Legal
Privacy Policy
Last updated: September 13, 2026
Who this applies to
This policy covers Reasonline (“we,” “us”), used by instructors to design AI-supported learning experiences and adaptive assessments, and by students to complete them. It applies whenever you create a Reasonline account, or use Reasonline as a student to work through a Learning Experience, submit an assessment, or respond to George.
What we collect
- Instructor account data — email address, and institutional or team affiliation where applicable.
- Course and learning-design content — syllabus or course material an instructor uploads or provides, the capabilities and Learning Experiences built from it, and instructor-authored assessment tasks, rubrics, and criteria.
- Student submissions and learning activity — the artifact a student submits (text, a file, audio, or video), the student’s name and email, their work within a Learning Experience, and their timed responses to George’s questions (written, audio, or video).
- Dialogue transcripts and evidence records — the text of George’s generated questions, the student’s responses, a machine-generated transcript synced to any audio or video recording, and the resulting evidence records connected to a course capability.
- Learning Intelligence and Course Pulse insights — patterns and recommendations generated from the evidence above (for example, a recurring misconception across several students, or a capability with little evidence yet), always traceable back to the underlying evidence.
- Usage and technical data — sign-in timestamps, session identifiers, and the basic technical logs needed to operate and secure the service.
- Marketing request forms — if you submit a Learn or Complete Early Access request, or a pilot request, we collect what you enter in that form (name, email, institution, role, and the other fields on the form) and, where present, basic campaign-attribution information (referring source and landing page).
Subprocessors — who else touches this data, and why
We use a small number of subprocessors, each for a narrow, specific purpose. This list matches what we describe on our Trust & Security page.
- Supabase — hosts our application database and file storage, with row-level security enforced by the database itself so one institution’s data is isolated from another’s. Receives essentially all application data (accounts, course content, submissions, transcripts, evidence records) because it is our hosting and database provider.
- Anthropic (Claude) — powers George’s dialogue questions and evidence review in both Reasonline Learn and Reasonline Assess, and also supports Learn-side course authoring: analyzing instructor-provided course/syllabus material, extracting candidate capabilities, drafting Learning Experiences and assessments, and generating Course Pulse / Learning Intelligence insights. Receives only what a given job needs — the relevant task or course material, the student’s work where applicable, and the dialogue or evidence transcript so far.
- Deepgram — transcribes audio and video responses only. Receives the audio/video recording and returns a text transcript; used for no other purpose.
- Stripe — processes subscription payments. Receives billing and payment details directly through Stripe’s own hosted checkout; card details never reach Reasonline’s own servers.
- Resend — sends transactional email where email notifications are configured, such as confirming receipt of an Early Access or pilot request. Receives only the email address and message content needed to send that email.
- Cloudflare Turnstile — provides bot/spam protection on sign-in forms where enabled. Receives browser/device signals used only for that purpose, not academic content.
We do not sell student or instructor data, and we do not use student submissions to train AI models.
The role of the instructor and institution
For student data, the instructor — and, where applicable, their institution — is the data controller: they decide what learning experiences and assessments to run and who participates. Reasonline acts as a data processor, handling that data only to provide the service as configured, and only for as long as the account or applicable agreement requires. We are preparing a formal Data Processing Agreement, a HECVAT response, and a documented FERPA posture for institutional pilots. None of these is finalized today, and we won’t claim a compliance status until it’s real — the same standard described on our Trust & Security page.
Retention
- Account data is retained for as long as the account is active, plus a limited period afterward for reactivation and our own recordkeeping.
- Student submissions, learning activity, evidence records, and transcripts are retained for the duration of the course or term and a reasonable period afterward for instructor and institutional recordkeeping, unless a specific institutional agreement sets a different schedule.
- Marketing request-form submissions are retained for as long as reasonably needed to follow up on the request.
- Deleted data is removed from active systems promptly; backups cycle out over time rather than being purged instantly, consistent with standard operational practice.
Deletion and export requests
An instructor, student, or institution can request a copy of their data, or request deletion, by contacting info@reasonline.org. We’ll confirm the request, verify identity where appropriate, and aim to act within 30 days — an institutional agreement may specify its own process and timeline instead.
Security
Role-based access control, per-school data isolation enforced at the database level, and audit logging of sensitive administrative actions are described in more detail on our Trust & Security page. We do not currently hold a SOC 2 report or other third-party security certification.
Children’s privacy
Reasonline is intended for use by instructors and students in the context of coursework administered through an educational institution. We rely on the instructor’s and institution’s own policies and consents for the students they enroll in a course or assessment, consistent with how classroom EdTech tools typically operate.
Changes to this policy
We’ll update the date above whenever this policy changes, and for material changes we’ll take reasonable steps to notify active account holders.
Contact
Questions, deletion requests, or data-export requests: info@reasonline.org