Privacy Policy

This Privacy Policy explains how Novastone AI LLC ("Novastone," "we," "us," or "our") collects, uses, and protects information when you use the LessonPlanningForTeachers service at lessonplanningforteachers.com (the "Service"). LessonPlanningForTeachers is an AI-assisted lesson planning tool for K-12 educators built to store as little as possible: plans you save are scrubbed of names before storage, chat transcripts are never stored, and deleting a plan deletes it for good.

1. Information We Collect

1.1 Account Information

1.2 Payment Information

Payments are processed entirely by our third-party payment processor. We never see, collect, or store your card number, bank details, or billing address. We receive from the processor only a customer identifier, subscription status, and transaction confirmation.

1.3 Usage Counts

To enforce plan limits (for example, weekly free-tier limits), we store a simple numeric count of how many lesson plans your account has generated in the current period. These counts contain no content, no timestamps beyond a period start date, and no information about what you planned.

1.4 Technical Information

Like most web services, our hosting and infrastructure providers may temporarily process standard technical data such as IP addresses, browser type, and request logs for security, abuse prevention, and operational purposes. We do not use this data for advertising or profiling.

2. Information We Do NOT Collect

The Service is designed so that the following never touches our database:

3. How Lesson Generation and Storage Works

When you request a lesson plan, your input (state, grade, course, standards, topic, and optional classroom notes) first passes through our automated privacy filter, which swaps names for labels and removes contact details and IDs. The scrubbed input is then sent over an encrypted connection to our large language model provider solely to generate the response. Under our configuration and their API terms, inputs are not used to train models and are not retained by the provider beyond transient processing and short-lived abuse-prevention logs.

The generated plan is saved to your account library, in its scrubbed form, so you can return to it, revise it, and build materials (exit tickets, quizzes, worksheets) from it. Plans stay in your library until you delete them; deleting a plan removes the row and its materials from our database for good.

4. How We Use Information

We use the limited information we hold only to:

We do not sell personal information. We do not rent personal information. We do not build advertising or behavioral profiles of teachers or students, and your account content is never used for advertising.

5. Student Privacy: FERPA, COPPA, and State Laws

5.1 FERPA

The Family Educational Rights and Privacy Act (20 U.S.C. § 1232g) governs how schools share education records with vendors. The Service is designed so that schools and teachers can use it without disclosing any FERPA-protected records to us: we do not request, receive, or store education records or student personally identifiable information. If a user nevertheless types student-identifying information, the automated filter swaps names for labels and removes contact details and IDs before that input is used or stored, as described in Section 3. Districts may request our standard Data Processing Addendum at legal@lessonplanningforteachers.com.

5.2 COPPA

The Service is directed to educators, not children. Only adults may create accounts, students never log in, and children never interact with the AI system. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us at privacy@lessonplanningforteachers.com and we will delete it.

5.3 State student privacy laws

Our practices align with state student privacy statutes modeled on SOPIPA (including California SOPIPA, New York Education Law § 2-d, and similar laws): no sale of student data, no targeted advertising, no non-educational profiling, and no retention of student information. Because stored content contains labels instead of student names, most obligations these laws impose on vendors are satisfied by architecture rather than by policy alone.

6. Third-Party Service Providers (Subprocessors)

We work with a small number of service providers in the categories below. Each receives only the data its role requires, under contract, and nothing more.

Service categoryData they handle
Authentication and database hostingAccount email, hashed credentials, usage counts, entitlement records, saved plans (name-scrubbed), saved classroom preferences
Payment processingPayment details (collected directly by the processor); we receive status only
AI model inferenceLesson request inputs, processed transiently; not used for model training
Application hostingStandard technical request data
Optional sign-in providersBasic profile information you authorize during sign-in
Advertising measurementPage visits and sign-up events on our website, with standard cookie and device identifiers
Product analytics and session replayPage views, clicks, and screen recordings of product use; typed text is masked and the name swap list is excluded

Schools and districts can request the current named subprocessor list as part of a Data Processing Addendum at legal@lessonplanningforteachers.com.

We may also disclose information if required by law, regulation, or valid legal process, or to protect the rights, safety, and security of the Service and its users.

7. Cookies

We use strictly necessary cookies (the authentication session cookies that keep you signed in) plus the two measurement tools below.

An advertising measurement pixel, provided by a social media advertising platform. The pixel sets its own cookies and processes page-visit and account-signup events on our website. We use it to measure our own advertising. It does not receive your plans, notes, classroom content, or anything you type into the planner. You can block it with any standard tracker blocker or through the platform’s ad preferences, and the Service works exactly the same without it.

A product analytics and session replay tool. It records pages visited, features used, and recordings of product use so we can analyze and improve the Service. Recordings mask everything you type, the name swap list is excluded from recordings entirely, and any plan visible on screen is the scrubbed version with labels instead of names. These events travel through a domain we operate, and you can block them with any standard tracker blocker; the Service works exactly the same without it.

8. Data Retention

DataRetention
Saved lesson plans and materials (name-scrubbed)Until you delete the plan or your account.
Chat transcripts and revision messagesNever stored. They exist only in your browser session.
Saved classroom preferences (last-used course, grade, standards)Until you change them or delete your account.
Account information (email, hashed password)Until you delete your account.
Usage countsRolling periods only; purged within 14 days of period end.
Analytics events and session recordingsHeld by our analytics provider under our retention settings; recordings roll off automatically after a short retention period. Email us to delete your analytics profile sooner.
Subscription and entitlement recordsDuration of subscription plus the period required by tax and accounting law.

9. Your Rights and Choices

Depending on your jurisdiction (including under GDPR, UK GDPR, CCPA/CPRA, and similar laws), you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. Because we hold so little data, most requests are simple:

We do not sell personal information, and we have not sold personal information in the preceding 12 months. The measurement tools described in Section 7 share limited usage data with our advertising and analytics providers; you can opt out of both at any time with a standard tracker blocker, and your plans are never part of ad targeting.

10. Security

We use encryption in transit (TLS), hashed credential storage, row-level security on our database, and least-privilege access controls. Our primary security control, however, is architectural: names are scrubbed from content before it is stored, chat transcripts are never stored, and you can delete any plan at any time. No method of transmission or storage is 100% secure, but we have minimized what exists to attack.

11. International Users

The Service is operated from the United States and is intended for US educators. If you access it from elsewhere, you understand that your limited account information will be processed in the United States.

12. Changes to This Policy

If we make material changes, we will notify you by email or a prominent notice in the Service at least 14 days before the change takes effect. We will never retroactively weaken the privacy commitments that applied to content you stored before a policy change.

13. Contact

Novastone AI LLC
Email: privacy@lessonplanningforteachers.com
Website: lessonplanningforteachers.com

For district procurement and Data Processing Addendum requests: legal@lessonplanningforteachers.com