ImagineAI LLC

Student Privacy Terms

Effective date: November 24, 2025

Last updated: July 17, 2026

Download MSPA Exhibits A/B/F (PDF)

Who may use the Service

  • Designed for classroom use with students (including under 13) under a teacher or school’s authorization.
  • Students join with a classroom code issued by a teacher. Teachers create their own accounts.
  • By creating a teacher account or enabling student access, you represent that you are authorized by your school or district to do so and that you will obtain any required parental consent under COPPA/FERPA/PPRA and Massachusetts 603 CMR 23.00.

What the Service Does

ImagineAI lets students create illustrated books through conversational AI and image generation. Teachers oversee class activity via a dashboard scoped to their own classes and students; students can access only their own work and assigned classes.

Where separately enabled, the private Friends feature lets a child use a generated author identity, connect through a one-use code only after approval by both linked adults, and receive an explicit invitation to collaborate on a book. It does not create a public child directory, public friend graph, social feed, or direct-message service.

Student Data Ownership and School Official Status

The LEA (school/district) owns and controls Student Data and Pupil Records. ImagineAI LLC acts as a “School Official” with a legitimate educational interest, under the direct control of the LEA for FERPA and Massachusetts law purposes. Students and teachers own the creative content (books, text, images) they produce; ImagineAI retains ownership of its platform and underlying technology. We will use Student Data only to provide and support the Service as described here.

Data We Collect

  • Identifiers: teacher email, student email (for login only), student username, optional student name as entered on a book title page, classroom code.
  • Account security: hashed password or federated auth credentials.
  • Student work: generated or imported text, images, optional audio, book materials, classroom/friend collaboration content, and the grants/moderation records needed to protect those features.
  • Optional Friends data: a service-generated author name, seeded/chosen and claim/cooldown state, an optional private AI-avatar prompt and saved/worn images, one-use invite-code state, linked-adult approval and friend-connection state, and derived book-collaboration grants.
  • Optional native notifications: a service-only device token and installation/generation state used only for transactional delivery.
  • System logs: minimal service logs (e.g., timestamped requests, error traces) without storing IP addresses beyond transient transport logs required by hosting providers.
  • We do not use biometrics, precise location, disability/IEP/ELL flags, race/ethnicity, health, discipline, advertising identifiers, or voice/audio for biometric identification. User-supplied pictures and optional voice/audio are processed only for the requested book, media, transcription, or playback feature.
  • The optional adult-account verification build is not a student verification feature: students are not asked for a government ID, selfie, or payment card through it. It must not be enabled for a district adult-account use case without advance subprocessor notice, contract/region review, and an updated data-flow disclosure.

How We Use Student Data

  • Operate the chat and image generation needed to build books.
  • Display class dashboards for teachers, restricted to their students.
  • Provide support, security, and service reliability.
  • Review an individual student account or its content when needed to provide the Service — to troubleshoot a problem, respond to a teacher, parent, or district request, investigate unusual activity, or keep students safe. Production access is limited to the founder/administrator and is authenticated and logged, per Exhibit F.
  • Improve the Service using de-identified or aggregated data only; we do not attempt to re-identify students.

What We Do Not Do

  • No selling or renting Student Data.
  • No targeted advertising, marketing, or profiling of students or families.
  • No disclosure of Student Data to third parties except subprocessors listed below, or as required by law after notice to the LEA unless legally prohibited.
  • No use of Student Data to train third-party models; prompts/outputs sent to listed model providers are processed only to generate the requested result under the applicable provider terms.

