Frequently asked questions

Reference answers for privacy, security and procurement reviews.

Data and residency#

Storage and processing locations#

Everything Litly stores is in Canada. The database, every uploaded file and every backup live in Amazon’s ca-central-1 region, encrypted at rest, and never leave it.

AI processing may occur outside Canada. Writing coach requests go to Amazon Bedrock, which routes each request to whichever of ca-central-1, us-east-1, us-east-2 and us-west-2 has capacity. An individual request may therefore be processed in the United States, and the region used is not reported per request. No prompt or response is stored in any of them, and Bedrock provides no setting that confines the configured models to one country.

An all-Canada configuration using different models is available for boards that require in-country inference. Model selection and expected output quality are reviewed during deployment.

MFIPPA and residency requirements#

Ontario’s MFIPPA does not impose a data residency requirement. Boards should assess cross-border processing within their privacy impact assessment and contractual requirements.

Access and privacy legislation differs by province, and some provinces impose residency or disclosure requirements that Ontario does not. Boards outside Ontario should confirm their own obligations. The all-Canada inference option above is available where in-country processing is required.

US CLOUD Act#

Data processed in the United States is reachable under the CLOUD Act. Data stored in ca-central-1 may also be reachable, because AWS is a US company subject to US law regardless of where its servers are. Moving inference into Canada narrows this exposure without removing it.

Model training#

Student writing is not used to train AI models. AWS states that it does not use inputs or outputs to train models or share them with model providers. The current AWS statement is available on request.

The Litly AWS account is configured for zero data retention, so prompts and responses are not written to durable storage. A safety exception is described on the sub-processor page.

Sub-processors#

Amazon Web Services. The sub-processor page lists the services, processing locations and data involved.

Access#

Who can access student work#

The teachers of the classes that child is in, and board administrators. Not other students. Access is resolved per class, document and conversation. A caller without access receives “not found” rather than confirmation that the record exists.

Access reporting#

Every read or change to a child’s record is logged with the actor, the time, the route and the reason. A board can export the log filtered to one student, which is the report that answers a parent asking who has seen their child’s work.

Coverage is complete: the build fails if any route touching a child’s record lacks a log classification. See Security.

Log integrity#

The log is append-only, enforced in the database, and is not erased by a deletion request. Disclosures are kept seven years, refused attempts twelve months.

The AI coach#

What the writing coach does#

The writing coach uses the assignment, rubric, learning profile, current draft and comment threads to provide questions and feedback. It can leave inline comments and suggest edits that the student accepts or rejects.

It does not write the submission, and it does not grade.

Grading and automated decisions#

The writing coach does not grade. A teacher writes the assessment against the rubric and decides when it is released. Litly makes no automated decisions about a student.

What is sent to the model#

The assignment and its instructions, the rubric, the student’s learning profile and any teacher notes attached to it, the draft, its comment threads, the student’s current selection, and any files the student uploaded to the conversation.

Nothing about other students is sent. Nothing is retained by the model provider.

Support levels and scaffolding#

AI support is set per class and per student, including off. Teachers can also provide sentence frames and word banks. When a first language is recorded, the writing coach can use it to support planning.

Safeguarding#

The safeguarding read#

Student writing is separately assessed for indications the child may be at risk of harm — to themselves, from others, or to others. This covers messages to the writing coach, comments and saved versions of drafts. If something is found, an alert goes to the teachers who know that child. Students are not notified when a comment or draft raises a concern.

If it is not acknowledged, it follows the board’s escalation timer. Closing an alert requires a written reason. School staff decide what action to take.

Alert emails contain the student’s name and concern category, not the message or rationale. Details remain behind sign-in. The writing coach also directs the student to a trusted adult and provides board-configured crisis contact information where available.

Staff access to student writing#

A safeguarding concern may disclose relevant student writing to the student’s teachers and the staff a board names as safeguarding contacts, while the concern is open. Boards should document this collection, use and disclosure in their privacy impact assessment.

Safeguarding record retention#

The board sets the period. Until then, safeguarding records are retained indefinitely.

In Ontario, Part X of the Child, Youth and Family Services Act prescribes no retention period and requires the organisation to have a policy. The board is the organisation responsible for setting that policy. Boards in other provinces should set the period their own child-protection obligations require.

A safeguarding record also survives a deletion request, retaining the student’s identity and the content associated with the concern.

Retention and deletion#

Retention periods#

Student data is kept for the period in the board’s records schedule, set by the board in the product. The default is seven years after a class ends, which aligns with common Ontario student record schedules. Boards elsewhere should set the period their own schedule requires.

A class is treated as ending at the school year end if a teacher has not already ended it.

Student deletion#

Deletion removes the data rather than hiding it. A board administrator schedules it; it takes effect after a seven-day hold, during which the board can cancel the request or export the record for its own files. The data is then destroyed and a certificate records what was destroyed and under which rule.

What survives a deletion#

Three categories remain:

  1. A safeguarding record, where one was raised about that student — see above.
  2. The access log, including usernames, as the record of access and disclosure.
  3. Encrypted production database backups, which age out within fourteen days. Deletion means deletion from the live system.

Data export#

A student’s whole record exports as a single file: their work as readable pages, the full version history, the writing coach conversations, their uploads as uploaded, their profile and the teachers’ notes.

At the end of an agreement, Litly coordinates exports for all students held by the board within 30 days of a written request. Each student record is assembled separately and delivered through time-limited downloads to a board administrator. After delivery, deletion proceeds.

Redaction#

Redaction removes content from a student’s work without deleting the record. Where a school needs to take custody of something a student wrote, the content is exported to the school and removed from Litly, while the record that the work existed, was submitted and was marked remains. Any copy of that content held on a safeguarding record is removed too; the record of the concern remains. Both the student and the teacher see a notice on the page.

Curriculum#

Curriculum coverage#

The Ontario curriculum, covering Language (2023) for grades 1 to 8 and English courses for grades 9 and 10. Teachers select expectations for an assignment, and the writing coach uses them alongside the rubric.

Additional provincial curricula are planned. Curriculum tagging is optional: assignments, rubrics, feedback and assessment work without it, so a board outside Ontario can use Litly with its own rubrics and expectations while its curriculum is added.

Security and compliance#

SOC 2 and third-party audits#

Litly has no SOC 2 report, ISO 27001 certification or third-party penetration test. Current assurance materials are the technical and engineering controls described on the security page.

Breach notification#

Within 24 hours of becoming aware, with a fuller report within 72.

“Becoming aware” means a confirmed breach. Notification includes the information available at the time and is updated as the investigation continues.

Open-source licensing#

Litly contains no GPL or copyleft dependencies. Every dependency must appear on a fixed permissive licence list or the build fails.

Single sign-on#

Current deployments use username and password, with emailed password recovery for staff. Authentication integration requirements can be reviewed during evaluation.

Roster import#

Current deployments manage students and class membership directly in Litly. Roster integration requirements can be reviewed during evaluation.

Commercial#

Pricing#

Commercial terms are provided during evaluation based on the deployment.

Data processing agreements#

Litly signs board data processing agreements. A technical schedule covering processing, security, retention and sub-processors is available on request.

Support#

Product and technical support are provided directly by the Litly team. Support requirements can be included in a board agreement.