CyberScholar Terms, Conditions & Privacy
Terms of Service, Conditions of Use, and Privacy Commitments for Educational Institutions, Students, Educators, and Parents
Version 2.0 — Last Updated: August 17, 2026. Supersedes the CyberScholar Terms and Conditions dated March 11, 2026.
Summary of our commitments
Institution data belongs to the Institution, not to us. We do not sell data or metadata, ever. We do not advertise or market to students, staff, or families. We do not mine data for purposes the Institution has not agreed to. We do not send identifiable student information to external AI model providers, and we do not train any AI model on identifiable Institution data. We do not change how data is collected, used, or shared without the Institution’s prior notice and consent. We return or destroy data on the Institution’s instruction. These commitments are contractual, not aspirational
1. Introduction and Scope
Welcome to CyberScholar, an AI-powered educational platform for K–12 schools, colleges, and universities. This document (the "Terms") sets out the terms of service, the conditions of use, and the privacy commitments that govern use of CyberScholar by educational institutions, student users, educators, and parents. It combines in a single instrument what is often split across a terms-of-service document and a privacy policy, so that an institution evaluating CyberScholar can find every data-handling commitment in one place.
The scope of this document includes data ownership, data collection practices, permitted and prohibited uses, artificial intelligence safeguards, subprocessor governance, user and parental rights, security controls, breach response, data retention and destruction, and international compliance. CyberScholar is designed with student data privacy as a first-order design constraint, not as an afterthought. By using CyberScholar, you agree to these Terms on behalf of yourself and, if applicable, your organization or minor child.
1.1. Compliance with Privacy Laws
CyberScholar operates in compliance with the Illinois Student Online Personal Protection Act ("SOPPA", 105 ILCS 85/) and aligns its practices with the following legal frameworks, to the extent each applies to a given Institution or user:
FERPA — the U.S. Family Educational Rights and Privacy Act (20 U.S.C. § 1232g; 34 CFR Part 99), under which CyberScholar operates as a "school official" with a legitimate educational interest, under the direct control of the Institution.
COPPA — the Children’s Online Privacy Protection Act (15 U.S.C. §§ 6501–6506), for users under 13.
PPRA — the Protection of Pupil Rights Amendment (20 U.S.C. § 1232h), governing surveys and the collection of information on protected topics.
HIPAA — the Health Insurance Portability and Accountability Act, to the extent an Institution is a covered entity and CyberScholar were to handle protected health information. CyberScholar does not collect or process protected health information in the ordinary course (see 3.5).
Washington SUPER Act — the Student User Privacy in Education Rights Act (RCW 28A.604), together with Washington’s student-records and data-breach statutes, for Institutions in the State of Washington.
New York Education Law § 2-d and its Parents’ Bill of Rights, for Institutions in the State of New York.
California SOPIPA and AB 1584 (Cal. B&P Code § 22584; Cal. Ed. Code § 49073.1), for Institutions in the State of California.
GDPR / UK GDPR — the General Data Protection Regulation and its United Kingdom equivalent, for data subjects in the European Economic Area and the United Kingdom.
Other applicable law — including PIPEDA in Canada, the Australian Privacy Principles, and any other student-privacy or data-protection law applicable to an Institution’s jurisdiction.
CyberScholar additionally observes the substantive commitments of the Student Privacy Pledge and is prepared to execute state and regional student data privacy consortium agreements, including the Student Data Privacy Consortium National Data Privacy Agreement (NDPA) and its state exhibits.
1.2. Intended Users
CyberScholar is intended for use by students in grades 6–12 (including minor children with school authorization), by higher education students, and by teachers, faculty, and school and district administrators. If you are under 18, you may use CyberScholar only with consent and oversight from a parent or school official, consistent with legal requirements. Institutions deploying CyberScholar must ensure any required parental notice or consent is obtained for minor students’ use of the platform. These Terms form a binding agreement between CyberScholar and its educational users, including the Institutions that license it.
1.3. Relationship to Institutional Agreements; Order of Precedence
Many Institutions require CyberScholar to execute a separate written instrument governing student data — a data sharing agreement, data privacy agreement, student data privacy addendum, FERPA/COPPA rider, or a consortium agreement. CyberScholar signs these instruments and treats them as controlling. Where such an instrument has been executed, the following order of precedence applies:
Applicable federal, state, and local law, and the Institution’s governing board policy;
The executed institutional agreement, including all of its exhibits and addenda;
These Terms;
Any other CyberScholar policy, documentation, or product notice.
Where these Terms provide a protection greater than the executed agreement, the greater protection applies to the benefit of the Institution, its students, and their families. No provision of these Terms operates to reduce, waive, condition, or limit any right of an Institution, student, parent, or eligible student under applicable law or under an executed institutional agreement. Any provision of these Terms that would conflict with an Institution’s statutory obligations is severed as to that Institution and has no effect. CyberScholar will not ask an Institution to accept terms that would place it in conflict with its legal duties, and does not require Institutions, students, or parents to submit to binding arbitration or to waive class-action rights as a condition of use.
1.4. Definitions
For purposes of these Terms, the following definitions apply:
CyberScholar (also "we", "us", "our") — The CyberScholar online learning platform and the entity that owns and operates it. CyberScholar is the "operator" of an educational online service as defined under SOPPA and the equivalent "operator", "service provider", "third-party contractor", or "processor" under the other laws listed in 1.1. The specific contracting entity is identified in the executed institutional agreement and in Section 12.
User (also "you") — An individual who accesses CyberScholar. This includes Student Users (learners using the platform for coursework) and Educators or School Administrators (teachers, faculty, or other authorized staff using the platform in an official capacity).
School / District / Institution — Any educational institution (K–12 school or district, college, or university) that has authorized use of CyberScholar for its students. An Institution typically enters into an agreement with CyberScholar to enable student use.
Parent — A parent or legal guardian of a Student User. In the context of minor students, parents hold specific rights regarding their child’s data under SOPPA, FERPA, the Washington SUPER Act, and other laws.
Eligible Student — A student who is 18 years of age or older, or who is enrolled in a post-secondary institution, and who therefore holds in their own right the privacy rights otherwise held by a parent.
Covered Information — Any personally identifiable information or materials linked to an identified or identifiable student that are not publicly available, and that are collected through the use of CyberScholar for school purposes. This includes a student’s name, email address, work submissions, drafts and revision history, assessment results, feedback comments, and usage logs. "Covered Information" is synonymous with "student personal data" as used in these Terms and is intended to be read at least as broadly as the equivalent term in SOPPA, the Washington SUPER Act, and California SOPIPA.
Institution Data — All data provided to, uploaded to, generated within, or derived from the use of CyberScholar by or on behalf of an Institution and its Users. Institution Data includes Covered Information, educator content, rosters, course structures, work products, scores, analytics outputs and reports about identified or identifiable individuals, and Metadata.
Metadata — Data generated about the use of the service rather than entered by a User, including timestamps, keystroke and revision telemetry, clickstream records, feature-use counts, device and session data, and system logs. Metadata linked or reasonably linkable to an identified individual is treated as Covered Information. CyberScholar does not sell, license, or trade Metadata in any form.
