Last updated: 2026-08-30
Applies to: the Trace website and application at https://trace.school, including the Agent Builder, the lesson and lab experience, the school portal, and the Trace SDK.
Contact: [email protected]
1. Who we are#
Trace Education operates Trace, a platform where K-12 students learn about AI through lessons, labs, and building agents.
Trace Education is registered as TraceEducation LLC. Our contact details are in §13.
2. What Trace does#
A teacher creates a class, assigns lessons, labs, and quizzes, and reviews students' submitted work. Students can also build agents in the Agent Builder and run them against approved AI models.
How we handle information depends on how you use Trace:
- Through a school. The school decides what Trace may do with student information, and we act on the school's documented instructions. Records about a student's schoolwork are education records belonging to the school under FERPA. Those relationships are governed by the Data Processing Agreement in addition to this policy.
- On your own. If you sign up independently, this policy governs how we handle your information.
3. Information we collect#
What we do not collect#
Trace does not collect:
- Home addresses, phone numbers, or government ID numbers
- Health information, IEP or 504 status, disability records, or counseling records
- Free or reduced lunch status, race, or ethnicity
- Discipline records or attendance records
- Photographs, video of students, or biometric identifiers
- Precise location data or GPS coordinates
- Advertising identifiers, and we run no advertising of any kind
We also have no integration with any student information system or LMS, so we never receive grades, rosters, or records from a school's own database. And we never receive your password: sign-in is handled by WorkOS, which holds credentials; Trace only ever sees a token confirming a successful sign-in.
Account information#
From WorkOS, when you sign up: your email address, username, first and last name, your role (student, teacher, or school administrator), and your date of birth. Date of birth is collected as an age gate; see §10.
Schoolwork and learning records#
- Which lessons, labs, and quizzes you have worked through, and how far you got
- Your answers to quizzes and unit tests, including free-response text you write
- Reflections and saved work inside interactive labs
- Assignments your teacher gave you, and the work you submitted against them
- Class membership, and coins earned (a progress marker inside Trace and nothing more)
Projects and AI interactions#
- The projects you build, stored as graph JSON, and a saved snapshot of each version you run
- Conversation messages between you and a model
- A record of each run: the input you gave it, and per-step events holding the model inputs and outputs, tool calls, and errors
- Credit ledger entries recording which model was used and how many tokens went in and out
Run history lets students review their work and teachers inspect submitted runs.
Contact, meetings, and support#
If you write to us through the contact form we receive your name, email, organization, and message. If you book a call, Cal.com processes the booking and we receive the meeting details. If we set up a shared Slack channel with your school, we process the email addresses we invite.
Operational records#
- Email deliveries. We store the transactional emails we send you, including their full body, so that support can see exactly what you received.
- Audit events. Security-relevant actions (sign-ins, permission changes, admin actions, privacy operations) are logged with actor, action, and outcome. Audit events contain no student content.
- Error reports. Backend errors are sent to Sentry as stack traces and operational metadata.
Analytics#
Trace uses PostHog for optional product analytics. See §5 and the Cookie Policy.
4. How we use information#
| Purpose | What it covers | Legal basis (EEA/UK) |
|---|---|---|
| Providing the service | Accounts, classes, assignments, running agents, showing a teacher their students' work | Contract (Art. 6(1)(b)); for school accounts, the school's instructions |
| Safety and moderation | Applying school-appropriate model instructions, reviewing tutor messages and final AI replies for harmful or cheating-enabling content, crisis support, abuse investigation | Legitimate interests (Art. 6(1)(f)); vital interests where a crisis is indicated |
| Security | Session revocation, rate limiting, audit logging, fraud and abuse prevention | Legitimate interests (Art. 6(1)(f)); legal obligation |
| Billing | Subscriptions, seats, credit accounting | Contract (Art. 6(1)(b)) |
| Product analytics | Understanding which lessons and flows work, and where the app breaks | Consent (Art. 6(1)(a)) |
| Support and service email | Answering you, onboarding a school, agreement receipts | Contract; legitimate interests |
| Legal compliance | Responding to lawful requests, enforcing our Terms | Legal obligation; legitimate interests |
AI models and training#
Trace does not use your data to train, fine-tune, or improve any AI model. This includes student work, prompts, model outputs, quiz answers, and project content.
