academy is a US-based controller with no EU establishment. For transfers of personal data from the EU/EEA to the United States, we rely on the European Commission's Standard Contractual Clauses (2021), specifically Module 1 (controller-to-controller) as incorporated into our Terms of Service and Privacy Policy per Art. 46(2)(c) GDPR. For UK data subjects, we rely on the UK Addendum to EU SCCs approved by the ICO under s.119A UK Data Protection Act 2018.
For transfers to US-based sub-processors, we require Module 2 SCCs (controller-to-processor) in each sub-processor's Data Processing Agreement. Our sub-processors and their transfer mechanisms are documented in the International Transfer Addendum, which includes a Transfer Impact Assessment (TIA) conducted on 2026-05-14.
To request a copy of the applicable SCCs, email hello@plio.academy.
11.4 Rights Under GDPR
GDPR rights are incorporated throughout this policy (Section 9). Additional rights include:
- Right to Withdraw Consent: Withdraw consent for processing anytime
- Right to Lodge Complaint: Contact your local data protection authority (DPA)
12. Security and Data Protection
12.1 Security Measures
We implement industry-standard security practices:
- Encryption in Transit: All data transmitted via HTTPS/TLS 1.2+
- Encryption at Rest: Database encryption for sensitive data
- Access Control: Role-based access control (RBAC) restricts employee access
- Authentication: Multi-factor authentication (MFA) available for guardians
- Vulnerability Management: Regular security audits and penetration testing
- Incident Response: Written procedures for detecting and responding to breaches
12.2 No Guarantee of Perfect Security
Despite these measures, no system is perfectly secure. We cannot guarantee:
- Absolute prevention of unauthorized access
- Complete protection against sophisticated attacks
- Immunity from zero-day vulnerabilities
We commit to continuous improvement and transparent communication in case of a breach.
12.3 Data Breach Notification
In case of a confirmed data breach affecting personal information, we will:
- Notify affected users and guardians via email without unreasonable delay
- Notify regulatory authorities as required by law
- Provide clear guidance on protecting personal information
- Publish a summary of the incident and remediation
For EU/UK data subjects, we will notify the competent supervisory authority within 72 hours of becoming aware of a confirmed breach, as required by GDPR Article 33.
13. Nonprofit Use of Data
13.1 Research and Program Evaluation
As a nonprofit, Plio Academy uses anonymized, aggregated learning data to:
- Publish research on learning outcomes and efficacy
- Apply for grants and demonstrate impact to funders
- Improve curriculum design and personalization
- Evaluate equity and access across demographics
Individual student data is never shared with funders or published without anonymization.
13.2 Fundraising and Donor Reports
We may share aggregate statistics with donors (e.g., "1,000+ students completed lessons," "average quiz score improvement: 20%"). Individual donor information is never shared with third parties.
14. Children's Educational Records (FERPA)
If Plio Academy serves as an educational institution under FERPA (Family Educational Rights and Privacy Act):
- Parents have the right to review and request correction of educational records
- We will not disclose records to third parties without consent (except as required by law)
- Records are retained per FERPA requirements (typically 5+ years)
Contact hello@plio.academy to submit a FERPA request.
15. Third-Party Links and Content
The Platform may contain links to external websites, educational resources, videos, or third-party content. This Privacy Policy applies only to Plio Academy services. Third-party websites have their own privacy policies, and we are not responsible for their data practices. We encourage you to review their policies before providing information.
16. Marketing and Promotional Communications
16.1 Opt-In and Opt-Out
Plio Academy respects your communication preferences:
- Marketing emails (newsletters, feature announcements) — you may opt out anytime
- Transactional emails (password resets, confirmations) — cannot be opted out while account is active
- Policy and legal updates — sent to all guardians as required
16.2 Targeted Communication
We do not use children's learning data for marketing purposes. Guardian-targeted communication is based only on explicit preferences and account history, never on children's educational performance or interests.
16.3 Unsubscribe
To unsubscribe from marketing emails:
- Click the unsubscribe link in the email footer
- Log in to your dashboard and change preferences
- Email hello@plio.academy with "Unsubscribe" in the subject
We will honor your request within 5 business days.
17. Analytics and Performance Monitoring
17.1 Plausible Analytics
We use Plausible on our public marketing site (plio.academy) to understand how visitors — guardians, educators, and donors — interact with that site. Plausible is a privacy-friendly alternative to Google Analytics that:
- Does not use cookies of any kind
- Does not track across websites
- Does not fingerprint devices
- Does not sell data to advertisers
- Complies with GDPR and CCPA by design, because it collects no personal data
Because Plausible sets no cookie and stores no data in your browser, it is not gated behind the cookie preferences banner the way a tracking-cookie-based tool would be — there is no cookie to consent to. We do not run Plausible on the learning platform (learn.plio.academy) or on any page a student uses, and we do not use session recording anywhere.
