Privacy Policy · LessonSmith
LessonSmith helps teachers generate lesson plans and Schemes of Work using AI. This policy explains what personal data we collect, why, who we share it with, and your rights.
1. Data we collect
A. Account and identity (via Clerk). Full name; email address; authentication identifiers and session tokens. If you sign in with Google, the basic Google profile Google shares with us (name, email, profile image). If you enter it, your TSC number (Teacher Service Commission registration number), a professional or government-issued identifier.
B. Profile and preferences. School name (shown on exported plans); school logo or badge image if you upload one; your teacher or display name; the app-interface language and the plan-output language (for example English or Kiswahili); theme choice; and your region and curriculum selection (a country or region plus a curriculum such as Kenya CBC, England National Curriculum, or IB). You set the region and curriculum yourself. It is not GPS or precise device geolocation, and we do not need your exact location to provide the service.
C. Lesson-plan generator inputs. Grade or class level; subject; strand and sub-strand; term (1, 2, or 3) and academic year; lesson date and time; roll (class size or number of learners); linked reference scheme of work; output template choice (CBC Standard, Compact, or Table); differentiation and inclusion preference; and the free-text notes or instructions you type for the AI.
D. Scheme-of-Work builder inputs. Subject, grade, language, and scheme scope (a full year or a specific term); additional notes; and the term calendar you set, meaning term opening and closing dates, holidays, labelled exception periods (for example "Sports week" or "KCSE mock"), and the teaching days of the week you select.
E. Support-plan inputs. The Support Plan tool drafts an individual plan for one learner who needs additional support, and it asks you for: the learner's name or initials, which is optional and may be left blank; their grade or class; the learning area you are focusing on; the categories of need you tick from a fixed list, such as a hearing impairment or a specific learning difficulty; your own notes on what the learner can currently do and what they are good at; and a review date. Some of this is sensitive data about a child. Section 13 sets out who is responsible for it and how to keep it to a minimum.
F. Content you generate and store. The lesson plans, Schemes of Work, and support plans you generate, including both inputs and outputs; and your saved library, templates, and quick-topic chips.
G. In-app AI assistant. The messages you send to the in-app chat assistant and its responses, retained as your chat history.
H. Payment data (via Polar). Subscription and transaction status and limited billing metadata from Polar (the plan purchased and the renewal state). We never see or store full card numbers; Polar, using Stripe, handles card details.
H1. School plan membership. If your school buys a School plan, we hold the school’s name and contact address, the number of seats it has paid for, and one record per seat: the email address the invitation was sent to, whether that seat is an administrator or a teacher, whether the invitation has been accepted, and the dates it was invited and accepted. That record is linked to your account once you accept.
Who can see it. Your school’s administrators can see the list of email addresses on the plan, each seat’s role, and whether an invitation has been accepted. That is a disclosure to your school, and it is what “we are paying for these teachers” means in practice. They cannot see your lesson plans, your schemes of work, your support plans, your assistant conversations, or how much of your allowance you have used — none of that is exposed to a school, on any screen or through any export.
We never join an account to a school by matching an email address or a domain. A seat exists because a single-use invitation link was accepted.
I. Usage and analytics (via PostHog). Pages viewed, features used, generation counts, and similar product events; device and browser information; and approximate location (country or city) derived from your IP address.
J. Technical and log data. IP address, timestamps, and error diagnostics (for example via Sentry) needed to operate and secure the service.
K. Demo accounts. When you press Try it without an account we create a temporary account for you. It has no name, no password and no address you can receive mail at: we generate an internal one so the account has an identifier. What you then make in the demo is stored the same way an ordinary account’s work is, and it is reached through a cookie held in your browser (ls-demo, listed in the Cookie Policy). We may delete a demo and its contents at any time. Terms Section 3b sets out what that means for anything you make in one.
L. Signals we use to stop one person taking many demos. When a demo is created we record two one-way hashes: one of your IP address, and one of your IP address together with your browser’s User-Agent, Accept-Language and the two client hints it sends unprompted. We keep the hashes and the time, and nothing else. We do not store the values they were made from, we cannot reverse them back into an address, and they are not linked to your account or to any demo you create. They are used for one purpose, which is to count how many demos have recently come from one connection, and they are deleted after 30 days. This is not device fingerprinting: we read nothing out of your device and we store nothing on it for this purpose.
About your prompts, your TSC number, and your students. Treat anything you type into a generation as potentially shared with our AI providers (Section 4). Your TSC number is a personal identifier you choose to provide. Do not enter students' personal data (names, admission numbers, photos, health details, or other sensitive details) into prompts. The one exception is the Support Plan tool, which exists to draft a document about a named learner and is governed by Section 13. You are responsible for the content you submit.
