TeacherLens Trust Center

Designed to support school or board review with data minimization, teacher review gates, vendor transparency, and privacy-aware AI routing. This packet is not a substitute for legal, district, board, or procurement review.

Compatibility and Integration Status

Fits the tools schools already use—on purpose, and with clear boundaries.

TeacherLens starts with a reliable teacher-controlled handoff, then adds native connections only after scoped testing, administrator review, and required platform verification. A familiar product name below does not mean endorsement, certification, or an automatic data connection.

Integration status reviewed 2026-08-24.

Use Lesson Capture with your school platform today

  1. Review the lesson capture and approve the exact output.
  2. Copy the reviewed text—or, where shown, download a PDF or DOCX.
  3. Paste or upload it yourself in your school-approved learning or communication platform.

TeacherLens does not open your LMS, read its data, or post anything automatically. You decide what is shared.

Default controls

  • Nothing posts to an LMS, classroom, calendar, email, or family channel by default.
  • Teachers review Lesson Capture outputs before copying, downloading, uploading, or sharing them.
  • Native integrations must disclose the exact data they read, the actions they can take, and who approves access.
  • Pre-launch and planned connections remain labeled as unavailable until verified in the deployed product.

Status definitions

  • Available now — copy or download. A current TeacherLens workflow that does not require a native connection.
  • Deployment-controlled. Implemented, but an environment switch or pilot allowlist may limit availability.
  • Pre-launch. Built behind a hard gate and not available to public users.
  • Planned—not yet available. A roadmap target that will not be described as compatible until tested and verified.

Teacher-controlled handoff - Available now — copy or download

Tools and destinations: Google Classroom, Microsoft Teams, Brightspace / D2L, Canvas, Schoology, Moodle, Gmail / Outlook / Edsby, Other LMS.

Review a lesson recap, student study notes, practice next steps, or family summary, then copy the text—or, where shown, download a DOCX or PDF—for the destination you choose.

  • Data read: No data is read from the destination.
  • Actions taken: No automatic posting. The teacher chooses whether to copy, upload, or send the reviewed output.
  • Who approves: The teacher reviews the source capture and the final output before sharing.
  • Current boundary: Copy or upload only. This is a portable handoff—not a native LMS connection or automatic post.

Google account sign-in - Deployment-controlled

Tools and destinations: Google Identity.

Teachers can use a Google account for identity-only sign-in when Google authentication is enabled for the deployment.

  • Data read: Basic identity details authorized during sign-in, such as account ID, name, email, and profile.
  • Actions taken: Creates or links a TeacherLens account session and stores the encrypted authentication tokens and scopes needed for sign-in. It does not read Classroom rosters or post to Google Classroom.
  • Who approves: The user consents to sign-in. Deployment switches and pilot allowlists can restrict access.
  • Current boundary: Identity sign-in is separate from Google Classroom access and does not grant Classroom permissions.

Native Google Classroom workflows - Pre-launch

Tools and destinations: Roster import, Classroom posting, Student SSO.

Native Classroom features are built behind a code-level and environment-level gate while verification and trusted-app rollout paths are evaluated.

  • Data read: No Classroom data is read while the feature is gated off.
  • Actions taken: No lessons, announcements, roster changes, or student sign-ins are enabled while the feature is gated off.
  • Who approves: Future access would require teacher consent plus any school administrator and Google verification requirements.
  • Current boundary: Not available to public signups and not advertised as Google Classroom compatible.

Standards-based LMS and roster connections - Planned—not yet available

Tools and destinations: LTI 1.3 / LTI Advantage, OneRoster 1.2, Enterprise identity.

The priority district path is standards-based launch, roster, and identity support instead of one-off integrations for every school system.

  • Data read: No LMS, SIS, roster, or identity data is read through these standards today.
  • Actions taken: No grades, resources, memberships, or launch records are written through these standards today.
  • Who approves: A future rollout would require scoped implementation, security review, administrator configuration, interoperability testing, and applicable certification.
  • Current boundary: Roadmap only. TeacherLens does not currently claim LTI, OneRoster, or enterprise SSO certification.

Native Microsoft 365 education workflows - Planned—not yet available

Tools and destinations: Microsoft Graph, Teams for Education, Microsoft Entra ID.

A future Microsoft path may support identity, classes, assignments, and teacher-authorized handoff through Microsoft education APIs.

  • Data read: No Microsoft class, roster, assignment, or directory data is read through a native connection today.
  • Actions taken: No Teams assignments, class resources, or directory records are written through a native connection today.
  • Who approves: A future rollout would require tenant administrator consent, least-privilege scopes, school review, and staged verification.
  • Current boundary: Roadmap only. Current Microsoft Teams use is the teacher-controlled copy/download handoff above.

Privacy controls

  • No student emails required. Core TeacherLens and classroom workflows do not require student email accounts.
  • Private aliases by default. Students can be represented with initials, private aliases, and class-level notes instead of full names.
  • Lesson Capture review gate. TeacherLens does not persist raw audio after the transcription request. Audio is processed by the configured provider under the selected routing policy; provider retention depends on that configuration. Transcript and analysis outputs remain teacher-reviewed, and student-facing creation stays blocked until privacy review is complete.
  • Roster aliasing. Roster imports reduce names and student numbers to private classroom aliases before preview, commit, storage, export, or generation handoff.
  • Teacher-reviewed sharing. Resources, notes, and Lesson Capture outputs are drafted for teacher review before anything is copied, exported, or shared with students or families.
  • Export and deletion workflows. Teacher-owned profile, roster, Lesson Capture, and saved Studio resource workflows include export or deletion paths subject to backup, security, billing, contract, and legal retention limits.