De-Identified Data — Data from which all direct and indirect identifiers have been removed or irreversibly obscured, and which has been subjected to technical and contractual controls such that it cannot reasonably be used, alone or in combination with other information, to identify an individual student, educator, class, or Institution.
Subprocessor — Any third party engaged by CyberScholar that processes Institution Data in the course of delivering the service, including cloud infrastructure providers, AI model providers, and support tooling vendors.
AI Model Provider — A third party that supplies a large language model, machine-learning model, or comparable inference service used by CyberScholar to generate feedback or analytic output.
Targeted Advertising — Presenting an advertisement to a User where the advertisement is selected on the basis of Covered Information, Institution Data, or Metadata, or on the basis of a profile derived from any of these. CyberScholar does not engage in Targeted Advertising and displays no advertising of any kind.
Data Breach — Unauthorized acquisition, access, use, disclosure, alteration, or destruction of Institution Data that compromises its security, confidentiality, or integrity.
School Purposes — Purposes that customarily take place at the direction of the Institution or its personnel, or that aid in the administration of school activities, including instruction, assessment, administration, and support of educational functions.
2. Ownership and Control of Institution Data
This section exists because Institutions must be able to demonstrate that they, and not their vendors, own and control student records. Every commitment in it is intended to be enforceable as written.
2.1. Ownership of Institution Data
All Institution Data — including all Covered Information, student and educator work product, records, Metadata, and derived records such as scores, analytics, dashboards, and reports about identified or identifiable individuals — is and remains the exclusive property of the Institution, or, as applicable, of the student or educator author in accordance with the Institution’s own policies. CyberScholar claims no ownership interest of any kind in Institution Data.
Nothing in these Terms grants CyberScholar, by implication, estoppel, course of dealing, or otherwise, any right, title, or interest in Institution Data, content, or intellectual property, except the limited license expressly stated in 2.2. Neither the Institution nor its staff or students grant CyberScholar any rights in data, content, or intellectual property beyond that limited license. Institution Data is not an asset of CyberScholar for any purpose, including accounting, financing, sale, merger, or insolvency (see Section 9.3).
2.2. Limited License to CyberScholar
The Institution grants CyberScholar a limited, non-exclusive, non-transferable, non-sublicensable (except to Subprocessors under Section 5), revocable license to host, store, process, transmit, and display Institution Data solely to the extent necessary to perform CyberScholar’s obligations to the Institution and to deliver the contracted educational service. This license terminates automatically upon the return or destruction of the data under Section 8, or upon the Institution’s written revocation.
This license confers no right to use Institution Data for any other purpose whatsoever, including commercial exploitation, advertising, marketing, resale, licensing, research not authorized by the Institution, product development on identifiable data, or the training or fine-tuning of any AI or machine-learning system except strictly as permitted in Section 4.4.
2.3. Direct Control and No Re-Disclosure
The Institution retains direct control over all education records processed by CyberScholar. CyberScholar acts only on the documented instructions of the Institution with respect to the use and maintenance of those records.
CyberScholar will not re-disclose education records or Covered Information to any person or party without the prior written authorization of the Institution, except: (a) to approved Subprocessors under the flow-down conditions in Section 5; (b) as expressly directed by the Institution; (c) to a parent, eligible student, or user exercising a right under Section 6, through or with the knowledge of the Institution; or (d) where compelled by valid legal process. Where disclosure is compelled by legal process, CyberScholar will, unless legally prohibited from doing so, notify the Institution in advance of disclosure and provide a reasonable opportunity for the Institution to seek a protective order or other relief, and will disclose only the minimum data legally required.
CyberScholar will not disclose Institution Data to a foreign government, and will not comply with a foreign government demand for Institution Data, except where required by law and after notice to the Institution to the extent legally permitted.
2.4. Availability, Access, and Portability
Any Institution Data held by CyberScholar will be made available to the Institution upon request. Institutions have standing self-service export capability through their administrative dashboards. In addition, upon written request, CyberScholar will provide a complete export of the Institution’s data in a machine-readable, non-proprietary format (such as CSV, JSON, XML, or PDF as appropriate to the record type) within fifteen (15) business days, or sooner where required by law or by the Institution’s agreement, at no additional charge. Exports include Covered Information, Metadata linked to identified individuals, and the analytic records derived from them.
2.5. No Unilateral Change in Data Practices
CyberScholar will not change how Institution Data is collected, used, retained, disclosed, or shared in any material way without prior written notice to, and the written consent of, the Institution. Changes requiring notice and consent include, without limitation:
collecting a new category or field of personal data;
processing data for a new purpose;
engaging a new Subprocessor or AI Model Provider, or materially changing the role of an existing one;
changing the jurisdiction in which data is stored or processed;
changing retention periods; or
any change that would reduce a protection stated in these Terms or in the executed institutional agreement.
Notice will be given at least thirty (30) days before the change is scheduled to take effect, in writing to the Institution’s designated data privacy contact. If the Institution withholds consent, CyberScholar will either continue to operate for that Institution under the existing practice, or, where that is not technically feasible, permit the Institution to terminate without penalty and will return or destroy the Institution’s data under Section 8. Continued use of the service by individual Users does not constitute Institutional consent.
2.6. Co-Mingling, Tenancy and Segregation
CyberScholar may co-mingle Institution Data with data from other school systems or users only to the extent permitted by FERPA and other applicable law, and only where logical tenancy separation, access controls, and identity scoping ensure that no Institution’s data is accessible to, visible to, or retrievable by another Institution or its users. On request, CyberScholar will identify, isolate, and extract an Institution’s data in full, and will confirm in writing the technical means by which segregation is enforced.
2.7. Intellectual Property in the Platform
The Institution’s ownership of Institution Data does not transfer to the Institution any ownership of the CyberScholar platform, software, source code, models, rubric libraries, prompt architectures, interface designs, or documentation, which remain the property of CyberScholar and its licensors and are made available to the Institution under a limited, non-exclusive license for the term of the agreement. Neither party acquires rights in the other’s pre-existing intellectual property. Improvements to the platform that are derived from De-Identified Data under Section 4.4 belong to CyberScholar; the underlying Institution Data does not.
3. Data Collection and Use
CyberScholar is built to enhance learning while minimizing the data we collect. We collect only the data necessary to fulfil our obligations to the Institution as defined in our agreement with it — data that is adequate, relevant, and limited to what is required for the educational purpose. All data is collected and used in accordance with these Terms and applicable privacy law.
3.1. Categories of Data We Collect
Account Information: the student’s name and email address (usually provided by the Institution or through a roster sync) for login and identification. CyberScholar does not require or collect Social Security numbers. Where an Institution supplies a student identifier for roster matching, it is stored as an opaque key and is not used for any other purpose.
Educational Content: content students create or upload on the platform — essays, assignments, project submissions, survey responses, peer review, and other work product — together with teacher-provided materials such as rubrics, prompts, knowledge-base documents, and feedback on student work.
Usage Data and Learning Analytics: contextual data generated as students work, including login and submission timestamps, keystroke and revision telemetry, clickstream data, and system logs. All such CyberAnalytics data is used to provide formative feedback and to track learning progress, and is visible to the learner and their educators. This data supports student self-regulation of AI use and reflective learning; it is not covert surveillance and is not used for behavioural monitoring outside the platform.
