1. Who this policy covers
This policy applies to:
- Teachers and school staff with a Kuraplan account, whether they signed up themselves or were added by their school.
- Schools that buy Kuraplan for their staff. Where a school is the customer, the school decides what its staff use Kuraplan for and Kuraplan processes information on the school's instructions.
- Parents and carers using Kuraplan at home, and the learner profiles they create.
- Students who use Kuraplan through their teacher or school.
- Anyone who visits kuraplan.com, contacts us, or receives email from us.
It covers kuraplan.com, app.kuraplan.com, kuraplan.io (the classroom join door) and our emails.
2. What we collect
Account. Name, email address, country, school (if any), year levels, subjects, curriculum choice, and how you sign in (magic link or Google). We never see or store a password: sign-in is by emailed link or Google.
What you make. Lesson plans, unit plans, worksheets, slides, quizzes, activities, images, audio, chat conversations with the assistant, and files you upload. These contain whatever you put in them.
Learner profiles (home accounts). A first name or nickname and a year level, entered by the parent.
Student responses. When a student uses something a teacher has shared with them, they enter a first name or nickname and their responses. We store that name as typed, the responses, any score, timestamps and any messages to the AI helper, attached to the teacher's account. Students are asked for nothing else.
Billing. Name, email, billing country and subscription status. Card details go straight to Stripe and never touch our servers.
Usage. Pages and features used, resources created, device and browser type, IP address, and the approximate location we derive from it for currency and curriculum defaults. No precise location.
Support. Emails, contact-form messages and feedback you send us.
From others. If a colleague invites you, we receive your name and school email from them. If your school sets up school-wide access, we receive the staff list it gives us.
3. What we use it for
- Providing the service: generating, storing and showing your resources and conversations.
- Personalising defaults: curriculum, year level, subject, country.
- Running your subscription and sending receipts.
- Transactional email: sign-in links, invitations, account notices, deletion confirmations.
- Product news, only if you opted in, with unsubscribe in every email.
- Support.
- Understanding how the product is used so we can improve it (aggregate analytics).
- Keeping the service secure and detecting abuse.
- Meeting legal obligations.
We do not sell personal information. We do not share it for market research. We do not show advertising inside Kuraplan.
4. How the AI features handle your information
What is sent. When you ask the assistant for something, your request, your curriculum settings and relevant context (for example the resource you are editing) are sent to a third-party AI model. If you upload a file to use with the assistant, its text is sent too.
Where it goes. Requests go through Vercel AI Gateway to OpenAI (served through Microsoft Azure), Anthropic, Google, and Amazon Bedrock. All processing is in the United States. Every provider is used under business terms that prohibit training on our data.
Zero data retention. All of our AI models are used under zero data retention terms. The provider processes your request, returns the reply, and keeps nothing: no prompts, no outputs, no copies for review. If a provider cannot serve a request under those terms, the request goes to another provider that can, or fails; it is never sent to a retaining endpoint. A list of our providers and what each receives is available on request from support@kuraplan.com.
No training. We do not use your content, prompts, uploads or learner details to train any model, and our providers are contractually prevented from doing so.
Kuraplan Shield. Shield is designed to stop personally identifiable information (PII) from ever being seen by a third-party AI model. It runs on our servers before a request leaves them. It replaces names, email addresses, phone numbers and similar details with placeholders, sends the placeholder version to the model, and puts the real details back in the reply. The original values never leave our servers. Teachers can turn Shield on in Settings, and a school can configure it to apply automatically to all of its teachers.
Students and AI. Where students use AI features in Kuraplan, the student's input and the task they are working on go to the model; the student's name does not.
Logs. We keep the conversation and the resource you asked for as part of your account. Operational logs record which features were used, when, and the cost of each request, not the text of prompts or replies. Retention for each is in the table in section 10.
5. Where your information is stored
- Database and files: Supabase on Amazon Web Services, United States (us-west-1).
- Backups: encrypted before they leave our systems, stored with Cloudflare R2 in Oceania, kept 90 days, and restore-tested.
