Structal Privacy Policy

Effective Date: October 27, 2022

Updated Date: November 30, 2023

The Structal platform (“Platform”) and the Structal web browser extension software (“Extension”) is owned and operated by Structal, LLC (“Structal”). Structal takes your privacy seriously and this document represents its commitment to transparency about its collection of, use of, disclosure of and efforts to safeguard your personally identifiable information and software usage information. We have tried to make the policy clear and welcome any questions or feedback at privacy@structal.ai.

Our collection, use, and sharing of student Personal Information (defined below) is governed by the provisions of the Family Educational Rights and Privacy Act (“FERPA”), the Children’s Online Privacy Protection Act (“COPPA”), and other applicable laws that relate to the collection and use of Personal Information of students. This Privacy Policy is compliant with both COPPA and FERPA.

Throughout this Privacy Policy the words “we”, “us” and “our” refer to Structal, and the words “you” and “your” refer to the user (such as a student that you are responsible for as a teacher or your child or a minor under your guardianship) visiting the Platform or Extension (the platform, the web browser extension software and any associated mobile application collectively are referred to in this Policy as the “Application”). This Privacy Policy applies to information that we collect at or through the Application and our handling of such information. Please review the Application’s Software Agreement terms, which govern your use of the Application.

By accessing and using the Application, you consent to our collection, use and sharing of your and your child’s information and data, and other activities, as described below.

Summary

While we hope you’ll read the whole privacy policy, the following is a brief overview:

  • We do not sell or rent you or your students' data
  • We make money by selling a premium version of our product
  • We only collect information necessary to provide you and your students with reading support
  • We only process digital texts that you or your students explicitly give us access to by activating the Structal extension
  • We use a small number of trusted third parties to help with providing our product
  • You retain ownership of your data

1. What Information Does the Application Collect?

(a) Information You Provide to Us

Personal Information: We may ask you, your child or a minor under your guardianship to provide us with, or you might submit via the Application, personally identifiable information, which is information that identifies an individual personally, such as one’s first and last name and email address (“Personal Information”).

We collect the following categories of information for teachers or adults over the age of 18 for the purposes of account creation and providing the service:

  • Name (First, Last)
  • Email address
  • Single Sign On information (e.g. Google or Microsoft account)
  • School affiliation
  • Class information
  • Information about what they are reading and where they have used the extension only when they have activated the Structal extension
  • Payment information if an adult is purchasing the premium product. We do not store this information on our servers, handling it through a third-party.

We collect the following information for students for the purposes of account creation and providing the service:

  • Name (First, Last)
  • Grade level
  • Single Sign On information (e.g. Google or Microsoft account)
  • Classes they are enrolled in
  • Information about what they are reading and where they asked for help with texts only when they have activated the Structal extension
  • Information about how they answer questions through educational games in our Platform

Note that we do not collect your students’ email addresses, nor do we contact them or allow them to contact us.

We may collect this Personal Information through various forms and in various places on the Application, including account registration forms, or when you otherwise upload data to and interact with the Application. Structal will only collect Personal Information necessary to fulfill its duties as outlined in its agreement with the student’s teacher, guardian, or school district.

(b) Information Collected or Stored As You Access and Use the Application

In addition to any Personal Information or other information that you choose to submit to us via the Application, like most web-based services, we use technologies that automatically (or passively) store or collect certain information whenever you visit or interact with the Application (“Usage Information”). Our third-party service providers may also collect Usage Information via automated means. This Usage Information may be stored or accessed using a variety of technologies that may be downloaded to your personal computer, browser, laptop, tablet, mobile phone or other device (a “Device”) whenever you visit or interact with our Application. This information is necessary to the performance of our services.

That primarily, but not exclusively, entails Usage Information collected via Structal’s web browser extension software to enable the artificial intelligence learning features that support reading. While the Extension is downloaded and associated with your web browser is activated, we have direct visibility into all of the content that you access via your web browser that you give us access to by activating the extension, which all falls under the category of Usage Information. Another example are cookies to support login. To the extent we associate Usage Information with Personal Information that we collect directly from you on the Application, we will treat it as Personal Information.