Subprocessors

  • Supabase (database and authentication; managed PostgreSQL).
  • Google Cloud Firebase/Firestore and Firebase Storage (generated-book content and related private media).
  • Railway (web application and durable assistant-runner hosting) and Trigger.dev (background jobs).
  • Resend (transactional email for teachers, parent/guardian consent and friend approvals, and internal operational notices). Student emails are not used for marketing.
  • OpenAI, Anthropic, Fireworks AI, and Together AI (requested text/chat generation and moderation).
  • Google image models, FAL.ai, and WaveSpeed (requested image/video generation; WaveSpeed is used by the standalone Google Veo 3 Fast text-to-video route).
  • ElevenLabs (optional generated audiobook narration).
  • Epic Games Kids Web Services (parent/guardian adult verification when the separately gated Parent Controls integration is enabled).
  • Apple Push Notification service (minimal native notification delivery).
  • Stripe and Apple (optional commerce/subscription processing) and Lulu plus the private ImagineAI print service (optional physical-book fulfillment). ImagineAI does not store card or bank-account numbers.

Each subprocessor is bound by written terms requiring at least the same data protections as this Agreement. We will notify the LEA before adding or replacing a subprocessor and give an opportunity to object.

Security

  • Encryption in transit (HTTPS/TLS) and at rest for stored data.
  • Access to production data is limited to the founder/administrator on a need-to-know basis; confidentiality obligations apply.
  • Credentials are protected; passwords are hashed.
  • Supabase-managed backups for the database (US-only). Retention follows Supabase policy; deletions propagate to backups as their retention windows expire.
  • We conduct periodic risk reviews and will remediate identified issues.

Parent/Student Access and Corrections

Upon an LEA request, we will provide or correct a student’s personally identifiable information within required timelines (target within 72 hours, earlier if state law requires). If a parent or student contacts us directly, we will refer them to the LEA and cooperate with the LEA’s instructions.

Data Retention and Deletion

  • We keep student accounts and work while the classroom is active.
  • Upon LEA request, we will return specified Student Data within 3 days and delete it as soon as practicable (target within 3 days), with written confirmation.
  • Outside of LEA requests, we keep data only as long as needed to support the classroom and delete promptly when the LEA ends use of the Service or instructs deletion.
  • Completed account deletion removes or de-identifies the applicable private author identity/cooldown state, every saved/worn avatar/media object, friend grants, and device registrations under the documented deletion process. Severing a friend relationship revokes that relationship's derived book grants and access.
  • Friend invite codes expire after seven days and cannot authorize access after expiry, consumption, or rotation. Terminal relationship and invite-code state may remain as service-only operational/security records until account deletion or earlier cleanup.
  • De-identified data may be retained for service improvement, never for re-identification.

Data Breach Notification

If Student Data is accessed or acquired by an unauthorized person, we will notify the LEA within 72 hours of confirmation (or faster if state law requires, e.g., 24 hours initial notice in some states) and provide the required details. We will cooperate with any investigation and remediation.

Third-Party Requests for Data

We will direct third parties (including law enforcement) to request Student Data from the LEA. We will not disclose Student Data unless required by law and, where lawful, will give the LEA prior notice.

Content Rights

Students and teachers retain ownership of the content they create. By using the Service, you grant us a limited license to host, process, and display that content solely to operate the Service for the classroom.

Copyright and User Content

Users may not upload, publish, share, or otherwise make available content that infringes another person's copyright or other intellectual property rights. ImagineAI may remove or disable access to allegedly infringing material and, in appropriate circumstances, suspend or terminate accounts of users who repeatedly infringe or submit infringing content.

Copyright notices should be sent to the designated agent listed on our Copyright / DMCA Notice.

General Offer of Privacy Terms

ImagineAI LLC agrees to extend these privacy terms to any Massachusetts school district that signs the General Offer of Privacy Terms (Exhibit E of the Massachusetts Student Data Privacy Agreement). Price and service scope may be set separately, but privacy protections remain the same.

Governing Law and Venue

This Agreement is governed by the laws of the Commonwealth of Massachusetts. Venue and jurisdiction reside in the state and federal courts located in Plymouth County, Massachusetts.

Contact

ImagineAI LLC
Email: kyle@imagineai.one
Privacy/Security Contact: Kyle Maloney
(Physical notice address available to districts upon request.)