MiniReportLive

Privacy Policy

MiniReport Live — a product of Learning Innovation Systems, LLC.
Effective Date: August 24, 2026  |  Last Updated: August 24, 2026

MiniReport Live is a classroom tool where students read two short sources on a topic, collect facts organized into focus areas, and write a paragraph for each focus area. We built it for educators, and we take student privacy seriously. This policy explains what data we collect, why, how we protect it, and when we delete it.

The short version: Students never create accounts — just a first name or nickname. All student work is automatically deleted 30 days after a session is created, and teachers can delete it sooner. There are no analytics or tracking scripts of any kind. We do not sell data, serve ads, or build student profiles.

1. Who We Are

MiniReport Live is operated by Learning Innovation Systems, LLC ("LIS," "we," "us," or "our"). "You" refers to any user of MiniReport Live — teachers, students, or school administrators.

2. What Data We Collect

We collect different information depending on your role.

Teachers

Teachers sign in with their EduProtocols Live account (Google sign-in). Through that sign-in we receive and store the teacher's name, email address, and Google account identifier, which are used solely to identify the teacher and associate them with the sessions they create. We also store the sessions a teacher creates: the session topic, the reading sources they provide, the focus-area names they define, join codes, and the scores they assign to student work.

Student Session Data

Students do not create accounts. They join a live session with a short class code shared by their teacher — no login, no email. During a session we collect:

DataPurpose
First name or nicknameShown to the teacher so they can see who has joined and grade work
Focus-area notesThe numbered facts the student collects for each focus area, visible to the teacher
ParagraphsThe student's written paragraph for each focus area, visible to the teacher
Teacher-assigned scoresOptional formative feedback from the teacher (notes pass/fail, paragraph 1–10); never shown to students
Session metadataTimestamps used to run the activity
A random session identifierStored only in the student's own browser (localStorage) so a refresh doesn't lose their place

All student session data above is retained for at most 30 days (see Section 5). We do not collect student email addresses, dates of birth, student ID numbers, device identifiers, IP addresses for tracking purposes, or any other persistent student identifiers.

3. How We Use Data

All data we collect is used exclusively to provide the MiniReport Live service — running the live activity and showing the teacher their class's work. We do not use student data to advertise, to build profiles, to sell to third parties, or to train machine learning models. MiniReport Live contains no analytics, advertising, or tracking scripts of any kind; the only browser storage it uses is functional (keeping a student in their session and a teacher signed in).

4. Where Data Is Stored

We use the following infrastructure providers, which store data in the United States:

ProviderRoleData Stored
SupabaseDatabaseAll session content listed above (teacher sessions, student names, focus-area notes, paragraphs, scores)
CloudflareApplication hostingServes the app; processes requests in transit (not persisted)
Google FirebaseTeacher authentication onlyTeacher name, email, and Google account identifier (the shared EduProtocols Live sign-in). No student data touches Firebase.

All data is transmitted using TLS encryption in transit, and the database is encrypted at rest by Supabase.

5. Data Retention & Deletion

Every session — including all student names, notes, paragraphs, and scores in it — is automatically and permanently deleted 30 days after the session was created. This purge is enforced by a scheduled job at the database level and requires no action from teachers, students, or administrators. Teachers can also delete any session sooner from their dashboard, which immediately and permanently removes all student work in that session. Teacher account data (name, email) is retained while the teacher has an EduProtocols Live account and is deleted on request.

6. FERPA Compliance

MiniReport Live is designed to support schools' compliance with the Family Educational Rights and Privacy Act (FERPA). When a school or district enters into a Data Processing Agreement (DPA) with us, we act as a "school official" with a "legitimate educational interest" under FERPA: we use student data solely for the educational purpose for which it was provided, disclose it to no one except the infrastructure subprocessors listed above (and only as necessary to provide the service), maintain reasonable safeguards, and delete it automatically within 30 days. We are prepared to sign the Student Data Privacy Consortium (SDPC) National Data Processing Agreement or a district's own DPA upon request.

7. COPPA Compliance

MiniReport Live may be used by children under 13 in a school setting. Under the Children's Online Privacy Protection Act (COPPA), schools may consent to the collection of student information on behalf of parents when the data is used solely for an educational purpose. By allowing students to use MiniReport Live, the school represents that it has the authority to provide this consent. We do not collect more information than is reasonably necessary to participate: no student accounts, a display name only, and automatic deletion within 30 days.

8. State Privacy Laws

We have designed our data practices to align with common requirements across state student-privacy laws, including California (SOPIPA), New York (Education Law 2-d), Illinois (SOPPA), and Colorado (Student Data Transparency and Security Act): minimal collection, no sale or commercial use of student data, automatic deletion, and transparency about subprocessors. If your state has specific requirements not addressed here, please contact us.

9. Security

We implement the following technical safeguards:

10. Third-Party Access

We do not sell, rent, lease, or share student data with any third party for commercial purposes. The only third parties that process session data are the infrastructure subprocessors in Section 4, each only to the extent necessary to deliver the service and each bound by their own data processing terms. We run no analytics, error-tracking, or advertising services — none.

11. Data Breach Notification

In the event of a data breach affecting student information, we will notify affected schools and districts without unreasonable delay and no later than 72 hours after becoming aware of the breach, including a description of the data involved, the date or estimated date of the breach, and the steps we are taking in response.

12. Your Rights

Schools and districts may request confirmation of deletion, details about our data handling practices, or termination of processing under an active DPA. Teachers may delete any of their sessions at any time and may request deletion of their account data. Parents may contact their child's school to ask how MiniReport Live is used in the classroom. Because students have no accounts and student data is deleted automatically within 30 days, there is no persistent student record beyond that window for us to provide or delete.

13. Changes to This Policy

We may update this policy from time to time. If we make material changes to how we handle student data, we will notify schools and districts with active DPAs at least 30 days before the changes take effect. The "Last Updated" date above reflects the most recent revision.

14. Contact Us

Learning Innovation Systems, LLC
20409 Yorba Linda Blvd. Suite K2 225
Yorba Linda, CA 92886
Email: support@eduprotocols.com