Privacy Policy

SPU Stewardship Holdings LLC (Delaware) · d/b/a S.T.E.W.A.R.D. Consulting
Effective: April 2026

Who we are

S.T.E.W.A.R.D. Tutor is a K-12 AI tutoring platform for Mathematics and English Language Arts, grades 3-8, operated by SPU Stewardship Holdings LLC, a Delaware limited liability company, doing business as S.T.E.W.A.R.D. Consulting.

What we collect

Teacher data: Name, email address, and school affiliation via Google OAuth, Clever SSO, or ClassLink SSO. Used solely for account management and platform administration.

Student data: First name only (no last name), grade level, classroom assignment, a hashed PIN (the PIN itself is never stored), and learning interactions (questions, responses, mastery progress). We do not collect student email addresses, phone numbers, social media accounts, location data, or biometric data.

IEP/504/ELL accommodation data: Instructional accommodation flags only (e.g., "extended time," "text-to-speech"). We never store full IEP/504 documents, diagnosis information, or disability categories. Accommodation flags are encrypted at rest using AES-256-GCM field-level encryption.

What we NEVER do

FERPA compliance

For schools and districts, we operate under the "school official" exception (34 CFR § 99.31(a)(1)). Student education records are accessible only to the assigned teacher and authorized school administrators. We execute Data Processing Agreements (DPAs) with districts in all 12 supported states.

COPPA compliance

For students under 13, we obtain verifiable parental consent through either the teacher's school consent authority or our built-in parental consent workflow. Under the updated COPPA rule effective April 22, 2026, we provide separate consent for any AI-related data processing beyond the educational service.

COPPA 2.0 commitment: We maintain a written data retention policy, a designated data security coordinator, and conduct annual risk assessments as required by the 2025 COPPA amendments.

Data security

All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Student PINs are hashed using scrypt with per-student random salts. Sensitive fields (IEP accommodations, parent contact info) use AES-256-GCM field-level encryption. Every AI interaction passes through PII scanning, injection detection, input sanitization, and output safety scanning before any data reaches students.

Data retention and deletion

Active student data is retained for the duration of the school's subscription. Upon subscription termination, student data is retained for 90 days to facilitate potential renewal, then permanently deleted. Parents may request immediate deletion of their child's data at any time by contacting [email protected]. Deletion is completed within 72 hours.

State privacy law compliance

We comply with student data privacy laws in all 12 states we serve: Louisiana (La. R.S. 17:3914), Maryland (Md. Code Ann., Educ. §4-131 SOPPA), Mississippi (Miss. Code Ann. §37-1-3), Alabama (Ala. Code §16-1-30.1), Tennessee (Tenn. Code Ann. §49-1-708), Georgia (Ga. Code Ann. §20-2-324.2), Virginia (Va. Code Ann. §22.1-289.07), Washington D.C. (D.C. Code §38-831.01), North Carolina (N.C. Gen. Stat. §115C-401.1), South Carolina (S.C. Code Ann. §59-1-490), Arkansas (Ark. Code Ann. §6-18-109), and Kentucky (Ky. Rev. Stat. §365.734).

Your rights

To exercise any of these rights, contact [email protected].

Contact

SPU Stewardship Holdings LLC
d/b/a S.T.E.W.A.R.D. Consulting
Email: privacy@steward-tutor.local

Terms · COPPA · Data Retention · Home