Legal

Privacy Policy

Last updated: April 20, 2026

EduEthics.ai takes privacy seriously because we handle student educational records, and under FERPA and similar laws we have a legal obligation to handle them correctly. This policy explains what we collect, why we collect it, and what we do with it.

Who we are

EduEthics.ai is a product of ScholarBar Education LLC, a Florida limited liability company. Our mailing address is in Clearwater, Florida. The data controller for purposes of this policy is ScholarBar Education LLC.

What we collect

Account information. When you register as a student, we collect your first name, last name, school email address, and institution affiliation. Instructor and administrator accounts additionally collect authentication credentials through our identity provider, Clerk.

Learning activity. As you progress through modules, we record which frames you've completed, your answers to interactive exercises, your assessment scores, the time you spend in each module, and interactions with the AI teaching assistant.

Technical data. IP address, browser type and version, device characteristics, and pages visited. Used for security (rate limiting, bot detection, geoblocking) and for analytics that help us improve the product.

AI Lab conversations. Your conversations with the AI teaching assistant are logged for quality assurance and safety monitoring. They are not used to train AI models.

How we use your data

We use your data to deliver the course, track your progress, issue certificates, report grades to your institution (if you accessed the platform through an institutional deployment), and improve the product. We use aggregated and anonymized analytics to understand usage patterns and identify where students get stuck. We do not sell your data to third parties. We do not use your data for advertising. We do not share your data with data brokers.

FERPA compliance

When you access EduEthics.ai through an institutional deployment, your student records are treated as educational records under FERPA. Your institution is the controller of those records; we are the data processor acting on your institution's behalf. Our Data Processing Agreement with each institution specifies the scope of our processing, retention periods, breach notification procedures, and your rights as the student.

Data retention

Active student records are retained for the duration of your enrollment plus seven years, consistent with standard academic records retention. Analytics data is retained for 180 days. Security event logs are retained for 90 days. Visitor tracking data is retained for 60 days. You may request deletion at any time by emailing admin@edupolicy.ai, subject to your institution's record retention obligations.

Security

Data is encrypted at rest using industry-standard AES-256 and in transit using TLS 1.2 or higher. Access to production data is limited by role-based access controls. We maintain a full audit trail of every data access event. We perform nightly automated maintenance including security event review and database integrity checks. We run DB-backed rate limiting, honeypot detection, and IP-based geoblocking to reduce attack surface.

Your rights

You have the right to access the personal data we hold about you, to correct inaccurate data, to request deletion (subject to retention obligations), to export your data in a portable format, and to object to specific processing activities. To exercise any of these rights, email admin@edupolicy.ai. We respond within 30 days.

Cookies and tracking

We use first-party cookies and localStorage for session management and to remember your preferences. We do not use third-party advertising cookies. Our analytics are first-party (we host and process them ourselves, not through Google Analytics or similar).

Children

EduEthics.ai is built for higher education and is not directed to children under 13. If we learn we have collected data from a child under 13 without verifiable parental consent, we will delete it. If you believe we have such data, contact admin@edupolicy.ai.

Changes to this policy

We update this policy when our practices change. Material changes will be communicated to institutional administrators via email. The "last updated" date at the top of this page always reflects the current version.

Contact

Questions about this policy, or about our data practices generally, should be directed to admin@edupolicy.ai.