Student Data Privacy
1. Overview
Ereading.AI is a free collection of modern reading activities with optional auto-grading, LMS integration, and AI-assisted feedback. It is built for classroom use. This page describes our student-data practices for the people who evaluate and approve classroom software.
Our approach is data minimization. Students can use most of Ereading.AI with no account at all: a class code requires no login and no email address, and an LMS launch identifies a student only through the identifier the school's system provides. We keep what we need to return grades and result documents, and nothing more.
- Operator: Ereading Worksheets Inc., an Illinois S corporation, incorporated in 2010.
- Service: Ereading.AI (https://ereading.ai).
- Hosting: Vultr (The Constant Company, LLC), located in United States (Chicago, Illinois).
- Privacy contact: [email protected].
2. Compliance at a Glance
Ereading.AI is designed to help schools meet their obligations under the following laws. Each card summarizes what we actually do.
FERPA
Family Educational Rights and Privacy ActWhen a school or district uses Ereading.AI, we act as a school official with a legitimate educational interest, under the school's direct control. We use education records only to provide the service and never re-disclose them.
COPPA
Children's Online Privacy Protection ActWe minimize the data we collect from students, support the school-consent model for classroom use, and do not knowingly collect personal information from a child under 13 without school or parental consent. If we learn that a child under 13 created an account without such consent, we delete it.
Illinois SOPPA
Student Online Personal Protection Act (105 ILCS 85)As an Illinois operator we do not sell student data, do not use it for targeted advertising, do not build student profiles for non-educational purposes, maintain reasonable security, will enter a written agreement with the school, and will notify the school of a breach without unreasonable delay and no later than 30 days.
Other state laws
SOPIPA and comparable student-privacy statutesFor districts outside Illinois we honor the same core duties: no sale of student data, no targeted advertising to students, reasonable security, and deletion on request.
3. Student Data We Collect
The table below is a complete inventory of the data elements Ereading.AI collects, where each comes from, why we collect it, and how long we keep it. Free anonymous use writes nothing to our database at all.
| Data element | Collected from | Purpose | Where it is stored | Retention |
|---|---|---|---|---|
| Email address | Account holders (teacher, parent, or student) at sign-in | Authentication and account contact | Account record | Until the account is deleted |
| Name (first, last, display) | Account holders, optional | Personalizing the account and result documents | Account record | Until the account is deleted |
| Google account identifier | Users who sign in with Google | Authentication (no password is created or stored) | Account record | Until the account is deleted |
| Role, timezone, date and time format | Account holders | Service configuration and display | Account record | Until the account is deleted |
| LMS identifiers, name, and email | Google Classroom or LTI launch payloads | Locating the student's submission and returning the grade | Session and attempt records | 14 days (free) or the life of the paid plan plus 30 days |
| Class code and student-entered display name | Students accessing an activity through a class code | Assignment tracking and daily usage limits | Class code and attempt records (no account is created) | 14 days for free usage |
| Activity responses, scores, and feedback | Students completing activities | Grading and building the result document | Attempt records; detailed responses are scrubbed after the PDF is finalized on paid tiers | See the retention schedule below |
| Result PDF (may contain the student name, responses, and AI feedback) | Generated at submission | The canonical record of the completed activity | Access-controlled file on our server | 14 days (free) or up to 2 years (paid) |
| Hashed IP address (class code sessions) | Class code activity access | Daily usage limits and abuse prevention | Stored only as a SHA-256 hash, never as a raw IP | With the daily usage record |
| IP address and browser user agent (signed-in sessions) | Signed-in users, including students with accounts | Session security and abuse prevention | Session record | Removed when the session expires |
| Payment identifiers | Subscribers, through Stripe | Managing subscription status | Subscription record (no card numbers ever reach our servers) | As required for accounting and tax |
| Public discussion name, email, and IP | Anyone who posts a comment on a public page | Displaying the comment and moderation follow-up | Comment record (email is not shown publicly) | Until removed by the commenter request or moderation |
We do not collect student dates of birth, home addresses, phone numbers, or biometric data, and we never ask a student for a password.
4. How We Use Data
We use the data we collect only to operate the educational service:
- to launch and deliver lessons and activities with the teacher's chosen settings;
- to grade responses and return scores and result links to the connected LMS gradebook;
- to generate result documents for teachers and students;
- to provide AI-assisted feedback and scoring on eligible paid tiers;
- to enforce usage limits and prevent abuse of class codes and assignment links;
- to send transactional email, such as sign-in links and result delivery;
- to keep the service reliable and secure.
