Privacy Policy

Effective September 3, 2026. Last updated September 3, 2026.

This policy was written against what the software actually does, rather than assembled from a template. Every statement in it is verifiable against the running system, and where something is planned rather than built, it says so in the same sentence.


1. Who this covers

Clarity Space is an organization tool for students who need executive-function support. It reads a student's coursework from their school's learning management system and presents it in a form that is easier to act on. It is operated by Clarity Space LLC, registered 2026-08-29. Development and system administration are carried out by ScopeForged LLC under contract, which is why it appears in the subprocessor list.

This policy covers the application at app.getclarityspace.com and the marketing site at getclarityspace.com.

Accounts belong to a parent or guardian. A student may hold their own login inside a family account, created by their parent. Students do not create accounts independently.


2. What we collect

From your school's learning management system, when you connect it

Read-only. Nothing is ever written back.

• Class names, and the teacher name and email address the system attaches to a course
• Assignment titles, descriptions, due dates, and whether an assignment is missing
• Scores and course grades
• Announcements and course pages

From you
• A student's first name, and a profile photo if one is uploaded
• Grade level, if entered
• The student's own notes, and any files attached to them
• Account identity: name and email address for each login
• Accessibility and display preferences — dyslexia-friendly mode, reduced motion, theme

Automatically
• A self-hosted error log recording the account, the page, and the browser when something breaks
• An append-only audit log recording actions taken on an account

What we deliberately do not collect

No home address. No date of birth. No government identifier of any kind. No location or GPS. No disciplinary, behavioral, health, or attendance records. No biometric data. No advertising identifiers. No browsing activity outside the product.


3. What we never do with student data

These are commitments, and several are also Florida law under Statute 1006.1494:

• We do not sell student data. Not to anyone, under any circumstance.
• We do not use it for targeted advertising, and the product contains no advertising.
• We do not build profiles of students for any purpose other than the educational one the family is using the product for.
• We do not use student data to train artificial-intelligence models. There is no AI in the product at all — no model, no provider, no dependency.
• We do not share student data with the student's school or district unless a district has an agreement with us and the family knows about it.
• The product carries no analytics, advertising, or tracking code. No Google Analytics, no Meta Pixel, no session recording, nothing. Verified by scanning the application and the marketing site.


4. Who else touches the data

Three contracted providers, and each is a processor acting on our instructions:

Beneath those: Amazon Web Services underlies Supabase and the email delivery path, and Cloudflare fronts file storage as a content-delivery network, so files may be cached at edge locations worldwide.

Two flows we declare because they exist

Voice dictation sends audio to Google on Chrome. The dictation feature uses the browser's own speech recognition. On Chrome and Chromium browsers that means the recorded audio goes to Google's servers for transcription. We did not choose Google and we have no agreement with them for this — it is how the browser works. The feature sits behind a switch and can be turned off entirely. See the voice-dictation position document for the full detail.

Word lookups reach two dictionary services. The dictionary and thesaurus call api.dictionaryapi.devand api.datamuse.com from our servers, not from the student's browser, so no student IP address or identity is exposed — but the word being looked up does reach them.


5. Where the data lives

In the United States, in Supabase's us-east-1 region — Northern Virginia. Application code runs in the same region, and files may be cached at edge locations worldwide.

This was a Canadian region until September 3, 2026. We moved because some school districts require student records to remain on United States infrastructure, and we would rather answer that question with a plain yes. Everything moved: coursework, notes, attachments, profile photos, account identities and the encrypted integration credentials. The Canadian copies are kept briefly as a rollback and then permanently deleted; until that is done, a copy of the data still exists there.


6. How long we keep it, and how it gets deleted

A deletion request completes within 30 days. A district disenrollment notice completes within 90 days, which is the outer bound Florida law sets.

Deletion reaches four places, not one: the database rows, the stored files, the content-delivery cache in front of those files, and the authentication record. We learned the third one the hard way — a file kept being served from cache after it was removed at the source — so our procedure treats the cache as its own step and verifies the public address afterward rather than assuming.

The audit log is the exception, and we say so rather than let it surface later. It is append-only by design; an audit log whose entries can be deleted on request is not an audit log. On a deletion request we keep the entry and anonymize who it points at. What survives is that something happened. What is removed is who it happened to.


7. Your rights as a parent or guardian

You may, at any time:

• See everything we hold about your child — it is all visible in the product
• Correct it, directly in the product
• Export it — ask us and we produce the file. A self-service export is planned, not yet built
• Delete it, including the entire account
• Disconnect the learning-management connection, which deletes the stored credential immediately
• Withdraw consent, which is the same as deletion

To exercise any of these, use the product, or contact us at the address in section 10. We do not require a form, a reason, or a phone call.

Students under 13. We rely on parental consent, obtained from the parent who creates the account, rather than collecting consent from a child.


8. If a district is involved

Where a school district has an agreement with us, that agreement governs, and any conflict between it and this policy resolves in favor of the agreement. A district may notify us that a student has left, and we delete that student's records within 90 days and confirm in writing with the date.

Records that originate in the district's own system remain the district's education records. We are a processor of them, not an owner.


9. Security

• Every database table enforces row-level access control, so one family's records cannot be read by another. This is verified automatically on every change to the code, not asserted.
• A child cannot see a sibling's records, even inside the same family account.
• Learning-management credentials are encrypted with AES-256-GCM, and the key is never stored in the database.
• Files are private and served through short-lived signed links.
• Transport is encrypted, and the application sets a content security policy and related browser protections.

We will not claim to be unbreachable. If student data is exposed, we notify the district's named contact within 72 hours of confirming it, and affected families in the same window, with a written report following.


10. Contact

privacy@getclarityspace.com

Use it to ask about this policy, to see, correct, export or delete a student's records, or — if you are a district — to send a disenrollment notice. We do not require a form, a reason, or a phone call, and the timescales in section 6 apply from the day the request arrives.


11. Changes

If this policy changes in a way that materially affects how student data is handled, we will notify account holders before it takes effect, rather than changing the page and dating it.

Effective date: September 3, 2026.