Privacy Policy
Precision Start™ by Third Eye Education Analytics LLC
Effective Date: March 2026 · Last Updated: July 15, 2026
1. Who We Are
Precision Start™ is a teacher-facing math intervention planning tool built and operated by Third Eye Education Analytics LLC. The platform helps K-8 teachers identify prerequisite skill gaps before a unit begins, group students by shared instructional need, and deliver matched intervention plans.
Precision Start™ is designed for school staff. Students do not use the platform directly. All student data in the system is provided by school-authorized personnel (teachers and administrators), not by students or parents.
Contact: Andre Aina, Third Eye Education Analytics LLC — andre@thirdeyeanalytics.org
2. What Data We Collect
2.1 Administrator Data
- Name and email address (used for account creation and authentication)
- Actions taken within the platform (processing uploads, publishing reports, reviewing classifications)
2.2 Teacher Data
- Name and email address (used for account creation and authentication)
- School affiliation (assigned during the invite-based onboarding process)
- Classes created and unit configurations (grade, subject, target standards)
- Override decisions and free-text notes on student classifications
- Per-student lesson feedback (Met, Approaching, Not Yet, or Absent) submitted after each intervention lesson
- Lesson completion tracking and intervention cycle progress
- Lesson count overrides (when a teacher customizes the number of lessons per intervention cycle)
- Instructional role assignments within each class (e.g., lead teacher, co-teacher, interventionist, instructional coach, paraprofessional, substitute). When a teacher overrides a student's classification, the teacher's instructional role is recorded alongside the override for system improvement purposes.
- Interaction timing data: how long a teacher spends reviewing a student before making an override or move decision (used to improve classification accuracy and identify cases where the system should flag for review)
- Review session identifiers: a random session ID generated each time the Starting Point Report is opened (used to correlate multiple decisions within a single review session for system improvement)
2.3 Student Data (Provided by School Staff)
Student data is entered into the system exclusively by school-authorized teachers and administrators. Students never create accounts or interact with the platform. The student data we process includes:
- Student first and last name
- Assessment performance data (mastery levels and misconception categories, as scored by EdLight, PBC, our assessment scoring subprocessor)
- Tier classification (Enrichment, Independent, On Level, Emerging, Intervention)
- Instructional grouping assignments, including an instructional setting tag per group (e.g., pull-out, push-in, station rotation, whole class, independent work) set by the teacher
- Prerequisite skill gap analysis results
- Longitudinal gap tracking across units and school years (which standards each student has gaps in, closure history, intervention records including lessons delivered and outcomes)
- Checkpoint assessment scores and progress monitoring data
- Per-lesson session feedback from teachers (Met, Approaching, Not Yet, or Absent) associated with each student
- Intervention cycle membership: student progress data (session feedback, checkpoint results, and group assignments) is organized into intervention cycles, which represent the period between regroupings within a unit. Each cycle is identified by a system-generated cycle ID.
We do not collect: Social Security numbers, home addresses, phone numbers, disciplinary records, health records, or any data beyond what is necessary for instructional grouping and equity analysis.
2.4 Optional Demographic Data (School-Controlled)
Precision Start™ does not collect demographic data by default, and demographic analytics are not part of the standard service. If a school specifically requests equity analytics, the school may provide its own demographic data for us to join to that school's existing records. This is entirely optional and initiated by the school.
