Privacy Policy — String Education

Last updated: March 1, 2025

1. Introduction

This Privacy Policy explains how String Education ("String," "we," "us," or "our") collects, uses, stores, and protects personal data when you use our AI-powered educational operating system and related services (collectively, the "Platform").

By accessing or using the Platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use the Platform.

Commitment to Student Privacy

String is built with student privacy at its core. We comply with applicable student data protection laws and never sell personal information of students or minors.

2. Data We Collect

We collect the following categories of data to deliver and improve our educational services:

2a. Account & Profile Data

  • Registration information: name, email address, role (teacher, student, parent, administrator), and school or institution affiliation.
  • Authentication data: encrypted passwords and, where applicable, single sign-on tokens.
  • Profile preferences: language, notification settings, and accessibility options.

2b. Educational & Usage Data

  • Curriculum content: lesson plans, assignments, grades, and assessments created or managed within the Platform.
  • Student performance data: quiz results, progress metrics, and learning analytics.
  • Interaction data: features used, pages visited, session duration, and actions taken within the Platform.

2c. Technical Data

  • Device information: browser type, operating system, screen resolution, and device identifiers.
  • Network data: IP address, approximate geolocation (country/region level), and referral URLs.
  • Cookies & similar technologies: we use strictly necessary and analytics cookies. See our Cookie Policy for details.

3. AI-Powered Features & Data

String uses artificial intelligence to personalise learning experiences, generate insights, and assist educators. When you interact with AI-powered features:

  • Input data (e.g., questions, prompts, uploaded materials) may be processed by our AI models to generate responses.
  • AI outputs are generated algorithmically and may not always be accurate — educators should review AI-generated content before relying on it.
  • We do not use student personal data to train general-purpose AI models. AI model improvements are performed only on aggregated, de-identified datasets.
  • AI-related data processing is subject to the same security and retention standards as all other personal data.

4. Data Sharing & Third Parties

We do not sell your personal data. We may share data only in the following circumstances:

  • Service providers: trusted third-party vendors who help us operate the Platform (hosting, analytics, email delivery) under strict data processing agreements.
  • School administrators: educational institutions may access data related to their students and staff as permitted by applicable law.
  • Legal obligations: when required by law, regulation, or valid legal process.
  • Business transfers: in connection with a merger, acquisition, or sale of assets, with prior notice to affected users.
  • With your consent: for any purpose you explicitly authorise.

5. Legal Compliance

5a. GDPR (European Economic Area)

  • We process personal data under lawful bases including consent, contractual necessity, legitimate interests, and legal obligations.
  • EEA users have rights to access, rectification, erasure, restriction, portability, and objection.
  • We maintain a Record of Processing Activities and have appointed a Data Protection Officer.
  • For cross-border transfers, we rely on Standard Contractual Clauses approved by the European Commission.

5b. CCPA (California) & FERPA (United States)

For California residents and U.S. educational institutions:

  • CCPA: California residents may request disclosure of data collected, request deletion, and opt out of any sale of personal information. String does not sell personal information.
  • FERPA: Where String acts as a "school official" under FERPA, we access education records solely for the purposes authorised by the educational institution. We do not use education records for targeted advertising.

6. Data Retention

  • Active accounts: personal data is retained for as long as your account remains active and as necessary to provide the services.
  • After account deletion: we delete or anonymise personal data within 90 days of an account deletion request, except where retention is required by law.
  • Backup systems: residual copies in encrypted backups are purged within 180 days.
  • Aggregated data: de-identified, aggregated data may be retained indefinitely for research and service improvement purposes.

7. Security Measures

We implement industry-standard technical and organisational measures to protect your data, including:

  • AES-256 encryption for data at rest and TLS 1.2+ for data in transit.
  • Regular penetration testing and vulnerability assessments.
  • Role-based access controls and multi-factor authentication for internal systems.
  • Continuous monitoring, intrusion detection, and incident response procedures.
  • Annual security audits and employee security awareness training.

No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: request correction of inaccurate or incomplete data.
  • Erasure: request deletion of your personal data ("right to be forgotten").
  • Restriction: request that we limit how we process your data.
  • Portability: receive your data in a structured, machine-readable format.
  • Objection: object to processing based on legitimate interests or direct marketing.
  • Withdraw consent: where processing is based on consent, you may withdraw it at any time.

9. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, please contact us:

String Education

Attn: Data Protection Officer

123 Education Lane, Suite 400, London, EC2A 1NT, United Kingdom

privacy@string.education