Device and Technical Data: technical information such as IP addresses, browser type, and cookies or similar identifiers, used for security, network integrity, session management, and platform stability. CyberScholar uses no third-party advertising, analytics, or tracking cookies.
Educator and Institution Data: information uploaded by teachers or the Institution, such as class rosters, course structures, and reference materials added to a class Knowledge Base. Such information is treated as Covered Information where it contains student identifiers, and as confidential Institution Data in all cases.
3.2. What We Do Not Collect
CyberScholar does not collect, request, or require, and Institutions and Users should not upload:
Social Security numbers or other government identification numbers;
biometric identifiers or biometric information, including facial geometry, fingerprints, voiceprints, gait, or keystroke biometrics used for identification (keystroke telemetry is used only as a writing-process signal and is never used as a biometric identifier);
precise geolocation data;
medical, mental health, or disability records, or other protected health information;
juvenile justice, disciplinary, immigration status, free-and-reduced-lunch, or family financial records;
religious affiliation, political affiliation, or sexual orientation;
payment card numbers or financial account details from students or parents;
any record of a User’s browsing, search, or activity outside the CyberScholar platform.
If an Institution’s use case requires any of these categories, it must be agreed in writing in advance and documented in the institutional agreement, with a specific lawful basis, purpose limitation, and retention period. Absent that, if such data is inadvertently supplied, CyberScholar will delete it on discovery or notice and will inform the Institution.
3.3. How We Use Collected Data
Providing the Service: authenticating users; processing assignment content, drafts, and revision telemetry to generate AI-supported formative feedback and writing support; displaying that feedback to the student and educator. All of these uses are strictly for the educational purpose of improving student learning.
Supporting Teacher Judgment: compiling AI Composition Reports, progress dashboards, and analytics showing how a draft evolved and how much AI assistance was used, so that educators can make informed pedagogical decisions. The teacher, not the system, makes the decision.
Maintaining and Securing the Platform: operating, monitoring, troubleshooting, and securing the service; investigating suspected security incidents or violations of these Terms.
Service Communications: using contact information to send service-related notifications such as password resets and material platform updates. We do not send marketing communications to students, and we do not market to staff, parents, or guardians using Institution Data.
Improving the Platform: using De-Identified Data only, and only as constrained by Section 4.4.
Legal Compliance: complying with valid legal obligations, subject to the notice commitment in 2.3.
3.4. Prohibited Uses — What We Will Never Do
The following are absolute prohibitions on CyberScholar and, by flow-down, on every Subprocessor:
No sale of data or metadata. CyberScholar will never sell, rent, trade, license, or otherwise transfer for consideration any Institution Data, Covered Information, or Metadata, in identifiable, pseudonymous, or aggregated form, to any party, for any purpose. This prohibition survives termination and applies in any corporate transaction (see 9.3).
No advertising or marketing to students, staff, or families. CyberScholar displays no advertising. We will not use Institution Data to advertise or market to students, staff, parents, or guardians, and we will not engage in Targeted Advertising or build advertising profiles. We will not permit any Subprocessor to do so.
No data mining for unauthorized purposes. CyberScholar is prohibited from mining Institution Data for any purpose other than those expressly agreed with the Institution. We do not amass a profile of a student except in furtherance of School Purposes.
No use beyond School Purposes. Data is processed only for K–12 or authorized educational purposes and is not further processed in any incompatible way. We do not repurpose student information for external research, product marketing, or any purpose not in service of learning, except as De-Identified Data under Section 4.4.
No unauthorized disclosure. Covered Information is not disclosed to third parties except as permitted in 2.3 and Section 5. Student data is not made available to other students or external entities without the Institution’s authorization. Within a class, students may see one another’s contributions only in controlled, teacher-configured activities such as peer review.
No identifiable data to AI Model Providers. See Section 4.
No re-identification. See Section 4.5.
No automated decisions without human review. See Section 4.6.
3.5. Health Information, HIPAA and PPRA
HIPAA. CyberScholar is not a covered entity and does not collect or process protected health information in the ordinary course of delivering the platform. Student records held by a school are education records under FERPA rather than PHI under HIPAA in the ordinary case. Where an Institution nevertheless requires it, CyberScholar will execute a Business Associate Agreement and will apply HIPAA-equivalent controls to any data covered by it.
PPRA. CyberScholar will not administer, and will not enable a third party to administer through the platform, any survey, analysis, or evaluation that reveals information concerning the protected categories identified in the Protection of Pupil Rights Amendment — including political affiliations, mental or psychological problems, sexual behaviour or attitudes, illegal or self-incriminating behaviour, critical appraisals of family members, privileged relationships, religious practices or beliefs, or family income — without the Institution’s express written direction and confirmation that any required parental notice, opt-out, or prior written consent has been obtained. Where CyberScholar provides psychometric or attitudinal survey instruments as a platform feature, their content, deployment, and consent posture are controlled by the Institution.
4. Artificial Intelligence: Processing, Training, and Safeguards
CyberScholar is an AI-mediated learning environment. Institutions are entitled to know exactly what leaves their tenancy, what a model provider is permitted to do with it, and what is used to train anything. This section states those answers.
4.1. How AI Is Used
CyberScholar uses large language models and other machine-learning components to generate formative feedback on student work, to support rubric-referenced assessment, to power in-context writing assistance, and to produce analytic summaries of the writing process. Some models are operated by CyberScholar; others are accessed as inference services from external AI Model Providers. In every case the constraints in 4.2 through 4.8 apply.
4.2. No Identifiable Student Data Leaves the Platform
CyberScholar does not send personally identifiable student data to external AI Model Providers. Identity is resolved and held within CyberScholar’s own environment. Where an external model is used to generate feedback on a student’s work, CyberScholar transmits only the content and the relevant instructional prompt, without the student’s name, email address, institutional identifier, class identifier, or Institution name. Requests are keyed to ephemeral, non-reversible identifiers that carry no meaning outside CyberScholar’s systems.
CyberScholar additionally applies automated detection and redaction to strip incidental personal details — names, addresses, contact details, and similar identifiers appearing inside the body of submitted content — before transmission to an external model. Institutions may request a written description of this pipeline, and may request that specific assignment types be processed only by models operated within CyberScholar’s own infrastructure.
4.3. Contractual Requirements on AI Model Providers
Every external AI Model Provider used by CyberScholar is engaged on enterprise terms that contractually require, at minimum:
Zero data retention — no storage of prompt or completion content beyond the duration of the inference call, save where a short operational retention window is technically unavoidable, in which case it must be disclosed to Institutions and must not exceed thirty (30) days;
No training or fine-tuning on any content transmitted by CyberScholar;
No human review of transmitted content, except where CyberScholar has expressly authorized a narrow safety review and has confirmed it operates on de-identified content;
No onward disclosure of transmitted content to any further party;
No use of transmitted content for the provider’s own purposes of any kind, including product improvement, benchmarking, or evaluation.
CyberScholar does not use consumer-tier or free-tier model endpoints for any Institution Data. Where a provider cannot or will not meet these conditions, that provider is not used.