Usage Information includes:

Log information: Like most online services, when you are actively using the Structal platform, we automatically collect some information in our server logs. This helps us to understand how the service is being used so we can improve it for you and to maintain the security of the service.

Examples include:

  • your Device functionality (including browser, operating system, hardware, mobile network information);
  • the URL that referred you to our Application;
  • the areas within our Application that you visit and your activities there

Note that to further protect your privacy, we anonymize your IP address.

Cookies and other similar technologies: We (or our service providers) may use various technologies to collect and store information when you visit our Application, including clear GIFs (also known as “web beacons”), “tags”, “scripts”, and “cookies” ("Cookies"). We also make use of persistent secure cookies: a persistent cookie remains after you close your browser (although they can be removed) and may be used by your browser to identify you on subsequent visits to the Application. We may also use, collect and store information locally on your device using mechanisms such as browser web storage (including HTML 5). Like many services, Structal uses these technologies to tailor our Application for you, and to help the Application work better for you - for example, by remembering your language preferences.

Cookie Usage: We use Cookies for the following purposes:

Strictly Necessary. We may use Cookies that we consider are strictly necessary to allow you to use and access our Application, including cookies required to prevent fraudulent activity and improve security.

Provider Type Purpose
Structal First party cookie User authentication
Google Sign-In Third party cookie Application sign-in
Clever Sign-In Third party cookie Application sign-in
ClassLink Sign-In Third party cookie Application sign-in
Microsoft Sign-In Third party cookie Application sign-in

Performance Related. We may use Cookies that are useful in order to assess the performance of the Application, including as part of our analytic practices or otherwise to improve the content, products or services offered through the Application.

Provider Type Purpose
Google Analytics Third party cookie Understand how users are using Application
Sentry Third party cookie Application performance and error monitoring
Stripe Third party cookie Payment processing

Functionality Related. Functionality cookies allow our Application to remember your site preferences and choices you make, such as your language. This allows our Application to provide personalized features. They are anonymous and don’t track browsing activity across other websites.

Provider Type Purpose
Structal Local Storage User settings for the Extension

Security Related. These kinds of cookies help us keep our Application safe and secure by supporting and enabling security features, as well as helping us detect suspicious activities that are in breach of our Terms of Service or otherwise pose a threat to our ability to provide our services. We use security cookies, among others, to prevent fraudulent use of login.

Provider Type Purpose
AWS WAF Third party cookie Protect your account and our application

Marketing Related. These cookies track your activity when Structal's team communicates with teachers/adults by email so we can assess the effectiveness of our communications. These are only used in email communication with adults, and thus do not affect students.

Provider Type Purpose
SendGrid Web beacon To assess email performance and communications effectiveness
Streak Web beacon To assess email performance and communications effectiveness

Note that we do not use marketing tracking technology to track you over time across 3rd party websites to provide targeted advertising.

Cookie Choices and Consent.

Most browsers allow you to disable cookies should you choose that you do not want any of these to be set. Please note, that this will affect the performance of our application and many features may not work properly.

We obtain your consent to our information storage or collection Cookies by providing you with transparent information in our Privacy Policy and providing you with the opportunity to make a choice to disable cookies as set forth above. Please note that we are not required to obtain your consent to the Cookies identified above that are strictly necessary.

Do Not Track

Various third parties are developing or have developed signals or other mechanisms for the expression of consumer choice regarding the collection of information about an individual consumer’s online activities over time and across third-party web sites or online services (e.g., browser do not track signals). While we try to take your privacy concerns very seriously, currently we do not monitor or take any action with respect to these signals or other mechanisms.

(c) Information Third Parties Provide About You

We do not currently use information provided by third parties about you.

(d) Interactions with Third-Party Platforms

The Application includes functionality that allows login to the Application from a third-party website or application, commonly referred to as Single Sign On. The use of this functionality may involve the third-party operator providing certain information, including Personal Information, to us. When you register with the Platform, you may have an option to use your Microsoft, Google, Clever, or ClassLink account provided by a third-party site or application to facilitate the registration and log-in or transaction process on the Application, or otherwise link accounts. If we offer and you choose to use this functionality to access or use our Application, the third-party site or application may send Personal Information about you to us. If so, we will then treat it as Personal Information under this Privacy Policy, since we are collecting it as a result of your accessing of and interaction on our Application.

