Who We Are
Welcome to RevolutionEd, operated by iCode Technologies LLC. Our platform empowers educators with advanced AI-driven tools to create custom lesson plans, quizzes, and educational experiences for K-12 students. This privacy policy describes how we collect, use, and protect personal information on our admin.revolutioned.ai portal, which serves educators and school administrators.
What Personal Data We Collect and Why
Account and Profile Information
Name, email address, school affiliation, and role are collected during registration. This information is used to create educator accounts, manage classes, and provide access to educational features.
Student Data (Provided by Teachers)
- First and last names of students
- Quiz responses and educational activity
- Interests submitted by students
- AI chat interactions (moderated and accessible to teachers only)
- Voice/audio recordings created when a student reads aloud during pronunciation practice (the read-aloud "Listen and Learn" module only plays audio and records nothing)
- Photographs or images uploaded as part of an activity or profile
Student accounts are never created directly; access is granted through teacher-generated QR codes or links.
Cookies
- Session Cookies: Enable secure login and save user preferences.
- Analytics Cookies: Collected through Google Analytics to help us understand user interactions. (Google Signals and user-provided data collection are disabled.)
Users can revoke cookie consent via their account profile settings.
Media Uploads
Educators may upload media (e.g., images, documents). We advise users to avoid uploading media with embedded location metadata (EXIF GPS).
Embedded Content
Our platform may feature embedded content from trusted providers (e.g., YouTube, Vimeo). Such content behaves as if visited on the host site, which may collect personal data or use cookies in line with their respective privacy policies.
How We Use Your Information
- To personalize lesson plans and student experiences
- To facilitate collaboration between teachers and students
- To analyze learning outcomes and improve platform features
- To enable secure storage of content in connected Google Drive accounts (for educators)
Legal bases (EU/UK GDPR). Where the EU or UK GDPR applies, we rely on these lawful bases: performance of our contract with your school or with you (Art. 6(1)(b)); compliance with our legal obligations (Art. 6(1)(c)); your consent where required, such as for non-essential cookies (Art. 6(1)(a)); and our legitimate interests in providing, securing, and improving the Service (Art. 6(1)(f)). Student personal data is processed on behalf of and under the authority of the school. We use AI tools to assist educators; we do not make decisions producing legal or similarly significant effects about students solely by automated means — an educator remains responsible for educational decisions.
AI & algorithm transparency. For a plain-language explanation of every place we use AI or an automatic decision — what each does, the information it uses, the human oversight, and your override/opt-out choices — see our AI & Algorithm Transparency disclosure (Texas SCOPE Act, Tex. Bus. & Com. Code ch. 509 — advertising & algorithm disclosure, § 509.055).
Children's Privacy (COPPA) and the School Consent Exception
RevolutionEd is designed for K-12 schools and is made available to students at the direction of their school or district. Where a student is under 13, we rely on the school to provide consent on behalf of parents under the COPPA "Schools Exception" — personal information is collected solely for the use and benefit of the school and for no other commercial purpose. Consistent with that exception:
- We collect personal information from students only to provide the educational service the school has authorized.
- We do not use student personal information for advertising, sell or rent it, or build profiles for any non-educational purpose.
- We do not condition a student's participation on disclosing more personal information than is reasonably necessary for the activity.
The school owns the data. Student data is and remains the property of, and under the control of, the school or district (and, as applicable, the parent or eligible student). RevolutionEd acts only as the school's data processor and obtains no ownership right, license, or interest in student data beyond the limited right to process it to deliver the service the school has authorized. When a school leaves or asks us to delete its data, we return the data to the school before destroying it.
Parental rights. Because the school provides consent as the parent's agent, a parent who wishes to review the personal information collected from their child, direct its correction or deletion, or refuse to permit further collection or use should contact their child's school, which will instruct us as the data processor; we act only on the school's verified instruction. Parents may also submit a request directly through our Parent Privacy Request form (review, refuse further collection, or request deletion), or contact us using the details below; we will route the request to the controlling school/district and track it on our response timeline.
