Charlotte AI

Privacy at Charlotte AI

Charlotte AI keeps classroom data focused on reading practice. We collect the minimum information needed to run teacher accounts, student accounts, class rosters, assignments, and progress reports.

What We Store

  • Teacher name, email, and hashed password.
  • Student name, email, and hashed password for standard classes.
  • For recovery-key protected classes: student numbers, encrypted identity data, and a one-way email lookup hash.
  • Classroom names, grade level, assignments, uploaded reading text, and question data.
  • Student answers, attempts, completion status, and scores for teacher review.
  • Contact requests: name, email, grade level, and optional phone or school.

What We Avoid

  • No ads, ad tracking, or student behavior profiles.
  • No student phone numbers, addresses, birthdates, or payment details.
  • No uploaded original files kept after text extraction.
  • No API keys or secrets in browser code.
  • No raw classroom recovery keys stored by Charlotte.

How We Protect It

  • HTTPS-only production traffic and HTTP-only session cookies.
  • Managed cloud hosting and managed Postgres with provider encryption controls.
  • Teacher-held classroom recovery keys for database-anonymous student rosters.
  • Class-scoped teacher and student access checks on every protected route.
  • Rate limits, bot checks, dependency scanning, and security headers.

Retention

  • Contact requests are automatically removed after the configured retention window.
  • Classroom records remain available to teachers until they archive or delete them.
  • Students can keep one simple account for every class their teacher enrolls them in.