4.4. Training, Model Improvement, and Product Enhancement
Any Institution Data used to train, fine-tune, evaluate, benchmark, or otherwise enhance any artificial intelligence system, large language model, machine-learning model, or product feature will be de-identified and/or anonymized before such use. No identifiable Institution Data is ever used for any of these purposes.
De-identification for this purpose means removal or irreversible obscuring of direct identifiers (names, emails, identifiers, Institution and class names) and of indirect identifiers and quasi-identifier combinations capable of singling out an individual, together with the contractual and technical prohibitions on re-identification stated in 4.5. Where content is sufficiently distinctive that de-identification cannot be assured — for example, an autobiographical essay — it is excluded from training and improvement uses rather than de-identified.
Institutions may opt out entirely. An Institution may, by written notice at any time, direct that none of its data be used for model training, evaluation, or product enhancement in any form, including in de-identified form. CyberScholar will honour that direction, will confirm it in writing, and will not condition access to the service or any feature on the Institution declining to exercise this right.
CyberScholar does not contribute Institution Data, in any form, to the training of third-party foundation models.
4.5. Prohibition on Re-Identification
CyberScholar will not attempt to re-identify De-Identified Data, and will not permit or assist any other party to do so. This prohibition is written into every Subprocessor agreement. De-Identified Data is not released externally in any form that permits re-identification, and aggregate reporting suppresses small cells: CyberScholar does not publish or externally report statistics derived from groups smaller than ten (10) individuals, and applies complementary suppression where a small cell could be inferred by subtraction. Institution and school names are not disclosed in research or marketing outputs without the Institution’s separate written permission.
4.6. Human Oversight and Automated Decision-Making
AI output in CyberScholar is formative and advisory. No AI-generated score, classification, flag, or recommendation is used as the sole basis for any decision producing a legal or similarly significant effect on a student — including a grade of record, promotion or retention, placement, discipline, eligibility, referral, or any determination affecting a student’s academic standing. An educator with authority over the student always sits between the model output and any consequential decision, and retains the ability to override it.
Students and educators can see the AI outputs that concern them, can see the basis on which they were produced to the extent the system can express it, and can contest or annotate them. CyberScholar supports human-in-the-loop moderation of AI-generated feedback at the Institution’s configuration.
4.7. Prohibited AI Applications
CyberScholar does not, and will not without an Institution’s specific written authorization and applicable legal review, use AI for:
emotion recognition, affect detection, or inference of a student’s mental or emotional state;
biometric identification or biometric categorization of students;
predictive risk scoring of individual students for discipline, safety, or law-enforcement purposes;
monitoring of student activity outside the CyberScholar platform;
inference of protected characteristics such as race, ethnicity, religion, disability, immigration status, or sexual orientation;
proctoring, invigilation, or covert behavioural surveillance.
4.8. AI Transparency and Change Control
CyberScholar maintains and makes available to Institutions a current list of the AI Model Providers in use, the purpose for which each is used, and the data categories transmitted to each. Adding or substituting an AI Model Provider is a material change in data practice and is subject to the notice-and-consent requirement of Section 2.5. Institutions may request model-level restrictions, including confining their tenancy to a specified subset of approved models.
5. Third-Party Service Providers and Subprocessors
5.1. Permitted Engagement
CyberScholar engages Subprocessors only where necessary to deliver core services — cloud hosting, storage, AI inference, email delivery, error monitoring, and comparable functions. Subprocessors are granted the minimum access required and may use Institution Data solely to provide services to CyberScholar in furtherance of the Institution’s purposes.
5.2. Flow-Down of Obligations
Every Subprocessor is bound by a written agreement imposing data protection, confidentiality, security, and use-limitation obligations at least as protective as those in these Terms and in the Institution’s executed agreement, including the prohibitions on sale, advertising, data mining, training on identifiable data, and re-identification. All Subprocessors, successor entities, and assignees of CyberScholar are subject to the terms of the Institution’s agreement. CyberScholar remains fully liable to the Institution for the acts and omissions of its Subprocessors as if they were its own.
5.3. Disclosure of Subprocessors
CyberScholar will share the names of its Subprocessors with an Institution upon request, and maintains a published list of the third parties to whom it discloses Covered Information, as required by SOPPA. The list identifies each Subprocessor, its function, the categories of data it may access, and the jurisdiction of processing. It is reviewed and updated at least annually and whenever a material change occurs. A summary of categories appears at Appendix C.
5.4. Objection and Substitution
An Institution may object in writing to a proposed new Subprocessor within the thirty (30) day notice period under Section 2.5, stating reasonable data protection grounds. CyberScholar will work in good faith to provide an alternative, to exclude that Institution’s data from the Subprocessor’s scope, or, failing either, to permit termination without penalty with return or destruction of data under Section 8.
6. Student, Parent, and Educator Rights
6.1. Scope of Rights
CyberScholar upholds the rights of students, parents, and eligible students regarding personal data, in accordance with SOPPA, FERPA, the Washington SUPER Act, New York Education Law § 2-d, California SOPIPA, the GDPR, and other applicable law. The following rights are guaranteed and are facilitated through our platform and policies.
Right to Inspect and Review: Parents of K–12 students have the right to inspect and review their child’s Covered Information collected or generated by CyberScholar, including data maintained by the Institution, by us as operator, or by any Subprocessor on our behalf. An eligible student holds this right in their own name.
Right to Obtain a Copy: Parents and eligible students may request a paper or electronic copy of the student’s information. CyberScholar, in coordination with the Institution, will provide a readable copy of all of the student’s personal data held. Electronic copies are provided at no charge. Requests are fulfilled within the timeframe applicable to the Institution — under FERPA, within forty-five (45) days of the Institution’s receipt of the request, and sooner where state law requires.
Right to Request Correction: Where a parent or eligible student believes data is factually inaccurate or incomplete, they may request correction. Where the data is maintained by CyberScholar, we will correct any confirmed inaccuracy and inform the Institution of the correction within ninety (90) calendar days of the request, or sooner where required, and will promptly propagate the correction so that reports and analytics reflect it. Where the data is maintained by the Institution, the Institution handles the correction and notifies the parent.
Right to Request Deletion: Parents and eligible students may request deletion of the student’s Covered Information, where allowable under applicable state and federal record retention law. CyberScholar will delete the requested data from active systems, will instruct Subprocessors to do likewise, and will confirm completion to the Institution and requester. Where a record must be retained by law, we will say so plainly, will identify the retaining party, and will restrict the record’s use to the purpose that requires its retention.
Right to Data Portability: Students, parents, and eligible students may obtain the student’s data in a commonly used, machine-readable format. Institutional exports under 2.4 are available for bulk requests.
Right to Restrict Processing: Where the accuracy of data is contested or its use is disputed, a requester may ask that processing be restricted pending resolution. CyberScholar will honour reasonable restriction requests received through the Institution.
Right to Know and Consent to Software Use: Parents have the right to know which online tools are used in their child’s classroom and to grant or withhold consent. CyberScholar is fully transparent with Institutions about its data practices, enters SOPPA-compliant agreements, and supports district posting requirements. Where an Institution’s policy requires parental consent, CyberScholar relies on the Institution to obtain and document it. If a parent declines consent, the student should not use the platform, and CyberScholar will disable the account promptly on the Institution’s instruction so that no further data is collected.
