Privacy
Privacy & Student Data
Last updated: September 28, 2026
Veridian helps educators plan lessons, organize instructional materials, reflect on teaching, and build useful classroom context over time. This policy explains what Veridian collects, how student information is handled, who processes it, how long it is kept, and how it is deleted. Where this policy makes a commitment, we intend it to be read as a commitment, not a description of intent.
Summary of Our Student Data Commitments
- • We do not sell student data, and we never will.
- • We do not use student data for advertising or to build advertising profiles.
- • We do not use student data to train, fine-tune, or otherwise develop AI models — ours or anyone else's.
- • Our AI providers are contractually prohibited from training their models on data submitted through Veridian. The providers that receive student context may not use it to improve their products either.
- • Student data belongs to the educator and, where applicable, the school. We process it only to provide Veridian to them.
- • Product improvement, analytics, and quality work are performed on de-identified or aggregated data, not on identifiable student information.
Who Veridian Is For
Veridian is intended for educators, tutors, homeschool parents, microschool guides, and other adults who create or manage learning materials. Veridian is not intended for direct use by children or students, and accounts may only be created by adults age 18 or older.
Educators are responsible for confirming they have the authority to enter classroom, student, curriculum, and instructional information into Veridian, including any consent or authorization required by their school, organization, or applicable law.
Information We Collect
Account and billing
- • Account information, such as name, email address, authentication details, access status, and account settings.
- • Billing and subscription information if you purchase a paid plan, including your plan, subscription status, and a record of purchases, usage credits, and invoices. Payment card details are handled by our payment processor and are not stored by Veridian.
- • Usage-metering information used to apply your monthly usage allowance, such as which account performed AI actions and the estimated cost of those actions.
- • If you take part in a referral or promotion, referral information such as your referral code, whether a code you shared was used, and records of any resulting discounts or account credit.
Classroom and student information
- • Classroom information provided by educators, such as class names, grade levels, subjects, and teaching context.
- • Student roster information entered or imported by educators — a name the teacher chooses to recognize each student (full legal names are not required; a first name, initials, or a nickname is enough), active status, and teacher-written learner context.
- • Instructional observations derived from teacher inputs, stored against an internal student identifier rather than a student name.
Instructional content
- • Teacher notes, class context, instructional reflections, materials feedback, and memory signals created from those inputs.
- • Chat messages, prompts, assistant responses, conversation history, edit requests, retry or cancel actions, and feedback submitted through Veridian.
- • Curriculum documents, standards, pacing guides, course outlines, and instructional materials uploaded or pasted into Veridian.
- • Text extracted from sources attached in chat, along with summaries, chunks, embeddings, file names, file types, file sizes, hashes, preparation status, and source-usage records. For these sources, Veridian extracts and stores the text and does not retain the original file.
- • Files you attach to finalized materials in your Library, such as PDF, Word, PowerPoint, and image files. These are stored as complete files in encrypted storage, along with their file name, type, and size, so you can download them later or include them in exports.
- • Materials, assessments, worksheets, rubrics, exports, and other instructional artifacts created or edited in Veridian.
Operational records
- • Usage, device, log, and diagnostic information needed to operate, secure, and troubleshoot the service.
- • Support, feedback, safety, billing, and diagnostic records, which may include account identifiers, workflow information, model usage, token usage, cost estimates, latency, errors, and source metadata.
- • Messages submitted through our public contact form, including the name, email address, and message you provide.
How We Use Information
We use information to provide Veridian to you, including to:
- • Create, edit, organize, retrieve, and export instructional materials.
- • Use teacher-provided context to support planning and classroom-aware recommendations.
- • Generate summaries, instructional observations, and memory signals that help future planning.
- • Maintain accounts, authentication, access control, security, billing, and support.
- • Send occasional emails to account holders about changes to the service, including new and updated features and the plans available. You can ask us to stop these at any time by emailing support@veridiangrove.ai.
- • Detect, investigate, and prevent abuse, security incidents, and service failures.
We separate providing the service from improving it. Work to improve Veridian's quality, performance, routing accuracy, and reliability is performed using de-identified or aggregated information, operational telemetry, and content that does not identify a student. We do not use identifiable student information for product development or model improvement.