FERPA annual notice. Under FERPA (34 CFR § 99.7), your school or district — not RevolutionEd — is responsible for the annual notification of FERPA rights to parents and eligible students, including the rights to inspect and review education records, to request the amendment of inaccurate records, to consent to certain disclosures, and to file a complaint with the U.S. Department of Education. As the school's data processor, RevolutionEd supports and does not displace or replace that notice; we refer you to your school or district's annual FERPA notification for a full description of these rights and how to exercise them, and we honor requests routed to us by the school.
New York students. For students in New York State, our Parents' Bill of Rights for Data Privacy and Security (issued under New York Education Law § 2-d) is available on our Parents' Bill of Rights page, from your school, or on request.
Languages / accessibility of this notice. Under FERPA, NY Education Law § 2-d / 8 NYCRR Part 121, and NYC Chancellor's Regulation A-820, your school or district is responsible for providing notices to parents and guardians in a language and format they can access (including translation for families with limited English proficiency). As the school's data processor, RevolutionEd supports that obligation: on a school's or family's request we will provide the source text of this notice and the Parents' Bill of Rights for translation, and we will furnish the documents in an accessible format. Contact us using the details below.
Our Core Privacy Commitments
RevolutionEd is built for K-12 schools, and we hold ourselves to the privacy commitments that student-privacy reviewers (including the Common Sense Privacy Program) treat as the minimum bar for a trustworthy education product. We make each of the following commitments without exception for students, teachers, and account holders:
- We do not sell personal information. We do not sell or rent personal information to any third party for monetary or other valuable consideration.
- We do not use personal information for third-party marketing. We do not disclose personal information to third parties for their own marketing, and we do not send our users third-party marketing communications.
- We do not use personal information for targeted advertising. We do not use personal information to deliver targeted, behavioral, or interest-based advertising, and we serve no third-party advertising in the Service.
- We do not allow third-party tracking. We do not permit third parties to collect personal information through the Service to track users for their own purposes.
- We do not track users across other apps or websites. We do not engage in cross-app or cross-site tracking of users over time across services we do not operate.
- We do not build commercial profiles. We do not create or use profiles of students for any advertising, marketing, or other non-educational commercial purpose.
These commitments apply to all personal information, and student personal information is additionally used only to provide the educational service authorized by the student's school or district. They restate, in one place, commitments that also appear throughout this policy and that are contractually binding on us under our agreements with educational agencies.
Data Sharing and Sub-Processors
We do not sell or rent personal information to third parties. We use the following sub-processors for infrastructure, AI generation, identity, payments, communications, curriculum and reference data, document viewing, browser-side telemetry, and browser-side asset delivery. All sub-processors operate from facilities located in the United States. RevolutionEd has a written agreement with each that binds them to data protection standards no less protective than those in our agreements with educational agencies.
1. Infrastructure & Hosting (server-side)
- Google Cloud Platform (Alphabet Inc.) – Application hosting (Cloud Run),
database (Cloud SQL for MySQL), object storage (Cloud Storage), container registry (Artifact
Registry), identity management (Cloud IAM), secret storage (Secret Manager), edge protection
(Cloud Armor + Cloud CDN), DNS (Cloud DNS), audit logging (Cloud Logging). Continuously
attested under SOC 2 Type II, ISO/IEC 27001, ISO/IEC 27017, and ISO/IEC 27018. Data Processing
Addendum executed. All data resides in the
us-central1region (United States).
2. AI Generation (server-side)
- Google Gemini API – Primary AI generation: lesson plans, quizzes, narratives, presentations, images, text-to-speech, and lesson individualization. For most generation we send only the lesson topic, grade level, and prompt text. For the optional lesson-individualization features, a teacher may additionally send a student's name, grade and reading level, interests, and teacher-authored IEP/accommodation notes so the output can be tailored to that student — this is processor use to deliver the educational service under the FERPA school-official exception and NY Education Law § 2-d, never a sale and never used for advertising. Prompts are not used for model training (per Google Cloud API terms). See the authoritative sub-processor list (Exhibit A) for exactly what each processor receives.
