Privacy Policy
Last updated: September 1, 2026
1. Introduction
This Privacy Policy describes how BYTSized LLC ("Company," "we," "us," or "our") collects, uses, and discloses information when you use Studiorum (the "Service"), including our iOS applications for students and teachers. We are committed to protecting the privacy of all users, including students who are minors. This policy applies to teachers, students, school administrators, and school district staff.
2. Definitions
- Personal Information: Information that identifies or can reasonably be used to identify an individual.
- Student Data: Personal information collected from or about students in connection with their use of the Service, which may constitute "education records" under FERPA.
- User Content: Content created, uploaded, or submitted by users, including tests, questions, student submissions, and documents.
- School Official: The role BYTSized LLC performs under FERPA—acting on behalf of an educational institution with a legitimate educational interest.
3. Information We Collect
3.1 Account Information
When you register or sign in, we collect:
- Email address
- Display name
- Profile picture (when signing in via Google OAuth)
- User role (teacher, student, administrator)
- Subscription status and weekly AI usage data (how much of your usage allowance has been used)
- Age eligibility confirmation. Student sign-up (and guest or anonymous activity entry) uses a neutral age screen: the birth year entered is checked in the browser and immediately discarded — it is never transmitted or stored. We keep only a timestamped confirmation of eligibility.
- Teaching profile — courses taught, grade levels, and standards jurisdictions (teachers, optional)
- Grading preferences and writing voice samples you provide to personalize AI feedback (teachers, optional)
3.2 Usage Data
We automatically collect technical and behavioral data when you use the Service, including:
- IP address
- Browser type and version
- Device identifiers
- Pages visited and features used
- Timestamps and session duration
- AI usage metering and activity logs
- Push notification tokens, if you enable notifications in our mobile apps
3.3 User Content
We collect and store content you create, upload, or submit through the Service, including:
- Educational questions, tests, rubrics, and generated activities (teacher-created)
- Student submissions and answers, including typed responses, drawings, audio recordings, photos, and uploaded files
- Documents, images, and video links uploaded or provided for AI processing
- Conversations with chatbot learning activities (saved as part of the test submission so teachers can review them)
- In-test Q&A chat messages between a student and their teacher
3.4 Test Monitoring and Academic Integrity Data
When a teacher enables test-security features for a specific test, we record monitoring data during that test only:
- Tab and window switches, including how long the student was away, and exits from fullscreen
- Copy, paste, and right-click attempts while the test is open
- A device and browser snapshot (device type, browser user agent, and — when a lockdown browser is required — the lockdown environment and its verification status)
- Presence signals ("heartbeats") that show the teacher who is actively testing
Typed written answers also record an editing timeline (for example, counts of paste, drag-and-drop, and undo events, and typing-pattern metrics). Teachers can replay how an answer was written and may run an AI-assisted process analysis that produces an authenticity signal. That signal is reviewed by the teacher; it is advisory and is not an automated determination of misconduct. Students are informed when monitoring is enabled, and monitoring never extends beyond the test itself. Tests taken embedded inside a school's LMS (LTI iframe) do not run these monitoring features; a test opened from the LMS in its own browser tab can be monitored like any other.
3.5 Information from Your School's LMS (LTI)
If your school connects Studiorum to its learning management system via LTI 1.3, we receive identity and roster information from the LMS as authorized by the institution — typically name, email address, profile photo, course roles, and a student information system identifier — and we send grades for Studiorum assignments back to the LMS gradebook.
3.6 Guest Sessions
You can browse parts of the Service as a guest through an anonymous session. Guest sessions are not linked to a name or email address; content a guest submits while taking a shared test is associated only with the anonymous session.
3.7 Payment Information
Payment card information is collected and processed directly by Stripe, Inc. We receive only limited transaction metadata (e.g., last four digits, transaction status). We do not store full payment card details.
3.8 Information from Third-Party Sign-In
When you sign in with Google, we receive your name, email address, and profile picture from Google in accordance with the permissions you grant during the sign-in flow.
3.9 Class Membership and Learning-Progress (Mastery) Data
When a student joins a teacher's class (with a join code or through the school's LMS), we record the class membership — the student's display name and account linked to that class roster.
