Data Sovereignty & Student Privacy
Last updated: July 2, 2026
This page is maintained by LemonSugar Ai LLC to answer common questions from schools, districts, and families about how student data is handled inside LemonSugar Ai. It describes controls that are enabled today. It is not a certification or a substitute for our Privacy Policy or Data Processing Addendum.
What we mean by “student data”
Student data covers information a learner submits or generates while using the app: the account profile (name, email, grade band, language), conversations with the tutor, uploaded photos and documents used for homework help, flashcards, saved answers, study progress, and technical logs needed to run the service (device type, IP, timestamps, error traces).
We do not knowingly collect data from children under 13 without verifiable parental consent, and we do not sell personal information. See Do Not Sell or Share.
Where student data is stored
Account data, conversations, and uploaded files are stored in our managed Postgres database and object storage operated by Supabase, with primary hosting in the United States and optional EU region for eligible customers on request. Edge traffic (CDN, TLS termination, DDoS protection) is served by Cloudflare's global network.
Model inference (the AI response to a question) is routed to the model best suited to the request. Providers may include OpenAI, Anthropic, Google, and open-source models via OpenRouter. Only the content needed to answer the current question is sent to the selected provider. The full list of sub-processors is at /sub-processors.
Encryption
Data is encrypted in transit with TLS 1.2+ between the app, our backend, and every sub-processor. Data at rest in the managed database and object storage is encrypted using AES-256. Backups inherit the same encryption.
Access controls
- Row-Level Security is enabled on every user-data table, so a signed-in user can only read and write their own rows.
- Admin database access is restricted to a small number of named engineers, protected by SSO and short-lived tokens, and used only for support, incident response, and maintenance.
- OAuth tokens for connected accounts (e.g. Google Calendar, Google Classroom, Canvas) are stored server-side and never exposed to the browser.
- Guardian and classroom links require explicit opt-in from the student before any shared visibility is granted.
Model providers & training
LemonSugar Ai does not train its own foundation models on student conversations. When a request is routed to a third-party model provider, we use API endpoints configured with the provider's no-training / zero-retention settings where available. Provider-specific commitments are summarized on /model-providers.
Retention & deletion
- Conversations and uploads are retained while the account is active so students can review, resume, and search their own work.
- Students can delete individual conversations, uploads, or saved items at any time from inside the app.
- Users can disable conversation history entirely in Settings → Privacy & Security.
- Account deletion removes personal data within 30 days, except where retention is required by law (e.g. tax and payment records). Request deletion any time — see below.
- Backups roll off within 35 days.
Rights for students, parents, and schools
Students and their parents/guardians can access, correct, export, or delete their data. Schools acting as the data controller under a signed DPA can exercise the same rights on behalf of enrolled students. To submit a request, email hello@lemonsugar.ai with the subject “Student data request”. We verify identity before releasing or deleting data and respond within 30 days.
Compliance posture
We align our practices with FERPA, COPPA, GDPR, and California's CCPA/CPRA and SOPIPA. LemonSugar Ai LLC is not currently SOC 2 or ISO 27001 certified; we are happy to share our security questionnaire and DPA on request. For district procurement, contact hello@lemonsugar.ai.
Incident response
If we discover a security incident affecting student data, we will notify affected users and, where applicable, the school administrator without undue delay and within the timelines required by applicable law. Researchers can report suspected issues per our security.txt.
- Stripe — secure payments
- 30-day money-back
- No training on your data
- 18 models, one bill