Privacy Framework Review Map

TeacherLens is designed to support school, board, district, and legal review against these frameworks. This map describes product controls for review and is not a legal conclusion.

  • PIPEDA (Canada private-sector privacy review). Review focus: Consent, limiting collection, safeguards, access/correction, retention, and accountable privacy practices for commercial services. TeacherLens controls: data minimization with no student emails required for core workflows; privacy-aware provider routing; raw capture audio is sent to the configured transcription provider, then transcript text is sanitized before downstream analysis and storage; teacher-owned export and deletion workflows subject to legal, security, backup, billing, and contract limits. Official reference: Office of the Privacy Commissioner of Canada - PIPEDA
  • Ontario MFIPPA + Education Act (Ontario school-board and education-record review). Review focus: School-board collection, use, disclosure, access, security, retention, and student-record obligations. TeacherLens controls: school-review packet, DPA/vendor questionnaire path, and data-residency review support; class-level Lesson Capture analysis with teacher review gates before student-facing sharing; roster imports reduced to first-name initials or private aliases before storage or generation handoff. Official reference: IPC Ontario - Ontario's access and privacy legislation
  • FERPA + PPRA (United States school privacy review). Review focus: Education-record access/disclosure, school official/vendor review, parent/student rights, and survey/assessment-related privacy review. TeacherLens controls: teacher-reviewed resources and school-controlled sharing paths; no student email requirement for core classroom workflows; support for school procurement review, vendor questions, and retention/deletion review. Official reference: U.S. Department of Education - Student Privacy Policy Office
  • COPPA (United States child privacy and school consent review). Review focus: Parental notice/consent, school-authorized educational use, data minimization, and child-directed service review. TeacherLens controls: core student workflows avoid student email accounts; teacher and school review gates before student-facing sharing; privacy policy, Trust Center, and support contact paths for school notice and procurement review. Official reference: FTC - Children's privacy guidance

Subprocessor and Vendor Review

  • Hosting and database infrastructure. Purpose: Operate the application, database, storage, logging, security controls, and uptime monitoring. Student data exposure: May process account, class, resource, transcript, and operational data needed to provide the service.
  • AI routing and transcription. Purpose: Route generation, transcription, image, and structured analysis tasks through model providers using OpenRouter as the provider surface. Student data exposure: Raw capture audio is sent through OpenRouter to the configured transcription provider because text does not yet exist to redact. The resulting transcript is sanitized before downstream text analysis and storage; automated screening reduces, but cannot guarantee removal of, names, identifiers, and private support details.
  • Teacher sign-in and school-approved tools. Purpose: Provide teacher sign-in and, where supported, separately reviewed calendar or classroom workflows. Student data exposure: Google sign-in is identity-only. Direct Google Classroom roster import, posting, and student sign-on are not currently available. Any future connected workflow requires product support plus the required teacher, provider, and district approvals.
  • Payments and billing. Purpose: Process subscription status, invoices, payment events, tax records, and billing receipts. Student data exposure: Student classroom content is not needed for billing.
  • Support and email. Purpose: Handle teacher support requests, school review questions, privacy operations, and incident follow-up. Student data exposure: Teachers are instructed to avoid sending raw student records in support messages.

AI routing

Provider surface: OpenRouter.

TeacherLens uses OpenRouter as server-side infrastructure for model routing, not as resold raw API access. Provider details are documented for school review while normal teacher/student screens stay focused on product outcomes.

  • data_collection: deny where supported
  • require_parameters: true where supported
  • zdr: true when the deployment environment requires zero-data-retention routing
  • task-specific model routing so routine work can use lower-cost models while QA and repair preserve quality
  • no provider names, model names, or internal cost receipts in normal teacher/student UI

Normal teacher and student screens do not expose provider or model names; provider details live in admin review surfaces such as the Trust Center.

Lesson Capture Handling

  • TeacherLens does not persist raw audio after the transcription request. Audio is processed by the configured provider under the selected routing policy; ZDR applies only when configured and available.
  • A sanitized transcript review draft and its analysis are stored immediately so the teacher can review them. By default, scheduled cleanup deletes an unreviewed draft after 24 hours; a configured or written school policy may set another deadline. Reviewed captures remain available until the teacher deletes them or a written school-pilot retention schedule requires earlier deletion.
  • Unreviewed review drafts: by default, scheduled cleanup removes them after 24 hours if teacher review is not completed; a configured or written school policy may set another deadline. Cleanup receipts keep only counts and capture ids, not transcript, title, analysis, or student evidence text.
  • Privacy flags block student-facing generation until the teacher reviews or redacts the capture.
  • TeacherLens asks teachers to use first-name initials or neutral aliases and applies automated redaction to common full-name and student-ID patterns before Lesson Capture outputs are stored. Automated screening can miss uncommon, ambiguous, or context-free names, so it is a risk-reduction control, not a guarantee. Teachers must review the capture and remove any remaining personal details before marking it reviewed or sharing it.

Questions for School Review

  • DPA or vendor questionnaire
  • Named subprocessor table
  • Data-residency review
  • Breach or incident contact path
  • AI-provider and model-routing explanation
  • Retention and deletion workflow review

Public Review Packet

Download school-review packet - Markdown packet for school or board privacy, vendor, AI-routing, and Lesson Capture review.