We do not use student data for advertising, marketing profiles, or any purpose unrelated to the educational service.
5. Service Providers (Subprocessors)
These are the third-party services that can receive data in order for Ereading.AI to function. The "student data" column shows whether the provider can receive any student data.
| Provider | Purpose | Data shared | Student data | Location |
|---|---|---|---|---|
| OpenAI | primary AI grading and feedback | Passage context, the question, the student response text, and the rubric. No name, email, or account identifier is sent. | Yes | United States |
| Google (Gemini API) | AI grading and feedback (fallback) Distinct from Google Workspace and Classroom APIs. |
Same de-identified payload as above. | Yes | United States |
| Anthropic | AI grading and feedback (fallback) | Same de-identified payload as above. | Yes | United States |
| xAI (Grok) | AI grading and feedback (fallback) | Same de-identified payload as above. | Yes | United States |
| Google (Sign-in and Classroom) | teacher and student sign-in, assignment creation, and grade passback Use of Google data follows the Google API Services User Data Policy, including Limited Use. |
Verified email, name, and Google id; course and coursework identifiers; submission ids and scores. | Yes | United States |
| Stripe | subscription payment processing | Billing identifiers only. Card details are entered on Stripe-hosted checkout and never touch our servers. | None | United States |
| SparkPost (Bird) | transactional and report email delivery | Recipient email and message content. Result-delivery emails may include a student result PDF. | Yes | United States |
| ElevenLabs | text-to-speech generation for lesson audio | Lesson and passage text only. Used in our authoring tools; students never contact this service, and generated audio is stored on our own servers. | None | United States |
| Vultr (The Constant Company) | cloud hosting and infrastructure | All service data resides on hosting located in the United States (Chicago, Illinois). | Yes | United States |
|
Google AdSense
Planned |
advertising to free, not-signed-in users | Standard ad requests. Never loaded for signed-in members with a paid plan, and never based on a student's responses, scores, or learning activity. | None | United States |
Content-dependent embeds
When a lesson or activity includes an embedded video, that video is loaded from the provider (for example YouTube through the privacy-enhanced youtube-nocookie domain, or Vimeo). The student's browser contacts that provider directly, which lets the provider see the request. We use privacy-enhanced embedding where available and load these only when the content contains a video.
6. AI-Assisted Grading and Feedback
On eligible paid tiers, open-ended student responses may be sent to an AI provider for automated scoring and feedback. The providers are listed in the table above. We choose among them based on availability, cost, and quality, and the specific provider can change over time.
What is sent
- the reading passage or activity context (text only, length-limited);
- the question or prompt;
- the student's written response;
- the scoring rubric, when one exists.
What is never sent
- student names, email addresses, or account identifiers;
- teacher, school, class code, or LMS identifiers;
- any information that links a response to a specific person or school.
De-identification here is structural, not just a policy: the code that builds an AI request carries only the prompt, response, rubric, and passage context, with no identity field. AI grading never runs on free-tier usage and can be turned off per assignment by the teacher. We select providers whose standard API terms do not use submitted data to train their models, and we encourage districts to review each provider's terms independently.
7. Security Practices
- All connections use HTTPS and TLS encryption in transit.
- Authentication is passwordless (Google sign-in or one-time email links). We never create or store passwords.
- Session and sign-in tokens are stored only as SHA-256 hashes, never in the clear.
- Class code IP addresses are stored only as SHA-256 hashes.
- LMS refresh tokens, access tokens, and LTI signing keys are encrypted at rest with AES-256-GCM.
- Session cookies are set with the HttpOnly, Secure, and SameSite flags.
- Cross-site request forgery protection is enforced on state-changing requests using timing-safe comparison.
- All database access uses prepared statements with bound parameters.
- Result PDFs are reachable only through a unique, expiring, access-controlled link, with no-referrer and no-index protections and a locked storage directory.
- For signed-in members with a paid plan, advertising code is never loaded or executed, so no ad request, script, or cookie is emitted.
- We use no third-party analytics services, behavioral tracking tools, or advertising pixels.
No system can guarantee absolute security. We apply reasonable technical and organizational safeguards appropriate to the sensitivity of educational data, and we monitor for unauthorized access.
