Chính sách bảo mật cho GuidED (School)
GuidED (School) bởi Krystle Wright
Privacy Policy
Last updated: July 17, 2026
Effective Date: July 17, 2026
1. Introduction
GuidED (“GuidED,” “we,” “our,” or “us”) respects the privacy of students, educators, parents, and educational institutions. This Privacy Policy explains how we collect, use, disclose, and protect personal information when users access or interact with GuidED’s services available at guidedcentral.com (the “Platform”).
GuidED provides student AI usage analytics, and educational insights, designed for use by schools and districts in compliance with applicable privacy laws, including the Family Educational Rights and Privacy Act (FERPA), Children’s Online Privacy Protection Act (COPPA), General Data Protection Regulation (GDPR), and California Consumer Privacy Act (CCPA).
By accessing or using the Platform, you acknowledge that you have read and understood this Privacy Policy.
- Information We Collect
We collect only the information necessary to deliver, maintain, and improve our services.
a. Personal Information
Name, email address, and role (student, teacher, administrator)
Educational institution affiliation
Login credentials (hashed and encrypted)
Contact preferences
b. Student Data
When GuidED is used by a school or district, we may process limited student data such as:
AI interaction history and engagement metrics
Learning analytics and progress data
Device and browser information (non-sensitive)
GuidED acts as a data processor on behalf of the educational institution, which remains the data controller and owner of all student data.
c. Supported-editor revision evidence
When enabled by an educational institution, GuidED may capture the original AI-generated text used as a revision baseline and the resulting revised text from supported editors, including Google Docs, to calculate a Genuine Revision Metric. The metric describes the amount of text transformation between those two snapshots. GuidED does not collect or store a keystroke history, key-by-key replay, or every intermediate draft.
Original and revised snapshots are available only to authorized users under institutional role permissions and plan controls. They are subject to the same classification, minimization, security, access logging, deletion, and retention rules as other student activity content. GuidED limits collection to the snapshots and attribution metadata reasonably needed to pair the revision and calculate the metric; high-confidence personal content may be minimized, and records are retained only for the institution's applicable retention period.
The Genuine Revision Metric is an educational learning indicator, not proof of authorship, plagiarism, cheating, intent, or misconduct. It must not be used by itself for discipline, grading, or another high-stakes decision; authorized staff should review context and apply professional judgment.
d. Automatically Collected Information
We automatically collect non-identifiable information such as IP address, usage logs, and browser type for system security and analytics. When the GuidED browser extension is installed on a school-managed device, it may access limited browsing history (URLs on registered AI platforms only) to detect AI conversations that were not observed at creation. Raw browsing history is not stored on our servers — only minimized AI interaction data derived from visibility sweeps, consistent with live capture minimization. Cookies and similar technologies are used solely to maintain secure sessions; no advertising or cross-site tracking cookies are used.
- How We Use Information
We use information only for legitimate educational and operational purposes, including to:
Provide, operate, and improve the Platform
Evaluate and report student AI interaction and learning engagement data
Maintain system integrity, availability, and security
Respond to customer support and compliance requests
Comply with legal obligations and educational privacy requirements
We do not sell, rent, or use personal information for advertising, profiling, or marketing purposes.
- Legal Bases for Processing (GDPR)
For users in the European Economic Area, GuidED processes personal data under one or more of the following legal bases:
Performance of a contract with the educational institution
Compliance with a legal obligation
Legitimate interests in maintaining and improving our services
Consent, when required
- Data Retention and Deletion
We retain education-related personal and student data only for as long as necessary to fulfill our contractual obligations or legal requirements. After an organization’s subscription is terminated (i.e., there is no active, trial, or pilot_active subscription), student activity data is retained for 2 years for backup integrity, after which it is securely deleted or anonymized. Student roster records are retained or deleted at the school’s direction.
