Privacy Policy

How we collect, use, and protect your data.

Updated April 24, 2026Chinuch App LLC (DBA Chabad Chinuch)
1.

Introduction

Chinuch App (“we,” “our,” or “us”) is committed to protecting the privacy of our users. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our educational management platform.

We comply with the Family Educational Rights and Privacy Act (FERPA), the Children's Online Privacy Protection Act (COPPA), and other applicable student privacy laws.

2.

Information We Collect

2.1 Student Data

We collect student information provided by schools or parents, including:

  • Student names, grade levels, and class assignments
  • Attendance records
  • Behavior logs and incident reports
  • Assessments, grades, and academic progress
  • Standards and skills tracking data
  • Bus check-in/check-out records
  • Emergency contact information
  • Parent/guardian information

2.2 Teacher & Staff Information

  • Names, email addresses, and contact information
  • School affiliation and role
  • Class assignments and schedules
  • Login credentials (encrypted)

2.3 Parent Information

  • Names, email addresses, and phone numbers
  • Relationship to students
  • Account credentials

2.4 Usage Data

  • Log data (IP addresses, browser type, pages visited)
  • Device information
  • Usage patterns and preferences
  • Audit logs of data access and modifications

2.5 Financial and Payment Data

When schools or parents use our payment features, we collect payment-related information through our payment processor, Stripe:

  • Credit/debit card details (processed and stored securely by Stripe, not stored on our servers)
  • Bank account information for ACH payments (tokenized account and routing numbers)
  • Billing addresses
  • Payment history and transaction records
  • Account ownership verification details

Important: We use Stripe Financial Connections to securely verify bank account ownership and enable ACH payments. We do not access your bank balance, transaction history, or any other financial data beyond what is necessary for payment processing.

3.

How We Use Your Information

We use the collected information solely for educational and school operational purposes:

  • Provide and maintain our educational services
  • Track student progress and academic performance
  • Facilitate communication between teachers, students, and parents
  • Generate reports and analytics for educational improvement
  • Manage attendance and behavior tracking
  • Handle transportation and bus logistics
  • Process tuition payments, event fees, and other school-related payments
  • Ensure platform security and prevent fraud
  • Comply with legal obligations (FERPA, COPPA, state laws)

We do NOT use student data for:

  • Advertising or marketing purposes
  • Behavioral profiling for commercial purposes
  • Selling or renting data to third parties
  • Any non-educational purpose
4.

Data Sharing and Disclosure

We do not sell, trade, or rent student data. We may share information only with:

  • The School: Teachers, administrators, and authorized staff within the school organization
  • Parents/Guardians: For their own children's records, as authorized by the school
  • Service Providers: Vendors who assist in platform operations. All must sign data protection agreements
  • Legal Requirements: When required by law, court order, or to protect rights and safety

We never share student data with advertisers or unrelated third parties.

5.

Data Security

We implement industry-standard security measures to protect your data:

  • Encryption of data in transit (HTTPS/TLS) and at rest
  • Secure authentication with password hashing
  • Role-based access controls
  • Multi-school data separation
  • Audit logs for all data access and modifications
  • Regular security audits and updates
  • Secure data centers with physical security
  • Incident response procedures
  • Regular backups with encryption

A detailed Security Policy is available upon request or at /legal/schools.

6.

FERPA Compliance

We comply with the Family Educational Rights and Privacy Act (FERPA) and are designated as a School Official with a legitimate educational interest. We:

  • Protect student education records as required by FERPA
  • Limit access to authorized school officials and parents
  • Do not disclose personally identifiable information without consent
  • Allow parents to review and request corrections to their child's records
  • Maintain student data ownership with the school
  • Provide data export capabilities upon request
  • Delete data according to school requests and retention policies
7.

COPPA Compliance

We comply with the Children's Online Privacy Protection Act (COPPA). For children under 13:

  • Schools may consent on behalf of parents for educational use
  • Parents may directly provide consent through school invitation
  • We collect only information necessary for educational services
  • We do not allow children to submit personal information directly
  • We do not use children's data for advertising or commercial purposes

For detailed COPPA information, see our COPPA Notice.

