โ† Back to QoreGuide

Information for school communities

Privacy policy

About this policy

QoreGuide supports science assessments for participating schools and districts. This draft covers the public information pages and the school assessment portal.

To finalize: identify the legal operator, its contact details, the covered domains, and the applicable school agreements.

Information collected

  • Account and roster information: names, school email addresses, school and district affiliations, grade levels, class memberships, and account roles.
  • Assessment information: assigned assessments, student responses and submitted work, attempt status and timestamps, scores, and teacher feedback or grading notes.
  • Account and access records: password hashes, temporary access and verification records, sign-in activity, and records used to manage account access and limit repeated unsuccessful requests.
  • Browser information: sign-in cookies and limited browser storage, described in the cookie policy draft.

School personnel provide roster information; users provide account details and assessment work when using the portal. Students use their school email address as an account identifier, but do not need to receive email to create or reset a password through the class-code process.

To finalize: inventory production server logs, support records, uploaded files, assessment packages, and any third-party embedded content.

How information is used

The application uses this information to connect users to their schools and classes, provide access to assessments, save student work, support grading and feedback, and manage sign-in and account recovery.

To finalize: approve explicit commitments concerning advertising, sale or sharing of data, analytics, research, and AI training. These business practices cannot be established from the portal code alone.

Access and service providers

The portal uses account roles and class assignments to control access to school and assessment functions. Teachers review work associated with their assigned classes. Administrative access depends on assigned permissions.

The deployment scripts use Amazon Web Services for hosting and database infrastructure, and the email integration uses Amazon Simple Email Service for account messages when enabled.

To finalize: verify the complete provider list, production configuration and locations, support access, permitted disclosures, contractual safeguards, and the school authorization process, including participation by younger students.

Retention and deletion

Account deactivation or class unenrollment should not be understood as deletion of historical assessment records.

To finalize: specify retention periods for accounts, assessment work, logs and backups; establish school-requested export and deletion procedures; and explain what happens when a school stops using QoreGuide. No retention period is promised in this draft.

Questions, corrections, and requests

Students and families can begin by contacting their teacher or school administrator about school-provided account information and assessment records.

To finalize: add a direct operator privacy contact, the process for access/correction/deletion requests, response timeframes, incident notification procedures, and how material policy changes are communicated.