Privacy Policy
Last updated: August 12, 2026. This policy describes how SOL Learning (“SOL,” “we”) handles personal information and education records when you use the SOL application.
1. Who this policy covers
This policy applies to students, faculty, and administrators who use SOL at participating institutions, and to visitors of our public marketing and documentation pages.
2. Education records (FERPA)
When SOL is used for coursework, we process education records on behalf of the institution — for example section rosters, quiz attempts, scores, AI grading rationale, discussion transcripts, and related audit events. Under FERPA, the institution is typically the education agency/institution; SOL acts as a service provider / “school official” only under a written agreement with that institution (see our FERPA rider template shared during contracting).
Student rights to inspect, amend, or request deletion of education records are exercised through the institution. SOL executes institution-directed access, amendment, or purge requests using admin tools and documented retention procedures.
3. Information we collect
- Account data: name, email, authentication identifiers (via Clerk), role (student / professor / admin), and payment status when the paywall is enabled.
- Coursework data: enrollments, quiz content and attempts, grades, discussion sessions, and faculty exports initiated in-product.
- Technical data: IP address and user-agent on security-relevant audit events; error diagnostics via Sentry (PII scrubbing defaults in production); rate-limit counters in Upstash.
4. How we use information
- Provide authentication, coursework, grading, and faculty tools
- Enforce role-based access and section-scoped visibility
- Operate AI-assisted grading and discussion features (see §6)
- Maintain security, audit, fraud prevention, and rate limiting
- Process payments when the institution enables the paywall (Stripe)
- Comply with law and institutional contracts
SOL does not email quiz results, rosters, or grades. Auth emails (sign-in / verification) are sent by our authentication provider and do not include education-record grade content.
5. Subprocessors
We use vetted subprocessors to operate SOL. Current categories include authentication (Clerk), hosting (Vercel), database (Neon), AI inference (OpenAI), payments (Stripe, when enabled), rate limiting (Upstash), and error monitoring (Sentry). A maintained inventory lives in our compliance binder for institutional review under NDA.
6. Artificial intelligence
Short-answer grading and discussion bots may send minimized student text (answers / transcripts) and rubric context to OpenAI. We require production configuration that disables training on customer content and uses the strongest available retention controls (Zero Data Retention / equivalent). Application code avoids sending student name, email, or account IDs in model prompts.
7. Retention and deletion
Default retention for active coursework data is the active term plus three years, unless an institution contract specifies otherwise. Soft- deleted catalog objects can be hard-purged by administrators. Institutions may request purge of specific education records; we document completion in the audit log. Audit logs are retained for at least one year (prefer three).
8. Security
SOL uses HTTPS/TLS in transit, encryption at rest for the primary database (provider-managed), role-based access control, security headers, production rate limiting, and an append-only audit log for sensitive actions (including gradebook views and grade exports). Faculty CSV exports are delivered over an authenticated HTTPS session; files downloaded to local devices should be stored and disposed of according to institutional restricted-data rules.
9. Sharing
We do not sell personal information. We share data with subprocessors under contract, with the institution that licensed SOL, when required by law, or to protect the security of users and the service.
10. Children
SOL is designed for higher-education and adult learners in institutional deployments. It is not directed at children under 13.
11. Changes
We may update this policy. Material changes will be reflected by updating the “Last updated” date on this page. Institutional contracts control where they conflict with this general policy for education records.
12. Contact
Privacy and education-record requests: contact your institution’s SOL administrator, or the operations contact named in your institution’s agreement with SOL. Product documentation: Docs. Terms of use: Terms.