Effective 8 September 2026
Privacy policy
This policy covers two kinds of information and Litly’s role for each.
Part A covers student and staff information in the product. The school board has custody and control of it, and Litly processes it on the board’s instructions.
Part B covers information provided directly to Litly through this website or by email. Litly controls this information.
Part A — school data
Information held#
Held on a board’s instructions, only to operate the product:
- Student and staff accounts: username, display name, an optional email address, role and class membership.
- Student work: drafts, version history, uploaded files, comments and conversations with the writing coach.
- Teacher-authored material: assignments, rubrics, assessments, learning profiles, notes and language supports.
- Guardian contact details, where a school has entered them, with consent state and delivery records.
- Safeguarding records: a category of concern, a short rationale and a copy of the words that raised it, from a message to the writing coach, a comment or a saved version of a draft.
- An access log of who read or changed what, and why.
Litly does not collect dates of birth, home addresses, phone numbers, payment details, advertising identifiers, location data, biometric data or behavioural analytics.
Purpose#
To provide student writing, teacher feedback and assessment, safeguarding workflows, records management and access reporting to the board.
School data is not used to train AI models, to build profiles beyond the teaching purposes the board configures, or for marketing. School data is not sold.
Disclosure#
Within a board, access is resolved per class, document and conversation:
- Teachers reach the students in the classes they teach.
- Board administrators reach the classes in their board.
- Safeguarding staff reach a concern they were told about rather than every concern in the board. Access for staff handling a concern ends thirty days after it is closed. Staff a board names as safeguarding contacts keep access for as long as the board keeps the record. The words that raised a concern are shown only to those contacts and the class’s teachers, and only while the concern is open, including a comment the student has since deleted. Contacts can also read the piece of work it was raised on, read-only, for the same period. Other staff see the concern without the words or a link to the work, and cannot respond to it unless the board names them a contact.
- Guardians receive only work a teacher deliberately sends, and only where the address has been verified and consent recorded. Every message carries an unsubscribe link.
Outside the board, Amazon Web Services is the only sub-processor. The sub-processor page lists what it handles and where, including the one safety exception to Bedrock’s zero-retention setting.
Requests for access to student records are directed to the board. Litly releases student information only on the board’s instructions, or where required by law.
Processing locations#
Stored in Canada. AI processing may occur in Canada or the United States; see data residency.
Retention#
The board sets its retention periods and Litly applies them. The default is seven years after the end of the school year in which a class was taught.
A board administrator can schedule a student’s deletion. The account is disabled when the request is made, and the data is destroyed after a seven-day hold during which the board can cancel the request or export the record. Each destruction writes a certificate recording what was destroyed and under which rule.
Deletion means deletion from the live system, subject to three exceptions: a safeguarding record, the access log, and encrypted production backups that age out within fourteen days. See what survives a deletion.
Access and correction requests#
Under the access and privacy legislation that applies to the board — in Ontario, the Municipal Freedom of Information and Protection of Privacy Act — the school board has custody and control of the record. Requests to access or correct student information go to the board.
A board can export a student’s whole record, and can export the access history for a single student to answer a question about who has seen their work.
Questions about Litly’s role can be sent to privacy@litly.ai.
Security#
The security page describes hosting, encryption, access control, accounts and engineering controls.
Boards under agreement are notified of a personal data breach within 24 hours of confirmation, with a fuller report within 72 hours.
Part B — website and correspondence
Website data collection#
No cookies. No analytics. No JavaScript. No third-party requests, no embedded fonts, no tracking pixels, no session replay, no advertising.
The web server keeps request logs for operational and security purposes. These logs are retained briefly and are not used to create visitor profiles.
Email correspondence#
Litly keeps incoming messages and replies to manage the request and maintain a record of the correspondence. This may include a name, email address, organization and any information included in the message. Litly is the controller of this information.
Correspondence is retained while the request is active and for two years afterward, then deleted. Contact information is not added to a mailing list or shared for marketing.
Deletion requests can be sent to privacy@litly.ai. Information may be retained where required by contract or law.
Children#
This website is not directed at children, and Litly does not knowingly collect information from children here. A child’s use of the product is governed by Part A and by their school board.
Changes to this policy#
Material changes are published here. Boards under agreement are notified before a material change takes effect.