Data Collection Practices
Last updated: July 16, 2026
| Data Type | Purpose | Retention | Shared With |
|---|---|---|---|
| Name & Email | Account creation, authentication | Account life + 3 years | Instructor (name only) |
| School / Institution | Instructor verification, institutional reporting | Account life + 3 years | None |
| Assignment Submissions | Grading, academic record | Account life + 3 years | Course instructor |
| Scores & Grades | Gradebook, analytics, student progress | Account life + 3 years | Course instructor, LMS (via LTI) |
| IP Address | Security, fraud prevention, session management | 90 days | Sucuri (WAF) |
| Browser / Device Info | Platform compatibility, support troubleshooting | 90 days | None |
| Payment Records | Transaction processing, refunds, accounting | 7 years | Stripe (processor) |
| Email Logs | Delivery confirmation, support follow-up | 1 year | Mailgun (delivery) |
| AI Hint & Explanation Requests (question text + answer attempt; adaptive assignments may add topic-mastery level and detected error patterns) | Generate on-demand homework hints and step-by-step explanations | Processed in real time; retention terms vary by provider (see Third-Party Services below) | Our AI model provider(s) — currently Groq and Alibaba Cloud (Qwen), with Anthropic for select workflows |
| Pseudonymized Course Metrics | Weekly AI analytics summaries for instructors | Summaries stored with course records; input retention terms vary by provider (see Third-Party Services below) | Our AI model provider(s) (pseudonymous labels only — no names or emails) |
| AI Interaction Log (student ID, feature used, question ID, adaptive skill ID, hint level, model/method when recorded, outcome — never answer or response text) | Internal audit trail of AI tutoring feature usage | Account life + 3 years (with education records) | None (internal only) |
| Record of Access to Education Records (accessor ID and role, student ID, record type, action, course, timestamp — administrative and support interfaces) | Supports FERPA § 99.32 record-of-access obligations | Account life + 3 years (with education records) | None (internal only) |
| Instructor Lesson Plans (where enabled: generated content, standard reference, grade band, any differentiation source lesson, model metadata — not the free-text topic or notes) | AI-assisted lesson planning; saved to the instructor's account | Account life + 3 years | Anthropic (generation requests only — see Third-Party Services below) |
Cookies & Tracking
Varsity Learning uses only essential cookies required for authentication and session management. We do not use advertising cookies, tracking pixels, or third-party analytics services (no Google Analytics, no Facebook Pixel).
- Session cookie: Authenticates your login session. Expires when you close the browser or after 2 hours of inactivity.
- CSRF token cookie: Prevents cross-site request forgery attacks. Essential for form security.
- Remember-me cookie: Optional, set only if you choose "Remember me" at login. Expires after 30 days.
What We Do NOT Collect
- Social Security numbers or government-issued IDs
- Biometric data (fingerprints, facial recognition)
- Location data (GPS or geolocation)
- Social media profiles or contacts
- Health or medical information
- Credit card numbers (handled entirely by Stripe)
Third-Party Services
Amazon Web Services (AWS): Hosting, database, and file storage. Data resides in US-West-1 (N. California). SOC 2, ISO 27001 certified.
Stripe: Payment processing. PCI DSS Level 1 certified. We never handle or store raw credit card data.
Mailgun: Transactional email delivery (password resets, enrollment confirmations). Email addresses shared for delivery only.
Sucuri: Web Application Firewall and DDoS protection. Processes HTTP requests including IP addresses.
AI model providers: Large language models, accessed through our AI inference gateway, for homework hints, step-by-step explanations, and instructor analytics summaries. The specific provider depends on the feature and current configuration, and currently includes Groq and Alibaba Cloud (Qwen models), with Anthropic's Claude used for select workflows. Each provider receives question/answer content (plus, on adaptive assignments, topic-mastery level and detected error patterns) and pseudonymized course metrics only — never student names, email addresses, or contact information — and acts as our processor under a data processing agreement that prohibits training its models on our data. Retention terms vary by provider; for example, Anthropic automatically deletes API inputs and outputs within 30 days (content flagged by its automated trust-and-safety systems may be retained longer under Anthropic's retention policies) and is SOC 2 Type II, ISO 27001:2022, and ISO/IEC 42001:2023 certified, with its subprocessor list published at trust.anthropic.com. Where enabled, an instructor-facing lesson-planning tool sends instructor-provided lesson details (topic, grade band, duration, notes, and — for the lesson-differentiation mode — the source lesson being adapted) and published academic-standards data to Anthropic (Claude); it does not read student data from Varsity Learning records, and instructors must not enter student personal information into lesson-planning fields. Generated lesson plans are saved to the instructor's account and retained like other account data.
LTI Integration Data
When Varsity Learning is integrated with a Learning Management System (Canvas, Blackboard, Moodle, Brightspace) via LTI 1.3, limited data is exchanged per the LTI specification: user identifier, course context, roles, and grade passback. The LMS controls what data is sent; we process only what is necessary for the integration.
Data Deletion Requests
To request deletion of your data, email support@varsitylearning.com. We will process requests within 30 days. Note that some data may be retained to comply with legal obligations or legitimate institutional records requirements.