5a. Rules-Based Classification of Student AI Activity (No Third-Party AI Classifiers)
To support school-authorized educational oversight while reducing unnecessary exposure of private student content, GuidED applies a deterministic, rules-based classifier implemented in our own product code. We do not send student prompts to a third-party or cloud artificial intelligence service for content classification. For a full disclosure of categories, confidence levels, precedence, minimization, and district guidance, see our Rules-Based Content Classification & Retention page.
Each captured prompt or model response is evaluated individually. Categories may include, for example:
Educational: activity that appears tied to schoolwork, studying, or other legitimate instructional use, which may be retained and shown according to the institution’s role permissions and policies.
Personal (non-educational): only when multiple conservative signals indicate content is unlikely to be school-related. Highly confident personal classifications may result in automatic minimization of raw message text in storage (replacing it with a neutral notice) while retaining limited audit metadata (such as classification category, confidence, and timestamps) so schools can still understand that an event occurred without retaining unnecessary private detail.
Safety risk: matches institution-configured risk keywords or built-in safety terms suggestive of self-harm, violence, exploitation, or similar concerns. Safety signals take precedence over personal minimization: content needed for appropriate school review may be retained in a minimized or redacted form rather than deleted outright.
Uncertain / ambiguous: when signals conflict or confidence is low, GuidED defaults to retention of the event for authorized educational visibility rather than treating the message as personal for minimization purposes.
Each event also receives a confidence label (HIGH, MEDIUM, or LOW). LOW confidence means the rules did not strongly verify the category, for example, Educational · LOW is not the same as confirmed classwork. Minimization of raw text applies to high-confidence personal classifications on consumer-style contexts, not to every non-homework message. Schools should treat Uncertain and Educational · LOW as needing staff judgment.
Parents may configure custom risk words in the GuidED browser extension; those words are transmitted only so the same rules-based logic can run server-side. When a keyword appears in clear educational context (for example, a chemistry lab report), the product typically retains the message for oversight and flags it for staff review rather than treating it the same as an unstructured safety crisis outside of schoolwork, exact behavior depends on institutional settings.
This section describes product behavior only and is not a substitute for legal review; institutions should have counsel validate classifications, retention periods, and disclosures for their jurisdiction.
Desktop Agent telemetry that does not include actual prompts is labeled separately (typically as low-confidence “uncertain” context) and is used only for high-level usage awareness unless and until transcript-like content is explicitly captured under a future product feature governed by this Policy.
- Data Security
GuidED employs technical and organizational measures to protect all data, including:
Encryption in transit (TLS 1.2 +) and at rest (AES-256)
Role-based access control (RBAC)
Secure U.S.-based hosting via Supabase and Netlify
Routine vulnerability testing and annual security reviews
Strict internal access logging and monitoring
GuidED is a projectunicorn.org, committed to secure data interoperability and student privacy.
- Third-Party Processors
We engage vetted service providers under written Data Processing Agreements (DPAs). These processors are contractually required to:
Use information only for the purpose of providing contracted services;
Implement equivalent or stronger security measures; and
Comply with FERPA, COPPA, and GDPR where applicable.
- International Data Transfers
All GuidED data is stored within the United States. If limited access from outside the U.S. occurs (e.g., support operations), such transfers are protected by Standard Contractual Clauses (SCCs) approved by the European Commission. - Your Rights
Depending on jurisdiction, users (or their parents/guardians, in the case of minors) may have the right to:
Access and obtain a copy of their data
Request correction or deletion
Object to or restrict processing
Withdraw consent (where applicable)
File a complaint with a supervisory authority
Requests may be submitted to info@guidedcentral.com.
- Data Breach Notification
In the event of a confirmed data breach involving student or personal data, GuidED will notify affected institutions within 72 hours of confirmation, providing relevant details and mitigation steps. - Updates to This Policy
GuidED may update this Privacy Policy periodically. Material changes will be communicated to registered administrators prior to taking effect. - Contact Information
Email: info@guidedcentral.com