Privacy Policy
Your privacy is important to us. Learn how we collect, use, and protect your information.
Who We Are
Welcome to RevolutionEd, operated by iCode Technologies LLC. Our platform empowers educators with advanced AI-driven tools to create custom lesson plans, quizzes, and educational experiences for K-12 students.
This privacy policy describes how we collect, use, and protect personal information on our admin.revolutioned.ai portal, which serves educators and school administrators.
What Personal Data We Collect and Why
Account & Profile Information
Name, email address, school affiliation, and role are collected during registration. This information is used to create educator accounts, manage classes, and provide access to educational features.
Student Data (Provided by Teachers)
- First and last names of students
- Quiz responses and educational activity
- Interests submitted by students
- AI chat interactions (moderated and accessible to teachers only)
Note: Student accounts are never created directly; access is granted through teacher-generated QR codes or links.
Cookies
Session Cookies: Enable secure login and save user preferences.
Analytics Cookies: Collected through Google Analytics to help us understand user interactions. (Google Signals and user-provided data collection are disabled.)
Users can revoke cookie consent via their account profile settings.
Media Uploads
Educators may upload media (e.g., images, documents). We advise users to avoid uploading media with embedded location metadata (EXIF GPS).
Embedded Content
Our platform may feature embedded content from trusted providers (e.g., YouTube, Vimeo). Such content behaves as if visited on the host site, which may collect personal data or use cookies in line with their respective privacy policies.
How We Use Your Information
We use collected information to:
- Personalize lesson plans and student experiences
- Facilitate collaboration between teachers and students
- Analyze learning outcomes and improve platform features
- Enable secure storage of content in connected Google Drive accounts (for educators)
Data Sharing and Sub-Processors
We do not sell or rent personal information to third parties. We use the following sub-processors for infrastructure, AI generation, identity, payments, communications, curriculum and reference data, document viewing, browser-side telemetry, and browser-side asset delivery. All sub-processors operate from facilities located in the United States. RevolutionEd has a written agreement with each that binds them to data protection standards no less protective than those in our agreements with educational agencies.
1. Infrastructure & Hosting (server-side)
Google Cloud Platform (Alphabet Inc.) – Application hosting (Cloud Run), database (Cloud SQL for MySQL), object storage (Cloud Storage), container registry (Artifact Registry), identity management (Cloud IAM), secret storage (Secret Manager), edge protection (Cloud Armor + Cloud CDN), DNS (Cloud DNS), audit logging (Cloud Logging). Continuously attested under SOC 2 Type II, ISO/IEC 27001, ISO/IEC 27017, and ISO/IEC 27018. Data Processing Addendum executed. All data resides in the us-central1 region (United States).
2. AI Generation (server-side)
Google Gemini API – Primary AI lesson plan, quiz, narrative, presentation, image, and text-to-speech generation. We send lesson topic, grade level, and prompt text; we do not send raw student PII. Prompts are not used for model training (per Google Cloud API terms).
OpenAI – Content moderation (for student-submitted text) and supplementary AI generation. Zero data retention and no training (per OpenAI API terms).
Microsoft Azure Cognitive Services — Speech – Pronunciation assessment and speech-to-text fallback. We send short audio clips (typically ≤30 seconds); audio is not retained per Azure terms.
ElevenLabs – Legacy text-to-speech and music generation (deprecation in progress; Gemini TTS is the active path). We send text strings only; no training on customer inputs (Enterprise tier terms).
3. Identity & Single Sign-On (server-side)
Google OAuth 2.0 / OpenID Connect – Teacher and administrator login via Google account.
Clever, Inc. – Single Sign-On and roster sync for districts that use Clever. Receives student/teacher ID, email, name, and section.
ClassLink, Inc. – Single Sign-On (launchpad.classlink.com) and OneRoster roster sync (nodeapi.classlink.com, oneroster-proxy.apis.classlink.com) for districts that use ClassLink. Receives student/teacher ID, email, name, grade, section, and enrollment.
4. Roster & Document Integration (server-side)
Google Classroom API – Optional teacher-initiated roster import for teachers who use Google Classroom. Receives teacher email, course roster, and student IDs/emails/names.
Google Drive / Docs / Slides APIs – Optional teacher-initiated export of generated documents to the teacher’s own Drive (drive.file scope only).
5. Payments & Communications (server-side)
Stripe, Inc. – Subscription billing and webhooks. Card data is captured directly by Stripe Elements (a Stripe-hosted iframe in the browser) and never touches RevolutionEd servers. Our servers receive only the billing email and Stripe customer / subscription IDs. PCI scope: SAQ A.
SendGrid (Twilio, Inc.) – Transactional email (account confirmations, password resets, notifications) and event webhook. Receives recipient email, name, and message body. Sender domain: registration@revolutioned.ai.
6. Curriculum & Reference Data (server-side)
JASON Learning – Curriculum resource lookup. Search query strings only; no PII.
