CodaClass Privacy Policy
Product: CodaClass (by Codachord Inc.)
Applies to: CodaClass accounts used by early childhood programs, schools, and their invited staff and parents/guardians
Effective: October 1, 2026
This Privacy Policy explains how Codachord Inc. (“we,” “Codachord,” “us”) handles personal information in connection with CodaClass, our classroom software for early childhood programs.
It works together with the CodaClass Terms of Use. If you are a FERPA-covered educational agency or institution (or you elect the education-records terms in writing), Annex A of the Terms also applies.
This Policy covers product use with program data. It is not the website / public-demo privacy notice at codachord.com/privacy.
Summary of key points in this Policy
- Your center owns child, family, and staff data. Codachord processes it to run CodaClass. We do not own it, sell it, or share it for marketing, and we do not use it to train AI models.
- Parents only see children they are linked to, and updates staff mark as visible to family.
- The center collects family notice and consent; Codachord does not.
- Questions about a child’s data go to the center first; Codachord assists the center.
- Some AI runs on Microsoft Azure; hosting is on Amazon Web Services. Azure does not keep prompts except samples flagged for human abuse review, which Microsoft typically deletes within 30 days.
- After your account ends, we delete the data (target 30 days), including backups.
- If a security incident compromises Customer Data, we notify the center within 72 hours of becoming aware.
1. Who this Policy covers
1.1 Customer / Center. The organization or person that creates or controls a CodaClass account (for example a center, school, program, or director) is the “Customer.” The Customer decides what child, family, and staff data goes into CodaClass.
1.2 Authorized Users. Staff and other people the Customer invites under the account, and parents/guardians (“Parents”) the Customer invites and links to specific children, are Authorized Users.
1.3 Who controls child data. The Customer controls child, family, and staff data it uploads or enters (“Customer Data”). Codachord processes Customer Data to provide, secure, support, and (as limited in Section 7) improve CodaClass for the Customer. Codachord does not own that data and does not use it for Codachord’s own marketing, or share it with others for marketing.
1.4 Family notice and consent for using CodaClass with real children are Customer-collected offline. Codachord does not provide enrollment, media-release, or state-licensing forms; your center handles those offline. Parents accept the Terms of Use and this Privacy Policy in-app on first login as they apply to Parents.
2. Information we process
Depending on how the Customer uses CodaClass, we may process:
2.1 Account and login information: names, emails, roles (director, teacher, parent, etc.), passwords (stored hashed), invite/accept status, and similar account metadata.
2.2 Child and classroom records: roster/profiles, room assignments, observations (text; photos/videos where enabled), daily logs, family notes and messages, check-in/out as available, standards tags, schedules, inventory, and related classroom content the Customer enters.
2.3 Family / Parent information: parent names, emails, which children they are linked to, and messages or notes they exchange through CodaClass.
2.4 Staff and program information: staff profiles, room assignments, and program settings needed to run the account.
2.5 Optional sensitive educational content: if the Customer stores IEP summaries, accommodations, or related notes, that content may be processed as Customer Data. CodaClass is assist-only for IEP/accommodations (see Terms); it is not an IEP eligibility or placement system.
2.6 Technical and security data: IP address, device/browser type, approximate timestamps, authentication events, and operational logs needed to run and secure the service. We design operational logs to avoid carrying children’s names, IEP text, or full request bodies where practical.
2.7 AI prompts and outputs: when staff use AI-assisted features, prompts and generated drafts may be processed by our AI subprocessor (Section 5) to return results. Staff must review AI outputs before relying on them.
We do not require Parents to provide more than the Customer needs to invite them and link them to their child(ren).
3. How we use information
We use personal information and Customer Data to:
3.1 Provide, operate, and maintain CodaClass for the Customer’s account (including parent messaging, check-in, and other features the Customer enables);
3.2 Authenticate users, enforce access controls, and keep the service secure;
3.3 Support the Customer (for example troubleshooting, export, or deletion assistance);
3.4 Improve reliability, UX, and support without using Customer Data for model training (Section 5.3 and Section 7);
3.5 Comply with law, enforce our Terms, and respond to valid legal process;
3.6 Send service-related notices (for example security, account, or Terms/Privacy updates) to account contacts.
We do not sell Customer Data. We do not use Customer Data to train, fine-tune, or improve foundation or generative AI models (ours or a third party’s), and we do not provide Customer Data to others for their model training.
4. What Parents can see
4.1 Parents only see children the Customer has linked them to.
4.2 Parents see family-visible updates the Customer’s staff share (for example family notes, messages, and observations marked visible to family). Staff-only notes and internal content stay off the Parent view.
4.3 Photos or videos in group activities may show other children. How media is used is governed by the Customer’s offline notice/consent practices; Parents should not reshare other children’s media outside CodaClass without permission.
4.4 Codachord does not expand Parent access beyond what the Customer configures.
5. AI, Azure, and other service providers
5.1 Microsoft Azure. CodaClass uses Microsoft Azure (and related Microsoft Azure services as needed) to process prompts and generate outputs (for example observation tagging, family-note drafts, lesson/activity plans, message translation). Microsoft is a subprocessor for that AI processing.
5.2 Other infrastructure. Current subprocessors for hosted CodaClass include Microsoft Azure (AI) and Amazon Web Services (hosting). On request, Codachord will provide a current subprocessor list for the Customer’s account.
