Privacy Policy
Effective 15 August 2026 Β· SoftwareConvene LLC (Indiana, USA)
SoftwareConvene builds tools for schools β ClassConvene (for educators), TeamConvene (for coaches and clubs), and FundCatalyst (team finances). We designed the platform to protect the people who use it, especially students. This policy explains what information we handle, how we use it, and β just as important β what we never do.
Who we are
SoftwareConvene LLC ("SoftwareConvene," "we," "us") is a company based in Indiana, USA. This policy applies to the SoftwareConvene websites and applications, including ClassConvene, TeamConvene, and FundCatalyst (together, the "Service").
What information we collect
Account information (educators & staff)
When a teacher, coach, or administrator creates an account, we collect their email address, a display name, the school or district they're associated with, and their role. If sign-in is handled through a provider (such as Google), we receive basic profile details from that provider.
Content you create and upload
The Service stores the content you put into it β for example assessments and results, professional-development entries, budgets and receipts, rosters, lesson materials, images, and documents.
Student information
How much we collect about a student depends entirely on whether their district has signed a data privacy agreement with us β that is the single most important thing to understand about this policy, and it is set out in full under Student data & schools.
- Without a signed agreement (an individual teacher using the Service on their own authority): a first name and the work the student submits. No account, no email address, no lasting student profile.
- With a signed agreement: first and last name, grade level, school email address, the district's own student ID number, the classes they are in, and their work β so results follow the student through the year, and so a record here can be matched to the school's own.
Any student information in the Service is provided and controlled by the school or teacher, and our roster tools support pseudonyms or class identifiers instead of full real names wherever a feature allows it.
Usage & device information
To keep the Service secure and working, we log basic technical information such as sign-in events, pages or features used, approximate storage used, browser/device type, and IP address. We use this for security, troubleshooting, and understanding which features are useful β in aggregate, not to profile individuals.
How we use information
- To provide, maintain, and improve the Service and its features.
- To authenticate users and keep accounts and data secure.
- To respond to support requests and the feedback you send us.
- To understand, in aggregate, how the Service is used so we can make it better.
- To comply with law and enforce our Terms of Service.
What we never do
- We do not sell or rent your information to anyone.
- We do not show third-party advertising, and we do not build advertising profiles of students.
- We do not use your content, or student content, to train artificial-intelligence models. When AI features run, the providers we use operate under commercial terms that do not train on the data we send (see AI features).
- We do not share personal information with third parties except the service providers needed to run the Service (listed below), or when required by law.
Connected vendors. We may make certain third-party vendors available inside the Service (for example, apparel, parts, or printing suppliers) purely as an optional convenience for teachers and teams. This is not advertising, and you are never required to use them. If you choose to use a connected vendor, any information you share with that vendor is handled under that vendor's own terms and privacy practices, not ours.
Student data & schools
We take student privacy seriously and aim to align with FERPA, COPPA (the Children's Online Privacy Protection Act, 15 U.S.C. Β§ 6501β6505 and 16 CFR Part 312), the PPRA, and applicable state student-privacy laws.
Schools direct the use of student data. When a school or teacher uses the Service with students, the school controls that student information. We act as a service provider β a "school official" with a legitimate educational interest under FERPA β processing it on the school's behalf and only to provide the Service. We do not decide what is collected; the school does.
How the school's permission works
Under COPPA, a school may give consent on a parent's behalf when an online service is used for a school purpose and the information is not used for any commercial purpose. That permission must exist before anything is collected. How we obtain it depends on which of the two arrangements below applies, and the arrangement decides how much we are allowed to collect.
1. Teacher-authorized use (no signed agreement with the district)
An individual teacher or coach may set up the Service without their district signing an agreement with us. When they do, they confirm to us that they are employed by the school they name and are authorized by that school to use the Service with students and to give the school's permission under COPPA. Because that permission rests on one educator's confirmation rather than a signed district agreement, we deliberately collect far less:
- No student accounts. Students join an activity with a class code and a first name. They do not create logins, and we do not keep a student profile for them afterwards.
