Effective August 29, 2026
Privacy Policy
This policy explains how My Assessment Tool processes educator account information and educator-entered student records.
Service audience
My Assessment Tool is an educator service for authorized adults. Children do not create accounts, sign in, or use the service directly.
Information we process
- Educator account information, including name, organization, email address, role, authorization acknowledgement, and authentication information.
- School-authorization information, including the organization and the name and title of its authorization contact.
- Educator-entered student records, including a first name or local alias, optional last name, exact birth date, classroom, notes, tags, assessment responses, scores, and progress history.
- Custom assessment templates and educator-entered assessment notes.
- Subscription status and provider identifiers. Payment card information is processed by Stripe, Apple, or Google and is not stored by My Assessment Tool.
- Security and operational information, including IP address, device or browser details, request identifiers, event type, and timestamps.
Purposes
Student records are used only to provide the educational assessment service requested by the authorized educator or organization. Exact birth date is used to calculate and display the student's current age. We do not sell student information, use it for targeted advertising, create commercial profiles from it, or use it for an unrelated commercial purpose.
Authorization
When the operator-reviewed school authorization workflow is enabled for an account or deployment, identifiable student records cannot be added or changed until the account holder acknowledges authorized educational use and the school or organization authorization is approved. Regardless of whether that additional workflow is enabled, account holders must have authority to use the service with the student information they enter. This process does not transfer My Assessment Tool's obligations as the service operator to a teacher, school, or parent. See the Student Data Notice for the notice provided to schools and organizations.
Analytics and application logs
Google Analytics is limited to an allowlist of general educator feature events on the production web application. Analytics events do not contain student or educator names, emails, birth dates, student identifiers, classroom identifiers, assessment responses, notes, or scores. Application request logs record field names and operational metadata rather than request or response contents.
Service providers and disclosures
Student information may be processed by infrastructure providers that host the application, database, and encrypted backups, and by authorized support personnel when necessary to resolve a request. Google reCAPTCHA processes security signals during authentication. Google Analytics, Stripe, RevenueCat, Apple, Google Play, and email providers are not sent student records by the application. Information may also be disclosed when required by law or in a business transfer subject to applicable student-data restrictions.
Review, correction, export, and deletion
Authorized educators can review and correct student records in the application, export a student's record from the student profile, archive records, or permanently delete the student and the student's assessments and responses. Account deletion permanently removes the account's student records, assessments, custom content, connected support accounts, and profile from the primary database. See Delete your account and data for the in-app deletion steps, alternate support request process, and applicable retention periods. Schools may ask us to review, export, correct, delete, or stop further collection of their student information. Parent or eligible-student requests may be routed through the school so authority and record ownership can be verified.
Retention
- Active student records are retained while the authorized account remains active and the records are needed for the stated educational purpose.
- Archived student records are permanently deleted after three years unless the educator deletes them sooner.
- A permanent student or account deletion removes the applicable records from the primary database immediately. Encrypted backup copies expire within 30 days and are not restored except for disaster recovery.
- Privacy audit events are retained for one year. Expired authentication and password-reset records are removed on a scheduled basis.
- Payment providers may retain transaction records under their own legal and financial obligations.
Security
We use access controls, tenant ownership checks, password hashing, short-lived access tokens, encrypted transport, restricted logs, authenticated billing webhooks, privacy audit events, and deletion procedures intended to protect student information. Access is limited to the account owner and support users connected by the account owner. No online system can guarantee absolute security.
Policy changes
Material changes to student-data collection, use, disclosure, or retention will be reflected here and presented for a renewed account acknowledgement where appropriate.
Privacy contact
Email support@myassessmenttool.net for privacy requests or school review materials. Do not send student records or sensitive information through unencrypted email.
