Privacy Policy
Last updated: July 16, 2026
1. Overview
Varsity Learning, operated by Varsity Learning, Inc. (a Delaware corporation), respects your privacy and is committed to protecting personal information. This policy describes our practices regarding data collected through varsitylearning.com and related services.
2. Information We Collect
Account Information: Name, email address, school/institution name, and role (student or instructor). Students may also provide a course enrollment key.
Academic Data: Assignment submissions, scores, grades, course progress, and interaction with course materials.
Technical Data: IP address, browser type, device information, and usage patterns collected via server logs.
Payment Data: Payment transactions are processed by Stripe. We do not store credit card numbers. We retain transaction records (amount, date, status) for accounting purposes.
AI Feature Data: If you use AI-powered features (such as homework hints and step-by-step explanations), we process the content you submit to those features — the question being worked on and your current answer attempt, plus, on adaptive practice assignments, your topic-mastery level and detected error patterns. We also keep an internal metadata log of each AI interaction, linked to your account (the feature used, question ID, adaptive skill ID, hint level, the model or generation method when recorded, and outcome) — never your answer text or the AI's response. See Section 5 for how AI providers process this content, and our Data Collection Practices page for the log's retention and internal-only handling.
Instructor Lesson-Plan Data (where enabled): For instructors using the AI lesson-planning tool, we collect the generated lesson plans together with the standard reference, grade band, any source lesson used for differentiation, and model metadata. See Section 5.
3. How We Use Information
- Provide and maintain the learning platform
- Authenticate users and manage accounts
- Enable instructors to view student progress and grades
- Process payments and manage subscriptions
- Send service-related communications (password resets, account notifications)
- Improve platform performance and user experience
- Comply with legal obligations (FERPA, subpoenas, court orders)
4. Information Sharing
We do not sell personal information. We share data only in these circumstances:
- Instructors: Can view their students' names, scores, and submissions within their courses
- Institutional Administrators: May access aggregate course data when operating under institutional agreements
- Service Providers: Stripe (payments), Mailgun (email delivery), AWS (hosting), third-party AI model providers (AI processing for homework hints, step-by-step explanations, instructor analytics, and — where enabled — instructor lesson planning; see Section 5) — all bound by data processing agreements
- Legal Requirements: When required by law, subpoena, or court order
We do not share data with advertising networks or data brokers.
5. AI-Powered Features
Varsity Learning offers AI-powered homework hints and step-by-step explanations for students, and AI-generated course-analytics summaries for instructors. These features are powered by large language models accessed through our AI inference gateway. The specific model provider depends on the feature and current configuration, and currently includes Groq and Alibaba Cloud (Qwen models), with Anthropic's Claude used for select workflows. Where enabled, instructors may also use an AI-assisted lesson-planning tool that processes instructor-provided lesson details (topic, grade band, duration, notes, and — for the lesson-differentiation mode — the source lesson being adapted) and published academic-standards data, with requests processed by Anthropic (Claude); it does not read student data from Varsity Learning records, and instructors must not enter student personal information into lesson-planning fields. Generated lesson plans — the generated content, the standard reference and grade band, any source lesson used for differentiation, and model metadata, but not the free-text topic or notes — are saved to the instructor's account and retained like other account data.
What is shared with AI providers: Hint and explanation requests include the question text and the answer attempt you submit; this content passes through an automated filter that redacts common personal-information patterns (email addresses, phone numbers, names volunteered in the text) before the request is sent, but this filter is best-effort and not a guarantee — please do not include personal information in your answer submissions. On adaptive practice assignments, these requests may also include your current mastery level on the topic and detected error patterns, so the response can address your specific misconception. Analytics requests include course-level engagement metrics under pseudonymous labels (e.g., “Student_123”) and do not include student names, email addresses, or contact information.
Provider obligations: We require each AI provider we use to process this data solely as our service provider under a data processing agreement, and prohibit use of submitted content to train their models. Specific retention terms vary by provider — for example, Anthropic commits to deleting API inputs and outputs within 30 days (except content flagged by its automated trust-and-safety systems, which may be retained longer under Anthropic's policies). Contact us for the retention terms of a specific provider.
Transparency: AI-generated content is labeled as such in the product. Hints and explanations are rate-limited, scoped to the question being worked on, and may contain mistakes — they supplement, and never replace, your instructor. Neither hints nor explanations affect your grades. AI feature data is never used for advertising or profiling.
6. Data Security
We protect data using industry-standard measures including:
- TLS 1.3 encryption for all data in transit
- AES-256 encryption for data at rest (AWS Aurora)
- Web Application Firewall (Sucuri) for DDoS and attack mitigation
- Bcrypt password hashing (passwords are never stored in plaintext)
- Regular security audits and vulnerability assessments
7. Data Retention
Account and academic data is retained for the duration of the account plus 3 years after the last login, to support transcript requests and institutional compliance. Payment records are retained for 7 years per accounting requirements. Users may request earlier deletion by contacting support.
8. Children's Privacy
Varsity Learning serves high school students (typically ages 14–18). We do not knowingly collect information from children under 13 without parental or school consent. If you believe a child under 13 has registered without consent, contact us and we will delete the account.
9. Your Rights
You have the right to:
- Access your personal data
- Request correction of inaccurate information
- Request deletion of your account and data
- Export your data in a portable format
- Opt out of non-essential communications
To exercise these rights, contact support@varsitylearning.com.
10. California Residents
Under the California Consumer Privacy Act (CCPA), California residents have additional rights including the right to know what data we collect and the right to opt out of the sale of personal information. We do not sell personal information.
11. Changes to This Policy
We may update this policy periodically. Material changes will be communicated via email or platform notification. The "Last updated" date at the top reflects the most recent revision.
12. Contact
For privacy inquiries: support@varsitylearning.com
Varsity Learning, Inc.
San Luis Obispo, CA