Privacy Covenant & Data Protection Policy
Date of Last Revision: May 30, 2026
This Privacy Covenant and Data Protection Policy (the "Covenant" or "Policy") establishes a binding administrative framework governing the retrieval, ingestion, storage, processing, dissemination, transmission, caching, and cryptographic scrubbing of all data, personal information, metrics, and behavioral telemetry generated, elicited, or otherwise transmitted during interactions with our proprietary digital architectures, subdomains, software platforms, and educational modules (collectively, the "Services"). These practices are administered by Successful Mathematics LLC, a Delaware limited liability corporation (together with its parents, subsidiaries, affiliates, successors, and assigns, "Successful Mathematics," the "Company," "we," "us," or "our") in strict adherence to applicable federal, state, and international regulatory mandates, including but not limited to the Family Educational Rights and Privacy Act (FERPA), the Children's Online Privacy Protection Act (COPPA), the California Consumer Privacy Act (CCPA), and the General Data Protection Regulation (GDPR).
1. Modalities and Taxonomies of Data Acquisition
The Company collects structured and unstructured information across distinct data classifications to ensure operational integrity and regulatory alignment. These classifications include:
- Account Provisioning & Registration Metrics: Upon creation of a user credential set, the Company retrieves and archives the user's legal name, primary and secondary communication vectors (including electronic mail addresses and telephone credentials), encrypted password hashes, and designated access roles (e.g., Student, Instructor, Administrator), as well as affiliated institutional or district identifiers.
- Educational Performance & Activity Telemetry: To support diagnostic learning and progress tracking, our systems continuously observe and log learning performance. This data encompasses curriculum progression, response inputs, assessment scores, temporal interaction maps, step-by-step mathematical reasoning steps, and AI-prompt parameters.
- Financial Entitlements & Subscription Data: Transactions associated with premium access tiers or digital currency acquisitions (e.g., MathCoins) are managed exclusively by Stripe, our PCI-DSS compliant payment processing partner. We maintain only tokenized receipt identifiers and subscription state flags; raw financial credentials never traverse or reside within Company-owned infrastructure.
- Device Configuration & Networking Logs: In alignment with cyber security protocols, we log network identifiers (IP addresses), user-agent strings, operating system variants, browser settings, and device telemetry to prevent fraud, enforce geo-fencing, and mitigate Denial of Service (DoS) attacks via Cloudflare.
2. Compliance Covenants: Statutory Obligations Under FERPA and COPPA
Due to our integration with public and private educational institutions, we enforce rigorous protocols to comply with youth privacy frameworks:
- FERPA Compliance (Institutional Student Records): The Company operates under the "School Official" exception delineated in 34 CFR § 99.31(a)(1), possessing a legitimate educational interest in student records. Educational data is treated as strictly confidential. Roster information and performance records are accessible only to verified instructors associated with the respective student's school district, preventing unauthorized cross-tenant exposure.
- COPPA Compliance (Minors Under 13 Years of Age): The Company strictly prohibits the collection of personal information from children under 13 years of age without prior verifiable consent from a parent, legal guardian, or authorized institutional representative. The Company does not participate in behavioral tracking, profiling, or direct monetization of student data. Parents and legal guardians possess the absolute statutory right to inspect, correct, restrict, or request the deletion of their child's data.
3. Delegated Processing and Third-Party Sub-Processors
We leverage compliant third-party sub-processors to facilitate core platform operations, governed by strict Data Processing Addenda (DPAs):
- Financial Processing (Stripe Inc.): Processes all card payments and recurring subscription billing. All payment data is collected directly by Stripe under PCI-DSS standards.
- Networking & Infrastructure Security (Cloudflare Inc.): Provides cryptographic transport (TLS 1.3), Content Delivery Network (CDN) caching, firewall policies, and DDoS protection.
- Generative Intelligence & Machine Learning Providers: When users engage with our Premium AI utilities, mathematical parameters (excluding PII) are transmitted to secure LLM endpoints. Our partners are contractually restricted from retaining, log-mining, or utilizing Company prompts for the purposes of foundational model training.
4. Purposive Utilization of Collected Information & Artificial Intelligence Training Regimes
The Company utilizes collected telemetry to maintain mathematical services, calculate performance-based achievements, prevent security breaches, and fulfill billing tasks.
Artificial Intelligence Training Policy: To improve our automated mathematical checking pipelines, the Company utilizes anonymized, aggregated learning vectors (such as mistake hierarchies). Under no circumstances are personally identifiable student details utilized to train machine learning systems. Users may modify their preferences regarding aggregate data ingestion within their account preferences panel.
5. Safeguarding Mechanisms & Cryptographic Zero-Trust Protocol
We deploy a zero-trust model to safeguard data from exposure:
- Encryption Standards: Data is encrypted at rest using AES-256 and in transit using TLS 1.3.
- Row Level Security (RLS): Our database implements strict PostgreSQL Row Level Security. Access to individual rows is restricted through cryptographic role checks, preventing multi-tenant data leaks.
- Data Breach Protocols: In the event of a verified database security breach, the Company will notify affected users and institutions within 72 hours of verification in accordance with statutory obligations.
6. Temporal Retention, Custody of Records, & Statutory Rights of Erasure
We store educational data only for the duration of the account lifespan or as specified in our contract with the educational institution. Users maintain legal rights of access, correction, and deletion under GDPR and CCPA.
Cryptographic Right to Erasure: To request deletion of your account, you must trigger the verification protocol. Upon verification, all records containing PII are queued for permanent deletion from active nodes and backup systems within 30 days. Accounts managed by an institution must coordinate deletion requests directly through the school administration.
7. Local Storage, Cookies, and Telemetry Tokenization
Our platform uses essential session tokens and HTTP cookies strictly for user verification, anti-forgery protection, and security tracking. We do not integrate third-party advertising cookie scripts or cross-site tracking pixels on our educational pages.
8. Unilateral Modifications & Amendments
We reserve the unilateral right to modify or amend this Privacy Policy at any time. Material revisions concerning student privacy will be highlighted through platform notices or direct email communication prior to enforcement, ensuring administrative transparency.
9. Inquiries, Administrative Redress, & Data Protection Officer Contact
For administrative inquiries, privacy concerns, or to execute legal data rights, please contact our Data Protection Officer at: support@successfulmathematics.com.