2. How we use your data
- Provide and personalize the service (generate and store your plans and SOWs).
- Tailor subjects, grade bands, and AI output to the region and curriculum you select, so plans match your local curriculum.
- Authenticate you and keep accounts secure.
- Process subscriptions and enforce tier limits.
- Analyze and improve features and reliability.
- Communicate service, billing, and support messages (see Section 11 for marketing).
- Comply with legal obligations and prevent abuse and fraud.
3. Legal bases (where applicable, e.g. GDPR/Kenya DPA)
- Performance of a contract: to deliver the service you sign up for.
- Legitimate interests: security, analytics, product improvement, and preventing abuse of the free demo (Section 1L).
- Consent: non-essential analytics and marketing cookies and marketing email where required.
- Legal obligation: tax, accounting, and lawful requests.
4. AI processing (important)
To generate content, the text you submit is sent to our AI providers, OpenAI (GPT-4o-mini) as primary and Google (Gemini Flash Lite) as fallback, and processed under their API terms. We use their API tiers, which are not used to train their models by default. This includes everything you enter in the Support Plan tool, so a learner's name or initials go to the AI provider if you type them. Section 13 explains how to avoid that. AI output may be inaccurate ("hallucinate"); review every generation before classroom use. We disclose our use of AI in-product and on our marketing pages so it is never hidden from you.
5. Sub-processors we share data with
We share the minimum necessary with vendors that process data on our behalf:
| Provider | Purpose |
|---|---|
| Clerk | Authentication & account management |
| Convex | Application database & backend functions |
| Polar | Payments (merchant of record; uses Stripe as the card processor) & subscription management |
| OpenAI (GPT-4o-mini API) | AI generation (primary) |
| Google (Gemini Flash Lite API) | AI generation (fallback) |
| PostHog | Product analytics |
| Vercel | Hosting / content delivery |
| Sentry (if enabled) | Error monitoring |
We do not sell your personal data. See Section 12 for how this is treated under California law (CCPA/CPRA).
6. International transfers
Some providers process data outside Kenya (for example in the EU or US). Where required, we rely on appropriate safeguards (such as standard contractual clauses) offered by those providers.
7. Data retention
We keep your account and content for as long as your account is active, and for a reasonable period afterwards to meet legal, tax, and security obligations. You can delete your content in-app or request account deletion (Section 9). Payment records may be retained as required by law. When you delete content or your account, we remove it from our live systems; residual copies may persist in encrypted backups and operational logs for a limited period until they are purged on our routine backup cycle, and we delete or de-identify the related analytics data.
A demo account and its contents are kept only while the demo exists. We may delete one at any time, and we do not undertake to keep it for any period. The hashes described in Section 1L are deleted after 30 days.
Support plans follow the same timetable, and we ask you to go further with them: delete a support plan as soon as its review date has passed and you no longer need it.
School plan seat records — the invited address, the role, and the invited and accepted dates — are kept while the seat exists, and after it is removed for as long as we need them to show who a school was billed for. That is no longer than the seven years we keep the payment records themselves.
8. Security
We keep secrets and API keys server-side, never in client code. Only authorized accounts can reach admin tools.
Your data is encrypted in transit over HTTPS, and it is encrypted at rest. Our database provider encrypts everything it stores with AES-256. Before your content reaches that database we encrypt it again under a separate key the provider does not hold, so a copy of the database on its own cannot be read. That second layer covers what you make in the app: your plan library, your schemes of work, your teacher profile, your school details and your support plans. The copy your browser keeps on your own device is encrypted too, under a key generated on that device which cannot be copied off it.
Encryption has limits, and we would rather name them than let them be assumed. It protects data that is stored or moving between us. It does not protect against someone who has taken control of the LessonSmith application itself, or of your own signed-in browser, because both can read whatever you can read. No system is perfectly secure, but we apply reasonable technical and organizational measures.
9. Your rights & control over your data
Subject to applicable law (Kenya DPA / GDPR), you may access, correct, delete, export, or restrict processing of your data, and object or withdraw consent. You can exercise the core rights yourself, while signed in, on your account page:
- Download export: a JSON file of your account record, your saved lesson plans and schemes of work, your settings, and your generation history.
- Delete account: permanently removes your account and your saved content from our live systems, subject to the records we must keep by law or for security, which are listed in Section 7 above and in Terms Section 10a.
You may also email privacy@lessonsmith.ai and we will respond within the period required by law. You may complain to a supervisory authority. In Kenya, that is the Office of the Data Protection Commissioner (ODPC); in the EU/UK, your local data-protection authority.