How Student Information Is Used
Student information is used only to help educators organize classrooms, plan instruction, and review instructional context on behalf of the educator or school that entered it.
Veridian stores instructional observations against an internal student identifier rather than embedding student names in memory records or summaries. This limits how widely names appear across the system, but it does not make those records anonymous: because the roster links an identifier to a name, we treat memory records, summaries, and embeddings derived from student information as student data subject to every protection described in this policy.
Student profiles and memory signals support planning and reflection. They are not permanent labels, diagnoses, evaluations, or determinations about a student, and Veridian is not used to make grading, discipline, placement, eligibility, or disability determinations.
Continuity, Memory, Search, and Embeddings
To make Veridian useful over time, we create and store summaries, memory signals, hashes, vector embeddings, retrieval indexes, source excerpts, and other internal representations derived from content entered into Veridian. This may include teacher notes, chat messages, materials feedback, uploaded or pasted files, curriculum materials, classroom context, and student context.
These representations are used only to provide Veridian features such as classroom continuity, retrieval, source-aware chat, deduplication, memory, and service reliability. Where they are derived from student information, they are treated as student data: they are not sold, not used for advertising, not used to train AI models, and they are deleted when the underlying record is deleted.
AI Processing
Veridian uses AI to generate materials, summaries, recommendations, embeddings, and learning signals from educator-provided information. To do this, relevant prompts, files, materials content, student context, class context, and feedback are sent to our AI providers for processing and returned to Veridian.
Student context sent for processing may include a student's display name or name where that name appears in the classroom context an educator has entered. We use paid, commercial AI services under data processing agreements. Under those terms, our AI providers do not train their models on prompts or responses submitted through Veridian. The providers that receive student context also do not use them to improve their products, and keep them only briefly for safety and abuse monitoring. The provider we use only to route messages receives them with roster names removed; see Service Providers and Subprocessors.
AI output may be incomplete, inaccurate, or inappropriate for a particular learner. Educators are responsible for reviewing AI-generated content before using it with students, families, or colleagues.
Service Providers and Subprocessors
Veridian uses the following providers to operate the platform. Each processes information only as needed to provide its service to Veridian, under contractual confidentiality and data protection obligations.
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, and file storage for attachments | All account, classroom, roster, materials, memory data, and files attached to materials |
| Vercel | Application hosting and delivery | Request, log, and diagnostic data; data in transit |
| Google (Gemini API, paid tier) | AI generation, classification, and embeddings | Prompts and context sent for processing, which may include teacher-provided student context and student display names |
| Anthropic (Claude API, commercial) | AI generation of lesson materials | Prompts and context sent for processing, which may include teacher-provided student context and student display names |
| TypeSafe (Jev API) | Routing decisions: what kind of request a chat message is and where it applies | The chat message and recent conversation, with names on the class roster removed before sending. TypeSafe does not train its models on this data. It may keep and use technical usage data derived from requests, such as logs and statistics, to operate and improve its service |
| Resend | Transactional, notification, and product-update email delivery | Recipient email addresses and the content of transactional, notification, and product-update emails (such as account, sharing, support, and service-update messages). No student data |
| Stripe | Payment and subscription processing | Billing and payment information. No student data |
We will update this list before adding a new subprocessor that processes student data, and schools with a signed agreement will receive advance notice of changes as provided in that agreement.
Security
We use administrative, technical, and organizational safeguards designed to protect information in Veridian, including:
- • Encryption of data in transit using TLS, and encryption of stored data at rest by our database and hosting providers.
- • Row-level security policies enforced at the database layer, so that educators can access only the classrooms, rosters, and materials belonging to their own account.
- • Authentication through a dedicated authentication domain, with account access gated by an approval process.
- • Least-privilege handling of administrative credentials, with elevated database access restricted to server-side operations.
- • Files attached to materials are held in private storage, scoped to the account and classroom that uploaded them, and are retrieved only through an authenticated session. They are not published at public links.
- • Logging and monitoring of errors and service activity for security and reliability purposes.
No online service can guarantee perfect security. Users should protect their account credentials, use Veridian only on trusted devices, and avoid entering information that is not needed for instructional planning.
