Student information is not required
Students do not need accounts for the core teacher workflow. Optional roster names used for per-student printing remain in the browser on the teacher's device. Class labels, saved materials, class displays, and Community content can be stored, so users must not type student names, grades, IEP or medical information, discipline records, or other student personal information into those fields.
The guarantees that matter to an administrator
These statements describe behavior verified in the current code. Deployed configuration and vendor contracts still require operational verification.
No student login required
Teacher accounts control creation. A teacher may present content through a public class-display surface, but students do not create accounts for that feature. This product design is not a legal conclusion about COPPA, FERPA, or district approval.
Encryption
Network traffic uses HTTPS/TLS. Google connection tokens are encrypted by the application with AES-GCM before storage when that integration is configured. Cloudflare supplies the hosting and D1 platform controls described in its own documentation.
AI requests are limited to the task
Generation sends the selected standards context or custom topic, teacher instructions, and any source text needed for the request to the configured AI provider. Some document types may include a teacher or school name when requested. Provider retention and training terms must match the actual deployed contract before they are stated as guarantees.
Data minimization
The service can store account and teaching profiles, class labels, saved resources, class displays, Google connections and export history, teams, posts, messages, rooms, reactions, mentions, reports, and security records. The optional local roster is separate from the synced class profile.
Your data, your control
The account drawer provides self-service controls. Each control must report failures honestly.
Export anytime
Download the account categories included by GET /api/account/export. Operational security records and copies at external destinations may be excluded; the export should identify its scope.
Delete anytime
Request deletion from Account drawer → Delete. The backend must return an error if a required account-data deletion fails instead of reporting a false success.
Minimize data and confirm local requirements
Teachers can use the core creation workflow without entering student records.
Subprocessors
The code supports these provider categories. Confirm the deployed list and contract terms during evaluation.
| Provider | What it does | Notes |
|---|---|---|
| Cloudflare | Hosting, Worker execution, D1 database, and optional Workers AI generation. | Core infrastructure provider. |
| Configured AI provider | AI generation and transformation. | May be Anthropic, a configured OpenAI-compatible endpoint, or Cloudflare Workers AI. Receives task context, instructions, and source text required for generation. |
| Google (Drive export) | Optional export to Google Drive / Docs / Slides. | Only when you connect Google and choose to export. We request the drive.file scope — per-file access to files you create with TeachersPlan, not access to your whole Drive. |
| Transactional email provider | One-time sign-in codes and requested email delivery. | The deployed provider must be confirmed operationally. |
Infrastructure claims belong to the provider
Talk to us — and tell us if you find something
Administrators can ask whether a current Data Processing Agreement (DPA) is available and send security questions to [email protected]. Do not assume an agreement exists until it is provided and executed.
Responsible disclosure: if you're a researcher and you find a vulnerability, email [email protected]. We welcome good-faith security research and will not pursue legal action against researchers who report responsibly.