10. Cookies & similar technologies
We use essential cookies to run the service (e.g. Clerk authentication) and analytics cookies (PostHog) to improve it. Analytics are not loaded until you have accepted these policies, and you can block or delete cookies in your browser. Every cookie and storage key we set is listed in our Cookie Policy.
11. Marketing & email communications
- We send service and transactional messages (billing, security, and account notices) as part of providing the service.
- We send marketing email only where permitted, and every marketing email includes a one-click unsubscribe, an honest subject line, and a valid postal address (consistent with CAN-SPAM and similar laws). Unsubscribing from marketing does not stop essential service messages.
12. California privacy rights (CCPA/CPRA)
If you are a California resident:
- We do not "sell" your personal information for money.
- We use analytics (PostHog) configured to avoid cross-context behavioral advertising. To the extent any analytics constitutes "sharing" under the CPRA, you may opt out via our cookie controls or a "Do Not Sell or Share My Personal Information" control where provided.
- You have rights to know, delete, correct, and opt out, and not to be discriminated against for exercising them. Use the in-app controls (Section 9) or email privacy@lessonsmith.ai.
13. Children and learner data
LessonSmith is intended for teachers and adults, not for use by children. Two different rules apply, and which one you are under depends on the tool you are using.
Lesson plans, Schemes of Work, and the chat assistant: do not enter learners' personal data. Do not type learners' names, admission or registration numbers, photographs, contact details, health or special-educational-needs information, behaviour records, or assessment results attributable to a named learner into any prompt, note, or upload in these tools. Describe your class in general terms instead, for example "a mixed-ability Grade 6 class of 40" rather than by naming pupils.
The Support Plan tool is the exception, because a support plan is a document about one child. It drafts the individual plan your education system expects for a learner who needs additional support: an IEP in Kenya, Nigeria, Ghana, India and the United States, an Individual Support Plan under South Africa's SIAS policy, a SEN Support plan under England's SEND Code of Practice, an Individual Learning Plan in Australia, and a Learning Support Plan in IB and Cambridge schools. Section 1E lists exactly what it asks you for.
Some of that is sensitive data about a child. A category of need is health-related data. It is sensitive personal data under Kenya's Data Protection Act 2019, a special category under Article 9 of the UK and EU GDPR, and special personal information under South Africa's POPIA. In the United States a completed plan is an education record under FERPA and is also subject to the confidentiality rules in IDEA.
Your school is the controller for it and we are the processor. By using the Support Plan tool you confirm that your school or employer permits you to draft these plans with an external tool, and that the school holds whatever lawful basis, parental consent or guardian consent its own law requires. We do not obtain that consent on your behalf and we are not in a position to. If you are not certain your school allows this, ask before you use the tool.
There is a contract behind that split. Our Data Processing Agreement applies to support-plan data on every account that uses the tool, not only where a school has signed its own copy. Terms of Use Section 6b puts it in force from the first time you give that confirmation. It sets out what we may do with the data, the security we owe, the sub-processors involved, and how we help your school answer a request from a parent or guardian.
Keep it to the minimum. The learner's name is optional. Initials are enough, and the draft reads the same with no name at all. If you leave it blank, the exported Word file and PDF print a ruled line for you to complete by hand at school, so the learner's identity never has to enter the Service. Do not enter a diagnosis, a medical or psychological report, a home address, a parent's contact details, a photograph, or an admission number. None of these improve the draft.
Where it goes. What you type is sent to our AI provider to draft the plan (Section 4), and the draft is saved to your library and synced to your account so you can open it on another device (Section 5). We do not use it to train any model. We keep it for the periods in Section 7, and you can delete any plan yourself from the library.
If you enter more than you meant to. Delete the affected plan or chat in the app and email privacy@lessonsmith.ai with the approximate date and time. We will delete it from our systems, including from backups on the next cycle, confirm to you when that is done, and record the incident. We will not use it for any purpose in the meantime. Where the law requires it, we will notify the Office of the Data Protection Commissioner or another regulator. We may suspend an account that keeps entering learners' personal data into the tools listed above after being warned.
If you are a parent or guardian reading this. Start with the school. The school decides what a support plan says, holds the consent or other lawful basis behind it, and answers requests to see, correct or delete it, because the school is the controller and we act on its instructions. You can also write to privacy@lessonsmith.ai. We will pass your request to the school, tell you that we have done so, and act on what the school instructs. Our Terms of Use are an agreement between us and the account holder. You are not a party to them, and nothing in them affects your rights or your child's rights under data-protection law.
14. Changes
We may update this policy. We will tell you about material changes in-app or by email, and revise the "Effective date".
15. Contact
VoussoirAI ("LessonSmith"), Nairobi, Kenya · privacy@lessonsmith.ai · A postal address is available on request by emailing privacy@lessonsmith.ai.