Trust Center
Built for students.
Trusted by families.
Plio Academy is a nonprofit. We have no advertising business model, no data to sell, and no incentive to collect more than we need. This page explains exactly how we handle student and family data.
Children's Online Privacy Protection
Children under 13 never create accounts directly on Plio Academy. Every student account is created and managed by a parent, guardian, or school administrator who provides verifiable consent. We apply COPPA protections to all users under 13 and extend similar care to all students on our platform regardless of age.
- Children never submit PII directly — guardian owns and controls all account data.
- A student profile holds a display name, an avatar, and a date of birth (used only to recommend an age-appropriate learning tier, never shown publicly or shared); no email, phone, or address.
- Lesson questions a student asks the Lio AI tutor are sent to Anthropic to generate educational answers, logged, and automatically moderated for safety — never used for advertising.
- With mastery tracking off, we still score every quiz, gate and retrieval question and show your child the result — we just don't add anything to their long-term mastery profile (skill estimates, review schedule, standards mastery, or gate progress). Turning mastery tracking on is what starts that profile.
- No behavioral advertising, no tracking pixels, no third-party marketing on student-facing pages.
- Any guardian may request full deletion of their child's data at any time — no questions asked.
- We do not sell, share, or rent student data to any third party for commercial purposes.
Does Anthropic train on our students' Lio conversations?
Plio does not use Lio conversation transcripts to train or fine-tune any AI model. Our vendor, Anthropic, publishes that it does not use commercial API inputs or outputs to train its models by default. On our side, messages are automatically scrubbed of personal information before they are sent or stored, and AI-tutor logs are permanently deleted after 30 days. If Anthropic's published terms change, we will update this page.
Educational Records Alignment
Plio Academy is designed to align with FERPA principles. When we partner with schools and districts, we act as a school official with a legitimate educational interest and handle education records accordingly.
- We never sell student education records or learning data to any party.
- Role-based access controls: teachers see only their students; guardians see only their children.
- District student data access via the district dashboard and roster sync is audit-logged.
- District data agreements available on request — contact privacy@plio.academy.
- If you are 18 or older, or you own your own Plio learning account, you may request your own education records directly — you do not need a parent or guardian to request them for you.
- Data portability: a guardian may request a full export of their child's progress, and an adult learner may request their own, by emailing privacy@plio.academy or from your account — we fulfill verified requests within 30 days.
Data Retention
| Data type | Retention period |
|---|---|
| Account & profile data | Retained while active. Auto-deleted after 24 months of inactivity; guardian-requested deletions completed within 30 days of verification. |
| Student learning progress (lesson progress, quizzes, exit tickets) | Deleted with the associated student profile (cascade); auto-deleted after 24 months of profile inactivity even if the profile is not otherwise deleted. |
| Mastery / skill-tracking (SRS) data, if enabled (skill estimates, per-question review schedule, per-question practice results) | Deleted with the associated student profile (cascade); auto-deleted after 12 months of profile inactivity — a shorter clock than the 24-month schedule above. Activity timestamps on these records are stored as a calendar day, not a time of day. |
| Guardian email (waitlist / contact form) | Until enrolled or removal requested |
| Server access logs | 30 days, then deleted |
| AI-tutor (Lio) conversation logs | 30 days, then permanently deleted (PII scrubbed before storage) |
| Skill-lab projects (child-written code) | Kept until profile deletion or an in-editor lab reset (README and project name PII-scrubbed before storage; code stored as written) |
| Donation records | 7 years (IRS nonprofit requirement) |
| Audit logs (privileged access) | 730 days (2 years) — covers a full Form 990 cycle and both statutory data-request look-back windows |
| Voice-advisor conversation transcripts (guardian and Lio, about a specific child) | 24 months (730 days) after the session ends — no audio is stored, text only, purged automatically once the session has ended |
| Shared-whiteboard session snapshots (redacted) | 90 days after the tutoring session, then permanently deleted (already redacted before storage) |
| Teen chat with Lio (conversation threads) — feature not yet active | 30 days from the start of the conversation, then permanently deleted (PII scrubbed before storage); also deleted with the student profile |
| Study-from-your-files: text extracted from an uploaded file — feature not yet active | 30 days, then the text is cleared. The uploaded file itself is deleted from storage as soon as its text is extracted, and in every case within 24 hours. The original filename is never stored. |
| Study-from-your-files: folders and generated study material (notes, flashcards, quizzes) — feature not yet active | Hard limit of 12 months from creation, then deleted; also deleted with the student profile |
| Guardian goals and private notes about a child | Kept until the guardian deletes them or the child's profile is deleted, whichever comes first (no separate timer). Never shown to the learner or a tutor, and never sent to an AI provider, email or notification. |
| Record of which adults viewed a child's progress signals — tutor view not yet active | 3 years (1095 days) from the view, then deleted; also deleted with the student profile. Stores who viewed and when, never the signal content. |
Accounts that go unused are cleaned up automatically: once a student profile has had no learning activity for 24 months, a monthly retention job permanently deletes it along with all of its learning data. Separately, when a guardian submits a deletion request (via our data-deletion form or by emailing privacy@plio.academy), our privacy team verifies it and completes the deletion within 30 days. Deleting a guardian account also automatically deletes every linked child profile and its data.
Accessibility
Every learner profile includes accessibility options guardians can turn on individually or apply as one of four named presets — Reading support, Focus, Low vision, and Calm.
Security Practices
Authentication
Powered by Clerk (SOC 2 Type II). Supports MFA, passkeys, and OAuth. No passwords stored by Plio.
Encryption
Database encrypted at rest (Neon/AWS AES-256). All traffic encrypted in transit (TLS 1.3). HTTPS-only — no plain HTTP.
Infrastructure
Hosted on Vercel edge network with DDoS protection. Database isolated in a private VPC. Secrets managed via environment variables, never committed to source.
Access control
Role-based permissions enforced at the database query layer. Staff access to production data requires 2FA and is fully audited.
Vulnerability management
Dependency updates automated via Dependabot. Security patches applied within 24 hours of disclosure. No unpatched critical CVEs.
Incident response
We notify affected users within 72 hours of a confirmed breach. Full post-mortems published within 30 days.
Sub-Processors
We use the following third-party services. Each is bound by a data processing agreement and may not use student data for any purpose other than providing services to Plio Academy.
| Vendor | Purpose |
|---|---|
| Clerk | User authentication and account management |
| Neon | Serverless PostgreSQL database hosting |
| Vercel | Application hosting, edge network, and CDN |
| Resend | Transactional email delivery |
| Anthropic | AI tutoring — generates Lio's replies to what a student writes or draws. Not used to train AI models. |
| LiveKit Cloud | Real-time video/audio for live 1:1 tutoring sessions |
| Stripe | Payment processing for donations |
| Plausible | Cookieless, privacy-friendly web analytics on the marketing site |
| Checkr | Background checks for volunteer tutors |
| Twilio | Mandated-reporter SMS alerts for safety incidents requiring review |
| Sanity | CMS for curriculum content — no learner data |
| ImprovMX | Mail forwarding for hello@, support@, privacy@, safety@, legal@, and security@plio.academy |
Last updated: May 2026. We will update this list before adding any new sub-processor.
Compliance Documentation
For district IT officers and procurement teams: E-Rate eligibility statement, state student-privacy law compliance table (IL SOPPA, CA AB 1584, NY Ed Law 2-d, TX SB 820, WA OSPI), FERPA school-official status, COPPA operator status, and CIPA notes.
Questions or concerns?
We acknowledge privacy requests within 5 business days and complete them within 30 days, as the applicable law requires. For data deletion requests, use the dedicated form.