8. Data Retention
We keep data only as long as needed for the purpose it was collected, and expired data is removed by automated jobs that run every day.
| Data | Kept for | How it is removed |
|---|---|---|
| Free usage with no account (anonymous) | Nothing is stored | Responses and the PDF are processed in memory and returned to the browser. No record is written. |
| Free usage through an LMS or class code | 14 days | The attempt record and result PDF are purged by an automated job that runs daily at 03:00 UTC. |
| Paid activity summaries and scores | Life of the plan plus 30 days | Kept while the subscription is active; purged 30 days after it ends. |
| Paid result PDFs | Up to 2 years | Purged by an automated job that runs daily at 02:00 UTC, or sooner if the paid plan ends first. |
| Detailed responses and AI payloads (paid) | Scrubbed after the PDF is finalized | The stored PDF becomes the only detailed record; transient response data is set to null. |
| Account profile | Until deletion | Removed when the account holder deletes the account or on a verified deletion request. |
| Payment and billing records | As required by law | Retained for accounting, tax, and legal compliance. |
9. Access, Correction, and Deletion
Schools, teachers, parents, and guardians may request access to the data we hold, correction of inaccurate data, or deletion of data, subject to legal retention requirements. Account holders can also delete their own account and all associated data from account settings, which removes the account record, the activity history, and the stored result PDF files.
For a school or district, we will delete or return student data on request, including at the end of a contract. Requests can be sent to [email protected]. We verify the identity and authority of the requester and aim to respond within 30 days.
10. Advertising
Ereading.AI may display third-party advertising from Google AdSense to free users, including anonymous visitors and signed-in users who do not have a paid plan. Users with a paid subscription or license, and students using Ereading.AI through a paid teacher's class code or connected LMS, do not see advertising.
- Advertising is never selected or personalized using a student's responses, scores, or learning activity.
- We do not build advertising profiles of students.
- For signed-in members with a paid plan, advertising code is never loaded or executed, so no ad request, script, or cookie is emitted.
- On pages a child may reach, advertising is served as non-personalized.
Advertising is not currently served anywhere on the site. This section describes how advertising will behave when it is enabled.
11. Children's Privacy (COPPA)
Ereading.AI is designed for use in schools, and we support school and district compliance with the Children's Online Privacy Protection Act.
- We minimize data collection from students. Class code access requires no account, no email, and no sign-in.
- For classroom use, a school may consent to the collection and use of student data on behalf of parents, consistent with COPPA's school-consent provisions, and we act only as the school directs.
- We do not knowingly collect personal information from a child under 13 without school or parental consent. If we learn that a child under 13 has created an account without such consent, we delete it.
- AI grading requests never include student-identifying information, and result identifiers do not contain student names.
12. FERPA
When a school or district uses Ereading.AI to provide instruction, we act as a school official with a legitimate educational interest under the Family Educational Rights and Privacy Act, performing a service the school would otherwise perform itself, under the direct control of the school with respect to the use and maintenance of education records.
- We use education records only to provide the service.
- We do not re-disclose education records except as directed by the school or as required by law.
- We return or delete education records on the school's request.
13. Illinois SOPPA
Ereading.AI is operated by Ereading Worksheets Inc., an Illinois corporation, and we take our obligations under the Illinois Student Online Personal Protection Act (105 ILCS 85) seriously. As an operator under SOPPA:
- We do not sell, rent, or trade student data.
- We do not use student data for targeted advertising.
- We do not create a profile of a student except in furtherance of school purposes.
- We maintain reasonable security procedures and practices, described in Section 7.
- We will enter a written agreement with the school or district that governs our handling of covered information.
- We will delete student data at the school's request.
- We will notify the school of any breach of student data without unreasonable delay and no later than 30 days after we determine that a breach has occurred, so the school can meet its own notification duties.
14. Breach Notification
If we determine that a breach has exposed student data, we will notify the affected school or district without unreasonable delay and no later than 30 days after that determination. Our notice will describe, to the extent known, what happened, the data involved, and the steps we are taking, so the school can fulfill its own notification obligations to parents and to any state agency.
15. Data Privacy Agreements
We are glad to put our commitments in writing. On request we will sign the SDPC National Data Privacy Agreement, a district's own data privacy agreement, or the Ereading.AI Data Privacy Agreement below, which sets out these same commitments in a form your district can execute.
To start an agreement or send your district's form, contact [email protected].
16. Contact and Operator Information
Questions about student data privacy, deletion requests, and data privacy agreements can be sent to [email protected].
Ereading Worksheets Inc.
5424 W. Devon Ave #46025
Chicago, IL 60646
Our commitments to schools are also expressed in our Privacy Policy and Terms of Service.