8.

State Student Privacy Laws

We comply with applicable state student privacy laws, including:

  • California SOPIPA
  • New York Education Law §2-d
  • Colorado SB 16-173
  • Texas Student Privacy Laws
  • Other applicable state regulations
9.

Data Retention and Deletion

We retain student data only as long as necessary:

  • Active Schools: Data is retained while the school's account is active
  • School Termination: Data is archived for 60 days, then permanently deleted
  • School Requests: We delete specific student records within 10 business days
  • Audit Logs: Retained for 1 year for compliance
10.

Data Ownership and Export

Schools own 100% of all Student Data. Schools may:

  • Access, edit, export, or delete student data at any time
  • Request full data exports in CSV, JSON, or SQL format
  • Request deletion of individual students, classes, or full database
  • Transfer data to other systems

We provide data exports within 10 business days of request.

11.

Breach Notification

In the event of unauthorized access or disclosure of student data, we will:

  • Notify affected schools within 72 hours of confirming a breach
  • Provide details about what happened and what data was affected
  • Describe steps taken to contain and remediate the issue
  • Offer guidance and support for schools
  • Cooperate fully in any investigation
12.

Your Rights

You have the right to:

  • Access your personal information
  • Correct inaccurate data
  • Request deletion (subject to legal requirements)
  • Opt-out of non-essential communications
  • Data portability and export
  • Review audit logs of data access

Parents requesting corrections or deletions should contact their child's school, as schools control educational records under FERPA.

13.

Subprocessors

We may use service providers (subprocessors) to support platform operations:

13.1 Infrastructure & payments

  • Hosting and infrastructure providers (e.g., Supabase)
  • Email notification services (e.g., SendGrid)
  • Security and monitoring tools
  • Payment processing (Stripe, Inc.) — PCI-DSS Level 1 certified

13.2 AI subprocessors

The following AI providers may receive prompts and receive responses as part of our AI-powered features. See Section 14 below for the strict rules we apply before any data reaches them.

  • Anthropic, PBC (Claude models) — lesson authoring, remediation diagnosis, report-card narratives, email drafting. Commercial terms.
  • OpenAI, OpCo LLC (GPT / gpt-4o models) — short structured completions, open-response grading, name transliteration. Business terms.
  • Google LLC (Gemini, Imagen, Vision) — image generation for educational slides, handwriting OCR for scanned assessments. Gemini API terms.
  • Perplexity AI, Inc. (Sonar models) — citation-backed research for teacher-facing content. Terms.
  • ElevenLabs, Inc. — text-to-speech and speech-to-text for accessibility features; audio is deleted after processing per provider DPA. Terms.

All subprocessors must sign data protection agreements and meet equal or higher security standards.

We do not permit any AI subprocessor to train on customer traffic. Our API settings or contracts with each provider above disable the use of our data for model training.

14.

AI Features, PII Handling, and Child Safety

Chinuch App uses AI models to help teachers and students with tasks such as generating lesson materials, drafting parent emails, transcribing speech, grading open-ended responses, and building remediation packets.

14.1 What we send to AI providers

We treat every outbound AI request as untrusted. Before any prompt leaves our servers, it passes through a centralized PII-scrub layer that:

  • Replaces a student's name with a pseudonym (e.g. "Student A" or "[Student]").
  • Replaces school IDs / NYC OSIS numbers with "[ID]".
  • Strips email addresses, phone numbers, street addresses, dates of birth, and any 13-19 digit sequence that resembles a credit-card number.
  • Drops structured fields like parent_name, parent_email, parent_phone, guardian_*, home_phone, dob, ssn, photo_url entirely.
  • Uses only opaque internal UUIDs when the AI needs a stable reference; those UUIDs are meaningless outside our system.

Where an AI feature needs the real name on the way back (for example, a parent email greeting), the pseudonym is substituted back into the response on our server, not in the AI's context.