5.3 No model training on Customer Data. Codachord will not use Customer Data (including prompts, completions, uploads, photos, voice, messages, or IEP text) to train, fine-tune, or improve any foundation or generative AI model. We will not sell Customer Data or provide it to others for their model training. Our use of Microsoft Azure is configured consistent with that commitment under Microsoft’s applicable product terms for the deployment we use. Azure does not keep prompts except samples flagged for human abuse review, which Microsoft typically deletes within 30 days.
5.4 Privacy gateways. Before content is sent to AI features, CodaClass applies privacy steps intended to limit identifying details (for example replacing names and contact details with placeholders where those steps apply). Staff can also choose to keep certain content off AI features. These measures reduce exposure; they do not mean sensitive educational content never reaches the AI subprocessor when staff use those features.
5.5 AI outputs are drafts/assistance only. The Customer’s staff remain responsible for what is saved, sent to families, or used with children.
6. Who we share information with
We share personal information / Customer Data only as needed to run CodaClass:
6.1 With the Customer and its Authorized Users, according to roles and links the Customer sets (staff see what their role allows; Parents see only linked children and family-visible content).
6.2 With subprocessors: Microsoft Azure (AI) and other infrastructure providers under Section 5, under contractual safeguards appropriate to the service.
6.3 With the Customer’s direction, for example exports the Customer requests, or support actions the Customer authorizes.
6.4 For legal and safety reasons, if required by law, valid legal process, or to protect the rights, safety, or security of users, Codachord, or others.
6.5 We do not sell Customer Data and do not share it for third-party advertising.
One Customer’s account is isolated from another’s; we do not give Customer A access to Customer B’s children.
7. Retention and deletion
7.1 During the subscription / account. The Customer may request export or deletion of Customer Data at any time. Codachord will provide a reasonable export (for example CSV or other common machine-readable format) and complete deletion or export within a commercially reasonable time (target: 30 days), except residual copies in routine backups (which are deleted within 30 days) and data we must keep by law.
7.2 After account cancellation or termination. By default, Codachord deletes Customer Data from the live instance within a commercially reasonable time (target: 30 days), subject to the same backup and legal-retention carve-outs. Parent and staff logins tied to that Customer Data end when the account ends or the data is deleted.
7.3 Optional short retention. If the Customer asks in writing (email is fine) to retain Customer Data after termination, we may keep it up to 90 days solely for product improvement and support analysis that is not model training (for example fixing bugs, measuring feature usefulness, improving output/UX). That retention is not permission to train models. After that window, or earlier on Customer request, we delete as in Section 7.2.
7.4 De-identified / aggregated statistics that cannot reasonably identify the Customer, a child, or a family may be retained for product metrics.
7.5 Pilot accounts. If the Customer is on a signed Pilot Agreement, that agreement’s retention choices (delete vs ≤90-day non-training retention after pilot end) control for that pilot period to the extent they differ from this Section.
8. Security
8.1 Codachord uses reasonable administrative, technical, and organizational measures appropriate to early childhood data, including access controls, encryption in transit and at rest, and tenant isolation for the Customer’s account.
8.2 If we become aware of a security incident that compromises Customer Data, we will notify the Customer within 72 hours of becoming aware and cooperate reasonably on investigation and remediation.
8.3 The Customer is responsible for staff device security, password hygiene, promptly removing access when someone leaves, and choosing which Parents and staff to invite.
9. Your choices and how to contact us
9.1 Parents / guardians: contact your center first. Questions about what is collected about your child, who can see it, media/photo choices, opt-outs, correction, or deletion of your child’s information go to your center / school (the Customer). Codachord will direct Parent requests about child data to the Customer and will reasonably assist the Customer. Codachord does not independently fulfill family access/deletion requests for Customer Data.
9.2 Customers (centers / schools). For export, deletion, subprocessor lists, security notices, or privacy questions about your account, contact Codachord at the support or privacy email published with this Policy (or the contact in your Pilot / order documents).
9.3 Your login profile. You may update your own login details in CodaClass when the product offers that. Parents and staff who need help with access should ask their center. Center account owners who need help with the account should contact Codachord.
9.4 Closing a Parent login does not by itself delete the child’s classroom records; those remain under the Customer’s control until the Customer requests changes or the account is deleted under Section 7.
10. Children
CodaClass is used by programs that serve young children. We process children’s information only as Customer Data under the Customer’s instructions and this Policy. We do not knowingly market CodaClass directly to children. Parents access CodaClass only after the Customer invites them.
11. International and state privacy notes
11.1 CodaClass is offered primarily for U.S. early childhood programs. Hosting and subprocessors may process data in the United States or other locations where those providers operate.
11.2 Where a U.S. state privacy law applies and treats Codachord as a “service provider” or “processor,” we process personal information only for the business purposes described here and in our agreement with the Customer, and we do not sell or share that information for cross-context behavioral advertising.
11.3 FERPA and education records: when Annex A of the Terms applies, Codachord acts as the Customer’s processor / school official as described there.
12. Changes
We may update this Privacy Policy. We will post the updated version and change the effective date (and may notify account contacts by email or in-product notice). Continued use after the effective date is acceptance, except where law requires a different process. Material changes that affect how we handle Customer Data will be communicated to Customers in a reasonable way before they take effect where practical.
13. Contact
For child / family data questions: contact your center or school (the Customer who invited you to CodaClass).
Codachord:
Codachord Inc.
Email: privacy@codachord.com