Skip to main content
gregariousTrust Center
Privacy Policy

Your data. Your students' data. Protected.

Last updated: April 2026

FERPA

Designed for FERPA compliance.

Gregarious is designed for FERPA compliance from the ground up. Student education records are protected, access is role-scoped, and data is never used for advertising or sold to third parties. If you have questions, contact us at cgb003@gmail.com.

1. What data we collect

Gregarious collects only the data necessary to operate the educational platform and to personalize the learning experience for enrolled students. We do not collect data for advertising, profiling, or resale.

Student data

  • Display name and grade level (for teacher and parent visibility)
  • Email address (for account login and notifications)
  • Assessment responses and timing (to power the adaptive engine)
  • Mastery scores and progress milestones (for reporting to teachers and parents)
  • Effort Points (EP) earned (visible to the student; aggregate visible to teacher)
  • Studio project content: titles, descriptions, and written components (stored privately; visible to the student and their teacher)
  • Pulse check-in responses: daily mood indicator and optional short text (shown in aggregate to the teacher; never shared outside the classroom)
  • Session activity: pages visited, features used, and session length (used for product improvement and anonymized research)

Teacher data

  • Name and school email address (for login and rostering)
  • Class rosters and linked student accounts
  • Content created or contributed (assignments, rubrics, annotations) with explicit consent
  • Usage patterns (to improve the teacher experience; never sold)

Parent data

  • Name and email address (for account creation and weekly summaries)
  • Linked child relationship (parent_id mapped to student account)
  • No payment data is stored by Gregarious; payments are processed by a PCI-compliant provider

2. What we do NOT collect

The following data is never collected by Gregarious under any circumstances:

  • Biometric data of any kind
  • Device identifiers (UDID, advertising ID, MAC address)
  • Location data (GPS or IP-based geolocation)
  • Social media account data or connections
  • Student behavioral data outside of the Gregarious platform
  • Financial information about families
  • Photographs or video of students
  • Audio recordings
  • Data from students who have not been enrolled in the platform by a school

3. How we use data

Data collected inside Gregarious is used for one purpose: improving the educational experience of enrolled students and supporting the educators and parents who serve them.

  • Student assessment data powers the adaptive engine. It is never shared with third parties for non-educational purposes.
  • Teacher usage data helps us improve the platform. It is never used to evaluate teacher performance outside the platform.
  • Aggregate, anonymized data may be used in research publications, including the founder's doctoral dissertation (IRB #2025-0847). Individual students and teachers are never identifiable in research outputs.
  • We do not serve advertising. We do not sell data. We do not share data with data brokers.
  • We do not use student data to train AI models without explicit opt-in consent.

4. Subprocessors

Gregarious uses the following third-party services to operate the platform. Each is selected for its privacy posture and is subject to a data processing agreement.

Supabase

Database and authentication

Stores all user accounts, student records, and activity data. Enforces row-level security at the database layer. US-based infrastructure. SOC 2 Type II certified.

Vercel

Application hosting and edge delivery

Hosts the Next.js application and serves it globally. No student data is stored at the CDN layer. SOC 2 Type II certified.

Anthropic

AI features (Claude API)

Powers tutoring, scoring assistance, and content generation. Student names and identifying information are stripped before every call. Anthropic's API terms prohibit using submitted data to train models.

Resend

Transactional email

Sends account confirmations, parent summaries, and breach notifications. Receives only the recipient email address and message content for that send.

We do not use third-party advertising networks, behavioral tracking pixels, or social media login integrations within the student-facing platform. Google Fonts are loaded via a CSS link tag; no student data is transmitted to Google in this process.

5. Encryption in transit and at rest

All data transmitted between your browser and Gregarious is encrypted using HTTPS/TLS 1.2 or higher. We do not allow plain HTTP connections.

Data stored in Supabase is encrypted at rest using AES-256. Database backups are also encrypted. Row-level security policies ensure that users can only access their own data at the database layer, not just the application layer.

All AI calls are sent over encrypted connections. Student-identifying information is stripped from these calls before they leave the platform. Every student-facing AI interaction routes through an internal safety-wrapper layer (safety-wrapper.js) that filters input, enforces the Socratic posture of the tutor, redirects self-harm or abuse disclosures toward a trusted adult, and blocks unmoderated AI image generation in the student experience. See /trust/ai for a full breakdown of what data is sent to AI services.