(e) Information Not Collected

We do not collect or process sensitive personal information/special category data or biometric data.

2. How Do We Use the Information Collected?

We may use your Personal Information or Usage Information that we collect about you:

  1. to provide the literacy support services that are core to Structal’s product and mission;
  2. to provide teachers/adults with information or services or to process transactions that you have requested or agreed to receive;
  3. to provide teachers/adults with information via email about new Structal product or service offerings on an ongoing basis, unless you opt out of receiving such emails;
  4. to enable you to participate in a variety of the Application’s features;
  5. to process your account inquiry, including verifying your information is active and valid;
  6. to improve the Application, to create new service offerings, to customize your experience on the Application, or to serve you specific content that is most relevant to you;
  7. to contact you with regard to your use of any of the Application and, in our discretion, changes to the Application and/or any of the Application’s policies;
  8. for internal business purposes;
  9. for billing purposes should an adult decide to subscribe to Structal Plus; and
  10. for purposes disclosed at the time you provide your information or as otherwise set forth in this Privacy Policy.

Please note that information submitted to the Application via a “contact us” or other similar customer inquiry function may not receive a response.

3. How and When Do We Share Information with Third Parties?

We will not share Personal Information with third parties for direct marketing purposes. We may, however, share non-Personal Information, such as aggregated, anonymous user statistics, with third parties.

We may share the information we have collected, including Personal Information, as disclosed below to provide the Application's services:

(a) Third Parties Providing Services on Our Behalf. We may use third-party vendors to perform certain services on behalf of us or the Application, such as hosting the Application, designing and/or operating the Application’s features, tracking the Application’s activities and analytics, and or performing other administrative services. We may provide these vendors with access to user information, including Device Identifiers and Personal Information, to carry out the services they are performing for you or for us. Third-party analytics and other service providers may set and access their own Cookies on your Device and they may otherwise collect or have access to Personal Information.

See below for a list of the third parties we work with and how we use them.

(b) To Protect the Rights of Structal and Others. We do not disclose any personal information about children to third parties, except to service providers necessary to provide the Application, as required by law (e.g. subpoena), or to protect the security of the Service or other users.

(c) Business Transfer. We reserve the right to disclose and transfer Personal Information: (i) to a subsequent owner, co-owner or operator of the Application or applicable database; or (ii) in connection with a merger, consolidation, restructuring, the sale of substantially all of our interests and/or assets or other corporate change, including, during the course of any due diligence process. If such transfer is subject to additional mandatory restrictions under applicable laws, we will comply with such restrictions. The successor entity will be subject to all applicable federal and state laws, including student privacy laws. In connection with such a transaction, we will also work to ensure that the successor entity has a commitment to student privacy.

4. Who are our third party service providers?

It is important to us that we keep your information safe and secure. To best provide our Application, and keep your information safe, we work with a few other companies. These companies ("third-party service providers", "collaborators" or "agents") will only have access to the information they need to provide the Application.

These providers are as follows:

  • Amazon Web Services (AWS) - hosting and managing Structal’s infrastructure, and for product/service functionality support and improvement
  • Google Services - analytics on our website ("Google Analytics"), supercharge our tutor functionality
  • OpenAI - supercharge our tutor functionality, see note below for more info
  • Quickbooks - invoice management
  • SendGrid - email provider
  • Sentry - monitoring the performance of our service, including errors
  • Stripe - payment processing
  • Streak - customer management

A note on how we use OpenAI: We use OpenAI to supercharge our reading tutor and make it feel, well, more like a tutor. Much has been made of ChatGPT and OpenAI's services, so we feel it's important to give you a clear idea of the precautions we take with the service. There is nowhere in the app for students to openly interact with the GPT service (i.e. to ask their own prompts). On our end, we tightly control the prompts we use to ensure their educational value. We also use an additional privacy setting with OpenAI to make sure yours and your students' data is not retained by OpenAI or used to train their model. Finally, while GPT has excellent content filtering to make sure your student doesn't ask for mature content, we apply additional content filtering ourselves as another line of defense against anything inappropriate making it to your students.