- No student email addresses, no last names required, no grade level, no student identifiers from a school information system.
- No lasting record tied to a named student. Work submitted this way is stored against the activity, not against a student identity that follows the student from class to class or year to year.
- This applies to students of any age, including students under 13 β the low amount of information we collect is precisely what makes it appropriate for younger students.
2. Agreement-backed use (the district has signed a data privacy agreement)
When a district or school signs a data privacy agreement with us, the school's permission is documented in writing before any student information is collected, and the fuller version of the Service becomes available to its teachers:
- Students may have their own accounts β first name, last name, grade level and school email address β so their work follows them across classes and through the year.
- A student account is only ever created after a class code has identified a class inside a district that has signed an agreement. The permission always exists first; the information is collected second. This ordering is enforced by the Service itself.
- Students of any age, including students under 13, may hold an account under a signed agreement. That is what the agreement is for: it is the school's documented, prior permission.
Whichever arrangement applies
- Data minimization. We collect only what a feature needs to work, and our roster tools support pseudonyms and class identifiers instead of full real names wherever that is workable.
- Ownership stays with the school. Student data belongs to the school and teacher. On request we will help export it, and we will delete it (see Keeping & deleting data).
- No student advertising and no AI training, as described above. We do not build profiles of students for any purpose other than showing their own teacher their own work.
- Parents may ask to see, correct or delete their child's information. Because the school controls the data, please contact the school first β we will act on the school's instruction promptly, and will help either of you directly if the school asks us to.
- Children's data security. We maintain a written security program covering student information specifically, in addition to the general measures under Security.
AI features
Some optional features use artificial intelligence β for example, reading a photo of a receipt to fill in its details, or helping summarize feedback. When you use one of these, the relevant content is sent to a trusted AI provider (currently Anthropic and Google) to generate a result, which you then review. These providers operate under commercial agreements that do not use the data to train their models. We send only what the feature needs and store only the result you choose to save.
A teacher can also connect an outside AI assistant of their own to their task list, which works the other way round β the assistant asks us. That is covered separately under Connecting an AI assistant to My Tasks.
Service providers we use
We rely on a small set of reputable providers to operate the Service. They process information only to provide their service to us:
- Google Cloud β hosting and infrastructure (United States).
- Supabase β database and authentication.
- Cloudflare β network security and delivery.
- Anthropic and Google (Vertex AI) β the AI features described above.
- Stripe β payment processing, if and when paid plans are offered (we do not store full card numbers ourselves).
Connecting other accounts (like Canva)
Some features let an educator or coach connect a personal account from another service β for example, Canva β so they can bring their own designs into the Service. Connecting an outside account is always optional and opt-in: you sign in and grant permission through that provider's own secure authorization screen, and you can decline or disconnect at any time.
When you connect Canva, we request the minimum access needed to let you browse and import your own designs β nothing more:
- We can see the list of your Canva designs and the details of the specific design you choose to import. We do not browse or pull anything you don't select.
- When you import a design, we export it and store the resulting image file in the Service just like any file you upload (for example, attached to a jersey request or design project).
- We store the access token from Canva encrypted, use it only to fetch the designs you ask for, and refresh it automatically so you don't have to reconnect constantly.
- We do not post to, edit, or delete anything in your Canva account, and we do not sell or share your Canva information.
Your use of Canva itself is governed by Canva's own terms and privacy policy. Connecting outside accounts is a feature for educators and coaches; students do not connect third-party accounts, and this feature does not involve student personal information.
Connecting an AI assistant to My Tasks
A teacher may connect an outside AI assistant β such as Claude, Microsoft Copilot, or Gemini β to the My Tasks list in ClassConvene, so they can say "add that to my task list" while working somewhere else. This is optional and off by default. Nothing is connected until a teacher connects it, and it can be disconnected at any time.
