Privacy Policy
Last updated: June 18, 2026
Lorsey AI Corporation ("Lorsey", "we", "us"), a Delaware corporation, provides a learning orchestration platform for K-12 schools. This policy explains what information we collect, how we use it, and the choices available to schools, educators, students, and families. It also describes the commitments we make when handling student information.
If a school district or school has a signed services agreement or data privacy agreement (DPA) with us, that agreement governs our handling of student data and controls over this policy to the extent of any conflict. We are glad to sign a district's DPA, including the Student Data Privacy Consortium National Data Privacy Agreement. To request our DPA, email [email protected].
Our commitments on student data
We align our handling of student personal information with widely adopted student-privacy principles:
- We do not sell student personal information.
- We do not use student personal information to serve targeted advertising, and we do not build advertising profiles of students.
- We use student personal information only to provide and improve the educational service the school has asked us to deliver, and for no other commercial purpose.
- We do not use student personal information to train third-party foundation models or our own models, and the AI provider we use processes that information under terms that do not permit using it to train their models.
- Student records belong to the school. We act on the school's behalf and under its direction, and we return or delete student data on request or when our agreement ends.
How our service is structured
Lorsey is provided to schools. The school (or district) decides which students are enrolled, which connected platforms to link, and who on staff has access.
- For student educational records, the school is the party that controls the data. Lorsey processes that data as a service provider acting on the school's behalf, consistent with the "school official" role under the Family Educational Rights and Privacy Act (FERPA).
- Students and parents reach Lorsey through links the school's staff share. Where a student enters information directly (for example, in the chat companion), we collect it on the school's behalf, for the school's educational purpose, and for no other commercial purpose.
Information we collect
Student information from connected platforms. When a school links a platform it already uses, we ingest per-student data from that platform to power the orchestration features. Depending on the platform this includes:
- Roster information: name, grade level, and class or section enrollment.
- Engagement and usage: activity, time on task, login recency, sessions.
- Mastery and performance: skill-level results, assessment scores, and progress against curriculum standards.
- Aptitude and growth data: norm-referenced scores and percentiles (for example, RIT scores and instructional-area sub-scores from NWEA MAP).
Connected platforms currently include IXL, Savvas Realize, and NWEA MAP. These are independent services operated by other companies; their own privacy policies govern your direct use of them.
Student activity inside Lorsey. When a student uses the Lorsey chat companion, we store the conversation so the student and their teacher can return to it. Teachers and parents may add notes about a student (for example, a learning preference or a context note), which we store as part of that student's profile.
Account information for staff. For teachers and administrators we store name, email address, a securely hashed password, and the organization the account belongs to.
Family contact information. A teacher or school may add a parent or guardian's email address and phone number so the school can share progress and send messages through Lorsey.
Access links. Student and parent pages are reached through a secret link (a token in the URL) that the school's staff share. The token is the access credential for that page.
Website visitors. When you visit our public marketing site
(lorsey.ai):
- If you submit the contact form, we collect the name, email, and message you provide, and use an anti-abuse check (Cloudflare Turnstile) to filter spam.
- We use analytics (Google Analytics via Google Tag Manager) and standard
server logs (such as IP address, browser type, and pages viewed) to
understand and improve the site. Our product surface (
/app/*) is not indexed and is excluded from public analytics of this kind.
How we use information
- To provide the service: unify each student's data into one view, surface what needs attention, generate guidance, and power the student chat companion.
- To generate plain-language summaries and message drafts for teachers and families using AI (see below).
- To authenticate staff and secure access.
- To communicate with the school, respond to support requests, and send service or transactional messages.
- To maintain, secure, debug, and improve the platform.
- To comply with legal obligations.
We do not use student personal information for any purpose beyond providing and improving the educational service to the school, except as required by law or expressly authorized by the school. Any use of student personal information to improve the platform is limited to improving the service we provide to that school. We do not use one school's student data to build products or features for other customers, and we do not use student personal information for any commercial purpose.
Artificial intelligence processing
Some features use a third-party AI provider (OpenAI) to turn a student's data into useful output: short narratives for teachers, draft messages for families, small-group materials, and the student chat companion.
- Relevant profile and activity data is sent to the AI provider only to generate that output for the school.
- The AI provider processes this data under terms that do not permit using it to train their models.
- We do not use student personal information to train our own or any third party's AI models.
