Student Data Privacy Policy
Last updated July 26, 2026
This Student Data Privacy Policy ("Policy") is maintained by Raising Readers with Elise, LLC ("we," "us," or "our") to explain how LitTrack ("the Service") collects, uses, stores, protects, and shares personal information about students ("Student Data"). It supplements our general Privacy Policy and Terms of Service. Where the two conflict with respect to Student Data, this Policy controls.
1. Who This Policy Applies To
LitTrack is used by individual reading tutors, interventionists, and specialists ("Educators") to plan lessons, track skills, and record assessments for the students they teach. Parents or legal guardians ("Parents") may be invited by an Educator to view their own child's progress through a parent dashboard. This Policy applies to any personally identifiable information about a student that an Educator or Parent enters into or generates within the Service.
2. Educator and Parent Responsibilities
Educators are solely responsible for obtaining any consent required by applicable law (including FERPA, COPPA, and state student data privacy laws) from parents, guardians, schools, or districts before entering Student Data into the Service. LitTrack is a service to the Educator, not a school-issued platform, and we do not independently verify enrollment, guardianship, or consent. By entering Student Data, the Educator represents that they have the authority to do so.
3. What Student Data We Collect
Depending on what an Educator chooses to enter, Student Data may include:
- Student first name (or nickname), grade level, and general notes
- Scope-and-sequence, target skills, and current-skill assignments
- Assessment responses, marks, scores, and skill mastery history
- Running record accuracy, words-per-minute, and error notes
- Session notes, lesson plans, and activity results
- Uploaded photos, PDFs, or attachments the Educator associates with a student
- Schedule information (session times, day of week, duration)
- For Parent accounts: the parent's email, name, and login timestamps
We do not ask Educators to enter student Social Security numbers, home addresses, government identifiers, medical diagnoses, or biometric identifiers. Educators should not enter this information into free-text fields.
4. How We Use Student Data
We use Student Data only to:
- Provide the Service to the Educator who entered it (and to Parents that Educator has invited)
- Generate lesson plans, assessments, reports, and practice activities within that Educator's account
- Maintain the security, integrity, and reliability of the Service
- Respond to support requests from the Educator or Parent
- Comply with applicable law
We do not sell Student Data, rent it, use it for behavioral advertising, or build advertising profiles from it.
5. AI Features and Student Data
Some Service features (activity generation, extraction from photos and PDFs, error analysis) send the relevant content to an AI provider on the Educator's behalf to fulfill that specific request. Content sent to the AI provider is limited to what is needed for the request and is transmitted over an encrypted HTTPS/TLS connection. AI usage is capped by plan: Premium includes up to 1,000 AI actions per month, Pro includes up to 300 AI actions per month, and Basic does not have AI features enabled. We rely on our infrastructure providers' and each AI provider's own published terms and security practices with respect to how submitted content is handled; we do not independently verify or guarantee those providers' data-handling or model-training practices.
6. Subprocessors
We rely on the following subprocessors to operate the Service. Each is bound by its own privacy and security terms. This is the same list published on our School & District Data Agreements page:
- Supabase, Inc. — Database, authentication, and file storage. All data submitted to the Service, including Student Data
- Lovable — Application hosting, deployment, and server functions. All data submitted to the Service, including Student Data
- Stripe, Inc. — Payment processing for LitTrack subscriptions and for family invoices a tutor issues through their own connected Stripe account. Educator and payer billing data. Family invoice line items are sent using a non-identifying reference (for example "Tutoring — Invoice #1042"); student names are not sent to Stripe.
- Google (Gemini) and other AI model providers, accessed through the Lovable AI Gateway — AI generation and content extraction requests initiated by the Educator, transmitted over HTTPS/TLS and subject to each provider's own published terms. Only the content included in the specific AI request
- Google LLC (Google Drive) — Optional per-tutor Google Drive connection used to browse and import the tutor's own files. Files the tutor selects, plus the connection's access tokens
We will update this list when subprocessors change. Educators who require a signed Data Processing Addendum (DPA) or subprocessor notification agreement should contact us before entering Student Data. We do not currently offer a pre-approved institutional agreement.