What a connected assistant can reach β and what it can never reach
A connected assistant can do exactly three things, and nothing else:
- Suggest a task, one at a time or several at once. A suggested task does not go on the teacher's list. It waits in a review area until the teacher personally accepts it.
- Read that teacher's own tasks β the title, notes, due date, priority and status of tasks belonging to the connected account only.
- Read the names of that teacher's classes, teams and events β names only, so a task can be filed against the right class.
A connected assistant can never see a student. Not a name, not an email address, not a student ID, not a score, an answer, a roster, attendance, or an IEP or 504 record. No class rosters, no counts, and no other teacher's information. This is not a setting a teacher or an administrator can widen β the connector reads through a fixed list of permitted fields written into the software itself, and an automated test blocks release if any student-bearing information can reach it by any route.
A connected assistant also cannot change, complete or delete anything. Every permission it holds is create-a-suggestion or read.
What this sends to the AI company
When a teacher asks a connected assistant to work with their tasks, the information listed above travels to that assistant's provider and is handled under that provider's own privacy policy, not this one β the same as anything else a teacher types into it. We therefore recommend connecting an assistant only for a teacher's own professional to-do list, which is what this feature is for. Because student information cannot pass through the connector at all, connecting one does not place student data with a third party.
We do not send anything to an assistant on our own initiative. Data moves only when the assistant asks for it on the teacher's behalf.
How the connection is authorized
- Connecting uses OAuth 2.1. The teacher signs in to ClassConvene directly and sees a screen listing exactly what is being allowed before approving. The assistant never receives or stores a ClassConvene password.
- The assistant receives a limited key that expires after one hour and is renewed automatically while the connection remains active. It is restricted to the two permissions above.
- We store only a one-way cryptographic hash of these keys, never the keys themselves. If our database were exposed, the keys in it could not be used.
- Disconnecting takes effect immediately β on the assistant's very next request β from the Connected apps panel on the My Tasks page. There is no waiting period, and no need to contact us.
- Requests are rate limited, and an unused connection's renewal key expires on its own after 60 days.
What we keep
Tasks a teacher accepts are ordinary ClassConvene content, kept and deleted on the schedule for educator content described below. A suggestion the teacher never acts on is automatically discarded after 30 days. We record which assistant is connected, its label, and when it was last used, so a teacher can recognise and revoke it. We do not keep a copy of the teacher's conversation with the assistant.
As everywhere else on the platform, we do not use any of this to train AI models, and we do not sell or share it.
Security
We protect information with several overlapping controls:
- Encryption. Data is encrypted in transit (HTTPS/TLS) β including the connection between our application and its database β and encrypted at rest.
- Per-account authorization. Every request for a record or file is checked against the specific account, team, or school it belongs to before access is granted, so each user can reach only the data they are authorized to see.
- Database-level lockdown. Row Level Security is enabled on our database as an additional safeguard, so the database itself refuses access to anything other than our authorized application.
- Private files. Uploaded documents β such as receipts, budgets, and forms β are stored privately. They are never publicly listed or served by a guessable link; they are delivered only through an authorized request that verifies your permission each time.
- Session & abuse protections. We use session protections, rate limiting, and security headers to help defend accounts.
No system is perfectly secure, but we layer these protections and work to respond quickly if something goes wrong.
Keeping & deleting data
We do not keep information indefinitely. Each kind of information has a defined life, and student information has the shortest.
Student information β 13 months
Student work and the records identifying the student who produced it are deleted 13 months after the work is submitted. Thirteen months covers a full school year plus a month of overlap, so a teacher can finish a year, close it out, and start the next one without losing anything they still need β and no longer.
- The clock runs from the date the work was submitted, not from when the account was last used, so an inactive account does not quietly extend it.
- A teacher or school may delete student information sooner, at any time, for any reason.
- If a school ends its agreement with us, student information is deleted on the schedule in that agreement, which is shorter than 13 months.
- Work submitted through teacher-authorized use carries no student identity to begin with, and the temporary session that allowed a student to submit it expires the same day.