This list may change over time, and we will work hard to keep it up-to-date. However, disclosure of your personal information to additional third parties or use of it for different purposes than those indicated in this Privacy Policy shall only be done after notifying you of all necessary information on any key elements affecting the processing of your personal data, either by directly emailing you with it or by updating this Policy and giving appropriate notice of it.

We will transfer your personal information to third-party service providers only for limited and specific purposes. We will ensure that our collaborators will safeguard personal information in a manner consistent with this Policy and that they will provide the same level of protection as per best industry standards. We recognize our responsibility and potential liability for onward transfers to agents. Where we have knowledge that an agent is using or disclosing personal information in a manner contrary to this Policy and/or level of protection as required by applicable laws and regulations, we will take reasonable steps to prevent, remediate or stop such use or disclosure. If we transfer personal information to non-agent third parties, that is to say, any new collaborators that are not included in the previously mentioned list, we will (1) notify you with all necessary information on any key elements affecting the processing of your personal data, and (2) ensure these parties will provide the same level of security as per best industry standards and in accordance with any applicable laws and regulations.

5. What About Information I Disclose Publicly or to Others?

Teachers have the ability to create customized literacy supports for their students. Their students will see these support when reading something for that class.

These customized literacy supports are also shown to other teachers in their school district to facilitate collaboration on supporting students.

We do not share student information publicly. Only their teachers can view the information they’ve asked for help with through the platform to allow them to understand where students have struggled.

6. Do you show advertisements on the platform?

We do not show advertisements on the platform and do not use third party trackers for advertisements.

7. How Do I Change My Information and Communications Preferences?

You are responsible for maintaining the accuracy of the information you submit to us, such as your contact information provided as part of registration. The Application may allow you to review, correct or update Personal Information you have provided through the Application’s registration forms or otherwise, and you may provide registration updates and changes by contacting us. If so, we will make good faith efforts to make requested changes in our then active databases as soon as reasonably practicable (but we may retain prior information as business records). Under the Children’s Online Privacy Protection Act, parents have a right to review or have deleted the child’s personal information. Structal shall take all commercially reasonable steps to comply with such requests (including from teachers).

Please note, however, that it is not always possible to completely remove or delete all student information from our databases and that residual data may remain on backup media or for other reasons. However, such copies and backups will be kept for a maximum of six months as part of our disaster recovery storage system and will not be accessible to the public, nor used by Structal in the normal course of business.

When you edit your Personal Information or change your preferences on the Application, information that you remove may persist internally for Structal’s administrative purposes. Teachers or school districts may cancel or modify our e-mail marketing communications they receive from us by following the instructions contained within our promotional emails or in some cases by logging into your Application account and changing your communication preferences. This will not affect subsequent subscriptions and if your opt-out is limited to certain types of e-mails the opt-out will be so limited. Please note that we reserve the right to send you certain communications relating to your account or use of our Application, such as administrative and service announcements and these transactional account messages may be unaffected if you choose to opt-out from receiving our marketing communications. If you have any questions about the Privacy Policy or practices described in it, you should contact us in the following ways: Postal Mail: Attention: Privacy Officer, Structal, LLC, 155 Seaport Blvd., Boston, MA 02210.; By e-mail: privacy@structal.ai

8. What About Transfer of Information to the United States?

Our Application is operated in the United States. If you are located outside of the United States, please be aware that information we collect, including Personal Information, will be transferred to, and processed, stored and used in the United States. The data protection laws in the United States may differ from those of the country in which you are located, and your Personal Information may be subject to access requests from governments, courts, or law enforcement in the United States according to laws of the United States. By using the Application or providing us with any information, you consent to the transfer to, and processing, usage, sharing and storage of your information, including Personal Information, in the United States as set forth in this Privacy Policy.

9. Who owns your data in the application?

Data is Property of User or LEA

All data collected by Structal as outlined in this policy (“Data”), is and will continue to be the property of the user, unless Structal is provided through a Local Education Agency (LEA), where all Data will remain the property of the LEA. Structal further acknowledges and agrees that all copies of such Data transmitted to Structal, including any modifications or additions or any portion thereof from any source, are subject to the provisions of this privacy policy in the same manner as the original Data. Structal and LEA agree that as between them, all rights, including all intellectual property rights in and to Data contemplated per the Privacy Policy, shall remain the exclusive property of the LEA. For the purposes of FERPA, Structal shall be considered a School Official, under the control and direction of the LEA as it pertains to the use of Data, notwithstanding the above. This provision does not apply to information that has been anonymized or de-identified or anonymous usage data (“De-Identified Data”) of Structal’s services. This De-Identified Data will only be used by Structal for product development, research, and anonymous usage statistics in compliance with relevant laws.