A school that requests this may provide any combination of the following:
- Accommodation status: IEP, 504 plan, and/or English Learner (EL/ELL) designation — used to provide accommodation-aware intervention suggestions
- Demographic identifiers: Race, ethnicity, and/or gender — used for equity reporting across tier classifications and intervention outcomes
- Socioeconomic indicators: Free/reduced lunch status — used for Title I reporting and resource allocation analysis
When demographic data is shared:
- It is stored within the school's existing data tenant, subject to the same security and isolation protections described in this policy
- Individual student demographic data is never sent to third-party services paired with student names or identifiers. Aggregate, de-identified demographic statistics (e.g., “60% of students in this tier are English Learners”) may be used to improve intervention recommendations
- Demographic data is used only within the requesting school's own analytics. It is not included in cross-school analysis
- Individual student demographics are never surfaced to users who do not already have access to that information in their school's Student Information System (SIS)
- Schools may revoke demographic data sharing at any time by request, and all demographic data — including any uploaded extract, the joined fields, and equity reports generated from it — will be purged within 30 days of a revocation request
- Schools that do not request this receive the full Precision Start™ experience without equity overlays — no features are withheld
2.5 Automatically Collected Data
- IP addresses (used for rate limiting and abuse prevention; not stored long-term)
- Firebase authentication tokens (used for session management)
- Anonymous page view analytics and Web Vitals performance metrics (collected by Vercel Analytics and Speed Insights; no personally identifiable information is included)
- Audit log entries recording significant platform actions (including but not limited to: login, report viewing, tier overrides, unit publishing and unpublishing, AI content generation and editing, student group moves and regrouping, checkpoint creation, unit processing, student work uploads, school joins, gap detection and closure events, and student profile creation)
3. How We Use Data
3.1 Student Data
Student data is used solely to deliver the contracted instructional planning service:
- Classification: Assigning students to skill-based tiers using rule-based algorithms (not AI) applied to assessment results
- Root cause analysis: Tracing skill gaps backward through a standards prerequisite graph to identify foundational needs
- Grouping: Clustering students with shared instructional needs into small groups (2-6 students)
- AI content generation: Generating intervention plans, classroom supports, and RTI documentation from de-identified instructional metadata, with an automated redaction layer on every request (see 4.1)
- Progress monitoring: Tracking gap closure through checkpoint assessments and per-lesson session feedback to measure intervention effectiveness, including cycle-level analytics that summarize activity within each intervention cycle (e.g., total lessons delivered, checkpoint count, and group count per cycle)
- Learning gap analysis: Displaying gap status, closure trends, and student watch lists to help teachers prioritize their intervention time
- Equity analysis (on school request only): When a school has requested equity analytics and provided its own demographic data, generating aggregated equity reports that show whether tier classifications and intervention outcomes are equitable across student groups. These reports use only aggregated, de-identified statistics and are visible only to school administrators.
- Data export: Generating CSV and PDF exports of student progress data for school use (these exports may contain student names and are the responsibility of the downloading user to handle securely)
System improvement: Within your school's own data, automated systems track the accuracy of teacher override decisions and correlate intervention feedback with gap closure to calibrate the service; this is core to the product. Separately, a school may opt in to contribute de-identified, aggregate statistical patterns across schools to improve intervention recommendations and classifier accuracy. Opted-in aggregate patterns may also support Provider's internal statistical research and product analytics; no research output ever identifies a student or teacher, and naming a school or district requires that school's prior written approval. All cross-school reporting enforces a minimum group size (n ≥ 5) designed to reduce the risk of re-identification, demographic data is excluded from cross-school analysis, and a school may withdraw at any time without losing any feature.
Student data is never used for advertising, marketing, profiling, behavioral prediction, or any purpose unrelated to instructional planning.
3.2 Teacher Data
- Authenticating access and scoping visibility to the teacher's own classes
- Delivering email notifications when reports are ready
- Recording override decisions for system improvement and compliance documentation
3.3 Administrator Data
- Authenticating admin access (via server-side allowlist)
- Operating the data processing pipeline (upload, review, publish)
- Viewing audit logs for compliance and quality assurance
4. Data Processing and Student Privacy
This section documents what data is and is not transmitted to external third-party services. Every claim below was verified through direct audit of the application source code.
4.1 How Identifiers Are Kept Out of AI Prompts
Prompts sent to AI services are built from de-identified instructional metadata (see 4.2). Direct student-identifier fields — a student's name, ID number, email address, or a parent's contact information — are not interpolated into AI prompts by design; the classification and content-generation code assembles prompts from the de-identified fields below.
As defense-in-depth, every outgoing AI request passes through an automated redaction layer on the single client through which all AI calls are made. It removes email, phone, and Social Security Number patterns. In addition, when a request is generated in the context of a specific group, the names of that group's students are redacted from any free-text field and replaced with a neutral placeholder — so a name that inadvertently appears in a teacher note or an imported misconception description is caught.
This name redaction is best-effort matching against the group's roster and is enforced centrally rather than by per-prompt convention. It is not a guarantee that every possible identifier embedded in free text — for example an ID number, a mailing address, or a parent's name — is detected. Our primary control is keeping identifier fields out of prompts in the first place; the redaction layer is a secondary safeguard.
