Skip to content

Eluency Privacy Policy & Security

Clear data practices for teachers, students, and mobile users.

This policy explains what Eluency collects, why it is needed, which providers help operate the service, and the choices available to users. Last updated July 29, 2026.

Privacy summary

The commitments that guide the product.

Eluency is designed around teacher control, student-data minimization, and no advertising business model.

Teacher-controlled profiles

Students use a teacher-issued access code instead of creating a separate password or billing account.

No data selling

Personal information and learning activity are not sold or used to create advertising profiles.

Private teaching content

Lessons, tests, files, and results remain connected to the authorized teacher account.

Deletion controls

Teachers can delete content, student profiles, and their account through supported self-service flows.

Information collected

Only the information needed to operate the service.

Teacher and account data

Profile and authentication: name, email, authentication provider, account identifiers, role, plan, country, timezone, and teaching preferences.
Teaching content: lessons, tests, vocabulary, conjugation choices, objectives, timing, categories, images, documents, and audio selected by the teacher.
Operations: assignments, notifications, drafts, settings, support conversations, and email-delivery preferences.
Billing: Stripe customer and subscription references where web billing applies. Full card details remain with Stripe.

Student profile and learning data

Profile: a teacher-provided name, unique access code, and an optional contact email stored for the teacher’s reference.
Learning activity: assigned lessons and tests, progress, answers, scores, attempts, completion, mastery signals, follow-up activity, XP, streaks, and goals.
Notifications: an optional device push token when notifications are enabled.
Not requested from students: date of birth, phone number, precise location, profile photo, payment card, or Eluency password.

Website and diagnostic information

When the website or apps communicate with Eluency, hosting and security systems may process standard request information such as IP address, browser or device type, timestamps, requested routes, response status, and operational error details. This information is used to deliver, monitor, troubleshoot, and protect the service—not for advertising profiles.

Mobile applications

Permissions are requested in context and limited to a clear feature.

The Android, iPhone, and iPad apps use the same Eluency account and backend while applying mobile-specific safeguards.

Secure authentication storage

Mobile authentication sessions are stored with the device secure-storage facility rather than ordinary unencrypted application storage.

Contextual notifications

Notification permission is requested after sign-in with an explanation of assignment, announcement, and learning-update alerts. It can be declined or changed in device settings.

Files chosen by the user

Teachers may select lesson images, documents, and audio. Eluency processes only the item the teacher chooses for the requested upload.

Restricted device access

The current mobile configuration does not request precise location, contact lists, camera capture, microphone recording, or broad external-storage access.

Android application backup is disabled in the current production configuration. Downloaded or drafted content may remain locally on a device until it is removed through the app, the app is uninstalled, or the operating system clears application storage.

How information is used

Specific data for specific product functions.

Provide the service

Authenticate teachers, open student profiles, store content, deliver assignments, save progress, and show results.

Communicate

Send account, support, assignment, completion, summary, security, and service messages according to available preferences.

Personalize learning

Resume unfinished work, review mistakes, calculate learning signals, and present teacher-assigned follow-ups.

Protect Eluency

Prevent abuse, investigate errors, secure sessions, enforce permissions, and maintain service integrity.

Improve reliability

Use aggregate usage and operational information to understand performance and prioritize fixes.

Meet obligations

Respond to lawful requests, enforce terms, manage billing records, and protect users and Eluency.

AI boundaries

AI tools are invoked by teachers for curriculum work.

Eluency does not use student profiles or results to train advertising or recommendation models.

Teacher-controlled submission

When a teacher chooses an AI generation or extraction feature, the prompt, curriculum text, or selected file content needed for that request may be sent to Google Gemini.

What teachers should know

Eluency does not intentionally attach student names, profiles, scores, assignments, or practice results to teacher AI requests.

A teacher can still type information into a prompt. Teachers must avoid including identifiable student information, confidential records, or content they are not permitted to share.

AI output can be incorrect. Teachers remain responsible for reviewing generated educational content before assigning it.

Service providers

The limited providers used to operate Eluency.

VercelWebsite and application hosting, deployment, and aggregate website analytics. Standard web request and device information may be processed to provide and protect the service.
SupabaseDatabase, authentication, and file storage for teacher accounts, student profiles, lessons, tests, assignments, progress, and uploaded assets.
StripePayment processing and subscription management where web billing is enabled. Eluency does not store full payment-card numbers.
GoogleOptional Google sign-in and teacher-invoked Gemini tools for curriculum and content generation.
AppleOptional Sign in with Apple for supported iOS account flows.
ExpoMobile application services and push-notification delivery when notifications are enabled.
ResendAccount, support, completion, and teacher-summary email delivery.