Parent Access

To the extent required by law the LEA shall establish reasonable procedures by which a parent, legal guardian, or eligible student may review student Data, correct erroneous information, and procedures for the transfer of student-generated content to a personal account, consistent with the functionality of services. Structal shall respond in a reasonably timely manner (and no later than forty five (45) days from the date of the request or pursuant to the time frame required under state law for an LEA to respond to a parent or student, whichever is sooner) to the LEA’s request for student Data in a student’s records held by Structal to view or correct as necessary. In the event that a parent of a student or other individual contacts Structal to review any of the student Data accessed pursuant to the Application, Structal shall refer the parent or individual to the LEA, who will follow the necessary and proper procedures regarding the requested information.

Data Retention

We only keep Data as long as is necessary to provide Structal's educational services.

Deleting inactive accounts: If a student’s account is inactive for eighteen (18) months or more (meaning the student has not used his or her account), Structal will automatically delete the student account, including all personal information provided by the student or collected by Structal from the student. We chose the eighteen (18) month term based on the estimated use of the Application, which usually coincides with an entire school year, plus an additional period of time in case teachers want to renew the use of the Application.

Request for deletion: When used at an LEA, School officials may request deletion of student accounts at any time by reaching out to privacy@structal.ai. Structal shall be entitled to require assistance and collaboration from the educational institution as reasonably necessary in order to appropriately attend the deletion request. When not used at an LEA, parents, guardians, or adult users may request to have their account deleted at privacy@structal.ai.

10. What About Security?

We endeavor to incorporate commercially reasonable safeguards to help protect and secure Personal Information. However, no data transmission over the Internet, mobile networks, wireless transmission or electronic storage of information can be guaranteed to be 100% secure. Please note that we cannot ensure the security of any information you transmit to us, and you use our Application and provide us with your information at your own risk.

Your Structal account is protected by an SSO login. You can help us protect your account from unauthorized access by keeping your SSO option's password secret at all times. We do not maintain any passwords in our databases. The security of your personal information is important to us. We work hard to protect our community, and we maintain administrative, technical and physical safeguards designed to protect against unauthorized use, disclosure of or access to personal information, such as:

Security Protocols: We periodically review our information collection, storage and processing practices, including physical security measures, to protect against unauthorized access to systems.

Security Technology: We continually develop and implement features to keep your personal information safe - for example, when you enter any information anywhere on the Service, we encrypt the transmission of that information with, at least, TLS v1.2 and v1.3 for all data in transit, and no less than AES256-CBC (256-bit Advanced Encryption Standard in Cipher Block Chaining mode) for encrypting data at rest.

Employee Access: We use best-effort practices to secure usernames, passwords and any other means of gaining access to users data. All employees interacting with student data sign confidentiality agreements and pass criminal background checks.

Employee Training: We provide periodic security training to those employees that operate or have access to users’ data.

We align with the internationally recognized ISO 27001 security standard.

We are committed to preventing unauthorized access to our systems and data, and will investigate any possible occurrence. In the event of a breach of student Personal Information, we will comply with all relevant breach laws to assist the School to provide notification if being used by an LEA, or will notify affected adults.

11. What About Changes to the Privacy Policy?

We reserve the right to change this Privacy Policy at any time. If we make material changes to the policy, we will notify your primary email or the primary email of authorized account administrators in the case of minors. Any changes will be effective immediately upon the posting of the revised Privacy Policy and your use of our Application indicates your consent to the privacy policy posted at the time of use. However, we will not use your previously collected Personal Information in a manner materially different than represented at the time it was collected without your consent. To the extent any provision of this Privacy Policy is found by a competent tribunal to be invalid or unenforceable, such provision shall be severed to the extent necessary for the remainder to be valid and enforceable.