Incident Notification
If we determine that student information in Veridian has been subject to unauthorized access, disclosure, or acquisition, we will notify affected educators and, where applicable, the affected school or organization without unreasonable delay, and within any timeframe required by applicable law or a signed school agreement. We may delay notice where a law enforcement agency requests it, or for the time reasonably needed to investigate the incident and restore the integrity of the service.
Our notice will describe, to the extent known, what happened, what categories of information were involved, what we have done in response, and what steps affected parties should take. Where a school agreement specifies a shorter notification period or additional requirements, that agreement controls.
Data Retention & Deletion
We retain information for as long as an account is active and the information remains useful for the instructional purpose it was entered for.
- • Educators can delete individual students, classrooms, materials, curriculum, and other instructional data from within Veridian. Deleting a student removes that student's roster record along with the memory records, summaries, and embeddings associated with that student.
- • Files attached to materials can be deleted individually, which removes both the stored file and its record. Files are also removed when the materials, classroom, or account they belong to are deleted.
- • Marking a student inactive is a visibility control, not a deletion. Inactive students are excluded from future planning context but their records remain until deleted.
- • You can delete your entire account from within Veridian (Account → More options → Delete account), or by contacting us. Deleting your account cancels your subscription and permanently removes your classrooms, rosters, student records, materials, memory, files, connections, and other personal data. In-app deletions take effect right away; a deletion request sent to us is completed within thirty days of confirmation.
- • A material you shared directly with another educator, and the copy they received, are retained independently of your account. Deleting your account removes your own copy but does not remove the copy another educator received; you can contact us to request removal of a material you shared, though a copy an educator has already received remains with them.
- • Deleted information may persist in encrypted backups and security logs for up to thirty days before it is overwritten in the ordinary course of our backup rotation.
- • Where a school or organization has a signed agreement with Veridian, we will delete or return covered student data on that school's request and at the end of the agreement, as specified in that agreement.
We may retain limited billing and transaction records after deletion — such as payment history, invoices, usage-credit ledger entries, and usage-cost records — de-identified from you where possible, to meet accounting, tax, audit, and legal obligations, resolve disputes, prevent abuse, and enforce our terms. We may also retain limited security and legal records for the same reasons. These retained records do not include student rosters, student context, or student memory records.
Educators With and Without a School
Veridian is used both by educators working within a school or organization and by homeschool parents, independent tutors, and microschool guides working on their own. Who controls the data differs between the two, so the sections below apply differently depending on which describes you.
School-based educators. Where you enter information about students enrolled in a school, that information is generally an education record belonging to the school, and we handle it on the school's behalf and under its direction. Your school's own policies apply to what you enter, and your school may require a signed agreement with Veridian before you use it. Requests for access, correction, or deletion from parents or guardians run through the school.
Homeschool parents and independent educators. Where you are teaching your own children, or working independently with families who have engaged you directly, you control the information in your account. There is no school intermediary, no separate agreement is required, and you can view, edit, export, and delete everything you have entered at any time from within Veridian. Requests to delete your account and all of its data can be sent to us directly.
Access, Correction, and School Requests
Educators can view, edit, and delete the student information in their own classrooms directly within Veridian.
Homeschool parents and independent educators control their own data directly and do not need to go through anyone to reach it.
Where student records are education records held on behalf of a school, rights of access and correction run through that school. If a school receives a request from a parent, eligible student, or guardian relating to information stored in Veridian, we will support the school in locating, correcting, exporting, or deleting that information, and will respond to such a request within thirty days. Parents and guardians should direct requests to their school or the educator who entered the information.
Student Privacy and School Use
When Veridian is used in a school or educational organization, the school or educator is responsible for determining whether Veridian is appropriate for their setting and for obtaining any necessary permissions. Veridian is intended for school-authorized or educator-directed educational purposes, and not for advertising, commercial profiling, or any purpose unrelated to instruction.
Where Veridian handles student education records on behalf of a school, we act under the school's direction and control, use that information only for the purposes the school has authorized, and do not redisclose it except to the subprocessors listed above or as the school directs. We do not use that information for our own purposes.