- OpenAI – Content moderation (for student-submitted text) and supplementary AI generation. Zero data retention and no training (per OpenAI API terms).
- Microsoft Azure Cognitive Services — Speech – Pronunciation assessment and speech-to-text fallback. We send short audio clips (typically ≤30 seconds); audio is not retained per Azure terms.
3. Identity & Single Sign-On (server-side)
- Google OAuth 2.0 / OpenID Connect – Teacher and administrator login via Google account.
- Clever, Inc. – Single Sign-On and roster sync for districts that use Clever. Receives student/teacher ID, email, name, and section.
- ClassLink, Inc. – Single Sign-On (launchpad.classlink.com) and OneRoster roster sync (nodeapi.classlink.com, oneroster-proxy.apis.classlink.com) for districts that use ClassLink. Receives student/teacher ID, email, name, grade, section, and enrollment.
- Have I Been Pwned (Pwned Passwords range API, api.pwnedpasswords.com) – Breached-password screening when a user sets or resets a password, so known-compromised passwords are rejected. Only the first five characters of the password's SHA-1 hash are sent (k-anonymity) — the password, the full hash, and all personal data never leave our server, so no PII is transmitted. If the service is unreachable the password change still proceeds (fail-open), so it is not a dependency of the login path.
4. Roster & Document Integration (server-side)
- Google Classroom API – Optional teacher-initiated roster import for teachers who use Google Classroom. Receives teacher email, course roster, and student IDs/emails/names.
- Google Drive / Docs / Slides APIs – Optional teacher-initiated export of
generated documents to the teacher's own Drive (
drive.filescope only).
5. Administrative & Communications (server-side)
- Stripe, Inc. – Retained only for administrative customer-record deletion:
during account/data disposal an administrator invokes Stripe's
Customer.deleteAPI on a legacy customer identifier. There is no payment surface — no self-serve checkout, no subscription billing, no Stripe Elements or card capture, and no Stripe inbound webhook (all removed 2026-06-30). District/enterprise licensing is billed off-platform by negotiated contract/invoice, not through Stripe. No cardholder data is stored or processed. - SendGrid (Twilio, Inc.) – Transactional email (account confirmations, password
resets, notifications) and event webhook. Receives recipient email, name, and message body.
Sender domain:
registration@revolutioned.ai.
6. Curriculum & Reference Data (server-side)
- JASON Learning – Curriculum resource lookup. Search query strings only; no PII.
- Texas Instruments – TI educational activity resource lookup and file downloads. Search queries; no PII.
- Library of Congress (www.loc.gov) – Primary source search for the Deep Dive History feature. No PII sent.
- Unsplash – Stock imagery for presentations. Search query strings only.
- Serper.dev – Web image-search proxy for presentation imagery. Search query strings only.
- YouTube (Google) – Video URL embedding (iframes loaded by the user's browser). Video URLs only; no PII.
- randomuser.me – Synthetic character profile generation for the Make It Stick chat feature. No outbound data — synthetic profiles are fetched.
7. Document Viewing (server-side URL handoff)
- Microsoft Office Online viewer (view.officeapps.live.com) – PPTX preview rendering. The user's browser passes signed Cloud Storage URLs to Microsoft's servers, which fetch the curriculum content to render slides server-side. No student PII is included in these URLs.
8. Browser-side Analytics & Tracking
- Google Analytics 4 – Anonymized analytics loaded directly via Google's
gtag.js(no tag manager). Google Signals is disabled, ad personalization is disabled, and IP anonymization is enabled. Loaded only after analytics consent on public pages; never on student pages or authenticated pages. - CallRail – Phone-number-swap script (
swap.js) for call attribution on public marketing pages only.
9. Browser-side Asset CDNs
The following content delivery networks deliver fonts, icons, and JavaScript libraries to the user's browser. RevolutionEd does not transmit any PII or education records to these networks.
- Google Fonts (
fonts.googleapis.com,fonts.gstatic.com) – Web fonts. - jsDelivr CDN – JavaScript libraries (Bootstrap, KaTeX, DOMPurify, Tom Select, Chart.js, marked, Three.js).
