Privacy Policy
ReqPath is a course-planning platform built for schools and the students they serve. This policy explains what we collect, why we collect it, how we protect it, and the choices you have. We have written it in plain language so that there are no surprises.
1. Who this policy covers
This policy applies to everyone who uses ReqPath: school administrators and staff who set up and manage a school, students who plan their courses, and visitors to our website.
When a school uses ReqPath, the school controls the information it adds about its students and staff, and ReqPath processes that information on the school's behalf to provide the service. For schools subject to the Family Educational Rights and Privacy Act (FERPA), ReqPath acts as a school official with a legitimate educational interest and is under the school's direct control with respect to the use and maintenance of education records. If a school has signed a data privacy agreement with ReqPath, that agreement also applies.
2. Information we collect
Information schools and users provide
- Account details: name, username, role, and password. Staff accounts include an email address; for students, an email address is optional. Student accounts include a graduation year. Passwords are stored only as a salted hash by our authentication provider. If a school enables Google sign-in, we also store the Google account identifier used to sign in.
- School information: school name, city and state, website domain, sign-in settings, and the name and email address of the billing contact.
- Course planning data: the class catalog, prerequisites, graduation requirements, schedules and section assignments, student course plans, plan submissions and counselor decisions (including counselor notes), and teacher profiles (the classes a teacher can teach, preferred classes, room, and maximum sections).
- Class ratings: difficulty and workload ratings that students and teachers give to classes. Other users see ratings only as averages.
- AI advisor messages: the messages a student sends to the AI advisor and the advisor's replies. See section 4 for how these are processed.
- Feedback: what you send through the feedback form (title, description, optional name and email address, your role, the page you were on, and your browser's user agent) or by email.
Information collected automatically
- Server logs: for each request, the IP address, the page or function requested, the time, the result, and the account and school making the request. We use these logs for security and troubleshooting. They do not include the content of forms or messages.
- Error records: when a request fails on our servers, we record the error message, the page or function involved, and the account and school involved, so that we can fix the problem. Error records are deleted after 30 days.
We do not use analytics, advertising, or tracking tools.
Payment information
Payments are processed by Stripe. We do not receive or store card numbers. We keep a record of each payment (amount, date, and status) and the billing contact for the school.
3. How we use information
We use the information we collect to:
- Provide the service: the course catalog, prerequisite tree, scheduling, student course plans, and the AI advisor.
- Authenticate users, protect accounts and school data, and limit repeated failed sign-in attempts.
- Process payments and keep billing records.
- Respond to support requests and feedback, and contact school administrators about their account or the service.
- Find and fix errors, and improve the service.
We do not sell personal information, we do not use it for advertising, and we do not use student data to train AI models.
4. The AI advisor
When a student uses the AI advisor, ReqPath sends the following to OpenRouter, which passes the request to the AI model provider we have selected (currently OpenAI):
- the student's recent messages in the conversation;
- the student's grade level, graduation year, and current course plan;
- the school's name, class catalog, graduation requirements, and average class ratings.
ReqPath does not send the student's name, username, or email address, unless the student types them into a message. These providers process the request to generate a reply under their own terms. ReqPath does not store AI advisor conversations on its servers; the most recent messages are kept in the student's browser so that the conversation can continue, and they are removed when the student signs out.
Schools can turn off the AI advisor for their students at any time.
5. How we share information
We share information only in these cases:
- Within your school: school staff can see student information according to their role. Students see only their own information, along with the shared catalog, published schedules, and average class ratings.
- Service providers: we use the following providers to run ReqPath. Each receives only the information it needs to perform its service for us.
- Supabase: database hosting and account authentication.
- Our web hosting provider: runs the ReqPath application servers.
- Stripe: payment processing.
- OpenRouter and the AI model provider it routes to (currently OpenAI): AI advisor replies, as described in section 4.
- Google: Google sign-in, when a school enables it. Our pages also load fonts from Google Fonts, which means your browser requests those fonts from Google's servers.
- jsDelivr: delivers a software library that our sign-in and application pages load.
- Legal requirements: when required by law, regulation, or valid legal process.
We do not share student information with anyone else, except as directed by the school.
6. How we protect information
Data is stored with our database provider, which encrypts it in transit and at rest. The database enforces row-level security, so each school's data is kept separate and each user can reach only what their role allows. Passwords are hashed and never stored in plain text, and repeated failed sign-in attempts are limited. Access to production data is limited to the people who need it to operate the service.
No system can guarantee perfect security, but we take reasonable measures to protect information from unauthorized access, loss, or misuse. If we learn of a security incident that affects a school's data, we will notify the school without unreasonable delay.
7. Data retention
- School and student data: kept while the school has an active account. When a school closes its account, we delete its data within a reasonable period, except for records we must keep for legal or accounting reasons, such as payment records. Before deletion, a school can ask us for a copy of its data in a standard format such as CSV.
- Deleted accounts: when school staff remove a student or staff account, that account and its course plan are deleted.
- Error records: deleted after 30 days.
- Server logs: kept for a limited period for security and troubleshooting.
8. Student privacy
ReqPath is designed for use by schools. We collect only the information needed to provide course planning, and schools control what student data is added and who can access it.
ReqPath is intended for high school students. If a school uses ReqPath with students under 13, the school is responsible for providing any consent required under the Children's Online Privacy Protection Act (COPPA) on behalf of parents, for the educational use of the service.
Parents and eligible students who want to review or correct education records should contact their school, which controls those records. You can also reach us at [email protected].
9. Your choices and rights
- Access and correction: users can view their account information in ReqPath, and school staff can correct roster information.
- Copies of data: schools can request a copy of their data by contacting us.
- Deletion: school staff can delete student and staff accounts from the dashboard. Students and staff can ask their school, or contact us, to request deletion.
- AI advisor: schools can turn the AI advisor off.
10. Cookies and browser storage
ReqPath does not use advertising or tracking cookies.
- Staying signed in: when you sign in, your session is kept in your browser's local storage, not in a cookie. Signing out removes it.
- Sign-in page: we remember the last school you selected, so you do not have to search for it again.
- AI advisor: a student's recent AI advisor messages are kept in the browser until the student signs out.
- ReqPath staff: our internal administration console uses one cookie to keep ReqPath staff signed in. School users never receive this cookie.
Some third-party services set their own cookies under their own policies: Google, when you use Google sign-in, and Stripe, on its checkout page. On a shared computer, sign out when you are finished.
11. Changes to this policy
We may update this policy as the service changes. When we make material changes, we will update the date at the top of this page and, where appropriate, notify schools directly. Continued use of ReqPath after changes take effect means you accept the revised policy.
12. Contact us
For questions about privacy or your data, contact us:
- Privacy: [email protected]
- General: [email protected]
- Support: [email protected]
See also our Terms of Service.
Questions about this page?Email [email protected]. You can also read our Terms of Service.