Providers receive the information reasonably required to perform their service and are not authorized by Eluency to use it for third-party advertising.

Retention and deletion

Information is kept only while it supports the account, service, or a legitimate obligation.

Active application data

Teacher accounts, content, student profiles, assignments, and results are generally retained while the relevant account or profile remains active. Teachers can remove individual content and student profiles or request deletion of the teacher account.

After deletion

Deleted information is removed from active application systems. Limited records may remain temporarily in provider backups, security logs, email-delivery records, or records required for fraud prevention, billing, dispute resolution, or law, and are isolated or removed according to their normal retention cycle.

Notifications and local data

Push tokens are retained while a profile and notification relationship remain active and may be invalidated when stale. Local drafts and downloaded assets remain on the device until removed by the user, app, or operating system.

Support and email records

Support correspondence and delivery records are retained only as long as reasonably needed to answer requests, maintain suppression and preference choices, diagnose delivery, protect the service, and meet legal obligations.

Your choices

Access, correction, notifications, email preferences, and deletion.

Privacy rights vary by location. Eluency will review a verified request and respond according to applicable law.

Access or correct

Review and update available teacher settings, or contact Eluency to request access, correction, or an export of account information.

Control communications

Change teacher email preferences where available, use unsubscribe links for optional summaries, and manage push permission in device settings.

Delete

Delete student profiles you control, remove teaching content, or use the account-deletion workflow for the teacher account and associated application data.

Students and children

Teachers and institutions remain responsible for authority and consent.

Eluency does not ask students for a date of birth and therefore does not independently determine a student’s age.

A teacher, school, parent, or guardian must have the authority and any required consent before creating a student profile or assigning content. Do not add information that is unnecessary for the learning relationship.

Eluency is designed around data minimization and teacher control, but formal COPPA and FERPA reviews remain in progress. Eluency does not claim certification under those frameworks.

Security

Controls designed to protect accounts, content, and learning records.

Transport and storage

Application traffic uses HTTPS. Supabase provides managed database, authentication, and storage security controls, including encryption at rest.

Access controls

Teacher authentication, student session validation, server-side authorization, database policies, and scoped storage access restrict protected operations.

Incident response

Suspected incidents are investigated, access is contained where possible, providers are engaged as needed, and affected users or authorities are notified when required by applicable law.

No online service can guarantee absolute security. If you believe an account or student access code has been compromised, contact Eluency promptly.

Privacy questions

Clear answers about the current service.

Do students create Eluency passwords?
No. A teacher, school, parent, or guardian creates and controls the student profile. The student uses the profile’s access code to open assigned work and is not asked to create an Eluency password or billing account.
Is student data sent to an AI model?
Eluency does not intentionally send student profiles, names, scores, assignments, or results to an AI provider. Teacher-facing AI tools process the curriculum text, files, or prompts a teacher chooses to submit. Teachers should not include identifiable student information in AI prompts.
Does Eluency sell data or use advertising trackers?
No. Eluency does not sell personal information, use third-party advertising networks, or build advertising profiles. Aggregate website analytics and operational service data may be processed by the providers listed on this page.
Can I delete my teacher account?
Yes. Use the in-app account deletion option or visit eluency.com/delete-account. Active paid subscriptions must be handled before final account deletion.
Can a teacher delete a student profile?
Yes. Teachers can remove student profiles they control. Associated active application data is removed, subject to limited security, legal, and provider-backup retention described below.
Can schools use Eluency with students under 13?
Eluency minimizes student information and uses teacher-controlled profiles, but formal COPPA and FERPA reviews remain in progress. A school or teacher must confirm that it has the necessary authority and consent before adding a student.
How can I ask a privacy question or request my data?
Email nathan@eluency.com or use the Contact page. Include the email connected to your teacher account and describe whether you are requesting access, correction, export, restriction, or deletion.

Contact

Ask a privacy or security question.

Eluency is based in Toronto, Ontario, Canada. For a privacy request, security concern, or institutional review, contact Nathan at nathan@eluency.com or use the contact form.

Policy last updated: July 29, 2026

Teacher-controlled by design

Teach across web and mobile with a clear view of how information is handled.

Start with one student profile free, or contact Eluency for privacy, security, and institutional questions.