6. Data retention

  • Active accounts: data is retained for the duration of the active account.
  • After a deletion request is submitted: personal data is purged within 30 days of the confirmed request.
  • After deletion: anonymized, aggregate research data with no linkage to any individual may be retained for dissertation purposes under IRB protocol #2025-0847.
  • Inactive accounts: accounts with no activity for 24 consecutive months are flagged for deletion. Account holders are notified by email 60 days before deletion.
  • Backups: encrypted database backups are retained for 30 days and then deleted.

7. Deletion process

Schools, parents, and eligible students may request deletion of any student account and all associated data. Here is how it works:

1

Email cgb003@gmail.com from the school's official address or the parent's email address on file.

2

Include: the student's display name, school name, and the reason for the request (optional).

3

We will confirm receipt within 2 business days and verify identity.

4

Deletion is completed within 30 days of the confirmed request.

5

You will receive a confirmation email when deletion is complete, including a summary of what was deleted.

You may also request a full export of your child's data before requesting deletion. We will provide a CSV of all stored records within 5 business days.

8. Breach notification

In the event of a confirmed data breach affecting student records, we will notify affected schools and parents within 72 hours of discovery. The notification will include:

  • What data was affected
  • When the breach occurred (if known)
  • What we have done to contain and remediate it
  • What you should do to protect yourself
  • Who to contact with questions

We will also file all required notifications under applicable state and federal law. Supabase handles encryption and breach response at the infrastructure layer under its SOC 2 Type II certification. We report security vulnerabilities disclosed to us within 48 hours of receiving the report.

9. FERPA posture

Gregarious is designed for FERPA compliance. We do not make blanket vendor-certification claims, because FERPA compliance is an obligation of the educational institution, not the vendor. What we do is design our systems so that schools can use Gregarious and remain in FERPA compliance.

  • Gregarious acts as a school official operating under the direction and supervision of the educational institution.
  • Student education records are accessible only to the student, their teacher of record, and their linked parent.
  • We do not share or disclose student education records to any third party without written consent, except as permitted under FERPA (e.g., a court order or legitimate educational interest).
  • We do not own student data. The school remains the data controller. Gregarious is the processor.
  • A Data Privacy Agreement (DPA) is available on request. Contact cgb003@gmail.com.

10. Parent and eligible-student rights

Under FERPA and our platform policies, parents and legal guardians of enrolled students have the following rights:

  • Right to inspect: Parents may request a full export of their child's data at any time.
  • Right to amend: Parents may request correction of inaccurate records.
  • Right to delete: Parents may request deletion of their child's account and all associated data. Deletion is processed within 30 days.
  • Right to restrict AI use: Parents may request that their child's data not be used for AI personalization beyond the core adaptive engine.
  • Right to opt out of research: Participation in IRB research (protocol #2025-0847) is opt-in only. Opting out does not affect access to any features.
  • Transfer of rights at 18: When a student turns 18 or enrolls in a post-secondary institution, FERPA rights transfer from the parent to the student.

To exercise any of these rights, contact cgb003@gmail.com.

11. Research use of anonymized data

The founder of Gregarious, Brian Adams, is a doctoral candidate at Notre Dame of Maryland University, advised by Dr. Rachel Durham, conducting research on EdTech Fatigue. The IRB approved the dissertation instrument under protocol #2025-0847. Some anonymized, aggregate usage data from the platform may be used in this research.

  • Participation in research data collection is opt-in only. Schools and parents must affirmatively consent.
  • Research data is fully anonymized before analysis. Individual students, teachers, and schools are never identifiable in any published findings.
  • Opting out of research does not affect access to any platform features.
  • Research data is handled under the IRB protocol, which includes data minimization, secure storage, and destruction after the dissertation is complete.
  • No research data is ever shared with third parties or used for commercial purposes.

12. Changes to this policy

Material changes to this privacy policy will be communicated to registered users by email at least 30 days before they take effect. The current version is always available at gregarious.app/privacy. Minor changes (such as clarifications that do not affect rights) will be noted in the "last updated" date.

13. Contact

Questions, requests, or concerns about privacy should be directed to:

Gregarious Privacy Contact
Brian Adams, Founder and EdD Candidate
StudentTeacherParentAdmin