Every model request includes instructions prohibiting provider retention and training: data_collection: deny and zdr: true. These apply to the Agent Builder, chat, speech-to-text, text-to-speech, the SDK gateway, and safety review calls.
The models available in Trace are a fixed allowlist. As of this date:
| Model ID | Name | What it does |
|---|---|---|
deepseek/deepseek-v4-flash-0731:nitro | DeepSeek V4 Flash | Chat and agent runs (the default model) |
xiaomi/mimo-v2.5 | MiMo 2.5 | Chat and agent runs |
openai/gpt-5.6-luna | GPT-5.6 Luna | Chat and agent runs |
qwen/qwen3-asr-flash-2026-02-10 | Qwen3 ASR Flash | Speech to text |
hexgrad/kokoro-82m | Kokoro 82M | Text to speech |
openai/text-embedding-3-small | OpenAI Text Embedding 3 Small | Embeddings, Trace SDK only |
We may add, remove, or replace models, including for privacy or safety reasons, and update this table when we do. Students can only use approved models.
What we remove before a prompt leaves us#
Prompts go through our backend rather than straight from the browser, which lets us strip identifiers first. Before content is sent to a model, or copied into a run event, we remove the signed-in student's own name, email, account ID, and date of birth, plus anything matching the shape of an email address, phone number, Social Security number, street address, or student ID. Authorized conversation and project records still keep the content needed for the product to work.
Redaction has limits:
- It removes the identifiers of the student who is signed in. It does not recognize a classmate's name, a teacher's name, or a school's name.
- It is pattern matching. Unusual spellings and formats can slip through.
- Audio sent to the speech-to-text model cannot be filtered; the recording itself is transmitted.
- The redaction applies to what we send out, not to what we store. The copy of a prompt held in your project, conversation, and run history is the original text you typed.
Students should not enter personal information about themselves or others into an AI system.
Automated decisions#
Trace does not make automated decisions that produce legal or similarly significant effects about a person. It does not compute a mastery score, a grade, or a judgment about a student's ability. Content moderation is automated and can block a message; a blocked message is not a decision about the student, and a teacher or administrator can always review it.
5. Cookies and analytics#
The WorkOS wos-session cookie is required to keep you signed in.
Analytics and session replay require consent:
- Product analytics is off by default. Activity before consent is not recorded or sent to PostHog later.
- Signed-in users are identified by account ID and role, without names, email addresses, or school details. Anonymous visitors have no stored person profile.
- Session replay requires a separate opt-in and masks typed inputs.
- Analytics is sent to PostHog through Trace's server.
- You can withdraw consent through Cookie preferences in the footer. This stops collection and clears the stored analytics identifier.
The Cookie Policy lists cookies, browser storage, retention periods, and controls.
Trace runs no advertising cookies, no ad pixels, and no cross-site tracking of any kind.
6. Who else sees your information#
People#
A teacher can see the work their own students do in their own class: progress, quiz answers, submitted projects, and the run history attached to a submission. Students can see who else is in their class. A school administrator can see the classes and teachers in their school. Nobody outside your class sees your work unless you deliberately share a project, and sharing can be revoked at any time.
Companies that help run Trace#
These are our processors. Each is bound by data-protection terms and receives only what its function requires. The authoritative list, including a machine-readable version at GET /api/v1/privacy/subprocessors, is at Subprocessors.
