Privacy Policy
Effective Date: May 11, 2026 | US Users Only
What We Collect
Teacher Accounts: When you create a TeachSpark account we collect your name, email address, and optional institution information. All payment processing is handled entirely by Stripe. TeachSpark never sees or stores your credit card or payment details — only confirmation that a subscription is active. Students: TeachSpark collects first name and last initial when a student begins an activity. No student account is created. Student responses and scores are retained for up to 13 months and are only accessible to the teacher who created the activity. Student data is automatically deleted 13 months after the submission date. Resume Codes: TeachSpark saves activity progress locally on the student's device to allow them to resume an in-progress activity. This data is stored in the browser's localStorage and expires automatically after 7 days.
Cookies & Local Storage
TeachSpark uses localStorage to remember your preferences and session information. Stripe, our payment processor, sets its own cookies to process transactions securely. We do not use advertising cookies or sell any user data.
Student Privacy & COPPA
TeachSpark is designed with student privacy in mind. We collect the minimum information necessary — first name and last initial — solely to record activity results for the teacher. No student profiles are created. TeachSpark does not knowingly collect personal information from children without teacher facilitation in a school context.
Data Security
All data is transmitted over encrypted HTTPS connections. Payment data is handled exclusively by Stripe and is never stored on TeachSpark servers.
Your Rights
Teachers may request deletion of their account and associated data at any time by contacting support@teachspark.app. Student submission data can be deleted by the teacher from their results dashboard.
AI-Assisted Scoring
When a teacher enables short-answer questions on an activity, TeachSpark may use AI to provide a first-pass score and feedback on student responses. The AI evaluates the response against the activity's rubric and scoring criteria. The teacher reviews and can override any AI-generated score before it becomes final. Student responses are sent to our AI provider solely for scoring purposes and are never used to train AI models.
Data Retention
Teacher Accounts: Teacher activity data (activities, lesson plans, worksheets, answer keys, units) is retained for as long as the teacher's account is active. Teachers can delete individual activities or student submissions at any time from their dashboard. Account deletion requests can be made by contacting support@teachspark.app. Student Data: Student submission data (names, responses, scores) and session data are automatically deleted 13 months after the submission date. This retention period covers one full school year plus summer. Teachers can also manually delete student submissions at any time before the automatic deletion. Generated Content: Activity HTML files, worksheets, and answer keys are retained for as long as the associated activity exists. When an activity is deleted, its generated files are also removed.
Breach Notification
In the event of a suspected or confirmed data breach involving student or teacher personal information, TeachSpark will: 1. Investigate and assess the scope of the breach within 24 hours of discovery. 2. Notify affected teachers and, where applicable, their school or district administration, within 72 hours of confirming the breach. 3. Provide affected users with a description of what occurred, the data involved, and steps they can take to protect themselves. 4. Take corrective action to prevent recurrence and document the incident. Breach notifications will be sent via email to the affected users' registered email addresses. Teachers are responsible for notifying their students' parents or guardians if student data is involved, in accordance with their school or district's policies and applicable state laws.
Incident Response & Vulnerability Disclosure
TeachSpark maintains an incident response process for security events. If you believe you have discovered a security vulnerability or have identified a privacy concern, please report it immediately to security@teachspark.app. Vulnerability Reports: We ask that you provide a detailed description of the vulnerability, including steps to reproduce it. We will acknowledge receipt within 48 hours and provide an initial assessment within 5 business days. We do not pursue legal action against good-faith security researchers who report vulnerabilities responsibly. Security Measures: TeachSpark's data is hosted on a SOC 2 Type II and ISO 27001 certified platform (Base44). All data is encrypted in transit and at rest. Access to production data is restricted to authorized personnel and is logged. We conduct regular security reviews through our hosting provider. Subprocessors: TeachSpark uses the following third-party services to process user data: - Base44 (application hosting, database, file storage) — SOC 2 Type II, ISO 27001 certified - Stripe (payment processing) — PCI DSS certified; TeachSpark never stores credit card data - Google (OAuth authentication, Google Classroom integration) — Google Cloud Platform - AI Provider (short-answer scoring) — used only for AI-assisted grading of student responses A current list of subprocessors is maintained and updated as services change. Districts and schools can request a subprocessor list and Data Processing Agreement by contacting support@teachspark.app.
Changes to This Policy
We may update this policy as TeachSpark grows. The effective date at the top of this page will always reflect the most recent version.
Contact
Questions? Email us at support@teachspark.app.