- Application servers: Vercel, United States.
- Email, analytics, support and other providers: a full list of providers, with each one's purpose, the data it receives and its country, is available on request from support@kuraplan.com.
All data is encrypted in transit (TLS) and at rest (AES-256).
6. Who can see your information
- Providers, each under a data processing agreement or business terms.
- Your school, if your account is on a school plan: school admins can see who has an account, when each person last used Kuraplan, usage totals, and the school's own settings. They cannot read your chat conversations or open your private resources. They can remove you from the school, which signs you out everywhere and stops sharing your resources with colleagues, but leaves your account and content with you.
- Colleagues, only when you share a resource with them or your school has sharing on by default.
- The public library, only if you choose to publish a resource. Published resources show your first name and school, and must not contain personal information about students. Resources made for a learner cannot be published.
- Authorities, where the law requires it or someone's safety is at risk.
- A buyer of the business, if Kuraplan is sold or merged; you would be told first and this policy would still apply.
7. For schools
Your role. When your school buys Kuraplan, the school decides how staff use it, and Kuraplan acts on the school's instructions for staff accounts linked to the school.
Separation. Users in one school cannot find, search or reach users or content in another school.
What admins can do.
- Add and remove teachers, and make another teacher an admin.
- Require Kuraplan Shield for all staff.
- Set how long chat conversations are kept: forever, or 90, 180 or 365 days, with older chats deleted nightly.
- Set school-wide instructions and defaults.
- Export a list of members with resource counts.
- Read an activity log of every admin action, who did it and when.
Removing a teacher signs them out on every device, un-shares their school resources, emails them and the admin, and is recorded in the log.
What admins cannot do. Read a teacher's chats, open a teacher's private resources, or see anything about other schools.
When a teacher leaves. Remove them in School settings. Their account and personal content stay theirs; the link to your school ends immediately.
When your contract ends. Tell us and we will remove the school link for all staff and, if you ask, delete the accounts of staff who want that. A full export of the school's content is available on request to support@kuraplan.com.
Data processing agreement. Available on request.
8. For parents and home users
Your account is yours, not your child's. Kuraplan accounts are for adults. A parent or carer creates the account and can add one or more learner profiles.
What we hold about a learner. The profile details you enter for the learner, and the resources and chats you make for that learner.
Learner resources are private. Anything made for a learner is visible only inside your account. It cannot be shared to the public library or with other users.
Consent. By creating a learner profile you confirm you are the child's parent or legal guardian.
Deleting. Delete a learner profile at any time in Settings, or delete your whole account; both remove the learner's details and resources immediately.
9. Students
When a student uses Kuraplan through their teacher, they enter a first name or nickname and their responses. That name is stored as typed with the responses and shown to the teacher. The student's name is not sent to the AI model. Schools and teachers can delete student responses at any time, and they are deleted with the teacher's account.
10. How long we keep things
| What | How long |
|---|---|
| Account and resources | While your account exists |
| Chat conversations | Until you delete them; school admins can set 90, 180 or 365 days for their school |
| Student activity responses | Until the teacher or school deletes them, or with the teacher's account |
| Operational logs (feature, time, cost; no prompt text) | 90 days, with error and access logs held by our providers under their own retention |
| Backups | 90 days, encrypted, then purged |
| Deleted accounts | Removed immediately; gone from backups within 90 days |
| Aggregated statistics that identify no one | May be kept |
11. Deleting your account
Delete your account from your account settings, or by emailing support@kuraplan.com from your account address. Either way you type or confirm a phrase, and deletion is immediate: your account, resources, chats, uploads, images, learner profiles, billing record and sign-in are removed, your subscription is cancelled, and you receive a confirmation email.
12. Your rights
Wherever you are, you can ask us to:
- tell you what personal information we hold about you and give you a copy;
- correct it;
- delete it;
- stop sending you marketing email (every email has an unsubscribe link);
- for UK and EU users: restrict or object to processing, and receive your data in a portable form (see section 15).
