Legal
Coeducate privacy policy
What Coeducate collects, what it is used for, what it is never used for, and how to have it removed. Last updated 3 September 2026.
Who operates this service
This service is operated under the brand Coeducate at the domain coeducate.ai. The contact address for every privacy matter, including access and deletion requests, is app@coeducate.ai.
Where a school, district or tutoring program uses Coeducate, that organization is the controller of the education records involved and Coeducate processes them on its instruction.
What we collect
- Account data. The email address you give us when you sign up, plus the page path you were on, referral information and any campaign parameters in the link you arrived through. We use these to reply to you and to understand which pages bring people who actually want the product.
- Roster identity supplied by the school. Where a school connects rostering, we hold the identifiers the school chooses to send: typically a name or display name, a class or section, and an internal student identifier.
- Student work submitted to the product. The text, answers and reasoning a student submits in a tutoring session, and the skills, states and evidence lines derived from it.
- Technical data. IP address, browser user agent and timestamps, used for security, abuse prevention and rate limiting.
We do not ask students for personal information, and there is no student-facing account signup on this website.
Student work
Student work is processed for exactly one purpose: producing the evidence card the school asked for. It is sent to a third-party model provider for inference under terms that exclude training use, and it is stored against the school's account so that mastery can be read over time.
The public Mastery Check demo on this website is separate and stores nothing at all. Text entered there is sent for inference and returned as a card; it is not written to any table and not written into any log. Before the request leaves your browser, text that looks like a name following "Student:", an email address or a phone number is replaced client-side.
What we never do
- We do not use student work to train or fine-tune models, ours or anyone else's.
- We do not sell, rent or license personal data to anyone, for any purpose.
- We do not run advertising in the product, and we place no advertising identifiers on student-facing screens.
- We do not send marketing to students, and we do not build behavioral or commercial profiles of them.
- We do not disclose education records to third parties except the processors listed below, or where law requires it.
FERPA, COPPA and legal basis
In the United States, Coeducate is intended to be used under the school official exception of FERPA: we act under the direct control of the educational institution with respect to education records, we use them only for the purpose the institution specifies, and we do not redisclose them.
Where students under 13 use the service, the school provides consent on the parents' behalf for educational purposes, which is only available to a vendor that limits use to that purpose. Our commitments above are what keep that available.
Coeducate does not hold a SOC 2 report, an ISO 27001 certificate, a COPPA safe harbor seal or a signed state data protection agreement. The student privacy page states this in full rather than leaving it to be discovered.
For website visitors and account holders outside a school relationship, we process the email address you provide on the basis of your consent and our legitimate interest in replying to you.
Who else touches the data
- A model inference provider, to produce diagnoses and evidence cards. Terms exclude use of the content for training.
- Hosting and infrastructure providers, to run the application and store data.
- An email delivery provider, to send confirmation codes and account email.
The current list of subprocessors is available on request, and is provided to Enterprise customers as part of data protection agreement review.
Retention and deletion
Student work and derived records are retained while the school's account is active, so that mastery can be read across sessions. They are deleted on request at any time, per student or in bulk, and deletion removes the stored work as well as the derived skills and cards.
On account closure we export the records for you and then delete them rather than retaining a copy. Signup email addresses are retained until you ask us to remove them.
Your rights and how to use them
You can ask what we hold, ask for a copy, ask for a correction, and ask for deletion. Parents and guardians should make requests concerning a student through the school, because the school is the controller of the record; we will act on the school's instruction promptly.
Send any request to app@coeducate.ai. We reply to email, usually within one business day, and we will tell you what we did rather than only that we received the request.
This website
Coeducate.ai uses a first-party session cookie so the demo's rate limit and the signup flow work. There is no advertising network on this site and no cross-site tracking pixel. If we ever add an analytics tag it will be a single, privacy-respecting one and this section will name it.
Changes and contact
If this policy changes materially, we will update the date at the top of the page and email account holders. Continued use after a change means the updated policy applies.
Questions, requests and complaints: app@coeducate.ai. See also the terms of service and the student privacy page.
See what a session actually produces
Run the Mastery Check on the sample work, or paste your own practice text. Nothing you type is stored.
Student work is never used to train models. No card required to try the demo.