| Provider | Purpose | What it receives | Privacy policy |
|---|---|---|---|
| WorkOS | Identity, authentication, organizations, multi-factor authentication | Name, email, username, password, date of birth | https://workos.com/legal/privacy-policy |
| Stripe | Subscription billing and payment processing (hosted Checkout and Customer Portal) | Billing and payment details; Trace never sees card numbers | https://stripe.com/privacy |
| OpenRouter | Routing prompts to the approved AI models | Prompt and response content, with direct student identifiers redacted, under a zero-retention instruction | https://openrouter.ai/privacy |
| PostHog | Product analytics and session replay, both consent-gated | Account ID and role, page and event data, web vitals | https://posthog.com/privacy |
| Cal.com | Scheduling meetings booked at /contact/meeting | Name, email, and booking details of the person booking | https://cal.com/privacy |
| Slack | Shared support channels with schools | Email addresses invited to a channel, and channel messages | https://slack.com/trust/privacy/privacy-policy |
| Sentry | Backend error monitoring | Stack traces and operational metadata; no student content | https://sentry.io/privacy/ |
| Resend | Transactional email | Recipient address and message content | https://resend.com/legal/privacy-policy |
| Hosting and database | Running the application and storing its data | All stored data | [Hosting provider and region to be confirmed] |
Behind OpenRouter sit the companies that actually serve each model: Alibaba (Qwen), DeepSeek, Xiaomi, OpenAI, and Hexgrad. OpenRouter publishes the serving provider and its data policy on each model's page. Our zero-retention instruction travels with every request.
Other disclosures#
We do not sell, rent, or trade personal information, or share it for cross-context behavioral advertising. We disclose information outside the list above only where the law requires it. If school data is involved, we tell the school first unless legally prohibited.
7. How long we keep information#
| Category | Retention |
|---|---|
| Account record | Kept while the account exists. On deletion, identifying fields are overwritten and the record is retained as a tombstone (see below). |
| Password | Never held by Trace. Held by WorkOS and removed when the WorkOS user is deleted. |
| Projects and project versions | Kept while the account exists. On deletion the title is replaced; the graph and version snapshots are retained in de-identified form. |
| Conversations and messages | Kept while the account exists. On deletion the message content is replaced with [deleted]. |
| Runs | Kept while the account exists. On deletion the run's input is cleared; per-step run events (which hold model inputs and outputs) are retained. |
| Learning records and submissions | Retained. They are the school's education records, and deletion is handled through the school. |
| Credit ledger | Retained. These are billing records. |
| Audit events | Automatically pruned after 365 days. Contain no student content. |
| Moderation flags | Retained. They record the category and time, never the message text. |
| Email deliveries | Retained, including message bodies, so support can reconstruct what you received. |
| Contact submissions and bookings | Retained until we no longer need them to answer you or to keep a record of the conversation. |
| Analytics (PostHog) | Only exists if you consented. Retained per PostHog's retention settings; withdrawing consent stops collection and forgets the browser. |
| Rate-limit counters (include your IP address) | Automatically deleted after 24 hours. |
Only audit events and rate-limit counters expire automatically. To request deletion of other data, see §8.
8. Deleting and exporting your data#
Account deletion#
Account deletion removes identifying information but does not erase every record. Deleting your account:
- Marks the account deleted, invalidates every existing session, and revokes API keys
- Overwrites your email, username, and name, and clears your date of birth
- Replaces conversation message content with
[deleted]and conversation titles with "Deleted chat" - Clears the stored input on your runs and replaces project titles with "Deleted project"
- Deactivates school memberships and freezes the credit account
- Deletes the corresponding user at WorkOS, which removes your password and login identity
What survives, in de-identified form: run event payloads, project and version graph JSON, submissions and learning records, credit ledger rows, audit rows, and email delivery records. They are no longer linked to a name or an email address, but they are not erased.
To request full erasure of a specific record, email [email protected]. We handle these requests manually and confirm completion. Schools should use the process in the DPA.
Before deleting your account, transfer any role you hold as a school's sole administrator or a class's lead teacher.
Export#
To request a JSON copy of your profile, projects, conversations and messages, runs, submissions, and credit ledger, email [email protected]. You can also use GET /api/v1/auth/account/export.
9. International transfers#
Trace is operated from the United States. Our hosting vendor and region are being finalized and will be named in the Subprocessors list.
OpenRouter routes prompts and responses to the provider serving the chosen model. Model developers include Alibaba, DeepSeek, and Xiaomi, which are headquartered outside the United States. Depending on the model, content may be processed outside the United States and the EEA. Every request carries our zero-retention instruction.
For personal data transferred out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with our processors, together with the technical measures described in §11. Schools with data-residency requirements should raise them before signing; §9 of the DPA is where residency commitments get written down.
