Privacy Policy

Version 2026-09-23.1 | Policy date: 2026-09-23

Operator-reviewed for adult testing with synthetic student data. Not approved for real-student use.

Terms of Service | Privacy Policy | Accessibility Statement

Adult testing and synthetic student records

The current release is for adults testing with synthetic student data only. Do not submit real student records or invite children. Student and guardian test roles do not establish that the person using the account is a child or a parent. Adult testers' names, email addresses, credentials, support enquiries, and operational records remain personal information even when the educational content is fictional.

If real student information is submitted accidentally, stop adding or sharing it and contact support@ligarion.com without repeating the sensitive content in email. Ligarion will assess containment, authorized handling, preservation needs, and appropriate disposition. This notice does not itself authorize collecting children's data.

Scope and institution control

This notice describes Ligarion Connect's web and mobile application and the related Ligarion website. Institutions authorize users and determine which educational features they use. Users cannot independently create an unrestricted account. Institution directions and applicable agreements govern institution records, subject to Ligarion's own legal obligations.

Program, School, and District licensing defines commercial and administrative scope; it does not replace record-level authorization. District billing or oversight does not automatically expose a covered school's messages, student records, or files. Cross-program or cross-school access requires a separately authorized scope and remains subject to active account, role, group, audience, and feature controls.

Information processed

Account and institution information includes names, email addresses, roles, institution and group membership, grade level where supplied, optional adult display names, profile photos, and account status. Registration does not ask users for a date of birth.

Enabled features may process messages, reports, blocking and moderation records, announcements and acknowledgements, attendance, check-ins and submitted photos, forms and answers, documents and versions, calendar and itinerary details, and guardian/student relationships. Submit only information needed for the educational purpose.

A public trial, annual-service, or quote request may include the adult representative's name, work email, title, phone number, organization name and website, country or region, requested plan and student-capacity estimate, request notes, source page, submission time, review status, and retained operator actions. The form must not be used for student names or records. For abuse prevention, Ligarion may process a one-way keyed hash derived from the request's network address instead of storing the raw address in the sales-request record.

Operational information includes authentication/session records, audit events, support requests, server/network logs, and, when mobile push is enabled, device installation identifiers, push tokens, platform, and app version. Institution billing administration may include business contacts, quotes, invoices, purchase-order and payment-approval records, service decisions, and optional external accounting references. Institution-controlled content may contain additional personal information supplied by its users.

Purposes and service providers

Information is used to review business requests, prevent abuse, provide the requested educational functions, authenticate users, apply role and institution permissions, deliver communications, provide support, administer institution accounts, investigate misuse, and preserve authorized records. Student information is not offered for sale or targeted advertising. Submitting a business request does not create an account, activate service, or authorize student use.

The service uses Supabase for database, authentication, files and backend functions; Cloudflare for web hosting and delivery; Resend for invitation, password-reset and other email delivery and website subscription communications where requested; Expo for mobile builds, updates and push delivery where enabled; and mobile platform services such as Apple's distribution and push services. Each receives information needed for its function, such as business-request fields sent to the Supabase request endpoint, email addresses and email contents for delivery, or push tokens and limited alert payloads for notifications. Provider agreements, retention settings and support access require review; this notice is not a certification of every provider's compliance.

The configured database region is US West. This does not mean that all provider support, email, network, backup or mobile processing occurs only in that region or only in the United States. Do not rely on this notice as a US-only residency guarantee.

Push notifications use limited alert content rather than full private message or student-record contents. Opening an alert still requires application access. Uploaded photos and files are processed for authenticated delivery, validation, moderation, support, and retained-record obligations; they are not a long-form video hosting service. External sites and an institution's exported copies are governed by their own controls and notices.

Who can access information

Access depends on an active institution account, role, group membership, feature settings, and applicable audience rules. Authorized staff may access education and moderation records that students or guardians cannot see. Some institution administrators can export authorized records. District administrators, billing contacts, and program administrators receive only the scopes explicitly granted to them; payment or organizational ownership alone does not grant private-content access. Support and platform administration must be limited to authorized operational needs.

Adult business-request information and its review history are available only to authorized platform operators and staff who need it to evaluate, provision, support, secure, or document the request. Information may also be disclosed when legally required or for authorized security and safety investigations. Such requests require review; a request from another user does not automatically authorize disclosure. Contact your institution about education-record access and correction, and contact Ligarion if you need help routing a request.

