Privacy Policy

School & Student Edition โ€” COPPA and FERPA Compliance

Effective Date: April 29, 2026  |  Last Updated: April 29, 2026

๐Ÿ›ก๏ธ COPPA Compliant ๐ŸŽ“ FERPA Compliant ๐Ÿ”’ Privacy First

Table of Contents

  1. Overview & Scope
  2. COPPA Compliance (Children Under 13)
  3. FERPA Compliance (School Use)
  4. Data We Collect
  5. How We Use Data
  6. Data Sharing & Third Parties
  7. Data Retention & Deletion
  8. Security
  9. Parent & Student Rights
  10. School District Adoption
  11. Contact Us

1. Overview & Scope

This Privacy Policy describes how BMcks Apps ("we," "us," "our") collects, uses, and protects information when students, parents, and teachers use SmartTutor at bmcksos.polsia.app/smarttutor.

SmartTutor is an AI-powered educational tutoring platform designed for students. It provides AI chat tutoring, quizzes, flashcards, study plans, and other learning tools. This policy is specifically designed to meet the requirements of:

Plain language summary: We collect as little data as possible. We don't sell student data. We don't show ads to students. Children under 13 need parental consent before using SmartTutor.

2. COPPA Compliance โ€” Children Under 13

Age Gate & Parental Consent

On first visit, SmartTutor asks users to confirm their age. Users who indicate they are under 13 years old are required to obtain verifiable parental consent before accessing any features. Until consent is received:

Parental Consent Process

  1. The child enters a parent or guardian's email address
  2. We send a consent email to that address with a verification link
  3. The parent reviews this Privacy Policy and clicks "I Give My Consent"
  4. Access is granted only after the parent clicks the verification link

What We Do NOT Collect from Children Under 13

No behavioral advertising for under-13 users. SmartTutor does not display behavioral advertising to any user. For users under 13, we additionally ensure that no third-party analytics or advertising SDKs have access to their data.

Parental Rights Under COPPA

Parents and guardians may, at any time:

To exercise these rights, see Section 9: Parent & Student Rights.

3. FERPA Compliance โ€” School Use

SmartTutor as a School Official

When schools or districts adopt SmartTutor as an educational tool, we operate as a "school official" under FERPA, meaning we:

Education Records

FERPA defines education records as records that are directly related to a student and maintained by an educational agency or institution. In SmartTutor, this includes:

Access Controls & Audit Logging

SmartTutor maintains an audit log of all significant data access events, including:

These logs are retained for a minimum of one year and are available to authorized school administrators upon request.

Data Export for Schools

Schools and parents can request a complete export of a student's data at any time. See Section 9 for the request process. We will respond within 30 days.

No sale of student data. We do not sell, rent, or lease student personally identifiable information (PII) to any third party. Student data is never used for marketing or advertising purposes.

4. Data We Collect

SmartTutor is designed with data minimization as a core principle. Most study data is stored locally on the user's device and never transmitted to our servers.

Data Stored Locally (on Device Only)

The following data is stored in the browser's localStorage and never sent to our servers:

Data Sent to Our Servers

Data Type When Collected Purpose Retained?
AI message content When using AI chat/quiz/flashcard features Generate AI response via our AI provider No โ€” processed in memory only
Parent email address When submitting parental consent request Send consent verification email Yes โ€” tied to consent record
Anonymous student ID When consent is requested or classroom is joined Link consent to student device session Yes โ€” until deletion requested
Classroom progress data When a student joins a teacher's classroom Show teacher the student's activity Yes โ€” until student/school requests deletion
IP address All server requests Security, abuse prevention Audit logs only (1 year)

What We Never Collect

5. How We Use Data

We use the limited data we collect strictly for these purposes:

No AI training on student data. Student interactions with SmartTutor's AI tutor are not used to train AI models. Queries are processed to generate responses and discarded.

6. Data Sharing & Third Parties

AI Provider

SmartTutor uses an AI language model (via an intermediary proxy) to generate tutoring responses. Message content is transmitted to this provider for processing. The provider does not retain message content and does not use it for training. No personally identifiable student information is included in AI requests.

Email Service

We use Brevo (Sendinblue) to send transactional emails (parental consent verification, data deletion confirmations). Brevo receives email addresses only for the purpose of sending these emails.

No Sale of Data

We do not sell, rent, or trade student personal information. Period.

Law Enforcement

We may disclose information if required by law, court order, or to protect the safety of users or the public. We will notify affected parties where legally permitted.

7. Data Retention & Deletion

Data CategoryRetention Period
Local device data (localStorage)Until user clears browser storage
Parental consent recordsUntil deletion requested, max 3 years
Classroom progress dataUntil deletion requested or student removed
FERPA audit logs1 year minimum, 3 years maximum
IP addresses in audit logs1 year
AI message contentNot retained (in-memory processing only)

Deletion Process

Data deletion requests are honored within 45 days per COPPA requirements. Upon receipt of a verified deletion request:

  1. Classroom progress data is immediately deleted
  2. Consent records are marked as revoked
  3. A confirmation email is sent to the requesting parent or guardian
  4. Any remaining data in backup systems is purged within 45 days

8. Security

We implement appropriate technical and organizational measures to protect student data:

In the event of a data breach, we will notify affected schools, parents, and users within 72 hours of discovery as required by applicable law.

9. Parent & Student Rights

Rights Under COPPA (for children under 13)

Rights Under FERPA (when used by a school)

How to Exercise Your Rights

Use the data deletion form within SmartTutor, or contact us directly:

๐Ÿ“ฑ In-App Data Request โœ‰๏ธ Email Request ๐Ÿ—‘๏ธ Delete My Data

We respond to all requests within 30 days. For COPPA deletion requests, data is removed within 45 days of verification.

10. School District Adoption

Schools and districts that adopt SmartTutor as an official educational tool may enter into a Data Processing Agreement (DPA) with us. The DPA formalizes:

To request a DPA or discuss district-wide adoption, contact us at info@bmcksapps.com.

School's Responsibilities

Schools using SmartTutor are responsible for:

State Student Privacy Laws: In addition to federal COPPA and FERPA, SmartTutor's data practices comply with applicable state student privacy laws including California SOPIPA, New York Education Law ยง2-d, and similar statutes.

11. Contact Us

For privacy questions, data requests, or to report a concern:

โœ‰๏ธ

Email

info@bmcksapps.com
We respond within 2 business days.

๐Ÿซ

School / District Inquiries

For DPA requests, bulk licensing, or FERPA compliance inquiries:
info@bmcksapps.com โ€” Subject: "SmartTutor School District Inquiry"

๐Ÿ“‹

Data Deletion / Access Requests

Use the Delete My Data page or email info@bmcksapps.com with "SmartTutor Data Deletion Request" in the subject line.

If you believe we have not adequately addressed your concerns, you may file a complaint with the Federal Trade Commission (FTC) at ftc.gov/coppa or the U.S. Department of Education at studentprivacy.ed.gov.