Individual student demographic data (race, ethnicity, gender, IEP/504/EL status, and socioeconomic indicators) is never sent to AI services alongside identifying information.
4.2 What Is Sent to Third-Party Services
The following de-identified instructional metadata may be sent to external services to generate pedagogically relevant content:
- Tier classification (e.g., “Emerging”) and instructional approach (e.g., “Representational”)
- Math standard codes (e.g., “4.NF.3”) and descriptions
- Misconception types (e.g., “conceptual,” “computation”) — not a student's raw work
- Student count per group (e.g., “4 students”)
- Aggregate confidence scores
- Curriculum metadata (module name, publisher, grade level)
- Instructional free text authored by educators — for example, school-defined academic-language notes or a teacher's lesson notes. These fields are passed through the redaction layer described in 4.1 before transmission so that names and pattern-based PII are stripped.
4.3 Pseudonymization
The codebase includes a formal pseudonymization module that can replace student names with generic identifiers (S001, S002, etc.), strip specified PII fields from data records, and reverse-map pseudonyms back to real names after processing. This utility is available for any future feature that approaches the AI boundary with student-level data.
4.4 AI Services Used
| Service | Provider | Purpose |
|---|---|---|
| Claude Haiku 4.5 | Anthropic | Reasoning, look-fors, CRA-P analysis, RTI documentation narratives |
| Claude Sonnet 4.5 | Anthropic | Intervention plans, supports, and assessments |
5. Third-Party Services
| Service | Provider | Role |
|---|---|---|
| Firebase Auth / Firestore / Storage | Google Cloud | Authentication, database, file storage |
| Vercel | Vercel Inc. | Application hosting, anonymous page view analytics, and performance monitoring (Web Vitals) |
| Anthropic Claude | Anthropic | AI content generation (de-identified metadata; direct identifiers kept out of prompts + redaction layer, see 4.1) |
| Resend | Resend Inc. | Transactional email notifications |
| EdLight | EdLight, PBC | Assessment scoring (subprocessor engaged by Precision Start) |
Google Cloud, Vercel, Anthropic, and Resend host and process data in the United States. EdLight has not specified a data processing location.
6. Data Security
Database Access Control
All database reads and writes flow through server-side API routes using the Firebase Admin SDK. The client-side Firebase SDK is used for authentication and file uploads to Firebase Storage. Firestore security rules deny all direct client-side reads and writes. Student work files are served through signed URLs with time-limited expiration.
Authentication and Authorization
- Every API request requires a valid Firebase ID token verified server-side
- Edge middleware rejects requests without valid authorization headers
- Teacher access is scoped to their own school and their own classes
- Admin access supports two levels: platform administrators (full access) and school administrators/coaches (scoped to their assigned school only)
- Teachers join schools through single-use, transactional invite codes
Multi-School Data Isolation
When multiple schools use the platform, each school's data is strictly isolated. Every API route that accesses school-scoped data validates that the requesting user has been granted access to that specific school. School administrators can only view, process, and manage data for their assigned school(s). There is no path through which one school's staff can access another school's student data, assessment results, or intervention records.
Security Headers
All HTTP responses include security headers: X-Content-Type-Options (nosniff), X-Frame-Options (DENY), X-XSS-Protection, strict Referrer-Policy, and a Permissions-Policy that disables camera, geolocation, and payment APIs. All traffic is encrypted in transit via HTTPS.
Rate Limiting
API endpoints are rate-limited per user or IP address: 10 requests/minute for AI generation, 5 for file uploads, 10 for authentication, and 60 for general API access.
Audit Logging
Every significant platform action is recorded in an audit log, including but not limited to: login, report viewing, student tier overrides, unit publishing and unpublishing, AI content generation and editing, student group moves and regrouping, checkpoint creation, unit processing, student work uploads, school joins, gap detection and closure events, and student profile creation. Each entry captures who, what, which resource, which school, and when. Logs are available to schools upon request.
7. FERPA Compliance
- School Official Exception: Third Eye Analytics operates as a “school official” with a “legitimate educational interest” under FERPA 34 CFR 99.31(a)(1). A Data Processing Agreement is executed with each school before any student data enters the system.
