Privacy for schools
What we hold, and what we deliberately don’t.
This is a plain-English explainer for teachers and school decision-makers. It sits alongside our formal privacy policy and data-processing terms, not in place of them.
No individual student data
LingoChorus is a teacher’s tool. There are no student accounts, no student profiles and no gradebook. The class feedback that powers the re-teaching loop is recorded at the class and item level — “most got it / mixed / most missed” — never as a record about a named child. You don’t enter student names to use it.
What a teacher account holds
A teacher signs in by email (a magic link — no password to store). Saved packs — the brief, the generated lesson, and its images and audio — belong to that teacher. Accounts are isolated from one another at the database level: one teacher cannot read another teacher’s packs. Media is kept in private storage and served through short-lived signed links, not public URLs.
The processors behind generation
Generating a lesson sends the brief (age, level, topic, length) to a small set of specialist providers: a language model for the text, an image model for the flashcards, and — only when you request it — a music model for sung audio. Auth, the saved-pack database and media storage are handled by our hosting and database provider. These are standard sub-processors; the brief contains no student personal data.
Generation stays server-side
All generation runs on the server; API keys never reach the browser. Nothing about a lesson is exposed publicly unless a teacher deliberately publishes it.
For a formal review
Schools that need a data-processing agreement or a completed vendor questionnaire can request one. We’d rather answer your compliance questions directly than have you guess from a marketing page. Get in touch about data processing.
Related: AI safety & limits · methodology