Compliance
Compliance & student data
LessonCraft is built to help schools and teachers handle lesson planning responsibly. This page outlines how we support FERPA-aligned workflows and protect education data.
Designed to support FERPA compliance
FERPA applies to schools and districts. LessonCraft provides controls that help schools manage access to lesson content and keep data minimal. Schools should use a DPA or vendor agreement to document responsibilities.
Data use commitments
- We do not sell customer data.
- We do not run ads or profile users for advertising.
- We do not use your lesson content to train public AI models.
How AI processing works
- We send your prompt and required context to our AI processing provider to generate lesson outputs.
- We minimize data and do not send passwords or payment details.
- We encourage teachers not to include sensitive student PII in prompts.
Subprocessors
- Supabase (authentication and database storage)
- Stripe (payments)
- Resend (transactional email)
- Vercel (hosting and delivery)
Security basics
- Access controls and role-based permissions for internal systems.
- Encryption in transit for data sent between services.
- Principle of least privilege and RLS where applicable.
Data retention & deletion
Lesson data is stored so you can edit and reuse plans. You can request deletion at any time by emailing support@getlessoncraft.com.
Contact & DPA request
For compliance questions or a DPA request, contact us at support@getlessoncraft.com. We can provide a DPA on request.