๐Ÿ“‹ California Student Data Privacy Agreement (CSDPA) - Exhibit E
โ† Back to Site

CALIFORNIA STUDENT DATA PRIVACY AGREEMENT

Exhibit "E" - General Offer of Privacy Terms

The Scribe Academy

Version 1.0 | December 2024

This Exhibit E provides The Scribe Academy's responses to the California Student Data Privacy Agreement (CSDPA) standard questions. The CSDPA is administered by the Student Data Privacy Consortium (SDPC) and provides a standardized framework for K-12 schools to evaluate vendor data privacy practices.

Reference: Student Data Privacy Consortium (SDPC)

SECTION 1: PROVIDER INFORMATION

Company Name:
The Scribe Academy
Website:
thescribesacademy.com
Contact Email:
support@thescribesacademy.com
Service Description:
AI-powered writing education platform for K-12 students featuring guided essay writing, AI feedback, and progress tracking.

SECTION 2: DATA COLLECTION

2.1 What student data elements are collected?

  • Identifiers: Name, email address (via Google Sign-In or email/password)
  • Educational Records: Writing submissions, outlines, essay drafts, AI-generated feedback reports
  • Progress Data: Mission completion status, scores, Brain Points (gamification currency)
  • Usage Data: Activity logs, navigation patterns, session timestamps
  • Preferences: Accessibility settings, TTS voice preferences, color themes

2.2 How is data collected?

  • User input during registration and writing activities
  • Google OAuth authentication (if selected)
  • Automatic logging of application usage
  • Teacher/admin input when inviting students

2.3 Is any data collected from third parties?

No. All student data is collected directly through the application or provided by the school/district during account setup.

SECTION 3: DATA USE

3.1 How is student data used?

  • Provide personalized writing instruction and AI feedback
  • Track student progress and generate reports for teachers
  • Enable accessibility features (TTS, color themes)
  • Support classroom management for teachers/admins
  • Improve service functionality and fix bugs

3.2 Is student data used for advertising?

NO. We do not use student data for advertising, marketing, or creating advertising profiles. We do not display advertisements to students.

3.3 Is student data sold to third parties?

NO. We never sell, rent, or lease student data to any third party.

3.4 Is student data used for AI model training?

No. Student writing submissions are not used to train AI models. AI feedback is generated using Google Gemini API with data processed in real-time and not retained for training purposes.

SECTION 4: DATA SHARING

4.1 With whom is student data shared?

Recipient Purpose Data Shared
Google Cloud (Firebase) Infrastructure hosting All application data (encrypted)
Google Gemini AI Writing feedback generation Writing content (not retained)
Google Cloud TTS Text-to-speech accessibility Text content for vocalization
Teachers/Admins Classroom management Student progress and reports
Parents (if configured) Progress reports Mission reports via email

4.2 Are subprocessors bound by data protection agreements?

Yes. All subprocessors (Google Cloud, Microsoft 365) maintain their own data processing agreements and comply with applicable data protection regulations.

SECTION 5: DATA SECURITY

5.1 What security measures are in place?

  • TLS 1.2+ encryption for all data in transit
  • AES-256 encryption for data at rest (Firebase)
  • Firebase Authentication with secure session management
  • Role-based access controls (Learner, Teacher, Admin, Developer)
  • Activity logging and audit trails
  • No direct database access - all operations via Cloud Functions

5.2 What certifications does the infrastructure have?

Google Cloud Platform (Firebase) maintains: SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, PCI DSS, HIPAA (with BAA), FedRAMP.

5.3 What is the breach notification policy?

In the event of a data breach, we will notify affected schools/districts within 72 hours of discovery, including details of the breach, affected data, and remediation steps.

SECTION 6: DATA RETENTION AND DELETION

6.1 How long is student data retained?

Student data is retained for the duration of the active account. Upon contract termination or deletion request, data is deleted within 60 days.

6.2 How can data be deleted?

  • Individual Student: Administrators can use "Full User Wipe" to permanently delete all student data
  • Bulk Deletion: Contact support for organization-wide data deletion
  • Contract Termination: All data deleted within 60 days of termination

6.3 What data is deleted?

Full deletion includes: user profile, writing submissions, mission reports, activity logs, progress state, and optionally Firebase Authentication records.

SECTION 7: PARENTAL RIGHTS (FERPA/COPPA)

7.1 How can parents access their child's data?

Parents should contact their school/district administrator, who can use the "Export User Data" feature to provide a complete data export in JSON format.

7.2 How can parents request data correction or deletion?

Parents should submit requests through their school/district. Administrators can modify student records or perform full data deletion using built-in tools.

7.3 COPPA Compliance for students under 13

For students under 13, the school/district provides consent on behalf of parents pursuant to the COPPA school consent exception (16 CFR ยง 312.5(c)(4)).

SECTION 8: ACCESSIBILITY

8.1 What accessibility standards are followed?

We are working toward WCAG 2.1 Level AA compliance and Section 508 conformance. Current features include keyboard navigation, focus management, screen reader support, and multiple color themes for color vision accessibility.

8.2 What accessibility features are available?

  • Text-to-Speech with multiple voice options
  • Color themes: Default, Deuteranopia-friendly, Protanopia-friendly, High Contrast
  • Keyboard-accessible navigation and focus trapping in modals
  • Semantic HTML structure with proper headings and landmarks

SECTION 9: CERTIFICATIONS AND COMPLIANCE

FERPA Compliant โœ“ Yes
COPPA Compliant โœ“ Yes (school consent model)
SOPIPA Compliant โœ“ Yes
California AB 1584 Compliant โœ“ Yes
GDPR Ready โœ“ Yes
CCPA Ready โœ“ Yes
Section 508 / WCAG 2.1 AA โšก In Progress
Student Data Privacy Pledge Signatory Pending

PROVIDER ATTESTATION

I certify that the information provided in this Exhibit E is accurate and complete to the best of my knowledge.

Signature:

Date:

Printed Name:

Title:

The Scribe Academy | AI-Powered Writing Education

thescribesacademy.com | support@thescribesacademy.com

Document Version: 1.0 | Last Updated: December 2024