- Educational Purpose Only: Student data is used solely for diagnostic grouping and intervention planning. It is not used for advertising, marketing, or profiling.
- School Ownership: Schools own all student data. Third Eye Analytics processes it on their behalf.
- Minimum Necessary: We collect only assessment performance and standard codes by default. We do not collect disciplinary or health records. Demographic data is used only when a school explicitly requests equity analytics and provides its own demographic data (see Section 2.4).
- No Re-disclosure: Student data is not shared with unauthorized third parties. AI services receive de-identified instructional metadata; direct identifiers are kept out of prompts and an automated redaction layer runs on every request (see Section 4.1).
- Audit Trail: All access to student data is logged with user identity, action, and timestamp.
8. COPPA Compliance
The Children's Online Privacy Protection Act (COPPA) applies to online services that collect personal information directly from children under 13.
- Students do not use Precision Start™. There are no student accounts, no student logins, and no student-facing interface, and students cannot access or control any part of the platform.
- All student data is provided by school-authorized staff (teachers and administrators), not by students or parents.
- No data is collected directly from children. The platform is accessed exclusively by adults.
Because Precision Start™ does not collect information directly from children and is not directed at children, COPPA's direct-collection requirements do not apply. Student data is protected with the same rigor described throughout this policy.
9. Data Retention and Deletion
- During Service Agreement: Student data, classification results, intervention plans, and audit logs are retained for the duration of the active service agreement.
- End of Service: Upon termination, all student data is deleted within 30 days, unless the school requests earlier deletion or a data export.
- Data Export: Schools may request a complete export of their data in standard formats (CSV, JSON) at any time.
- Deletion Requests: Schools may request deletion of specific or all records at any time. Requests are fulfilled within 30 days.
- AI-Generated Content: Intervention plans and supports are deleted along with associated student data.
- Longitudinal Gap Data: Student gap tracking data (gap maps, intervention records, checkpoint history) is retained across units and school years to improve intervention accuracy. This data is included in deletion requests and removed when a school's data is deleted.
- Demographic Data: When a school revokes demographic data sharing, all demographic fields are purged within 30 days. Demographic data is also included in end-of-service and on-demand deletion requests.
- Intervention Cycle History: When student groups are restructured mid-unit (regrouping), prior-cycle session feedback, checkpoint results, and assessment data are preserved for longitudinal analysis and intervention effectiveness measurement. This historical data is included in deletion requests.
- Audit Logs: Retained for the service agreement plus 1 year for compliance, then deleted.
- Third-Party Retention: Anthropic does not retain API request data for training per its current policies. Schools should review each provider's policies independently.
10. Future Data Integrations
Precision Start™ may offer integration with external assessment platforms (such as MAP Growth, iReady, HMH, or EmpowerK12) and operational data systems (such as attendance records). When enabled by a school:
- External data is stored within the school's existing data tenant, subject to the same security and isolation protections described in this policy
- Data is used only to improve classification accuracy and instructional recommendations
- Schools control which integrations are active
- Individual student data is never shared between schools. De-identified, aggregate statistics may be analyzed across schools to improve system accuracy (see Section 2.4)
- External data is included in data deletion requests
11. Your Rights
Teachers
- Override any system classification at any time. The system recommends; the teacher decides.
- View all data associated with their classes and students through the platform.
- Modify student records, group assignments, and notes.
Schools and Districts
- Schools own all student data. Third Eye Analytics processes it on their behalf.
- Request a complete data export at any time.
- Request deletion of any or all data. Fulfilled within 30 days.
- Request access to audit logs pertaining to their data.
Parents and Guardians
Parents and guardians should direct questions about their child's data to their school. The school manages all parent requests regarding educational records under FERPA.
12. Changes to This Policy
We may update this policy to reflect changes in our practices, technology, or legal requirements. When we make material changes:
- Schools with active service agreements will be notified by email at least 30 days before changes take effect
- The “Last Updated” date at the top of this policy will be revised
- The previous version will remain available upon request
13. Contact
For questions about this privacy policy, data practices, or to submit a data request:
Andre Aina
Third Eye Education Analytics LLC
andre@thirdeyeanalytics.org
© 2026 Third Eye Education Analytics LLC. All rights reserved.