The mastery dashboard records evidence of learning — one record per graded question, per student. Each record contains: the curriculum topic or standard the question assessed (a code such as "4.3" or a state-standard notation); whether the answer earned credit and its teacher-assigned point weight; a truncated copy of the question text (for the teacher's drill-down view); and identifiers linking the record to the student, teacher, class, and assignment. We never record free-form judgments about a student: teacher observations ("demonstrated this in discussion") are positive-only — they can add to a student's record, never subtract from it.
Who sees mastery data:
- The teacher sees full mastery data for their own classes.
- The student sees only their own mastery map and practice results — never classmates' data.
- Counselors or tutors can see read-only class dashboards, and only for classes a teacher explicitly shares. Sharing is per class, revocable at any time, and grants no ability to modify anything.
- Other teachers see nothing — mastery data is never pooled across teachers.
- Studiorum staff have operational access for support and debugging only.
A student's self-directed study sessions are visible only to that student. Practice a teacher assigns reports results back to that teacher — students see this distinction in the product.
4. How We Use Your Information
We use the information we collect to:
- Provide, operate, and improve the Service;
- Authenticate users and manage accounts;
- Process payments and manage subscriptions and usage allowances;
- Power AI-generated content, grading, and tutoring features (see Section 6);
- Communicate with you about your account, updates, and support;
- Monitor and analyze usage for performance, security, and product improvement;
- Comply with legal obligations and enforce our Terms of Service;
- Detect and prevent fraud, abuse, and unauthorized access.
We do not sell, rent, or share your personal information for advertising or marketing purposes.
5. Legal Bases for Processing
We process your information based on:
- Performance of a contract: To provide the Service you have requested.
- Legitimate interests: To improve the Service, ensure security, and prevent abuse.
- Legal obligation: To comply with applicable laws.
- Consent: Where you have explicitly consented, such as for optional communications.
6. Third-Party Services and AI Processing
We share data with trusted third-party providers only as necessary to provide the Service:
| Provider | Purpose | Users Affected |
|---|---|---|
| Google Firebase | Authentication, database, file storage, hosting | All users |
| Google Gemini | Teacher activities: AI content generation, digitizing paper tests, document and video processing, text-to-speech, image analysis and generation, writing-process analysis, and teacher-initiated AI grading of submitted student work | Teachers (student submissions are processed during AI grading) |
| Anthropic Claude | Student activities: the Magis AI tutor, conversation practice, roleplay and adventure games, chatbot activities, and student explanation and feedback flows | Students (and teachers previewing student activities) |
| Stripe | Payment processing for subscriptions and extra usage purchases | Teachers / subscribers |
| YouTube | Searching for educational video content (Data API, teacher side); embedded video playback inside activities loads from YouTube for the viewer | Teachers (search); any user viewing an activity with an embedded video |
| Google Forms API | Exporting tests as Google Forms | Teachers only |
| Google Maps / Street View | Scene imagery for Field Trip activities and map questions (content generation only — no user location data is collected or sent) | Teachers only |
| Wikimedia Commons | Sourcing openly licensed educational images | Teachers only |
| Wikipedia / Wikisource, PoetryDB | Sourcing public-domain texts, poems, and reference material for content generation | Teachers only |
| Common Standards Project | Looking up academic standards frameworks | Teachers only |
Student work submitted for AI grading or tutoring (such as essays, short answers, audio, and images) is transmitted to the AI providers above solely to provide those features. We do not use third-party advertising or analytics SDKs anywhere in the Service.
Each provider's use of your data is governed by their respective privacy policies. We encourage you to review them: Google, Anthropic, Stripe.
7. Student Data and FERPA
BYTSized LLC is committed to complying with the Family Educational Rights and Privacy Act ("FERPA"), 20 U.S.C. § 1232g.
- We act as a "school official" under FERPA when used by educational institutions, meaning we process student education records only to provide the Service.
- We do not sell Student Data or disclose it to third parties except as necessary to operate the Service or as required by law.
- AI providers (Google Gemini and Anthropic Claude) are engaged as service providers and are not authorized to use Student Data to train general-purpose AI models outside the scope of their service agreements.
- Schools or districts requiring a signed Data Processing Agreement ("DPA") should contact us at support@studiorum.io.
Student and Parent Rights under FERPA: Eligible students (or parents/guardians of students under 18) may request access to, correction of, or deletion of their education records by contacting support@studiorum.io.