Right to Be Notified of a Data Breach: Parents, eligible students, and Institutions have the right to timely notification of a breach affecting Covered Information (see Section 7.10).
Educator Rights: Educators hold, in respect of their own personal data and their own instructional content, the same rights of access, correction, deletion, and portability. CyberScholar does not use educator analytics for employment evaluation and will not provide educator-level performance analytics to an Institution for evaluative purposes without the Institution’s written direction and confirmation that it has met any applicable notice or bargaining obligation.
6.2. Exercising These Rights
Parents of K–12 students should ordinarily exercise these rights through their Institution, which is the primary custodian of the student’s education records and holds direct administrative access to most platform data. CyberScholar will assist the Institution promptly and will meet the applicable statutory timeline. Eligible students and users in higher education may contact CyberScholar directly. CyberScholar verifies identity and authority before disclosing or acting on personal data, and will not disclose a minor’s data to a person whose authority the Institution has not confirmed.
Requests may be directed to the Data Protection Contact in Section 12. CyberScholar does not charge for exercising these rights and will not retaliate against, or degrade service to, any User or Institution that exercises them.
7. Security and Breach Response
7.1. Information Security Program
CyberScholar maintains a documented, written information security program with administrative, technical, and physical safeguards appropriate to the sensitivity of student data. The program is aligned to the NIST Cybersecurity Framework and to ISO/IEC 27001 control objectives, is owned by a named individual, and is reviewed and updated at least annually and after any material incident or change in the threat environment. The program meets or exceeds the "reasonable security procedures and practices" standard required by SOPPA and equivalent state law.
7.2. Encryption
All data in transit between user devices, CyberScholar systems, and Subprocessors is encrypted using TLS 1.2 or higher with modern cipher suites. All Institution Data at rest — in databases, object storage, and backups — is encrypted using AES-256 or an equivalent industry-standard algorithm. Encryption keys are managed in a dedicated key management service with restricted access and periodic rotation.
7.3. Access Control
Access to Institution Data is granted on a least-privilege, need-to-know basis and is role-based. Administrative and production access requires unique named accounts with multi-factor authentication; shared or generic credentials are prohibited. Access is reviewed at least quarterly, and is revoked immediately upon role change or separation. All access to production systems containing Covered Information is logged, and logs are retained and monitored. Every individual with access is bound by a written confidentiality obligation. Institutions control access levels for their own staff within the platform so that each user sees only what they are permitted to see. Individuals employed by CyberScholar may access school records only when necessary to provide the service to the Institution, consistent with FERPA.
7.4. Personnel
Personnel with access to Institution Data are subject to confidentiality agreements, background screening where lawful and appropriate to the role, mandatory privacy and security training on hire and annually thereafter, and documented sanctions for violation of security policy. Access to production data is limited to a small, vetted team.
7.5. Testing, Assurance and Vulnerability Management
CyberScholar conducts continuous automated vulnerability scanning of its applications and infrastructure, maintains a documented patch management policy with defined remediation timeframes for critical and high-severity findings, keeps software dependencies current, and commissions an independent third-party penetration test at least annually. CyberScholar maintains, or is working toward, independent security attestation (such as SOC 2 Type II or ISO/IEC 27001 certification); its current attestation status is disclosed to Institutions on request. Summary results of penetration tests and attestations are made available to Institutions under a confidentiality undertaking. CyberScholar operates a coordinated vulnerability disclosure channel at the address in Section 12.
7.6. Hosting, Infrastructure and Data Residency
Institution Data is hosted in access-controlled, professionally operated data centres holding recognized security certifications (such as SOC 2 or ISO/IEC 27001) and protected by network segmentation, firewalls, and intrusion detection. Institution Data for United States Institutions is stored and processed within the United States and will not be transferred to or accessed from another jurisdiction without the Institution’s prior written consent, except where an Institution has agreed to a specific Subprocessor arrangement disclosed under Section 5. Student data is not stored on unsecured devices, personal equipment, or removable media.
7.7. Business Continuity and Backups
Backups are encrypted, access-controlled, and stored separately from production. Restoration procedures are tested at least annually. Backup retention cycles are defined and bounded so that deleted data ages out of backups within the period stated in Section 8.
7.8. Institutional Audit and Verification Rights
On thirty (30) days’ written notice, and no more than once in any twelve-month period absent cause, an Institution may verify CyberScholar’s compliance with these Terms by reviewing security documentation, policies, attestation reports, and completed security questionnaires, and by interviewing CyberScholar’s security personnel. Following a Data Breach affecting the Institution, or where the Institution has reasonable cause to believe a material non-compliance has occurred, the Institution may require a further review without waiting for the annual cycle, including an assessment by an independent third party engaged at the Institution’s expense and subject to confidentiality.
7.9. Insurance
CyberScholar maintains commercially reasonable cyber liability and technology errors-and-omissions insurance appropriate to the scale of its operations, and will provide a certificate of insurance to an Institution on request.
7.10. Data Breach Notification
Where CyberScholar determines that a Data Breach affecting an Institution’s data has occurred, it will:
notify the Institution’s designated data privacy or IT contact promptly and without unreasonable delay, and in no event later than forty-eight (48) hours after making that determination — and in every case within the shortest period required by applicable law or by the Institution’s agreement, including the seven (7) calendar days required under New York Education Law § 2-d and the thirty (30) days required under SOPPA;
provide a written incident report within seven (7) calendar days of the initial notification, updated as the investigation progresses;
immediately initiate its incident response protocol: investigate scope and nature, identify affected systems and data, contain the incident, patch or isolate compromised systems, revoke compromised credentials, and prevent further unauthorized access;
preserve forensic evidence and make it available to the Institution and to law enforcement as appropriate;
not make any public statement identifying an Institution without that Institution’s prior written approval, except where legally compelled.
Where law enforcement advises in writing that notification would impede a criminal investigation, notification may be delayed only as long as, and to the extent, the law permits, and will be made immediately once the restriction lifts. The Institution will be told that such a delay has been requested as soon as it is lawful to do so.
7.11. Contents of a Breach Notification
The notice to the Institution will include everything required by SOPPA and other applicable law, and at minimum:
the date or estimated date range of the breach, and the date of discovery and determination;
a description of the categories of Covered Information involved (for example, names, email addresses, assignment submissions, feedback records), and the number of affected individuals, by Institution;
how the breach occurred, to the extent known, and whether it involved a Subprocessor;
the steps taken to contain and remediate the incident, and the steps planned to prevent recurrence;
contact information for CyberScholar’s designated incident contact, for use by the Institution and by affected parents; and
any recommended protective actions for affected individuals.
The notice will describe categories of data rather than reproducing sensitive data itself.
7.12. Cooperation, Mitigation and Cost Allocation
CyberScholar will cooperate fully with the Institution’s notification obligations, including assisting in drafting parent notifications on request, and providing the information the Institution needs to notify parents within the thirty (30) days required in Illinois and within the equivalent period in other jurisdictions. After a breach, CyberScholar will conduct a root cause analysis and enhance controls accordingly.