17.2 Data Collected via Analytics
- Pages visited (page path only — no query strings)
- Button clicks we've explicitly instrumented (e.g. donate button, educator "Apply to teach")
- Device type and operating system (derived from the User-Agent header, discarded after aggregation — not stored per-visitor)
- Geographic region (country/state level, not precise location, derived from IP address which Plausible does not store)
We never identify individual visitors — Plausible has no visitor ID, no cross-session tracking, and no concept of an individual profile at all.
17.3 Anonymization
Plausible does not collect personal data to begin with — there is nothing to anonymize. Page views and events are aggregated into site-wide counts; no analytics event is ever linked to an individual guardian, donor, or student identity.
17.4 Disabling Analytics
Because Plausible collects no personal data and sets no cookie, there is no individual tracking to opt out of. If you would still prefer we not count your visit in aggregate site statistics:
- Enable "Do Not Track" or a content/script blocker in your browser — Plausible's script will not load
- Requesting confirmation of what aggregate data exists (there is no per-visitor record to delete) via hello@plio.academy
18. Sensitive Personal Information
18.1 What We Do NOT Collect
Plio Academy does not intentionally collect:
- Government IDs (SSN, passport number, driver's license)
- Payment card numbers (Stripe handles payment securely)
- Health or medical information (except voluntarily disclosed support)
- Biometric data (fingerprints, facial recognition)
- Genetic information
- Precise geolocation (GPS coordinates)
- Social media credentials or account numbers
18.2 Accidentally Received Sensitive Data
If you accidentally provide sensitive information (e.g., a child's SSN), we will:
- Delete it immediately upon discovery
- Not use it for any purpose
- Notify you that we deleted it
- Never ask you to provide such information again
19. User Responsibilities
19.1 Guardian Responsibilities
As a guardian, you are responsible for:
- Keeping your account login credentials confidential
- Monitoring your child's access to the Platform
- Reviewing privacy settings and communicating preferences
- Notifying us immediately if your account is compromised
- Updating contact information if it changes
19.2 Protecting Your Child's Privacy
- Do not share your child's student profile link publicly
- Use strong passwords and enable multi-factor authentication
- Do not disclose your child's activity in public forums
- Review our privacy policy with your child as age-appropriate
20. Special Considerations for Schools and Districts
20.1 School Administrator Accounts
If Plio Academy is used by a school or district:
- School administrators may create student accounts on behalf of students
- The school or district is responsible for obtaining parental consent
- FERPA and state student privacy laws apply in addition to this policy
- The school must execute a Data Processing Agreement (DPA) with Plio Academy
20.2 Shared Devices in Schools
Plio Academy sessions may be shared on classroom devices. We recommend:
- Using private browsing mode for shared devices
- Logging out after each session
- Clearing cache and cookies regularly
- Monitoring access via dashboard notifications
20.3 District Data Export
Schools and districts may request a data export of student progress in bulk. Plio Academy will provide exports within 10 business days of verification.
21. Dispute Resolution
21.1 Privacy Disputes
If you have a dispute regarding Plio Academy's privacy practices:
- First, contact us in writing at hello@plio.academy with details
- We will respond within 10 business days
- If unresolved, you may contact your state's Attorney General or the FTC
21.2 COPPA Complaints
Complaints about Plio Academy's compliance with COPPA may be filed with:
Federal Trade Commission
Bureau of Consumer Protection
https://reportfraud.ftc.gov
Or call 1-877-FTC-HELP (1-877-382-4357)
22. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Effective Date." For material changes affecting how we use children's data, we will notify guardians by email at least 14 days before the change takes effect.
Continued use of the Platform after changes become effective constitutes acceptance of the updated policy.
23. Contact Us
For questions, concerns, or requests related to privacy:
Plio Academy Privacy Office
Email: hello@plio.academy
We aim to respond within 5 business days.
For COPPA-specific concerns, you may also contact the FTC at ftc.gov.
END OF PRIVACY POLICY
Last Updated: September 29, 2026 — Section 4.3 and Section 6 now disclose Plio's math engine, which runs on Fly.io and processes the math expression your child types transiently (not stored, not logged; B-1334); previous update September 25, 2026 — Section 3.1 added the child's-state-of-residence disclosure (asked on the guardian dashboard, optional, used only to route a mandated report to the right state's child-protection authority — B-1218); previous update September 24, 2026 narrowed Section 6's third-party DPA sentence from an unverified blanket claim ("Each third-party service is bound by...") to a requirement statement plus the one substantiated instance (Anthropic, by incorporation into the Commercial Terms); prior update September 15, 2026 added to Section 4.3 (human tutors as a recipient of your child's live tutoring session content) and Section 6 (Human tutors disclosure row); earlier update August 5, 2026 added Section 4.3 (what happens to text your child types). This page is generated directly from docs/legal/privacy-2026-05.md — the markdown is the authoritative source; this is the complete policy, not a summary.