US Privacy & Compliance
Last updated: 9 September 2026
Processing and retention — 9 September 2026
Guide drafting and content review use Luna as the primary model, with Gemini as the configured backup, through OpenRouter. Safeguarding uses Llama Guard and, when needed, a separate Gemini curriculum reviewer. Model developers and the companies operating inference endpoints are not necessarily the same.
Our OpenRouter account has zero data retention (ZDR) enabled, and requests also require ZDR inference endpoints. This applies to provider processing of prompts and outputs, including retries and fallback. It does not delete your saved AILitKit guides, account records or necessary service metadata. OpenRouter permits temporary in-memory prompt caching under its ZDR policy.
Before new generation, automated safeguarding checks read the subject, stage, year group and topic, plus up to the first 1,000 characters each of the teacher description and extracted upload text. Llama Guard gives a first verdict; a Gemini reviewer runs if that verdict is unsafe, unavailable or unreadable. An additional direct OpenAI moderation check runs when configured, under its separate API terms. If no usable safeguarding verdict is available, generation pauses with a retry message. A usable unsafe verdict is preserved if its reviewer fails; hard-block categories cannot be cleared by that reviewer.
Before saving a newly generated guide, automated checks review lesson fit, accuracy, activity logic, resources, pupil language and AI literacy. Up to four batches inspect the draft against the teacher brief; one correction cycle is allowed, followed by another review of all batches. Failed or unavailable review prevents the new guide from being saved. Saved review evidence and resolved findings may quote the brief or draft. These checks can miss errors and are not human approval or a dedicated final-output safety classifier. Existing guides are not retrospectively checked; eligible saved guides may be reused.
Pupil-facing language is targeted using the year group or key stage supplied by the teacher. This is a class-level assumption, not an individual reading-age assessment. Teachers must adapt wording and resources for their actual readers, including SEND and EAL needs, and check third-party tools, links and safeguarding before classroom use.
While a guide is being built, its job record holds the request needed for processing and retries. On completion, failure or expiry, that record loses its input payload and duplicate output. Identifiers, scope, status, timings, usage and support diagnostics remain temporarily: completed jobs are eligible for deletion after 24 hours, and failed or expired jobs after seven days, at the next successful cleanup. The saved guide, its input description and review evidence follow the guide retention period.
After successful generation, cleanup deletes the original uploaded file and clears the extracted text from the upload record, keeping filename, type and date. Unused uploads and failed cleanup are eligible for the scheduled sweep once the upload is over one hour old. The sweep runs every 15 minutes; deletion can take longer if a cleanup attempt fails. Relevant source-derived material can remain in the saved guide and its review evidence.
Guide generation does not grade pupils, decide admissions or progression, or assess individual learners. Automated service checks do decide whether a request can proceed and whether a draft passes review. A second AI model is not human intervention. You can ask a person to review a refusal or flag by contacting hello@ailitkit.com or safeguarding@ailitkit.com; we aim to respond within five working days. A content flag is not a finding of misconduct by a teacher.
Do not enter identifiable pupil information, assessment records, safeguarding records, EHCP/SEN documents or staff personal data. AILitKit needs curriculum content only. Warnings and input cleaning do not guarantee anonymisation: information entered accidentally can still be processed and appear in a saved guide or audit evidence. Contact hello@ailitkit.com promptly if this happens.
Safeguarding audit retains a classifier explanation that may refer to screened content; ALLOW has no input snapshot, while flagged decisions additionally retain topic and a short description excerpt. Saved guide review evidence follows the guide retention period, including its 30-day undo window. Hosting logs and backups have separate service schedules. The school reviewer should obtain the current processor, transfer and retention evidence and record their own risk decision.
Key position
AILitKit is for adult teachers planning lessons. Student accounts and education records are not required. Teachers must remove identifying information before submission; accidental inclusion can still lead to processing. Schools should assess their own use and applicable obligations.
FERPA (Family Educational Rights and Privacy Act)
Does AILitKit access student education records? No. AILitKit processes only teacher-provided curriculum materials: lesson plans, schemes of work, and topic descriptions. Do not submit student grades, attendance, disciplinary information or other identifiable records. Accidental input is possible and should be reported.
FERPA designation: The district should assess its actual intended use and the applicable vendor agreement. Curriculum-only planning does not establish a blanket exemption if identifiable education records are submitted.
Directory information: Do not include student identifiers; staff account information is described in our privacy policy.
COPPA (Children's Online Privacy Protection Act)
Is AILitKit directed at children under 13? No. AILitKit is designed exclusively for adult teachers. The platform's interface, content, and functionality are all designed for professional educator use.
Does AILitKit collect information from children under 13? No. Children do not access the platform. There are no student-facing features, no student accounts, and no mechanism for children to submit information.
Parental consent: Not required. No child users interact with the platform.
CCPA (California Consumer Privacy Act)
California residents have the following rights regarding personal information we collect about teacher accounts:
- Right to know: You can request details of what personal information we collect. See our Privacy Policy for a complete inventory.
- Right to delete: You can delete your account and all associated data from your account settings, or by contacting us.
- Right to opt out of sale: We do not sell personal information to third parties.
- Non-discrimination: We will not discriminate against you for exercising your CCPA rights.
State privacy laws
Many US states have enacted or are enacting student data privacy laws (e.g. SOPIPA in California, SHIELD Act in New York). AILitKit's position is consistent across all state laws: we do not collect student data. The platform processes only teacher professional content for curriculum planning purposes.
Data practices summary
| Question | Answer |
|---|---|
| Student data collected? | No |
| Student accounts? | No |
| Data sold to third parties? | No |
| Data used for advertising? | No |
| AI data retention? | Zero retention |
| Account deletion available? | Yes, within 30 days |
Vendor privacy assessment
If your district requires a formal vendor privacy assessment, a pre-filled assessment is available from your account settings under Data Protection. This document answers the standard questions districts ask when evaluating ed-tech vendors.
Contact
For compliance questions or to request documentation for your district, contact hello@ailitkit.com.