Where a breach is attributable to CyberScholar’s act, omission, or failure of its safeguards, or to that of a Subprocessor, CyberScholar bears responsibility for the reasonable costs of response — including forensic investigation, notification of affected individuals, call-centre support, and credit monitoring or identity protection services where appropriate or required by law. The allocation of costs is stated in each Institution’s agreement; nothing in these Terms limits CyberScholar’s liability for its own breach of its privacy and security obligations (see 10.4).
7.13. Regulatory Notification
Where required, CyberScholar or the Institution will notify relevant regulators — for example the Illinois State Board of Education, a state attorney general, or a European supervisory authority within seventy-two (72) hours where the GDPR applies. CyberScholar will supply the Institution with the details and documentation needed to meet its own reporting and website-posting obligations, and will coordinate to avoid duplicate or inconsistent notification.
8. Data Retention, Return and Destruction
CyberScholar retains student data only for as long as necessary to fulfil the educational purposes for which it was collected and as required by law or by the Institution’s agreement. We do not retain personal data indefinitely or for unrelated purposes.
8.1. Retention During Service
Active use: account, assignment, and analytics data is retained for the duration of the student’s enrolment in the class or programme using CyberScholar, so that students and teachers can refer to past work and track progress over time.
End of course or year: at the close of a course, semester, or school year, course data is archived. Archived data remains available to authorized Institution officials and, where the Institution permits, to the student, for a period set by the Institution’s policy. Archived data remains fully protected by these Terms and is not used by CyberScholar for any purpose other than access by the Institution and its users.
8.2. Return or Destruction on Instruction
CyberScholar will ensure that all Institution Data in its possession, and in the possession of any Subprocessor or agent to which it has been transferred, is destroyed or transferred to the Institution, under the direction of the Institution, when the data is no longer needed for its specified purpose or at the request of the Institution. This will take place no later than six (6) months from that point, or within such other reasonable period as the parties mutually agree in writing. Where an Institution requires a shorter period, the shorter period governs.
On termination or expiry of an Institution’s agreement, or on discontinuation of use, CyberScholar will deactivate accounts and, unless otherwise instructed, return or destroy all Covered Information after a defined grace period allowing the Institution to export student work and records. The grace period is stated in the Institution’s agreement and does not extend the six-month outer limit above.
8.3. Method and Certification of Destruction
Destruction is performed so that data is rendered unreadable and irrecoverable, using methods consistent with NIST SP 800-88 media sanitization guidance. CyberScholar will provide the Institution with written certification of destruction, identifying the data categories destroyed, the date, the method, and confirmation that Subprocessors have destroyed their copies, within thirty (30) days of completion.
8.4. Backups and Residual Copies
When data is deleted from primary systems it is immediately removed from all user-facing interfaces and ceases to be processed. Residual copies may persist briefly in encrypted backup media, which are cycled and overwritten on a defined schedule not exceeding ninety (90) days. Backup data is never used for any active purpose. Where an Institution requires expedited purge from backups, CyberScholar will accommodate it except where retention is compelled by law.
8.5. Deletion Requests from Parents and Students
Valid deletion requests are actioned as described in Section 6.1, in coordination with the Institution, and are propagated to Subprocessors. Where a record retention law prohibits deletion for a period, CyberScholar will inform the requester which records cannot yet be deleted, why, and who holds them, and will restrict their use in the interim.
8.6. De-Identified Data After Deletion
Following deletion of a student’s personal data, CyberScholar may retain De-Identified Data for research, statistical analysis, and product improvement, subject to Sections 4.4 and 4.5 and to any Institution opt-out. Such data is not Covered Information because it can no longer be linked to any individual. Examples include aggregate measures of improvement across cohorts, with no names, identifiers, class, or Institution attached. An Institution that has opted out under 4.4 has its data excluded from this retention as well.
8.7. Routine Review
CyberScholar periodically reviews stored data and purges information no longer needed for any legitimate purpose. Where a student account has been inactive for an extended period and is not associated with an active Institution agreement, CyberScholar will consult the Institution before deletion, and will delete absent instruction to retain.
9. Institutional Assurance, Corporate Change, and Termination
9.1. Annual Compliance Statement
CyberScholar will provide each Institution, on request and at least annually, a written statement confirming continued compliance with these Terms and the Institution’s agreement, listing current Subprocessors and AI Model Providers, describing any material change in data practice during the period, summarizing the security assurance activities completed, and confirming that no Institution Data has been sold, mined, or used for advertising or for training on identifiable data.
9.2. Records of Processing and Impact Assessments
CyberScholar maintains records of its processing activities and will assist an Institution, at no additional charge, in completing a data protection impact assessment, a privacy threshold analysis, a state consortium agreement, a district vendor security review, or an equivalent instrument.
9.3. Change of Control, Successors and Insolvency
Institution Data is not a saleable asset of CyberScholar and will not be treated as one in any transaction. In the event of a merger, acquisition, reorganization, sale of assets, or other change of control:
CyberScholar will give each affected Institution written notice at least thirty (30) days before the transaction closes, to the extent legally permitted;
any successor or assignee is bound by these Terms and by the Institution’s executed agreement as a condition of the transaction, and must affirm that in writing;
the successor may not change data practices except through the notice-and-consent process in Section 2.5; and
the Institution may terminate without penalty and require return or destruction of its data under Section 8.
In the event of insolvency, receivership, administration, or bankruptcy, Institution Data does not form part of the estate available for transfer or sale, and CyberScholar will take all steps within its control to ensure the data is returned to Institutions or destroyed.
9.4. Termination for Privacy or Security Cause
An Institution may terminate its agreement immediately, without penalty and without prejudice to any other remedy, upon a material breach by CyberScholar of its privacy or security obligations. On such termination CyberScholar will return or destroy the Institution’s data under Section 8 at no cost, and will refund prepaid fees for the unexpired portion of the term.
9.5. Government and Law Enforcement Requests
CyberScholar will not voluntarily disclose Institution Data to law enforcement or any government body. Where a request or compulsory process is received, CyberScholar will assess its validity, will notify the Institution before responding unless legally prohibited, will provide the Institution a reasonable opportunity to object or seek protective relief, will disclose only the minimum data legally required, and will maintain a record of all such requests available to the Institution.
10. Acceptable Use and Platform Terms
10.1. Authorized Use
Users may access CyberScholar only through credentials issued to them and only for the educational purposes authorized by their Institution. Users must not share credentials, attempt to access another user’s account or data, circumvent access controls or tenancy boundaries, probe or test platform security without written authorization, scrape or bulk-extract data other than through provided export functions, reverse engineer the platform, or use the service to infringe intellectual property or to harass, defame, or endanger any person.
10.2. Content Standards and Minimization
Users should not upload personal data beyond what an assignment requires, and specifically should not upload the categories listed in Section 3.2. Educators configuring assignments, prompts, and knowledge bases are responsible for ensuring that the data they invite students to submit is appropriate to the educational purpose and consistent with their Institution’s policy.
