Data, privacy, and AI safeguards
TeacherHero stores the curriculum you write and the files you upload. Only curriculum fields and excerpts you explicitly confirm are sent to the AI model. No student data is required or wanted, your content is never used to train models, and deleting your account removes everything immediately.
Last reviewed · Written to be forwarded — every claim here describes behaviour enforced in the product, and the section on what we do not have is near the bottom.
What is stored, and what reaches the model
| Data | Stored | Sent to the AI model |
|---|---|---|
| Your account | Email address, display name, and — for Google sign-in — your Google account ID and profile image URL. A password hash only if you registered with a password. | Never sent. |
| Curriculum you write | Course, unit, week, and lesson fields: titles, learning targets, vocabulary, notes, standards you attach. | Sent. This is the context that makes each lesson continue the one before it. |
| Files you upload | The file, plus two separate texts: the full extracted text, and the excerpt you confirm. | Only the confirmed excerpt, and only for sources you switch on for that lesson. Extracted text you have not confirmed is never sent. |
| Generated lessons and exports | Generated sections, their version history, and the PDF, slide, and document files you build. | Earlier sections of the same lesson are sent forward, so a later section continues rather than repeats them. |
| Usage records | One row per AI call: which lesson, token counts, cost, duration, and the prompt version. No prompt or response text. | Never sent. |
| Student data | None. Nothing in the product asks for a student name, record, or grade, and nothing should be entered. | Never — because it is never collected. |
The two-column rule for uploaded material
When you upload a document or fetch a web page, TeacherHero stores two different texts against it. One is the full extraction — everything the parser could read out of the file. The other is the excerpt you confirm.
Only the confirmed excerpt is ever placed in front of the AI model, and only for sources you have switched on for that lesson. The full extraction stays in the database and is used for nothing else. This is why an unconfirmed source carries a “Not sent to AI” badge in the interface: it is a description of the code path, not a reassurance.
Documents above 50,000 characters cannot be auto-confirmed at all — you have to author the excerpt yourself, which means a long PDF cannot be sent to a model by accident.
AI safeguards
Teacher-supplied text is fenced as data. Curriculum fields, source excerpts, and refine instructions are all labelled to the model as classroom material to plan around rather than as instructions addressed to it. This matters because a confirmed excerpt is arbitrary text lifted out of a PDF or a colleague's worksheet: the teacher vouches that it is classroom material, not that nobody wrote “ignore your instructions” inside it.
Output is bounded to what students can be handed. The model is instructed that everything it writes may be printed and given to a child at the stated grade level, and is forbidden from producing content that identifies, profiles, diagnoses, or evaluates an individual student. That rule matches how the product actually works — it is given a class and a learning target, never a child.
Generation is structured, not open-ended. Every AI call returns a typed object validated against a schema before it is stored, and a response that fails validation is rejected and retried rather than shown. There is no free-form chat surface where a student could talk to a model.
A teacher reviews everything. Nothing generated is published, sent, or shown to students automatically. Every field is editable, and the export you hand out is one you chose to build.
Google Drive uses the narrowest scope that exists
Connecting Drive requests the drive.file scope and nothing wider. That scope grants an application access only to files it creates itself.
TeacherHero cannot list, open, or modify anything else in your Drive — not as a matter of policy, but because it was never granted the permission. Connecting Drive is also optional and separate from signing in; you are asked for it only when you first export to Drive.
Disconnecting is one step on our side and one on Google's: delete your account or remove the connection here, and revoke the app at myaccount.google.com/permissions.
Retention and deletion
Your content is kept until you delete it. There is no automatic expiry, because a unit you wrote last year is one you may teach again.
Deleting your account is immediate and irreversible, and you can do it yourself from your dashboard — it is not a support request. It removes your account, every course, unit, week, lesson, generated section, version history, uploaded file, export, and usage record, along with any lesson you published to the shared library.
One thing does not come back: a lesson another teacher already imported from the library is a full copy that they own, so it stays in their account. That is the same for any shared material, and it is why publishing to the library is a deliberate, per-lesson action rather than a default.
Deletion removes your records from the live database straight away. We do not yet publish a backup retention schedule, so we cannot tell you how long a deleted account could persist in a system-level backup image — if your district needs that answered before adoption, treat it as an open question and ask us.
Where it runs
TeacherHero runs on infrastructure operated by CX Ventures, with the database on hardware we control rather than a shared managed service. Traffic is served over HTTPS through Cloudflare.
Stored Google refresh tokens are encrypted at rest with a key held outside the database.
Who else receives your data
OpenAI
Generates lesson content. TeacherHero currently uses OpenAI's API for every AI call.
The curriculum context for the lesson being generated, plus any source excerpts you confirmed. Sent through the API, which OpenAI does not use to train its models.
Optional. Sign-in, and export to your Google Drive if you connect it.
For sign-in: your email, name, and profile image. For Drive: only the files TeacherHero itself creates — see the scope note below.
Cloudflare
Network layer in front of the application.
Request metadata in transit — IP address, user agent, requested URL. No curriculum content is stored there.
What we do not have
Competing tools merchandise these as badges. We do not hold them, so we do not claim them — and you should be able to find that out here rather than three weeks into a procurement conversation.
- No SOC 2 report. TeacherHero has not completed a SOC 2 Type I or Type II audit.
- No FERPA, COPPA, or Ed Law 2-D certification. These are laws rather than certifications, and vendors demonstrate compliance through signed agreements and controls. We have not completed that process, and we do not currently sign district data-privacy agreements.
- No Common Sense Privacy certification, and no state privacy-alliance listing.
- No student accounts, no admin console, no organization-wide access. TeacherHero is a single-teacher product today. There is no district tenancy, no SSO, and no administrator view of staff activity.
- If your district requires a completed vendor review or a signed data-privacy agreement before staff may adopt a tool, treat that requirement as unmet today and check with your district first.
Frequently asked questions
Is TeacherHero FERPA compliant?
TeacherHero holds no FERPA certification and does not currently sign district data-privacy agreements. It is designed so the question rarely arises: no student names, records, or work are collected, so there is no education record in the system to protect. Check with your district before adopting any tool.
Is my curriculum used to train AI models?
No. Your courses, units, lessons, and uploaded materials are not used to train any model, by us or by our AI provider — content sent through OpenAI's API is not used for training. Your material is also never published anywhere unless you deliberately publish a lesson.
What exactly gets sent to the AI provider?
The curriculum context for the lesson being generated — course, unit, week, lesson target, earlier lessons, and the sections already written — plus any source excerpts you explicitly confirmed. Extracted text you have not confirmed is never sent, and neither is your account information.
Can I delete my account and everything in it?
Yes, from your dashboard, immediately, without contacting anyone. It removes every course, lesson, upload, export, and usage record, plus anything you published to the library. Lessons another teacher already imported are copies they own and stay with them.
Can TeacherHero see the rest of my Google Drive?
No. Drive export requests the drive.file scope, which grants access only to files the application itself creates. Everything else in your Drive is invisible to it — not by policy but by permission. Connecting Drive is optional and separate from signing in.
Do students use TeacherHero directly?
No. It is a planning tool for teachers, with no student accounts and no chat surface a student could reach. Students see what you print or project — the packet, slides, and handouts you chose to export.
Your curriculum stays yours.
Nothing you write is published unless you publish it, nothing is used to train a model, and you can delete all of it yourself in one step.
Start planning free