No student data, by design
There is no student roster, no gradebook, no student accounts, and no student PII collected or stored on our servers. If you type class names to label a set of materials, those names stay local to your device — they are never sent to or stored by TeachersPlan. The cleanest way to protect student data is to never hold it, and that is the posture we chose.
The guarantees that matter to an administrator
Every claim below is literally true of the product we ship today.
Teacher-only — no student accounts
Only teachers create accounts. There are no student logins and no student-facing app. Because we collect no information from or about children, TeachersPlan carries no COPPA exposure — there is simply no child data to govern.
Encryption
Encrypted in transit (TLS) and at rest. Our database (Cloudflare D1) is encrypted at rest, and Google account tokens are additionally encrypted at the application layer with AES-GCM.
Never sold. Never used to train models.
We never sell your data and we never use it for advertising. Lesson generation runs on large-language-model APIs from our AI providers (currently Google's Gemini API, with Cloudflare Workers AI as a fallback); under the paid API terms we use, those providers do not train their models on our prompts or outputs. We do not sell your data or use your content to train any model we operate.
Data minimization
We store your email address, the materials you generate, and — only if you opt in — your school name and display name. That's it. No tracking across other sites, no advertising profiles.
Your data, your control
Teachers own their data and can take it or remove it at any time, with no email ticket required.
Export anytime
Download your account data whenever you want via your account's export endpoint (GET /api/account/export). Your materials are yours to keep.
Delete anytime
Delete your account and all associated data at any time from the Account drawer → Delete. No ticket and no waiting: you can remove your record entirely, on your own.
Student privacy — protected by collecting nothing
We approach student-privacy law the cleanest way possible: by not collecting student PII at all.
Subprocessors
A short, honest list — and Google Drive export only acts with your explicit consent.
| Provider | What it does | Notes |
|---|---|---|
| Cloudflare | Hosting, database (D1), and fallback AI generation (Workers AI). | Core infrastructure for the whole service. |
| Google (Gemini API) | AI lesson generation. | Receives the lesson request only (state, grade, subject, standard text, any topic you type) — never account data, roster data, or community content. Not used to train Google's models under the paid API terms. |
| Google (Drive export) | Optional export to Google Drive / Docs / Slides. | Only when you connect Google and choose to export. We request the drive.file scope — per-file access to files you create with TeachersPlan, not access to your whole Drive. |
| Resend | Transactional email — sign-in codes and materials you choose to email. | No marketing email; transactional only. |
Built on certified infrastructure
Talk to us — and tell us if you find something
Administrators evaluating TeachersPlan can request a Data Processing Agreement (DPA) and ask any security question at security@teachersplan.com.
Responsible disclosure: if you're a researcher and you find a vulnerability, email security@teachersplan.com. We welcome good-faith security research and will not pursue legal action against researchers who report responsibly.