Sign-in and account records β 13 months
We keep a record of sign-ins, sign-in attempts, and changes made to a student's account β for example when a coach or teacher created a login, reset a password, published a name to a public roster, or viewed a roster. These records exist so a school can answer a parent's question about what happened to their child's account, and so we can investigate a suspected break-in. They are deleted on the same 13-month schedule as student work, so this log cannot become the one place a deleted student still exists.
These records hold identifiers, dates and network information β not schoolwork, messages, survey answers or anything a student has written.
Aggregate figures β kept, but only where they cannot identify anyone
After student information is deleted, we may keep aggregate figures β for example the average score on a question, or how a group performed over time β so that teachers and schools keep access to year-over-year trends. These are counts and averages only. They contain no names, no email addresses and no identifiers, and they cannot be traced back to an individual.
To keep that true in practice, an aggregate is only retained when it covers 20 or more students. Figures drawn from fewer than 20 students are deleted along with the underlying work rather than kept, because a small enough group can identify the people in it. We do not attempt to re-identify aggregate data, and we do not permit anyone else to.
Educator accounts and school content
Assessments, lesson materials, professional-development records, budgets, rosters and similar content belonging to an educator or school are kept while the account is active, so that a teacher's own library survives from year to year. When an account is closed we delete its content within 90 days, except where we must keep specific records to comply with law β for example financial records we are required to retain for tax purposes.
Asking us directly
A school, teacher, parent or account holder may ask us to access, correct, export or delete information at any time by writing to [email protected]. We act on verified requests within 30 days. Where the information belongs to a school, we will confirm the request with the school before acting, because it is the school's data to direct.
Your choices & rights
You can view and update much of your information within the Service, and you can ask us to access, correct, export, or delete your data. Depending on where you live, you may have additional rights under laws such as FERPA or your state's privacy laws. Schools may exercise these rights on behalf of student data they control.
Cookies & local storage
We use only the storage needed to run the Service β for example, to keep you signed in and to remember preferences like dark mode. We do not use advertising or cross-site tracking cookies.
The Teacher Toolkit browser extension
The ClassConvene Teacher Toolkit is an optional Chrome/Edge extension for teachers. It is free, works without an account, and is not required to use anything on this site. It carries its own copies of these terms, which you can read inside it at any time.
What it stores, and where. Anything you put into it β class rosters (including student names, and any student number, email address or grade level you choose to include), parent and guardian contact details where your roster file contains them, and the documents you make such as seating charts, label runs, checklists and PDFs β is stored on your own computer, in that browser. It is not transmitted to us, and it is not on our servers.
What that means in practice. We cannot read it, export it, or recover it for you. If you uninstall the extension, reset your browser profile, or your device is re-imaged, it is deleted permanently and we hold no copy. The extension includes a Backup & restore feature so you can keep your own copy; that file is yours to look after.
What can leave your computer. By default the extension makes no network requests at all. Three things can send data, each only after you act:
- Roster sync β if you connect the extension to your account and your district has a signed data privacy agreement with us, you can send, for a class you choose, only: first name, last name, school email address and grade level. This is the same field list described under βStudent data & schoolsβ above. It never includes your documents, your notes, student numbers, or parent and guardian contacts β those remain on your device in every case.
- Feedback β the message you write, plus the extension version, browser version and which tool you were using. You see the exact contents before it is sent, and it is read by a person.
- An anonymous usage count β off unless you switch it on. At most once a week it sends a random installation identifier that you can reset, the extension version, and whether the installation is connected to an account. It contains no names, no student counts, and nothing about your documents.
The extension contains no artificial intelligence features. Nothing you load into it is analysed, and nothing is used to train any model.
The extension requests no access to any website and installs no code into pages you visit, so it cannot see your browsing.
Changes to this policy
If we make material changes, we'll update the date at the top and, where appropriate, notify account holders. Continued use of the Service after a change means you accept the updated policy.
Contact us
Questions, requests, or privacy concerns? Email [email protected], or use the π¬ feedback button inside the app.