Privacy Policy
Effective August 23, 2026
1. Our roles
For academy account, website, support, and billing information, Vindica decides why and how information is processed and acts as controller or business. For student records and other personal information an academy, school, or tutor submits or generates in the Service (“Customer Data”), that organization controls the data and Vindica processes it only on its documented instructions under our Data Processing Agreement. Students and families should normally direct records requests to their academy.
2. Information we collect
- Account and organization: staff name, work email, role, academy name, settings, communications, and support requests.
- Billing: plan, seat count, transaction and billing-contact information. Stripe processes card details; Vindica does not store full card numbers.
- Student Customer Data: name or identifier, grade and cohort, school name where provided, login code, parent or guardian contact where provided, responses, scores, activity, assignments, teacher notes, and reports.
- Technical and security: IP address, browser and device details, timestamps, authentication events, error logs, product usage events such as pages viewed, clicks, and scroll activity (used to operate and improve the Service), and essential cookies or local storage.
VindicaOS does not require health, biometric, precise-location, government-ID, or payment-card information about students. Customers should not upload it.
3. How we use information
- Provide, personalize, secure, troubleshoot, and support the Service.
- Score assessments and produce academy-directed diagnoses, homework drafts, classroom views, and reports.
- Manage accounts, subscriptions, free-school eligibility, and service communications.
- Comply with law, enforce agreements, prevent abuse, and protect users and the Service.
- Improve reliability and features using aggregated or de-identified information that is not reasonably linkable to a person.
Vindica does not sell personal information, serve behavioral advertising, share information for cross-context behavioral advertising, or use identifiable student Customer Data to train general-purpose AI models.
4. AI-assisted features
When an academy uses an AI-assisted feature, Vindica may send the minimum relevant prompt and content to Google Gemini or Anthropic to produce the requested explanation, draft, or support response. These providers process that information for Vindica under contract. Academy staff should review generated output before relying on it or sending it to a family.
5. When we disclose information
We disclose information to service providers listed below; when a customer directs us to do so; in a business transaction subject to appropriate confidentiality; or when reasonably necessary to comply with law, prevent fraud or harm, or protect rights and security. We do not disclose student data for providers’ independent marketing.
| Provider | Service | Information involved |
|---|---|---|
| Supabase | Database, authentication, storage | Account and Customer Data |
| Netlify | Hosting, functions, content delivery | Technical, account, and Customer Data needed for requests |
| Google Gemini | AI-assisted features | Minimum content submitted to a requested feature |
| Anthropic | AI-assisted support or content features | Minimum content submitted to a requested feature |
| Resend | Transactional email | Recipient address and message content |
| Stripe | Subscription billing | Billing contact and transaction data; no student records |
6. Children and education records
VindicaOS is provided through educational organizations and is not marketed for children to sign up independently. When a school authorizes collection from a child under 13 for an educational purpose in circumstances permitted by COPPA, Vindica provides the required notice, uses the information only for that purpose, and does not condition participation on collecting more information than reasonably necessary. A parent may contact the school or Vindica to review or request deletion of the child’s information; Vindica will verify and coordinate the request with the controlling school as appropriate.
Where FERPA applies and its requirements are satisfied, Vindica acts as a contractor performing an institutional service under the school’s direct control, uses education records only for the authorized purpose, and does not redisclose them except as permitted by the DPA and law. The Service and DPA also provide contractual controls that may help customers meet obligations under GDPR, UK GDPR, Korea’s PIPA, and similar laws; applicability depends on the customer and use.
7. Security
Vindica uses administrative, technical, and organizational safeguards appropriate to the risk, including encryption in transit and at rest, tenant isolation, role-based access, restricted production access, logging, backups, and incident-response procedures. No system is perfectly secure. Customers must protect credentials and notify us promptly of suspected misuse. See the security overview and DPA for details.
8. Retention and deletion
We retain Customer Data while an account is active or as instructed by the customer. Following a valid request or termination, we delete Customer Data from active systems within 30 days unless law requires retention; encrypted backups are overwritten on provider cycles, normally within 90 days, and are not restored except for continuity or disaster recovery. Account, billing, security, and legal records are retained only as long as reasonably needed for the purpose collected, contractual claims, tax, fraud prevention, or law.
9. Choices and rights
Depending on location, individuals may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to complain to a regulator. Student-record requests should normally go to the academy controlling the record; Vindica will assist it. Account holders may request access, correction, export, or deletion by emailing kevinchoi@vindicaseneca.com. We may verify identity and authority before acting. Authorized agents must provide proof of authority.
10. Cookies and communications
VindicaOS uses cookies or similar storage needed for sign-in, preferences, security, and core operation. We do not use third-party advertising cookies on student-facing pages. Account holders can opt out of optional marketing emails using the message link, but will continue to receive necessary service and security notices.
11. International transfers
Vindica and its providers may process information in the United States and other countries where they operate. Where required, Vindica uses recognized safeguards, including the European Commission Standard Contractual Clauses and the UK transfer addendum, as described in the DPA.
12. Changes and contact
We will post revisions here and update the effective date. We will notify account holders before a material change that reduces privacy protections. Privacy or COPPA questions and requests may be sent to kevinchoi@vindicaseneca.com.