- Cloudflare cdnjs – JavaScript libraries (Font Awesome, html2canvas, jsPDF, Spectrum color picker).
- MathJax CDN – LaTeX math rendering.
- Plotly CDN – Chart rendering on administrative dashboards only.
- Brandfolder embed – Bluebonnet curriculum preview embed (public embed key).
- Imgur – Static logo asset embedded in generated PDFs and emails. No user data flows to Imgur (logo fetch only). Migration to a self-hosted asset is planned.
Authoritative sub-processor list. The complete, current sub-processor list is published at /sub-processors (generated from the canonical Exhibit A, which is incorporated by reference into any Data Privacy Agreement executed between RevolutionEd and an educational agency). Before a new or replacement sub-processor begins processing student data, RevolutionEd gives the educational agency at least thirty (30) days' advance notice and an opportunity to object on reasonable data-protection grounds; removals and other material changes are notified within thirty (30) days. See how to object.
International Data Transfers
Our infrastructure and sub-processors are located in the United States. Where we process the personal data of individuals located in the EU, the UK, or other regions with cross-border-transfer requirements, those transfers are made under an appropriate safeguard — for example the EU-US Data Privacy Framework (and UK Extension) where the recipient is certified, or Standard Contractual Clauses together with a transfer risk assessment.
Data Security
- Encryption: AES-256 at rest, TLS 1.2+ in transit
- Access Controls: IAM-based least-privilege access, audit logging
- Password Security: scrypt hashing with unique salts
- Multi-factor authentication (MFA): available through your single sign-on provider (Google, Clever, or ClassLink), which your school or district can require; RevolutionEd does not store a separate password when you sign in with SSO
- Monitoring: GCP Security Command Center and automated intrusion detection
- Staff Training: Secure development and data privacy training
- Backups: Point-in-time recovery, with deleted student data excluded from backups
Data Retention
We retain personal information only for as long as reasonably necessary to provide the educational service and to meet legal, accounting, or reporting obligations. We do not retain children's personal information indefinitely. Student personal information is kept only for the period needed for its educational purpose and is then deleted or de-identified. Upon request or contract termination, student personal information is returned and/or securely deleted within 30 days, including from backups after the backup-retention window, and we provide a certificate of destruction on request. For New York City public-school (NYC DOE) data, we do not de-identify it at all: NYC DOE student data is returned to the school and/or securely destroyed only — never de-identified and retained (NYC DOE Chancellor's Regulation A-820).
The categories of data we hold and how long we keep each are summarized below; our full data-retention policy and schedule are available to educational agencies on request.
| Category | How long we keep it | Then |
|---|---|---|
| Student account & profile data | While the school uses RevolutionEd | Returned or securely deleted within 30 days of the school's request or contract end |
| Student work, assessments & AI interactions | While the school uses RevolutionEd (longer where special-education law requires) | Deleted or de-identified per the school's direction and applicable state schedule (NYC DOE: returned or securely destroyed only — not de-identified) |
| Voice recordings | Not kept — deleted immediately after the pronunciation score is produced | Already deleted (never stored) |
| Voice scores & student photos | While needed for the educational purpose, capped by state limits (1–3 years) | Automatically destroyed on the shortest applicable clock and on contract end |
| Payment/billing records | 7 years (tax & accounting); card numbers are never stored by us | Securely deleted after the accounting period |
| Staff account data | While the staff member is engaged | Deleted after engagement ends, plus any required HR period |
| Website analytics / email tracking | Up to 13 months | Deleted or anonymized |
| Consent & authorization records | For the life of the consent, plus 1 year | Securely deleted |
| Logs | At least 1 year (security) | Deleted on the logging-retention schedule |
Your Rights Over Your Data
Depending on your location and applicable law (including the EU/UK GDPR, the CCPA/CPRA, and U.S. state privacy laws such as the Connecticut Data Privacy Act), you may have the right to (see our dedicated Your Privacy Rights page for a full description and how to exercise each):
- Know about and access the personal information we hold about you
- Correct inaccurate personal information
- Delete your personal information
- Restrict or object to certain processing
- Receive a portable copy of your data (data portability)
- Withdraw consent where processing is based on consent
- Opt out of the "sale" or "sharing" of personal information and of targeted advertising — note that we do not sell or share personal information or use it for targeted advertising
- Limit the use of sensitive personal information
- Not be discriminated against for exercising your privacy rights
- Appeal a decision we make about a privacy request
To exercise any of these rights, submit a privacy request or contact us using the details at the end of this policy. If your request concerns a student's education records, we act on behalf of the student's school/district and will route your request to them as the controller of those records. If we decline your request, you may appeal by replying to our decision or contacting us at registration@revolutioned.ai; we will respond to an appeal within 45 days (within the period applicable law allows). You may also contact your state Attorney General or your data-protection supervisory authority (see "Complaints and Supervisory Authorities" above).