If a school, district, or organization requires a separate data processing agreement, student data privacy agreement, or similar written agreement, that agreement must be completed before Veridian is used in that setting, and its terms control over this policy where they conflict.
What Student Context Is For
Veridian is built to use the classroom context an educator provides. Many educators record how a student learns best — the pacing, grouping, supports, and presentation choices that help — so that generated materials reflect it. Making instruction more accessible and better tailored to individual learners is the intended use of student context, not an edge case.
That information is protected accordingly. Teacher-written student context, and anything derived from it, is never sold, never used for advertising, never used to train or improve AI models, and is deleted along with the student record when a student is deleted. It is used only to generate materials for the educator who entered it.
Describe supports in your own words rather than uploading or pasting formal records. A sentence such as "benefits from written instructions alongside verbal ones" is more useful to Veridian than an uploaded evaluation report, and it keeps formal documentation — evaluations, medical records, disciplinary records, and disability determinations — in the systems built to hold them. Enter what helps you plan, and nothing beyond that.
Exports and Third-Party Copies
Veridian allows educators to export or download instructional materials, including lesson plans, assessments, rubrics, answer keys, scoring information, and any classroom context included in the material.
Once a user downloads, shares, or imports content into another service, such as a document editor, cloud drive, school system, or learning management system, that copy leaves Veridian's control and is governed by the user's institution and the third-party service's own terms and privacy practices.
Google Drive
Connecting Google Drive is optional. If you connect it, Veridian asks Google for the narrowest Drive permission available: access only to files you choose in Google's file picker and files Veridian creates for you. Veridian cannot see, search, or open anything else in your Drive.
We use this access only to do what you ask: save exported materials to your Drive as Google Docs and Google Slides, and, when you choose a Doc or Slides file, bring a copy of it into Veridian as a source for your chat. A copy you bring in is handled like any file you upload, including the AI processing described above.
To keep you connected, we store the email address of the Google account you connected, the folder you chose for exports, and an encrypted access credential issued by Google. We never see or store your Google password.
We don't sell Google user data, use it for advertising, or use it to train AI models. People at Veridian don't read it, except when you ask us to, when needed for security, or when the law requires it.
You can disconnect Google Drive at any time under Account → Connected apps. Disconnecting revokes Veridian's access and deletes the stored credential. You can also remove Veridian's access from your Google Account's security settings. Deleting your Veridian account disconnects Drive as well.
Veridian's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Sharing Between Educators
Veridian lets an educator share a material directly with another educator they choose. This happens only when the educator chooses it.
Before a material is shared, we de-identify it: using the class roster, we replace student names, the educator's name, and the class name with neutral placeholders, and we ask the educator to review the result. This de-identification also runs on our servers when a material is shared, so it does not depend on the educator's device. It is designed to assist the educator and is not guaranteed to remove every name — it works from the class roster and may not catch a name that is not on the roster or that appears in an attached file. The educator reviews each material before it is shared and decides what is shared. To make this possible, we store the roster information described in "Information We Collect"; we use it to redact materials before sharing and to operate classroom features, and we do not sell it or use identifiable student information to train AI models or for advertising.
When a material is shared, the educator it is shared with receives their own separate copy that they may view and adapt. Because that copy is independent of the original, it persists even after the original is edited or deleted; the sharing educator may contact us to request removal of a material they shared, but a copy an educator has already received remains with them.
If an educator deliberately keeps a real name in a material they share, that name is included in the shared material. The educator controls that choice during review.
Children Under 13
Veridian does not knowingly collect information directly from children. Student roster information is entered by adult educators on behalf of their classroom. Where a school authorizes an educator to enter information about students under 13, we process that information solely to provide the educational service the school has requested, and never for advertising, profiling, or any commercial purpose.
Changes to This Policy
We may update this Privacy Policy as Veridian develops, including as features, providers, or laws change. If we make material changes affecting how student information is handled, we will update the date above and provide notice within the app, such as a notice the next time you sign in, and notice to schools with a signed agreement, before the change takes effect.
Contact
Questions about Veridian, privacy, student data, account access, subprocessors, or deletion requests can be sent to support@veridiangrove.ai. Schools requesting a data processing agreement or student data privacy agreement can use the same address.