10.3. Academic Integrity and AI Use
CyberScholar makes AI assistance visible rather than hidden: its analytics show the relative contribution of student and machine to a piece of work. The academic integrity policy that governs a student’s use of AI is set by the Institution and the educator, not by CyberScholar. CyberScholar provides the evidence; the Institution makes the judgment, consistent with Section 4.6.
10.4. Warranties, Liability and Remedies
CyberScholar warrants that it will provide the service with reasonable skill and care, in compliance with these Terms, the Institution’s agreement, and applicable law, and that it will maintain the safeguards described in Section 7. Except as expressly stated, the service is provided without further warranty of any kind.
Any limitation or exclusion of liability agreed between CyberScholar and an Institution does not apply to, and CyberScholar’s liability is not capped in respect of, CyberScholar’s breach of its confidentiality, privacy, or data security obligations, its unauthorized use or disclosure of Institution Data, or its indemnification obligations for a Data Breach attributable to it. CyberScholar will indemnify and hold harmless the Institution and its officers, employees, and agents against claims, losses, and reasonable costs arising from CyberScholar’s breach of these obligations or from its negligence or wilful misconduct.
10.5. Governing Law and Venue
These Terms are governed by the law of the State of Illinois, without regard to its conflict-of-laws rules, except that where an Institution’s executed agreement or its governing statute requires the law and venue of the Institution’s own jurisdiction, that law and venue govern for that Institution. CyberScholar does not require Institutions, students, or parents to accept binding arbitration or to waive class-action or jury rights.
10.6. Severability and Survival
If any provision is held unenforceable, the remainder continues in force. The obligations in Sections 2, 3.4, 4, 5, 6, 7.10–7.13, 8, 9.3, and 10.4 survive termination of any agreement or of a User’s access.
11. International Compliance Alignment
11.1. FERPA
When CyberScholar is used by a FERPA-covered institution, we operate as a "school official" with a legitimate educational interest, meaning we: (a) perform an institutional service or function that would otherwise be performed by school staff; (b) are under the direct control of the Institution with respect to the use and maintenance of education records; and (c) use education records only for authorized educational purposes. We do not redisclose FERPA-protected data except as FERPA allows. We assist Institutions with annual FERPA notifications and with responses to FERPA inquiries. Nothing in these Terms or our practices requires an Institution to act inconsistently with FERPA.
11.2. COPPA
For users under 13, CyberScholar complies with COPPA. We do not collect personal information from children under 13 without appropriate consent. In a school setting, we rely on the Institution to provide or obtain consent as the parent’s agent, consistent with FTC guidance. Registration is designed so that a child under 13 cannot create an account independently: accounts must be created by, or linked to, the Institution’s authorization. We supply Institutions with the information they need to inform parents. If a parent revokes consent, we will support the Institution in disabling the account and deleting the child’s personal data.
11.3. SOPPA (Illinois)
CyberScholar is a SOPPA "operator". We do not engage in targeted advertising, do not sell student data, do not amass a profile except in furtherance of School Purposes, maintain reasonable security, publish the list of third parties to whom we disclose Covered Information, delete Covered Information on the Institution’s request, support parental inspection, copying, and correction rights within the statutory timeframes, and notify the Institution of a breach within the statutory period. We enter written agreements with Illinois Institutions containing every term SOPPA requires.
11.4. Washington SUPER Act
For Institutions in Washington State, CyberScholar complies with the Student User Privacy in Education Rights Act (RCW 28A.604) and with district board policy. We do not engage in targeted advertising to students; we do not use covered information to amass a profile except in furtherance of K–12 School Purposes; we do not sell or rent covered information; we do not disclose covered information except as the Act permits; we maintain reasonable security; and we delete covered information at the direction of the school district. Where a Washington district’s data sharing agreement or board policy imposes a stricter requirement than these Terms, the stricter requirement governs (Section 1.3).
11.5. New York Education Law § 2-d
For New York Institutions, CyberScholar adopts the Parents’ Bill of Rights for Data Privacy and Security, will complete the required supplemental information and data security and privacy plan, aligns its controls to the NIST Cybersecurity Framework, and will notify the educational agency of a breach in the most expedient way possible and without unreasonable delay, and in no case more than seven (7) calendar days after discovery.
11.6. California SOPIPA and AB 1584
For California Institutions, CyberScholar complies with SOPIPA and Education Code § 49073.1: pupil records continue to be the property of and under the control of the local educational agency; pupils may retain possession and control of their own pupil-generated content; we do not use pupil records for any purpose other than those required or specified in the agreement; and we certify deletion of pupil records on request.
11.7. GDPR and UK GDPR
For data subjects in the EEA and the United Kingdom, CyberScholar acts as a processor to the Institution as controller and adheres to the following principles:
Lawfulness, fairness, and transparency — processing under contractual necessity or, outside a school context, consent, with clear notice through these Terms.
Purpose limitation and data minimization — collection strictly for specified educational purposes, as set out in Section 3.
Accuracy — prompt rectification under Section 6.
Storage limitation — bounded retention under Section 8.
Integrity and confidentiality — the controls in Section 7, with regulator notification within seventy-two (72) hours where required.
Accountability — records of processing, DPIA assistance, and a designated privacy contact under Sections 9.2 and 12.
CyberScholar supports the rights of access, rectification, erasure, restriction, portability, and objection as described in Section 6. We do not conduct marketing or profiling of the kind that would trigger objection rights, and we do not carry out solely automated decision-making producing legal or similarly significant effects (Section 4.6).
11.8. International Data Transfers
Where personal data is transferred from the EEA, the United Kingdom, or another jurisdiction to CyberScholar’s servers, appropriate safeguards are used — including the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum, supplemented by technical measures such as encryption and the de-identification pipeline in Section 4.2. Because we do not share identifiable data with unrelated third parties, cross-border flows are limited and controlled. Data residency commitments for United States Institutions are stated in Section 7.6.
11.9. Other Jurisdictions
In Canada we follow PIPEDA principles, obtaining consent through Institutions and limiting collection to what is necessary. In Australia we adhere to the Australian Privacy Principles. In all jurisdictions we endeavour to meet or exceed local legal requirements for student data protection. If any provision of these Terms would contradict a mandatory law of an Institution’s jurisdiction, that provision yields to the law while the remainder continues in force.
12. Governance and Contact
12.1. Privacy Governance
CyberScholar designates a Data Protection Officer (or equivalent privacy lead) responsible for oversight of compliance with SOPPA, FERPA, COPPA, state student privacy law, the GDPR, and these Terms; for maintaining the Subprocessor and AI Model Provider registers; for incident response; and for responding to Institution, parent, and student inquiries. We encourage Institutions to inform us of specific local requirements in their jurisdiction so that we can meet them.
12.2. Contact for Privacy and Data Protection
Email: privacy@cyberscholar.ai
Security and vulnerability reports: security@cyberscholar.ai
Phone: (217) 328-0405 (Mon–Fri, 9am–5pm US Central Time)
Post: CyberScholar, 2001 South First Street, Suite 202, Champaign, IL 61822, USA
The contracting entity for a given Institution is identified in that Institution’s executed agreement. Institutions requiring confirmation of the legal entity, its registration, and its authorized signatory may request this in writing at the address above.