Email privacy@kuraplan.com. We confirm your identity, then respond within 30 days, at no charge. If your account is linked to a school and the request concerns school-controlled data, we may need to involve the school.
13. Security
Every account has its own credentials and sign-in is by emailed link or Google; we store no passwords. Two-step verification with an authenticator app will be available soon, and schools will be able to require it. Data is encrypted in transit and at rest. Row-level security in our database means each user can only reach their own data and what has been shared with them. Access to production systems is limited to the founder, protected by multi-factor authentication, and logged.
Breaches. If we become aware of a breach likely to cause serious harm, we notify affected schools and users within 72 hours of becoming aware of it, with what happened, what was affected and what we are doing. We notify regulators where the law requires it and help schools with their own notifications.
14. Cookies and analytics
- Essential cookies keep you signed in.
- Product analytics inside the app: PostHog (EU-hosted) and Mixpanel, tied to your account, plus PostHog session replay with typed text masked. Used to understand and improve the product.
- Advertising measurement: we use cookies and similar technologies to measure which of our ads and pages lead to sign-ups. You can opt out through your cookie settings. Details: kuraplan.com/cookies.
- Error monitoring: Sentry receives error reports that may include your account identifier.
Cookie details: kuraplan.com/cookies.
15. Where you are
Kuraplan Inc is registered in the United States and processes information there. What follows is how we meet the privacy laws of the places our users are.
New Zealand
We handle personal information in line with the Privacy Act 2020 and its Information Privacy Principles. Information is stored outside New Zealand (United States, with backups in Oceania) with providers that protect it to a standard comparable to the Act. You can ask for access to or correction of your information at any time, and complain to the Office of the Privacy Commissioner (privacy.org.nz) if you are not satisfied with our response.
Australia
We handle personal information in line with the Privacy Act 1988 and the Australian Privacy Principles. Information is disclosed overseas (United States) to providers bound by contract to protect it. If a breach is likely to cause serious harm, we follow the Notifiable Data Breaches scheme and tell affected people and, where required, the Office of the Australian Information Commissioner (oaic.gov.au). You can complain to the OAIC if you are not satisfied with our response.
United Kingdom and European Union
Where UK GDPR or EU GDPR applies, our legal bases are: performing our contract with you (providing the service, billing, support); our legitimate interests (keeping the service secure, understanding how it is used, improving it); consent (marketing email, optional cookies); and legal obligation. Where a school is the customer, the school is the controller and Kuraplan the processor for staff data linked to the school.
You have the rights to access, correct, delete, restrict and object to processing, to receive your data in a portable form, and to withdraw consent. We respond within one month. Your information is transferred to the United States; transfers are covered by the UK International Data Transfer Agreement or the EU Standard Contractual Clauses, available on request. You can complain to the Information Commissioner's Office (ico.org.uk) or your local EU data protection authority. We make no decisions about you by automated means that have legal or similarly significant effects. Home accounts are created by a parent or guardian, who consents on the child's behalf.
United States
For schools: where a school shares education records with us, we act as a school official under the school's direct control for the purposes of FERPA, use the records only to provide the service, and delete them when the school asks. Where students under 13 use Kuraplan through a school, the school provides consent on parents' behalf under COPPA. For families: a parent or guardian creates the account and the learner profile.
For California residents: we do not sell personal information and do not show advertising inside Kuraplan. You can ask what we collect, ask for it to be deleted or corrected, and will not be treated differently for asking. We respond within 30 days and you can appeal a decision by replying to our response.
Canada
We handle personal information in line with PIPEDA. You can ask for access to or correction of your information, and complain to the Office of the Privacy Commissioner of Canada if you are not satisfied with our response.
16. Changes to this policy
We email account holders and show a notice in the product at least 14 days before a material change takes effect. Each version carries its effective date, and previous versions are available on request.
17. Contact
Privacy Officer: privacy@kuraplan.com
Everything else: support@kuraplan.com
Kuraplan Inc, United States