Privacy Policy
Last updated June 11, 2026
1. Who we are
The Philadelphia Literacy Initiative platform manages volunteer literacy tutoring: session logging, student progress tracking, and program reporting. This policy describes what the platform collects and how it is protected.
2. Students are never identified by name
Student records are de-identified by design. Students are tracked by a school-issued pseudonymous code (e.g. STU-1042) together with grade level and reading-assessment data. The platform stores no student names, addresses, birthdates or photographs. Tutors are instructed — at input time and by the Terms of Service — to never type student or family names into free-text notes.
3. What we collect
- Tutor accounts: name, phone number, and a password. Phone numbers are verified by a one-time code.
- Session records: dates, durations, session types, skills practiced, books read, per-student progress metrics, and free-text session notes.
- Visitor analytics: an anonymous _bm_vid cookie (set only after the cookie banner is accepted) counts pageviews and session timing. No third-party trackers, no cross-site tracking; stored in this app's own database and never shared.
4. Automatic redaction of personal information
Every free-text field a tutor submits (session comments, absence reasons, classroom observations) is scrubbed server-side before storage: email addresses, phone numbers and SSN-shaped strings are replaced with [redacted].
5. Encryption
All traffic is encrypted in transit (TLS). At rest, sensitive fields — tutor phone numbers, teacher names, session notes, absence reasons, classroom observations and feedback messages — are additionally encrypted with AES-256-GCM field-level encryption. Decrypted values are only ever returned to the record's owner or a program administrator.
6. Access controls and audit
Tutors can only see the students assigned to them and the sessions they themselves recorded. Administrator reads of student records that fall outside the assigned-tutor relationship are recorded in a student access log (retained 90 days), and every administrative change is recorded in an audit log (retained 180 days), supporting FERPA-style district data-protection audits.
7. Data leaving the platform
Reports shared outside the program use a de-identification boundary: students appear under per-export rotating pseudonyms that cannot be linked across releases, and any aggregate cohort smaller than 10 students is suppressed (US Dept. of Education PTAC guidance).
8. Retention
- Tutor accounts: archived 12 months after the last recorded session.
- Student sessions and progress: program duration plus 3 academic years.
- Access logs (including IP addresses): 90 days.
- Administrative audit log: 180 days.
- Phone verification codes: 5 minutes.
9. Your rights
Signed-in users can review their data via their profile and request deletion of their account and associated personal data. Contact the program administrator for data requests, corrections, or questions about this policy.