7. Data Sharing
We share Student Data only:
- With the Educator who entered it, and with Parents that Educator has explicitly invited for a specific student
- With the subprocessors listed above, strictly to operate the Service
- When required by law, subpoena, or court order — in which case we will attempt to notify the affected Educator unless prohibited
- In connection with a merger, acquisition, or sale of assets, in which case the successor is bound by this Policy or must provide notice and an opportunity to delete data
8. Security
We use commercially reasonable administrative, technical, and physical safeguards to protect Student Data, including:
- Encryption of data in transit via HTTPS/TLS
- Row-level access rules that limit each Educator's account to their own students
- Scoped Parent access limited to the specific student a Parent was invited for
- Access controls and least-privilege administrative access
Storage-level encryption at rest, backup schedules, and processing regions are determined by our infrastructure providers. We rely on their published practices and do not make independent commitments about them.
No system is 100% secure. We cannot and do not guarantee that Student Data will never be subject to unauthorized access. Educators and Parents are responsible for safeguarding their own login credentials and for signing out on shared devices.
9. Data Breach Notification
If we determine that Student Data in our custody has been subject to a confirmed unauthorized acquisition or disclosure, we will notify the affected Educator without unreasonable delay, and in any event within the timeframe required by applicable law. Our notice will describe, to the extent known, the nature of the incident, the categories of Student Data involved, the date or date range of the incident, the steps we have taken to mitigate it, and steps the Educator can take. It is the Educator's responsibility to notify affected Parents, schools, districts, or regulators as required by their own obligations.
10. Retention and Deletion
We retain Student Data only for as long as the Educator maintains an active account and continues to use the Service for that student, or as required by law. Educators may delete an individual student, an assessment, an attachment, or any other Student Data record at any time from within the Service, and the Service supports cascading cleanup of related records when a student or account is deleted. Educators may also close their account and request full deletion of all Student Data by emailing us at the address in Section 13. The following are targets, pending verification, and not guarantees: we aim to complete verified deletion requests within 30 days, and to remove deleted data from backup copies within 90 days through our routine backup cycle. Billing, tax, fraud-prevention, and transaction records that we are legally required to retain are kept for the period required by applicable law.
11. Parent Rights
Parent invitation links expire after 7 days, are single-use, and are invalidated immediately once redeemed. If an Educator revokes a Parent's access, any unused invitation link and the Parent's ability to sign in are invalidated immediately. After activation, a Parent signs in using normal authenticated credentials rather than the original invitation link.
A Parent invited to the Service by an Educator may, for the specific student they were invited for, request to:
- Review the Student Data visible in the parent dashboard for that student
- Request correction of factual inaccuracies
- Request deletion of that student's data
Because Educators are the party that entered the Student Data, Parents should generally direct such requests first to the Educator. Parents may also contact us at the address in Section 13, and we will coordinate with the relevant Educator.
12. Compliance Framework
We design the Service with reference to the following student data privacy frameworks, where applicable to the Educator's use:
- FERPA (Family Educational Rights and Privacy Act) — when an Educator is acting as a "school official" for a school or district using LitTrack under an outsourced institutional function
- COPPA (Children's Online Privacy Protection Act) — the Service is directed at Educators, not children under 13. Students do not create accounts. Any student information present in the Service is entered by an Educator or Parent who is responsible for parental consent
- State student data privacy laws, including but not limited to New York Education Law §2-d, California SOPIPA/AB 1584, Connecticut Public Act 16-189, and similar laws in other states, where applicable to the Educator's engagement
This Policy is not a substitute for a written Data Privacy Agreement between a school or district and Raising Readers with Elise, LLC. Educators representing a school or district should contact us for a signed agreement before entering Student Data on behalf of that institution.
13. Contact
For any question, request, or notice under this Policy — including breach notifications, deletion requests, Parent inquiries, and DPA requests — contact:
Raising Readers with Elise, LLC
raisingreaderswithelise@gmail.com
14. Changes to This Policy
We may update this Policy from time to time. Material changes affecting how we handle Student Data will be announced within the Service or by email to account holders before they take effect. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.
See also our Privacy Policy and Terms of Service.