- AI-generated output is assistive and may contain errors. It is intended to support educator judgment, not to replace it. The service does not make consequential decisions about a student without educator review.
- As a safety measure, messages a student sends in the chat companion are automatically screened for signs of self-harm or threats of violence. When the screen detects such a signal, it is surfaced to the student's teacher so a person can follow up. This is a duty-of-care safeguard, not a diagnosis, and a teacher always reviews it.
De-identified data
We may use de-identified data, with all direct and indirect identifiers removed so that a person cannot reasonably be re-identified, to develop, secure, and improve the service and for research about learning. We do not attempt to re-identify de-identified data, and we do not share it with any party unless that party agrees not to attempt re-identification.
Service providers and subprocessors
We share information with vendors who process it on our behalf, under contracts that limit their use to providing services to us. Each subprocessor that processes student data is bound by contract to the same use limitations and redisclosure prohibition that apply to us, may use student data only to provide services to us for the school's educational purpose, and may not sell it. They are service providers, not third parties with independent rights in the data.
| Provider | Purpose |
|---|---|
| DigitalOcean | Application hosting and database |
| OpenAI | AI generation (narratives, drafts, chat) |
| Postmark | Transactional and notification email |
| Sentry | Error monitoring (production) |
| Cloudflare | Anti-abuse check on the public contact form |
| Google Analytics | Marketing-site analytics only |
We do not disclose student personal information to any third party except to the service providers listed above, who process it on our behalf under contract, and as the school directs or the law requires. We will give the schools we work with advance notice of a material change to the subprocessors that handle student data, so a school can object before the change takes effect, consistent with our agreement with that school.
How we disclose information
We do not sell personal information. We disclose information only:
- to the service providers listed above, under contract;
- to the school that owns the student records, and to people the school authorizes;
- when required by law, legal process, or to protect rights, safety, and the security of the service; and
- in connection with a business transfer, subject to the commitments in this policy and our school agreements.
Data retention and deletion
We maintain a written data retention policy for the personal information we hold, including personal information collected from students.
- Student data. We collect student personal information only to provide the school's educational service, we retain it only as long as there is a business need for that educational purpose and for the duration of our agreement with the school, and we do not retain it indefinitely. We return or delete it at the school's direction or when our agreement ends, typically within 30 days, subject to any legal retention requirements. When we delete student data we destroy it using industry-standard methods across our systems and instruct our subprocessors to do the same, and we will provide written certification of destruction on the school's request.
- Non-student data. We keep contact-form submissions and related correspondence for up to 24 months; server logs and analytics data for up to 14 months; and staff account information and family contact information for as long as the related school account is active, and then for a limited period as needed for security, backup, and legal purposes.
A school may request access to, correction of, or deletion of student data it controls by contacting us, and we will respond within a reasonable period.
Security
We maintain a written information security program with safeguards appropriate to the sensitivity of the information we hold, including student information. As part of that program we designate personnel to coordinate it, assess internal and external risks at least annually, implement and test safeguards to control those risks, and review and update the program at least annually. We require our service providers to maintain appropriate security and to commit to it in writing.
The safeguards we use include encryption in transit and at rest, hashed account passwords, access controls scoped per organization, and append-only records for sensitive data. No method of transmission or storage is perfectly secure, but we work to protect information consistent with its sensitivity.
If we confirm a security incident affecting student or other personal information, we will notify the affected school without undue delay and in any event within 72 hours of confirmation, describe the nature and scope of the incident and the data involved, cooperate with the school's investigation and response, and provide the school a report it can use to meet its own notification obligations. Where the incident was caused by Lorsey, we bear the reasonable costs of legally required notifications.
Children's privacy (COPPA)
The platform is intended for use by schools, not for direct sign-up by children. Students do not create their own accounts; they reach the chat companion through a link the school shares.
Our chat companion is used by students, who may be under 13, under the school's authorization. Consistent with guidance from the Federal Trade Commission that allows schools to provide consent on parents' behalf in the educational context, the school provides any required consent for the school-authorized educational use of the service. We use students' personal information only for that educational purpose and for no commercial purpose.
We are responsible for our own compliance with the Children's Online Privacy Protection Act (COPPA) as the operator of the service. We provide the school with notice of our data practices and, on the school's request, a description of the personal information we collect from students, an opportunity to review or delete a student's information, and the ability to stop further collection or use of a student's information.
