Skip to main content
Trust Center

What we do with your students' data.

Gregarious was built by a classroom teacher and doctoral researcher. This page answers every hard question we could think of, honestly, including the ones we don't yet have full answers to.

Last updated: April 2026

1. What Gregarious does with student data

Student data in Gregarious is used for exactly one purpose: improving the educational experience of the student who generated it and supporting the educators and parents who serve them.

We collect:

  • Account information: display name, email address, role, and grade level.
  • Mastery activity: which standards were practiced, how many questions answered, scores earned, and session timing. This powers the adaptive engine.
  • Studio work: project titles, descriptions, and any written or creative content students produce. Visible only to the student, their teacher, and their linked parent.
  • Pulse check-ins: a daily mood indicator (emoji selection) and optional short text. Shown in aggregate to the student's teacher. Never shared outside the classroom.
  • Usage patterns: pages visited, features used, session length. Used to improve the product and for anonymized dissertation research. Never tied to a student's name in any published report.

We do not collect biometric data, device identifiers, location data, or any information unrelated to the student's learning activity.

2. Is student data sold?

No. Student data is never sold.

Gregarious does not sell student data to anyone, for any reason, ever. We do not share it with advertisers, data brokers, or any commercial third parties. The business model is school subscriptions, not data monetization.

We also do not use student data to show advertising, build commercial profiles, or train AI models without explicit opt-in consent from a parent or eligible student.

3. How is AI used?

AI in Gregarious serves three functions: Socratic tutoring, scoring assistance, and content generation for teachers. Here is what that means in practice.

  • Socratic tutor: When a student is stuck, the AI asks questions rather than giving answers. It never writes essays, answers comprehension questions for students, or completes assignments on their behalf.
  • Scoring assistance: AI scores open-response questions against a rubric. A human teacher reviews the AI's score for high-stakes items. See /trust/ai for a full breakdown.
  • Teacher tools: AI generates worked examples, reasoning scaffolds, and reflection prompts at a teacher's request. Teachers review all AI-generated content before it reaches students.

Student names and personally identifiable information are stripped from every AI call before it leaves the platform. The AI receives anonymized text only. Every student-facing AI interaction routes through an internal safety-wrapper layer (safety-wrapper.js) that enforces the Socratic posture, filters input, redirects self-harm or abuse disclosures toward a trusted adult, and blocks unmoderated AI image generation in the student experience.

For full documentation of every AI touchpoint, see /trust/ai.

4. Who can see my child's data?

Access is strictly role-scoped. A student cannot see another student's data. The following people can see a student's record:

The student

Their own mastery scores, EP, Studio projects, and pulse history. Nothing from any other student.

Teacher of record

Mastery data and pulse trends for their enrolled students only. They cannot see data from other teachers' classes.

Linked parent account

Their linked child's mastery percentage, EP, streak, and Studio projects. Read-only. No other students' data.

Brian Adams (founder; IRB approved the dissertation instrument under #2025-0847)

Anonymized, aggregate data only for dissertation research, advised by Dr. Rachel Durham at Notre Dame of Maryland University. Individual student records are not accessed for research purposes. The IRB protocol requires anonymization before any analysis.

Gregarious team

Individual records only to investigate a bug or support request, and only with the school's knowledge. Never for marketing or product analytics at the individual level.

5. How does deletion work?

Schools, parents, and eligible students have the right to request deletion of a student account and all associated data.

  • Email cgb003@gmail.com from the school's official address (or a parent's email on file).
  • Include the student's display name and the school name.
  • We will confirm receipt within 2 business days.
  • Deletion is completed within 30 days of the confirmed request.
  • You will receive a confirmation email when deletion is complete.

Anonymized, aggregate research data that cannot be linked back to any individual may be retained under IRB protocol #2025-0847 for dissertation purposes. This data has no name, email, or school identifier attached.

You may also request a full export of your child's data before requesting deletion. We will provide a CSV within 5 business days.

6. What happens if there's a breach?

In the event of a confirmed data breach affecting student records:

  • We will notify affected schools and parents within 72 hours of discovery.
  • Notification will include: what data was affected, when the breach occurred, and what we have done to contain it. We will also tell you what you should do.
  • Supabase handles encryption at rest (AES-256) and in transit (TLS 1.2+). Breach response is covered under Supabase's SOC 2 Type II certification.
  • We will file all required notifications under applicable state and federal law.

If you discover a security vulnerability, please report it to cgb003@gmail.com before public disclosure. We take responsible disclosure seriously and will respond within 48 hours.

7. Subprocessors

Gregarious uses the following third-party services. Each is subject to a data processing agreement, and each was selected in part for its privacy posture.

Supabase

Database and authentication

Security page ↗

Stores all user accounts, student records, and activity data. Enforces row-level security at the database layer. US-based infrastructure. SOC 2 Type II certified.

Vercel

Application hosting

Security page ↗

Hosts the Next.js application and serves it globally via edge network. No student data is stored at the CDN layer. SOC 2 Type II certified.

Anthropic

AI features

Security page ↗

Powers the Socratic tutor, scoring assistance, and worked-example generation. Student names and identifying information are stripped before any call. Anthropic's API terms prohibit using submitted data to train models.

Resend

Transactional email

Security page ↗

Sends account confirmations, parent summaries, and breach notifications. Receives only the recipient email address and message content for that send. No student performance data.

We do not use advertising networks, behavioral tracking pixels, or social media SDKs anywhere in the student-facing platform.

8. For district IT teams

Starting a district procurement review?

We want to make this as easy as possible. The documents below should cover most of what your review team needs. A Data Privacy Agreement (DPA) is available on request.

Gregarious is designed for FERPA compliance. Student education records are accessible only to the student, their teacher, and their linked parent. We act as a school official under the school's direction and do not own student data.

If your district has a student data privacy addendum (SDPA) template, send it to cgb003@gmail.com and we will review and sign it.

9. Questions we don't yet have full answers to

Honest transparency

Gregarious is an early-stage platform. We are committed to the security and compliance work below. Here is where we stand honestly, and where we are headed.

Is Gregarious SOC 2 certified?

Not yet. Our infrastructure (Supabase and Vercel) is SOC 2 Type II certified, which covers the storage and delivery layers. Gregarious itself as an application has not undergone a SOC 2 audit. We are working toward this. Timeline: 2027.

Has Gregarious had a penetration test?

Not yet by a third-party firm. The codebase follows security best practices including RLS on every database table, no raw SQL in application code, and encrypted connections. A formal third-party pen test is on the roadmap. Timeline: 2027.

Is there a bug bounty program?

Not yet formally. If you find a security issue, please report it to cgb003@gmail.com. We take responsible disclosure seriously and will work with you. A formal program is on the roadmap. Timeline: 2027.

Is Gregarious COPPA compliant?

Gregarious is designed for grades 5-12 and does not knowingly collect data from children under 13 without verifiable parental consent. Deployments involving students under 13 require a signed parental consent form administered by the school. We are evaluating formal COPPA compliance documentation. Timeline: 2027.

We would rather be honest about our current state than obscure it. If one of these gaps is a blocker for your district, reach out and we will talk through it.

Questions? Talk to a real person.

We are a small team. You will get a real answer from Brian, not a ticket number.

cgb003@gmail.com
StudentTeacherParentAdmin