10. Children#
Students under 13#
You must be 13 or older to create a Trace account independently. Students under 13 can join only through a valid school-authorized invitation.
Under the COPPA school-consent route, the school confirms its authority to consent on parents' behalf for school-directed educational use and accepts the related parental-notice obligations. The Data Processing Agreement records these commitments.
We do not knowingly collect personal information from a child under 13 outside this route. If you believe a child under 13 created an account without school authorization, write to [email protected] and we will remove it.
The school safety layer#
Every primary chat request gets the same Trace-owned school policy, regardless of age or sign-up route. It requires K-12-appropriate responses, refuses harmful and dangerous material, asks models to respond supportively to distress, and prevents direct help cheating on active tests or homework while allowing explanations, hints, practice, feedback, and legitimate teacher-facing work.
- Before a tutor message is stored or sent to the requested model, one low-reasoning DeepSeek V4 Flash call reviews only the privacy-redacted message. A blocked message is not stored or sent onward.
- Immediately before Trace returns or stores a final assistant reply, one low-reasoning DeepSeek V4 Flash call reviews the privacy-redacted reply.
- The reviewer is DeepSeek V4 Flash, developed by DeepSeek, a company headquartered in China, and reached through OpenRouter under a provider policy that forbids the provider from retaining or training on the text. It is a different model from the one that writes the reply, and it is the only model that sees a message for safety purposes.
- While the tutor works, it shows a short summary of its own reasoning and the lookups it ran. That summary is shown to you while you wait and is not stored with your conversation. The reply itself appears only after it passes the review above.
- Each review receives only its candidate message or proposed reply. It does not receive the conversation history, tools, embeddings, or internal model turns.
- A flagged verdict is enough to withhold the message or the reply. If Trace cannot obtain a valid safe verdict after one retry of a failed review, the message or reply is withheld and the safety check is reported as unavailable.
- The review covers sexual content, graphic violence, self-harm, hate or harassment, dangerous or illegal instructions, academic cheating, and other material inappropriate for a K-12 setting.
- Moderation flags record the category, scope, and time. They do not store the reply or a reviewer's explanation.
- The requested model's completed generation is charged normally, including when its reply is withheld. Trace pays for the safety review calls, two per tutor turn.
- Teachers and guardians can see a minor's AI interactions for supervision, and that access is itself audited
Parents#
If your child uses Trace through a school, FERPA gives you the right to inspect their education records and request corrections through the school. We act on the school's instructions. Parents can also request instructional material, including versioned Trace lessons.
If your child uses Trace independently, write to [email protected] and we will handle access, correction, or deletion directly.
11. Security#
Our security measures include:
- In transit: TLS everywhere, with HSTS sent on every response (
max-age=63072000; includeSubDomains; preload) - Response headers:
X-Content-Type-Options: nosniff,Referrer-Policy: strict-origin-when-cross-origin,X-Frame-Options: DENY,Content-Security-Policy: frame-ancestors 'none', and a Permissions-Policy that turns off camera, microphone, geolocation, and browsing-topics. A full script-source CSP is being rolled out; it needs a verified allowlist for WorkOS, PostHog, and Cal.com before it can be enforced without breaking sign-in. - Credentials: passwords live at WorkOS and never reach us. Model provider API keys stay server-side and are never exposed to a browser; students never hold a key.
- Authorization: every request touching student records is checked against class membership and ownership. Project sharing is re-checked on each open and can be revoked.
- Sessions: sessions can be revoked centrally, and are invalidated on account deletion.
- Limits: rate limiting, per-run caps on tokens, steps, and cost, and a fixed model and tool allowlist.
- Moderation: the school safety layer described in §10.
- Logging: audit events with actor, action, target, and outcome, pruned at 365 days.
Encryption at rest is provided by our hosting and database vendor; that vendor is being finalized and will be named in the Subprocessors list.
If something goes wrong. We investigate, contain, and notify affected schools and users without undue delay. New York State law requires notification to schools within seven calendar days of discovery, and we treat that as our standard everywhere rather than only in New York. Schools then notify parents under their own policies.