8. Children's Privacy (COPPA)
The student-facing features of the Service are designed for users aged 13 and older. We do not knowingly collect personal information from children under 13.
We enforce this with a neutral age screen at student sign-up, at guest preview entry, and before anonymous access to a shared activity. A session that does not pass the screen cannot proceed, and the answer given is discarded rather than stored. Student-facing YouTube embeds use YouTube's privacy-enhanced (no-cookie) mode.
If you are a parent or guardian and believe your child under 13 has used the Service, please contact us immediately at support@studiorum.io. We will investigate and promptly delete any information collected from a child under 13.
Teachers or administrators who create accounts on behalf of students are responsible for ensuring those students are at least 13 years old.
9. Data Retention and Deletion
We retain personal information for as long as your account is active or as needed to provide the Service. You can delete your account at any time from Account Settings → Account, or by contacting support@studiorum.io.
What is deleted when you delete your account:
- Your profile and all personal information (name, email, teaching profile, grading preferences and voice samples, age attestation);
- Your sign-in credentials and authentication record;
- Your usage and activity logs and study session history;
- Tests you published, together with the student submissions on those tests.
What is retained, and why:
- Instructional content you authored — questions, activities, and rubrics — is retained in de-identified form: it is permanently disassociated from your name, email, and account. We retain this content so it can continue to benefit educators, including through a planned searchable community activity bank. This retention is covered by the content license in our Terms of Service (Section 5).
- Your submissions on other teachers' tests are retained, because they are part of that teacher's or school's gradebook and constitute the institution's education records under FERPA. Requests concerning those records should be directed to the school; we will support the school in honoring them.
- Grades already passed back to a school's LMS remain in the LMS gradebook, which is controlled by the institution.
- Uploaded media files (such as drawings, audio recordings, and images) may persist in storage after account deletion. To request removal of specific files, contact support@studiorum.io.
- We may retain anonymized, aggregated data that cannot identify you, and certain records as required by law, to resolve disputes, or to enforce our agreements.
Mastery data specifically:
- Teachers can remove individual mastery evidence at any time: observations and score imports have one-click undo, and any question can be excluded from mastery tracking.
- Deleting a class removes its roster and settings. Graded work and its mastery evidence are preserved by default — deleting a student's academic history is too destructive to be a side effect of classroom housekeeping.
- Schools and families can request complete deletion of a student's data, including all mastery evidence, by contacting support@studiorum.io; requests are honored across all collections.
Retention limits: We retain personal information only as long as it serves the educational purpose it was collected for, on the lifecycle rules above — never indefinitely by default. Anonymous visitor sessions expire automatically after about 30 days of inactivity. We review our retention practices at least annually as part of our information security program.
10. Data Security
We implement commercially reasonable security measures to protect your information, including:
- Firebase security rules that restrict data access by user role;
- Encrypted data transmission (HTTPS/TLS);
- Firebase Authentication for secure credential management;
- PCI-compliant payment processing via Stripe.
No method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security. In the event of a data breach that materially affects your rights, we will notify affected users as required by applicable law.
11. Your Privacy Rights
All Users: Regardless of location, you have the right to:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate information.
- Deletion: Request deletion of your personal information, subject to legal retention requirements.
- Opt-Out: Opt out of non-essential communications at any time.
California Residents (CCPA): If you are a California resident, you have additional rights under the California Consumer Privacy Act, including the right to know what personal information we collect, the right to delete, the right to opt-out of sale (we do not sell personal information), and the right to non-discrimination for exercising these rights.
You can exercise the access and deletion rights directly in the app: Account Settings → Account → Export My Data downloads a copy of your data, and Delete My Account performs the deletion described in Section 9. For anything else, contact us at support@studiorum.io. We will respond within 30 days.
12. Cookies and Tracking
We use cookies and similar technologies (e.g., browser local storage, Firebase session tokens) to maintain session state, analyze usage, and improve the Service. You can control cookie settings through your browser, though disabling certain cookies may affect Service functionality. We do not use cookies for cross-site advertising or behavioral tracking.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and, where appropriate, by email. Changes are effective upon posting unless otherwise stated. We encourage you to review this policy periodically.
14. Contact Us
BYTSized LLC
Email: support@studiorum.io
For FERPA-related inquiries, data deletion requests, or DPA inquiries for schools and districts, please email support@studiorum.io with the subject line "Privacy Request."