12.3. Response Commitments
We acknowledge privacy inquiries within three (3) business days and respond substantively within the timeframe required by law, or within thirty (30) days where no shorter period applies. For security reasons we verify identity and authority before acting on a request concerning student data. Educators and administrators may also raise privacy questions through their CyberScholar account contact, though privacy-specific matters are best directed to the address above.
12.4. Complaints and Dispute Resolution
We aim to resolve concerns directly and in good faith. If you believe we have not adequately addressed a privacy concern, please tell us. Depending on your jurisdiction, you may also lodge a complaint with a supervisory authority or regulator — for example a Data Protection Authority in the EEA or United Kingdom, the Illinois Attorney General for SOPPA matters, the Washington State Attorney General, the U.S. Department of Education’s Student Privacy Policy Office for FERPA matters, or the Federal Trade Commission for COPPA matters. We would appreciate the opportunity to resolve the matter with you first, but nothing in these Terms conditions or delays your right to complain.
13. Changes to These Terms
Where we make material changes to these Terms or to our data practices, we will notify Institutions in advance in accordance with Section 2.5, and will notify individual Users where appropriate. Changes are made in compliance with applicable law and will not retroactively reduce the rights or protections available to Institutions, students, parents, or eligible students under SOPPA, FERPA, COPPA, state student privacy law, the GDPR, or an executed institutional agreement. Superseded versions are archived and available on request, and each version is dated.
By using CyberScholar, Institutions and Users acknowledge that they have read and understood these Terms and agree to abide by them. These Terms exist to protect students while enabling ambitious learning. CyberScholar will continue to earn the trust placed in it by Institutions, students, educators, and parents by keeping personal information safe and private in service of learning.
Appendix A — Jurisdiction-Specific Provisions
The provisions below apply in addition to, and where stricter than, the body of these Terms. They are summarized here; the full statutory text governs.
|
Jurisdiction |
Additional commitments |
|
Illinois |
SOPPA (105 ILCS 85/). Written agreement with each covered entity; published list of third parties receiving Covered Information; no targeted advertising, sale, or profiling outside School Purposes; deletion on request; parental inspection, copy, and correction rights; correction within 90 days; breach notice to the school within 30 days of determination; school website posting support. |
|
Washington |
SUPER Act (RCW 28A.604) and district board policy, including Puyallup School District Policies 2022 and 3235 and the Policy 2022 F1 Data Sharing Agreement. District ownership of and direct control over records; no re-disclosure without district authorization; no advertising or marketing; no sale of data or metadata; no data mining beyond agreed purposes; de-identification or anonymization of any district data used for AI, LLM, machine learning, or product enhancement; subcontractor names on request; subcontractors and successors bound; destruction or transfer within six months on district direction; access limited to employees who need it; district data available on request. |
|
New York |
Education Law § 2-d. Parents’ Bill of Rights for Data Privacy and Security adopted; supplemental information and data security and privacy plan supplied; NIST CSF alignment; breach notice to the educational agency without unreasonable delay and no later than seven calendar days after discovery. |
|
California |
SOPIPA (B&P § 22584) and AB 1584 (Ed. Code § 49073.1). Pupil records remain the property and under the control of the local educational agency; pupil-generated content may be retained by the pupil; certification of deletion on request; no use of pupil records beyond the agreement. |
|
EEA / UK |
GDPR and UK GDPR. Processor role; Standard Contractual Clauses and UK Addendum for transfers; 72-hour regulator notification; DPIA assistance; full data-subject rights support. |
|
Other states |
CyberScholar will execute applicable state student data privacy consortium agreements, including the SDPC National Data Privacy Agreement and its state exhibits, and will meet any additional statutory requirement of the Institution’s state. |
Appendix B — Crosswalk to District Data Sharing Agreement Requirements
This crosswalk maps the standard requirements found in K–12 district data sharing agreements — including the Puyallup School District Policy 2022 F1 form — to the clause of these Terms that satisfies them. It is provided so that a district privacy officer can verify coverage without reading the document end to end.
|
District requirement |
Where satisfied |
|
District retains direct control over all educational records; no re-disclosure to any other party without District authorization |
2.3; 9.5; 11.1 |
|
Provider will not use data to advertise or market to staff, students, or parents/guardians |
3.4; 1.4 (Targeted Advertising) |
|
No change to how data is collected, used, or shared without advance notice to, and consent from, the District |
2.5; 4.8; 5.4; 13 |
|
Provider collects only data necessary to fulfil obligations under the Agreement |
3.1; 3.2; 3.3 |
|
Provider is prohibited from selling data or metadata to any party |
3.4; 1.4 (Metadata); 9.3 |
|
Provider is prohibited from mining data for purposes other than those agreed |
3.4; 2.2; 4.4 |
|
Any District data used to train AI, LLMs, or machine learning, or for product enhancement, will be de-identified and/or anonymized |
4.4; 4.5; 8.6 |
|
Subcontractor names shared with the District on request; all subcontractors and successor entities bound by the Agreement |
5.2; 5.3; 9.3; Appendix C |
|
All data held by Provider, subcontractors, or agents destroyed or transferred to the District at District direction, no later than six months or a mutually agreed period |
8.2; 8.3; 8.4 |
|
Provider may co-mingle District data with other systems’ data as permitted by FERPA |
2.6 |
|
Provider employees may access school records only when necessary to provide the service |
7.3; 7.4 |
|
All rights, including intellectual property rights, remain the exclusive property of the District; Provider holds a limited, nonexclusive license solely to perform its obligations; no implied rights granted |
2.1; 2.2; 2.7 |
|
Any District data held by the Provider made available to the District on request |
2.4 |
|
Provider serves as a "school official" under FERPA and meets FERPA, COPPA, HIPAA, PPRA, and state student privacy law |
1.1; 3.5; 11.1–11.6 |
|
Reasonable security safeguards and timely breach notification |
7.1–7.13 |
|
Data retained only as long as needed; deletion certified |
8.1–8.7 |
Appendix C — Categories of Subprocessors
The table below describes the categories of Subprocessor CyberScholar engages. The current register naming each specific provider, its function, the data categories it may access, and its processing jurisdiction is maintained by the Data Protection Officer, published for SOPPA purposes, reviewed at least annually, and supplied to any Institution on request under Section 5.3. Additions and substitutions are subject to the notice-and-consent process in Section 2.5.
|
Category |
Function |
Data accessible |
|
Cloud infrastructure and storage |
Hosting of the application, databases, object storage, and encrypted backups |
Institution Data at rest and in transit, encrypted; provider has no plaintext application-level access |
|
AI model providers |
Inference for formative feedback, rubric-referenced assessment, and writing support |
De-identified content and instructional prompts only; no names, emails, identifiers, class or Institution names (Sections 4.2–4.3) |
|
Transactional email delivery |
Account, authentication, and service notifications |
Name and email address of the recipient only |
|
Error monitoring and observability |
Diagnosis of faults and performance issues |
System logs and technical metadata; personal data scrubbed from telemetry |
|
Support tooling |
Institution and educator support ticketing |
Contact details and the content of support requests |
|
Payment processing (institutional billing only) |
Invoicing and payment of Institution licence fees |
Institution billing contacts; no student data, no parent payment data |