12. Changes to this policy#
We update this policy when our practices change. Material changes are posted here with a new "Last updated" date, and we notify schools before changes affecting student information take effect. We will not apply a materially different use to information already collected without asking first.
13. Contact#
[email protected] reaches us for anything in this policy: access, correction, deletion, export, a school agreement, or a question about how something works.
We aim to respond within five business days, and in every case within the 30 days that GDPR and CCPA require. Where a request is complex we may extend that and will tell you why.
Postal mail: TraceEducation LLC, 531 Main Street, New York, NY 10044.
14. Regional supplements#
EEA and UK supplement#
Controller. For independent accounts, Trace Education is the controller. For school accounts, the school is the controller and Trace Education is the processor acting on its instructions; the Data Processing Agreement governs.
Legal bases. Set out per purpose in the table in §4: contract for providing and billing the service, consent for analytics, legitimate interests for security, safety, and support, legal obligation where the law requires, and vital interests in a crisis situation.
Your rights under Articles 15–22. You have the right to:
- Access your personal data and information about its use, under Art. 15.
- Correct inaccurate or incomplete data, under Art. 16.
- Request erasure under Art. 17, subject to the limits in §8. We will erase rather than pseudonymize where we can.
- Restrict processing while a dispute is resolved, under Art. 18.
- Receive your data in a structured, machine-readable format, under Art. 20. See §8 for export options.
- Object to processing based on legitimate interests, including on grounds relating to your situation, under Art. 21.
- Not be subject to solely automated decisions under Art. 22. Trace does not make such decisions; see §4.
- Withdraw consent at any time without affecting processing already carried out. Use Cookie preferences in the footer for analytics.
Exercise any of these by writing to [email protected]. We respond within one month.
Complaints. You may lodge a complaint with your local supervisory authority, or with the UK Information Commissioner's Office if you are in the UK.
Transfers. See §9. Standard Contractual Clauses plus the UK Addendum are in place with our processors.
Representative. Trace Education does not currently have an establishment in the EEA or the UK. An Article 27 representative will be appointed and named here if and when Trace's use in those regions requires one.
California supplement (CCPA/CPRA)#
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the preceding twelve months. We do not sell or share the personal information of consumers we know to be under 16.
Categories collected in the last twelve months, in CCPA terms:
| CCPA category | Collected | Examples | Disclosed to |
|---|---|---|---|
| A. Identifiers | Yes | Name, email, username, account ID | WorkOS, Slack, Cal.com, Resend, hosting |
| B. Customer records (Civ. Code §1798.80) | Yes | Name and email tied to a subscription | WorkOS, Stripe, hosting |
| C. Protected classifications | Age only | Date of birth, used as an age gate | WorkOS, hosting |
| D. Commercial information | Yes | Plan, seats, credit usage | Stripe, hosting |
| E. Biometric information | No | Not applicable | None |
| F. Internet or network activity | Yes | Page views, events, web vitals, only with consent | PostHog, hosting |
| G. Geolocation data | No precise location | Not applicable | None |
| H. Audio, electronic, visual | Audio only when a student uses a speech block | Recorded audio sent for transcription | OpenRouter and the serving model provider |
| I. Professional or employment information | Yes, for staff | Role at a school | WorkOS, hosting |
| J. Education information | Yes | Coursework, quiz answers, projects, runs, submissions | OpenRouter (content, redacted), hosting |
| K. Inferences | No | We build no profiles | None |
Sensitive personal information: Trace collects date of birth for age gating. We do not use or disclose sensitive personal information for purposes beyond those permitted by §7027(m) of the CCPA regulations, so the right to limit its use does not arise.
Your rights: to know what we collect and why, access a copy, delete or correct your information, opt out of sale or sharing, and exercise these rights without discrimination. Trace does not sell or share personal information for cross-context behavioral advertising. Contact [email protected] to exercise your rights. An authorized agent may act with your written permission, and we may ask you to verify the request directly.
Notice for students. Education records held for a school are handled through that school under FERPA, and a request routed to us will be forwarded to them.
Prepared for review by qualified counsel before it is relied on in a specific jurisdiction.