Texas Instruments – TI educational activity resource lookup and file downloads. Search queries; no PII.
U.S. Department of Education — College Scorecard (api.data.gov) – Public college data lookup. No PII sent.
Library of Congress (www.loc.gov) – Primary source search for the Deep Dive History feature. No PII sent.
Unsplash – Stock imagery for presentations. Search query strings only.
Serper.dev – Web image-search proxy for presentation imagery. Search query strings only.
YouTube (Google) – Video URL embedding (iframes loaded by the user’s browser). Video URLs only; no PII.
randomuser.me – Synthetic character profile generation for the Make It Stick chat feature. No outbound data — synthetic profiles are fetched.
7. Document Viewing (server-side URL handoff)
Microsoft Office Online viewer (view.officeapps.live.com) – PPTX preview rendering. The user’s browser passes signed Cloud Storage URLs to Microsoft’s servers, which fetch the curriculum content to render slides server-side. No student PII is included in these URLs.
8. Browser-side Analytics & Tracking
Google Tag Manager (container ID GTM-NNCX394P) – Tag container loaded into the user’s browser on authenticated and marketing pages.
Google Analytics – Anonymized analytics via the GTM container. Google Signals is disabled, user-provided data collection is disabled, IP anonymization is enabled.
CallRail – Phone-number-swap script (swap.js) for call attribution on marketing pages.
9. Browser-side Asset CDNs
The following content delivery networks deliver fonts, icons, and JavaScript libraries to the user’s browser. RevolutionEd does not transmit any PII or education records to these networks.
- Google Fonts (fonts.googleapis.com, fonts.gstatic.com) – Web fonts.
- jsDelivr CDN – JavaScript libraries (Bootstrap, KaTeX, DOMPurify, Tom Select, Chart.js, marked, Three.js).
- Cloudflare cdnjs – JavaScript libraries (Font Awesome, html2canvas, jsPDF, Spectrum color picker).
- MathJax CDN – LaTeX math rendering.
- Plotly CDN – Chart rendering on administrative dashboards only.
- Brandfolder embed – Bluebonnet curriculum preview embed (public embed key).
- Imgur – Static logo asset embedded in generated PDFs and emails. No user data flows to Imgur (logo fetch only). Migration to a self-hosted asset is planned.
Authoritative sub-processor list. The complete, canonical sub-processor list (Exhibit A) is maintained at legal/SUB_PROCESSOR_LIST.md in the RevolutionEd repository and is incorporated by reference into any Data Privacy Agreement executed between RevolutionEd and an educational agency. RevolutionEd will notify the educational agency of any addition, removal, or material change to a sub-processor within thirty (30) days.
Data Security
We apply comprehensive security measures to protect your personal information:
- Encryption: AES-256 at rest, TLS 1.2+ in transit
- Access Controls: IAM-based least-privilege access, audit logging
- Password Security: PBKDF2 hashing with unique salts
- Monitoring: GCP Security Command Center and automated intrusion detection
- Staff Training: Secure development and data privacy training
- Backups: Point-in-time recovery, with deleted student data excluded from backups
Data Retention
Student data is retained only as long as necessary for educational use. Upon request or contract termination, data is deleted or de-identified within 45 days. Backup data is purged of deleted student records within a 90-day window.
Your Rights Over Your Data
Educators and administrators may:
- View, edit, or delete their own account information
- Request an export or deletion of their data
- Contact us for assistance with privacy-related inquiries
All subject access requests (SARs) and deletion requests will be handled within 30 days, with extensions up to 60 additional days for complex cases, in line with GDPR requirements. Users will be notified within the initial 30 days if more time is needed.
Student Data Requests
If a parent or student contacts us directly, we will refer the request to the School Administrator. We act as a data processor under the school’s direction and will only process or delete student data upon the School’s instruction.
Breach Notification Policy
In the event of a breach involving student data, we notify the School within 72 hours of confirmation. Details provided include: nature, scope, affected systems, and mitigation steps. Notifications are delayed only if required by law enforcement. We coordinate closely with Google Cloud Platform to investigate and respond to incidents.
Law Enforcement and Legal Requests
iCode Technologies LLC may disclose personal information where required by applicable law or court order. The School will be notified unless legally prohibited. All requests are reviewed by legal and compliance personnel and documented internally.
Contact Us
If you have questions about this policy or your data:
Mailing Address
iCode Technologies LLC
3201 Dallas Pkwy St. 810
Frisco, TX 75034
Your Privacy, Our Priority
We are committed to protecting the privacy and security of educators and students. Our platform is designed with privacy by design principles and built on enterprise-grade infrastructure.
Data Protection
AES-256 encryption at rest and TLS 1.2+ in transit across all services
Transparent Sub-Processors
Full disclosure of every third-party service with written data protection agreements
User Control
Complete transparency and control over your personal data with 30-day response guarantee
