# TeacherLens Trust Center Packet

Product: TeacherLens
Owner: Milestone Teachers
Last reviewed: 2026-06-15

Designed to support school or board review with data minimization, teacher review gates, vendor transparency, and privacy-aware AI routing. This packet is not a substitute for legal, district, board, or procurement review.

## Privacy Controls
- **No student emails required.** Core TeacherLens and classroom workflows do not require student email accounts.
- **Private aliases by default.** Students can be represented with initials, private aliases, and class-level notes instead of full names.
- **Lesson Capture review gate.** Raw lesson audio is discarded after transcription. Transcript and analysis outputs remain teacher-reviewed, and student-facing creation stays blocked until privacy review is complete.
- **Roster aliasing.** Roster imports reduce names and student numbers to private classroom aliases before preview, commit, storage, export, or generation handoff.
- **Teacher-reviewed sharing.** Resources, notes, and Lesson Capture outputs are drafted for teacher review before anything is copied, exported, or shared with students or families.
- **Export and deletion workflows.** Teacher-owned profile, roster, Lesson Capture, and saved Studio resource workflows include export or deletion paths subject to backup, security, billing, contract, and legal retention limits.

## Privacy Framework Review Map
TeacherLens is designed to support school, board, district, and legal review against the following frameworks. This map describes product controls for review and is not a legal conclusion.

- **PIPEDA (Canada private-sector privacy review).** Review focus: Consent, limiting collection, safeguards, access/correction, retention, and accountable privacy practices for commercial services. TeacherLens controls: data minimization with no student emails required for core workflows; privacy-aware provider routing and server-side redaction before AI handoff; teacher-owned export and deletion workflows subject to legal, security, backup, billing, and contract limits. Official reference: [Office of the Privacy Commissioner of Canada - PIPEDA](https://www.priv.gc.ca/en/privacy-topics/privacy-laws-in-canada/the-personal-information-protection-and-electronic-documents-act-pipeda/pipeda_brief/)
- **Ontario MFIPPA + Education Act (Ontario school-board and education-record review).** Review focus: School-board collection, use, disclosure, access, security, retention, and student-record obligations. TeacherLens controls: school-review packet, DPA/vendor questionnaire path, and data-residency review support; class-level Lesson Capture analysis with teacher review gates before student-facing sharing; roster imports reduced to first-name initials or private aliases before storage or generation handoff. Official reference: [IPC Ontario - Ontario's access and privacy legislation](https://www.ipc.on.ca/en/education/ontarios-access-and-privacy-legislation)
- **FERPA + PPRA (United States school privacy review).** Review focus: Education-record access/disclosure, school official/vendor review, parent/student rights, and survey/assessment-related privacy review. TeacherLens controls: teacher-reviewed resources and school-controlled sharing paths; no student email requirement for core classroom workflows; support for school procurement review, vendor questions, and retention/deletion review. Official reference: [U.S. Department of Education - Student Privacy Policy Office](https://studentprivacy.ed.gov/)
- **COPPA (United States child privacy and school consent review).** Review focus: Parental notice/consent, school-authorized educational use, data minimization, and child-directed service review. TeacherLens controls: core student workflows avoid student email accounts; teacher and school review gates before student-facing sharing; privacy policy, Trust Center, and support contact paths for school notice and procurement review. Official reference: [FTC - Children's privacy guidance](https://www.ftc.gov/business-guidance/privacy-security/childrens-privacy)

## Subprocessor and Vendor Review
The exact named vendor list can change as infrastructure, contracts, and school requirements evolve. These categories are maintained for school review before larger rollout.

- **Hosting and database infrastructure.** Purpose: Operate the application, database, storage, logging, security controls, and uptime monitoring. Student data exposure: May process account, class, resource, transcript, and operational data needed to provide the service.
- **AI routing and transcription.** Purpose: Route generation, transcription, image, and structured analysis tasks through model providers using OpenRouter as the provider surface. Student data exposure: Uses minimized teacher-reviewed prompts where possible; privacy flags and server-side sanitizers reduce names, student identifiers, and private support details before AI handoff.
- **Authentication and connected classroom tools.** Purpose: Provide teacher sign-in and optional teacher-authorized integrations such as Google Classroom, Google Calendar, or Outlook Calendar. Student data exposure: Only active when the teacher authorizes the integration; planner/calendar workflows save class-level planning memory, not raw private event details.
- **Payments and billing.** Purpose: Process subscription status, invoices, payment events, tax records, and billing receipts. Student data exposure: Student classroom content is not needed for billing.
- **Support and email.** Purpose: Handle teacher support requests, school review questions, privacy operations, and incident follow-up. Student data exposure: Teachers are instructed to avoid sending raw student records in support messages.

## AI Routing
Provider surface: OpenRouter

TeacherLens uses OpenRouter as server-side infrastructure for model routing, not as resold raw API access. Provider details are documented for school review while normal teacher/student screens stay focused on product outcomes.

Safeguards:
- data_collection: deny where supported
- require_parameters: true where supported
- zdr: true when the deployment environment requires zero-data-retention routing
- task-specific model routing so routine work can use lower-cost models while QA and repair preserve quality
- no provider names, model names, or internal cost receipts in normal teacher/student UI

Teacher-facing rule: Normal teacher and student screens do not expose provider or model names; provider details live in admin review surfaces such as the Trust Center.

## Lesson Capture
- Raw lesson audio is discarded after transcription.
- Transcript and analysis are retained only when the workflow allows it after teacher review.
- Unreviewed review drafts: scheduled cleanup removes them after 24 hours if teacher review is not completed. Cleanup receipts keep only counts and capture ids, not transcript, title, analysis, or student evidence text.
- Privacy flags block student-facing generation until the teacher reviews or redacts the capture.
- Student names are never retained as full names. TeacherLens uses first-name initials only when the first-name signal is clear, such as Ava Singh becoming A. or Singh Aanya becoming A. because Aanya is the first-name signal. Last-name-only and ambiguous names stay neutral, such as A student or Student 001, and are not turned into last-name initials like S. Full first names, full last names, and student IDs are not stored in Lesson Capture outputs.

## Questions for School Review
- DPA or vendor questionnaire
- Named subprocessor table
- Data-residency review
- Breach or incident contact path
- AI-provider and model-routing explanation
- Retention and deletion workflow review

## Review Links
- [Privacy Policy](/privacy)
- [Security Summary](/security)
- [Terms of Service](/terms)
- [Trust Center](/trust-center)

## Public Review Packet
[Download school-review packet](/downloads/teacherlens/teacherlens-trust-center-packet.md)

Markdown packet for school or board privacy, vendor, AI-routing, and Lesson Capture review.

## External References
- [OpenRouter provider routing](https://openrouter.ai/docs/guides/routing/provider-selection)
- [OpenRouter data collection](https://openrouter.ai/docs/guides/privacy/data-collection)
- [U.S. Department of Education FERPA](https://studentprivacy.ed.gov/ferpa)
- [FTC children's privacy guidance](https://www.ftc.gov/business-guidance/privacy-security/childrens-privacy)

## Claims We Do Not Make
- privacy-law compliance badge language
- ready-for-all-student-privacy-laws badge language
- formal certification language
- school-system approval claim language
- single-country storage guarantee language
- no-risk security language
- guaranteed legal-compliance language