Security and its limits

Controls include encrypted network connections, authentication, institution/role restrictions, private file storage, and audit history for supported actions. These measures reduce risk but do not make unauthorized access impossible or establish a blanket FERPA, COPPA, or security certification.

Current protected photo and group-document delivery uses authenticated access checks rather than issuing new shareable signed media links. Previously issued links may remain valid until their expiry, and an authorized recipient may already have downloaded a copy. Access revocation cannot recall screenshots, exports or downloaded files. Do not share private content with unauthorized recipients.

Retention, account deletion, and requests

Account-access deletion is available in Profile Settings with identity confirmation. It disables sign-in and removes or deactivates relevant account/session and preference state. It does not erase institution-owned records, including identity and membership history, communications, forms, attendance, check-in history, published photos, documents, moderation history, and audit records.

Removing or replacing content generally retains the earlier record with restricted access. Only verified abandoned, never-published uploads are eligible for the implemented file-cleanup flows. Business requests, quotes, invoices, service decisions, support records, and review history may be retained as operational and commercial records. There is currently no automatic age-based purge of institution or sales-request records. Ligarion and the institution must establish a purpose-specific retention schedule, legal-hold process, and authorized disposition procedure; the preservation design is not a claim that all information may be kept indefinitely.

Active-service history, a limited post-service records window, internal retention, and a legal hold are separate concepts. Ending service or account access does not automatically erase retained records, and retention does not promise continued self-service access. Contact support@ligarion.com and your institution to request access, correction, restriction, or deletion, or to raise a retention concern. Identity and authority must be verified and applicable obligations assessed. The applicable rights and exceptions depend on the circumstances.

Children and education records

Real-student use is outside the current testing release. An institution invitation, a student's checkbox, or a guardian account link is not itself verified parental consent. Before children use the service, the institution and Ligarion must establish the applicable notices, authorization or consent, educational purpose, and data-processing arrangements. School authorization, where legally available, is limited to the educational use it covers.

Parents and eligible students should contact their institution about education-record rights and may contact Ligarion for help. Children should not provide unnecessary information. This notice does not establish that a particular institution's use satisfies FERPA, COPPA, or state requirements.

Requests, preservation and incidents

Noah Moody is Ligarion's responsible contact for privacy requests, incident response and legal preservation. Email support@ligarion.com or write to the address below. An initial request should identify the institution and general concern without attaching private student records, identity documents, passwords or account-recovery links. Ligarion may need to verify identity and authority through an appropriate channel before releasing or changing information.

A legal hold preserves the records within its scope; it does not authorize unrelated access, disclosure or indefinite retention of all records. The intended adult-testing schedule targets disposition of test account and synthetic feature records 90 days after evaluation ends, and minimal audit and request evidence after 12 months from evaluation end or case closure as applicable, subject to valid holds and applicable requirements. These are adopted planning targets, not currently implemented erasure deadlines: no automated purge or general personal-data erasure workflow is currently implemented. Ligarion must establish and validate the separately authorized disposition process before representing that data has been erased. Contact support@ligarion.com about a request or a retention concern.

Ligarion will assess reported security incidents, take appropriate containment and evidence-preservation steps, and provide notifications required by applicable law and agreements. Provider notification to Ligarion does not replace Ligarion's own responsibilities. This testing release does not promise continuous monitoring or a staffed 24-hour response service.

Choices and device permissions

Users can manage supported notification preferences in Profile Settings and device notification/photo permissions in operating-system settings. Authentication storage is used to maintain sign-in. Disabling necessary storage may prevent sign-in. Declining optional photo or push permissions does not itself authorize broader collection.

Privacy-notice acknowledgement records the document version shown. It is separate from optional permissions, parental consent, and an institution's legal authorization.

Updates and contact

The fixed version and date identify this operator-reviewed testing policy. The application requests acknowledgement only after deliberate publication of the version. Published versions and acknowledgement records are retained without inferring acceptance of earlier or later wording. Operator approval does not represent attorney review.

Ligarion LLC; PO Box 53, Hazel Green, AL 35750. Email support@ligarion.com for privacy, account, or accessibility requests. The signed-in About > Contact form is also available. Do not include unnecessary student information in an initial support enquiry.