FERPA
We handle student education records consistent with the FERPA "school official" exception (34 CFR 99.31(a)(1)): we perform an institutional service the school would otherwise perform, we are under the school's direct control as to the use and maintenance of education records, and we use those records only for the authorized educational purpose. We receive and process student education records under that exception, not as directory information, and we do not treat student data as directory information or use it without restriction.
We do not redisclose student education records to any other party except as the school directs and FERPA permits, and we bind our subprocessors to the same use limitations and redisclosure prohibition. We will not make a material change to how we collect, use, share, retain, or secure student data without advance notice to the school and, where a signed agreement or DPA so requires, the school's consent.
Protection of Pupil Rights Amendment (PPRA)
We do not collect student personal information for marketing or to sell it. The student chat companion is not used to administer surveys and is designed not to solicit information in the categories the PPRA protects. Where a school must provide PPRA notices or opt-outs, the school administers them, and we support the school's policy.
State student-privacy laws
For schools in states with student-privacy statutes (for example, California's Student Online Personal Information Protection Act, SOPIPA, and similar "operator" laws in Iowa, Nevada, and other states), we commit not to sell student information, not to use it for targeted advertising, not to build non-educational profiles, to use student information only for the educational purpose, to maintain reasonable security, and to delete student information at the school's request. State-specific terms are addressed in the DPA we sign with each district, including any state supplement that applies. Student education records remain the property of, and under the control of, the school district.
Rights of parents and eligible students
Because the school controls student education records, parents and eligible students should direct requests to inspect, review, correct, or delete those records to the school. We support the school by providing the student data we hold promptly, in time for the school to meet its legal deadline (generally 45 days under FERPA), and by making corrections the school directs.
Where we operate
Lorsey is operated in the United States and intended for use by US schools. If you access the service from outside the United States, you do so on your own initiative.
Cookies and tracking
On our public marketing site we use cookies and similar technologies:
Google Tag Manager and Google Analytics to measure site usage, and
Cloudflare Turnstile to protect the contact form from abuse. You can
control cookies through your browser settings. Our product surface
(/app/*) does not run these marketing analytics. We do not use Google
Analytics to share personal information for cross-context behavioral
advertising.
Your privacy choices and California residents
We do not sell or share personal information for cross-context behavioral advertising. If our configuration ever changed, we would provide a "Do Not Sell or Share My Personal Information" choice and honor recognized opt-out browser signals.
Student personal information we handle for schools is processed in our role as a service provider for the school, so requests about that information are directed to the school, and FERPA and our DPA govern it.
For other personal information we handle directly, that is, information about website visitors, school staff, and family contacts, residents of California and of other states with comprehensive privacy laws may have rights to know what personal information we collect, to access or delete it, to correct it, to opt out of any sale or sharing (we do none), and to limit the use of sensitive personal information (we do not use sensitive personal information for purposes that trigger this right). We will not discriminate against you for exercising these rights.
For the personal information we handle directly:
- Categories we collect: identifiers (name, email, phone), internet activity (server logs, analytics), and the content you send us (for example, a contact-form message or a note added to the product).
- Sources: you, the school that provides staff and family contacts, and your device or browser.
- Purposes: to provide and secure the service, respond to inquiries, communicate with the school, and operate and improve our marketing site.
- Third parties we share with for these business purposes: the service providers listed above.
- Sold or shared for advertising: none.
To make a request, email [email protected]. We will verify your request using the information we already hold (such as your account email) and respond within the period the applicable law requires.
Lorsey is currently below the size thresholds that make these comprehensive consumer-privacy laws legally binding on us, and we honor these rights as a matter of practice. This section applies in full if and when Lorsey becomes a covered business under those laws.
Accessibility
We are committed to making the service usable by people with disabilities and to conforming to the Web Content Accessibility Guidelines (WCAG) 2.1 Level AA. On request, we will provide a current accessibility conformance report (VPAT). To report an accessibility issue, email [email protected].
Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, notify the schools we work with. We will not begin using student data in a materially different way without first giving the affected school notice and a choice, consistent with our agreement with that school.
Contact us
Questions about this policy or our data practices:
- Email: [email protected]
- Lorsey AI Corporation, a Delaware corporation
- 305 E Huntland Dr, 5th Floor #3047, Austin, TX 78752
See also our Terms of Service.