All subject access requests (SARs) and deletion requests will be handled within 30 days, with extensions up to 60 additional days for complex cases, in line with GDPR requirements. Users will be notified within the initial 30 days if more time is needed.
Student Data Requests
If a parent or student contacts us directly, we will refer the request to the School Administrator. We act as a data processor under the school’s direction and will only process or delete student data upon the School’s instruction.
Complaints and Supervisory Authorities
If you have a concern about how we handle personal information, please contact us first using the details below so we can try to resolve it. You also have the right to lodge a complaint with a regulator:
- Schools and parents (United States): you may raise concerns with your school or district, with the U.S. Federal Trade Commission (FTC), or with your state Attorney General.
- Individuals in the EU / UK: you may lodge a complaint with your local data protection authority, or with the UK Information Commissioner's Office (ICO).
Breach Notification Policy
In the event of a breach or unauthorized release involving student data, we notify the affected School / educational agency in the most expedient way possible and without unreasonable delay, and no later than seven (7) calendar days after discovery (consistent with New York Education Law § 2-d and 8 NYCRR Part 121). Details provided include: nature, scope, affected systems, and mitigation steps. Notifications are delayed only if and to the extent a law-enforcement agency determines that notification would impede a criminal investigation. We coordinate closely with Google Cloud Platform to investigate and respond to incidents.
Law Enforcement and Legal Requests
iCode Technologies LLC may disclose personal information where required by applicable law or court order. The School will be notified unless legally prohibited. All requests are reviewed by legal and compliance personnel and documented internally.
Changes to This Privacy Policy
We may update this privacy policy from time to time. When we do, we revise the "Last Updated" date above and keep a record of each version so the wording in effect on any prior date can be retrieved.
Before we make a material change — for example, collecting a new category of personal information, using personal information for a new purpose, using students' personal information to train AI models, adding a new sub-processor with access to student data, disclosing information to a new recipient, retaining data longer than previously stated, or reducing your rights or our safeguards — we provide prominent notice in advance, typically at least 30 days before the change takes effect. That notice is given through an in-product banner and by email to account holders (schools and educators), in addition to updating this page, so you have an opportunity to review the change and, where applicable, to opt out before it applies to you.
Because students use RevolutionEd under their school's authorization (the COPPA Schools Exception), where a material change affects the collection, use, or disclosure of a child's personal information we obtain new authorization — school re-authorization or new verifiable parental consent — before that change is applied to information already collected, as required by the Children's Online Privacy Protection Act Rule (16 C.F.R. § 312.4(b) and § 312.5(a)(1)). We will not apply a material change retroactively to data governed by a prior version without the notice and any consent described here.
Contact Us
If you have questions about this policy or your data, contact our designated Privacy Officer — the data-protection point of contact for privacy requests, complaints, and breach inquiries:
- Arsenios Scrivens, Chief Privacy & Compliance Officer (Designated Privacy Officer & data-protection point of contact)
- Email (privacy & data protection): registration@revolutioned.ai
- Telephone: (972) 654-0412
- Mailing Address: iCode Technologies LLC, 3201 Dallas Pkwy St. 810, Frisco, TX 75034
Effective Date: May 21, 2026
Last Updated: June 10, 2026
Site: https://admin.revolutioned.ai/