Privacy Policy
TeachersPlan ("we", "us") helps teachers generate standards-aligned classroom materials. This policy explains what we collect, why, and the choices you have. We wrote it to be readable — if anything is unclear, email hello@teachersplan.com. School administrators may prefer our Trust Center, which covers our student-privacy posture and subprocessors in one place.
Student data — the short version
What we collect
- Your email address — to create your account and send one-time sign-in codes.
- Materials you generate and save — your lesson plans, slides, worksheets, etc., so your Library is there when you sign in.
- Basic technical logs — standard request metadata used to keep the service reliable and to prevent abuse (rate limiting). We do not sell this or use it for advertising.
What we do not collect
- No student names, grades, IEP details, or any student PII on our servers.
- No selling or sharing of your data with advertisers.
- No tracking you across other websites.
How sign-in works
We use passwordless email sign-in. When you log in we send a 6-digit code to your email; the code is stored only as a one-way hash, expires after 15 minutes, and is single-use. Sign-in tokens are scoped to your account.
Your generated materials
Lessons you save are tied to your account and visible only to you. You can delete any saved lesson from your Library at any time, which removes it from our database.
How your data is encrypted
Encrypted in transit (TLS) and at rest. Our database (Cloudflare D1) is encrypted at rest, and Google account tokens are additionally encrypted at the application layer with AES-GCM.
We never sell your data, and we never train AI on your content
We never sell your data and we never use it for advertising. Lesson generation runs on large-language-model APIs operated by our AI providers (currently Google's Gemini API, with Cloudflare Workers AI as a fallback). Under the paid API terms we use, these providers do not train their models on the prompts or outputs we send. We do not sell your data or use your content to train any model we operate.
Student privacy posture
We approach student privacy the cleanest way possible — by not collecting student information at all. We never collect or store student records on our servers. Class rosters and per-student copies live only in your browser's local storage, on your device. This data-minimization posture is how we align with SOPIPA-style state student-privacy laws: there is no student data to sell, profile, or target. (How FERPA applies is always a determination for your school or district — we're glad to answer questions from your administrator at security@teachersplan.com.)
Subprocessors
We use a short list of providers. Google Drive export acts only with your explicit consent:
- Cloudflare — hosting, database (D1), and fallback AI generation (Workers AI). Cloudflare maintains SOC 2 Type II and ISO 27001 certifications (these are Cloudflare's certifications as our hosting provider, not TeachersPlan's own).
- Google (Gemini API) — AI lesson generation. We send the lesson request (state, grade, subject, standard text, and any topic you type) to generate materials; no account data, roster data, or community content is included. Per Google's paid API terms, these inputs are not used to train Google's models.
- Google (Drive export) — optional export to Google Drive / Docs / Slides, only when you
connect Google and choose to export. We request the
drive.filescope — per-file access to files you create with TeachersPlan, not your whole Drive. - Resend — transactional email only (sign-in codes and materials you choose to email). No marketing email.
District & school use
Integration scopes are kept as narrow as possible (file-level Google Drive access, never full-drive), and we're glad to walk your district IT through the architecture. A Data Processing Agreement (DPA) is available on request.
Your data, your control — export & deletion
You can take your data with you or remove it at any time, without filing a ticket:
- Export anytime — download your account data via your account's export endpoint
(
GET /api/account/export). - Delete anytime — delete your account and all associated data from the Account drawer → Delete. No ticket, no waiting: you can remove your record entirely, yourself.
Prefer email? You can also reach us at hello@teachersplan.com from your account email, or contact security@teachersplan.com for security and administrator questions. A Data Processing Agreement (DPA) is available on request.
Changes
If we update this policy we'll change the date above and, for material changes, notify you by email.