14.2 What we never send to AI providers

  • A child's full name, email, phone number, street address, date of birth, or photo.
  • NYC OSIS / state school ID numbers.
  • Parent / guardian contact information.
  • Medical, IEP, or behavioral-health records linked to an identified child.
  • Payment card or bank-account numbers (those are handled only by Stripe).

14.3 Child-safety guardrails on every AI call

  • Every AI prompt that can reach a child is wrapped with a non-negotiable safety preamble that forbids sexual, violent, self-harm, substance-use, weapons, political, and age-inappropriate content, in line with Anthropic's guidance for organizations serving minors and equivalent OpenAI and Google policies.
  • AI-generated content shown to a student is visibly labeled as "AI-generated" and includes a way to report inappropriate output. Reports are reviewed by our safety team and the child's school.
  • AI is not used for disciplinary decisions, identity verification, mental-health diagnosis, or anything that permanently affects a child's record without a human reviewing it first.

For additional information specific to children under 13, see our COPPA Notice.

15.

Payment Processing

Our platform enables schools to collect tuition payments, event fees, and other school-related charges.

15.1 Payment Processor

All payment processing is handled by Stripe, Inc., a PCI-DSS Level 1 certified payment processor. We do not store credit card numbers or full bank account numbers on our servers.

15.2 Stripe Financial Connections

For ACH bank payments, we use Stripe Financial Connections to securely link and verify bank accounts. We do NOT access your bank balance or transaction history.

15.3 Payment Data Retention

Payment records are retained as long as the school account is active and for 7 years thereafter for tax and legal compliance purposes.

16.

SMS / Text Message Data

When a parent, teacher, student, or school administrator opts in to receive text messages from their school, we collect and process the following information solely for the purpose of operating that messaging program:

  • The mobile phone number provided
  • The date, time, source, and (where available) IP address and user-agent at the time of opt-in
  • The messages sent to and received from that number
  • Delivery status, error codes, and STOP / HELP keyword responses

16.1 How phone numbers are used

Phone numbers and SMS opt-in information are used only to deliver the messages described in our SMS Messaging Policy — attendance alerts, dismissal updates, school-to-parent messages, homework hotline notifications, and account verification codes.

16.2 No sharing for marketing

Phone numbers and SMS opt-in information are not shared with third parties or affiliates for marketing or promotional purposes, and are not sold or rented to anyone for any purpose. We do not use this data to build advertising profiles or to advertise to anyone.

16.3 Service providers

Phone numbers are shared only with our messaging service provider, Twilio Inc., which delivers messages on our behalf and is contractually bound to use the data only for that purpose. Twilio is the “CSP” (Communications Service Provider) for our A2P 10DLC campaign with The Campaign Registry (TCR).

16.4 Carrier visibility

By the nature of SMS, U.S. mobile carriers (and TCR, on the carriers’ behalf) receive the destination number, sender number, and message body of every message we send. Carriers may also see metadata such as message length and delivery status.

16.5 Retention & deletion

SMS message logs are retained for 12 months for delivery diagnostics and compliance, then deleted. Phone numbers themselves are retained as part of your school user profile and are deleted according to the rest of this Privacy Policy. You can delete your phone number at any time from parent notification settings or by asking your school administrator.

16.6 How to opt out

Reply STOP to any message to immediately stop receiving SMS from that school’s sender number, or turn off SMS in parent notification settings. Opting out of SMS does not affect your account or your ability to use the platform; you will continue to receive in-app and email notifications.

17.

Changes to This Policy

We may update this Privacy Policy periodically. We will notify schools of material changes via email or platform notification. Continued use of the platform after changes constitutes acceptance of the updated policy.

18.

Contact Us

If you have questions about this Privacy Policy:

Email: privacy@chinuchapp.com
Support: support@chinuchapp.com
Website: chinuchapp.com

For school-specific legal agreements, visit /legal/schools.

Questions about privacy?

Get in touch →