Privacy Policy
Last updated: March 2026
Overview
ScholarFlows ("we", "us", "our") is committed to protecting the privacy of students, parents, and school administrators who use our platform. This policy explains what data we collect, how we use it, and your rights regarding that data.
Information We Collect
We collect only what is necessary to provide course planning recommendations:
- Account information: Username and email address at registration
- Student profile: Grade level, academic interests, and career aspirations
- Usage data: Standard server logs (IP address, browser type, pages visited)
We do not collect Social Security numbers, government IDs, financial information, or any sensitive personal data beyond what is listed above.
How We Use Your Information
- To generate AI-powered course recommendations personalized to each student
- To provide administrators with enrollment forecasting and resource planning data
- To send account verification and platform communication emails
- To improve the accuracy and quality of our recommendation engine
We do not sell, rent, or share personal information with third parties for marketing purposes.
FERPA
ScholarFlows is designed to support FERPA compliance. We act as a "school official" with a legitimate educational interest when processing student data on behalf of a school or district. Schools retain ownership and control of all student educational records. We process this data only as directed by the institution and do not disclose it to unauthorized parties.
Schools deploying ScholarFlows should execute a Data Processing Agreement (DPA) with us before allowing student data to flow through the platform. Contact sales@scholarflows.com to request a DPA.
AI & Third-Party Processing
Course recommendations are generated using a third-party AI API. Student profile data (grade level, interests, career aspirations) is transmitted to this service to generate recommendations. No names, email addresses, or identifying information are included in AI requests. Please review the AI provider's data processing terms for additional details.
Data Retention
Account data is retained for as long as your account is active. You may request deletion of your account and associated data at any time by contacting us. School administrators may request bulk deletion of student data at the end of a contract period.
Security
We use industry-standard security practices including encrypted passwords (pbkdf2:sha256), CSRF protection on all forms, rate limiting on authentication endpoints, and HTTPS-only communication in production.
Contact
For privacy questions, data deletion requests, or to request a FERPA Data Processing Agreement:
sales@scholarflows.com
(415) 340-0951