← Back to 3XGenre Live

Privacy Policy

3XGenre Live — a product of Learning Innovation Systems, LLC.
Effective Date: July 29, 2026  |  Last Updated: July 28, 2026

3XGenre Live is a real-time classroom writing activity: a teacher displays one shared image (or other artifact) and students write a short response to it across three different genres — for example a haiku, a news headline, and a persuasive paragraph. We built it for educators, and we take student privacy seriously. This policy explains what data we collect, why, how we protect it, and when we delete it.

The short version: We collect the minimum data needed to run a live classroom session. Student data is automatically deleted within 24 hours. We do not sell data, serve ads, or build student profiles.

1. Who We Are

3XGenre Live is operated by Learning Innovation Systems, LLC. When this policy says "we," "us," or "our," it refers to Learning Innovation Systems, LLC. When it says "you," it refers to any user of 3XGenre Live — teachers, students, or school administrators.

2. What Data We Collect

We collect different information depending on your role.

Teachers

Teachers do not currently create accounts. A teacher starts a session by entering a writing prompt, choosing three genre labels, and providing one shared image — no email, password, or login is required. The teacher can supply that image by pasting a URL, searching a stock-image library, generating one from a text description, or uploading a file from their device. When a teacher uses the stock-search or image-generation option, the search term or description they type is sent to the relevant third-party service to return an image (see Section 10); these are teacher-initiated actions that involve no student data.

Student Session Data

Students do not create accounts. They join a live session using a short session code shared by their teacher. No login is required. Students do not upload images or files — the only image in a session is the shared artifact the teacher provides. During a session, we collect the following:

Data Purpose Retention
First name or nickname Display on the teacher's shared screen so the teacher can identify responses 24 hours (auto-deleted)
Written responses (three genre blocks) The short writing each student produces — a brief title and a short piece of writing for each of the three genres. Displayed to the class as part of the lesson activity. 24 hours (auto-deleted)
Teacher-assigned score (1–10) An optional score a teacher may give a submission as formative feedback. Shown back to that student on their own screen; not visible to other students. 24 hours (auto-deleted)
Session metadata Socket connection IDs and response-slot assignments used to route data in real time 24 hours (auto-deleted)
We do not collect student email addresses, dates of birth, student ID numbers, device identifiers, IP addresses for tracking purposes, or any other persistent student identifiers. Students never create accounts and do not upload any files.

3. How We Use Data

All data we collect is used exclusively to provide the 3XGenre Live service — displaying student responses on a teacher's shared screen during a live class session. We do not use student data for any other purpose. Specifically, we do not use student data to advertise, to build profiles, to sell to third parties, or to train machine learning models.

4. Where Data Is Stored

We use the following infrastructure providers, all of which store data in the United States:

Provider Role Data Stored
Railway Application hosting Processes session data in transit (not persisted)
Upstash Session data store (Redis) Student names, written genre responses, teacher-assigned scores, a reference to the teacher's shared image, and session metadata
Cloudflare R2 Image storage The teacher-provided shared image for a session (compressed). No student-uploaded content — students submit text only.
Betterstack Application monitoring & logs Operational logs (request counts, errors, performance metrics). No student names or response content.
PostHog Product analytics Anonymous usage-event counts (e.g., sessions created, responses submitted) and an anonymous browser identifier. No student names or response content.
Sentry Error monitoring Technical error diagnostics (error messages, stack traces) used to detect and fix bugs. No student names or response content.

All data is transmitted using TLS encryption in transit. Stored images (Cloudflare R2) and our application server (Railway) are encrypted at rest. The real-time session store (Upstash Redis), which holds student responses only briefly, is protected by TLS in transit and by automatic deletion within 24 hours; encryption at rest for that layer is available on an upgraded plan and will be enabled before any deployment that requires it (for example, under a district Data Processing Agreement).

5. Data Retention & Deletion

Student session data — including names, written responses, teacher-assigned scores, and all session metadata — is automatically and permanently deleted within 24 hours of the session's creation. The teacher's shared image is deleted on the same schedule. This deletion is enforced through automated expiration rules at the infrastructure level and does not require any manual action from teachers, students, or administrators.

If teacher accounts are introduced in the future, this policy will be updated to reflect the additional data collected and its retention period.

6. FERPA Compliance

3XGenre Live is designed to support schools' compliance with the Family Educational Rights and Privacy Act (FERPA). When a school or district enters into a Data Processing Agreement (DPA) with us, we act as a "school official" with a "legitimate educational interest" under FERPA. In this capacity, we agree to the following:

We use student data solely for the educational purpose for which it was provided. We do not disclose student data to any third party except our infrastructure subprocessors listed above, and only to the extent necessary to provide the service. We maintain reasonable administrative, technical, and physical safeguards to protect student data. We delete student data automatically within 24 hours.

We are prepared to sign the Student Data Privacy Consortium (SDPC) National Data Processing Agreement or a district's own DPA upon request.

7. COPPA Compliance

3XGenre Live may be used by children under 13 in a school setting. Under the Children's Online Privacy Protection Act (COPPA), schools may consent to the collection of student information on behalf of parents when the data is used solely for an educational purpose. By allowing students to use 3XGenre Live, the school represents that it has the authority to provide this consent.

We do not collect more information than is reasonably necessary to participate in a classroom session. Students do not create accounts, and all student data is deleted within 24 hours.

8. State Privacy Laws

Many states have enacted student data privacy laws with requirements that extend beyond FERPA. We have designed our data practices to align with common requirements across state laws, including those of California (SOPIPA), New York (Education Law 2-d), Illinois (SOPPA), and Colorado (Student Data Transparency and Security Act). Our practices include minimal data collection, no sale or commercial use of student data, automatic 24-hour deletion, and transparency about subprocessors.

If your state has specific requirements not addressed here, please contact us and we are happy to discuss how our practices align.

9. Security

We implement the following technical safeguards to protect student data:

All data is transmitted over TLS-encrypted connections. Access to infrastructure is restricted to authorized personnel using strong authentication. Session codes are randomly generated and expire automatically. Image upload URLs are cryptographically signed and expire within 5 minutes. Image download URLs are cryptographically signed and expire within 1 hour. Input validation and sanitization is applied to all student submissions, with length caps enforced on the server. We use rate limiting and size constraints to prevent abuse.

10. Third-Party Access

We do not sell, rent, lease, or share student data with any third party for commercial purposes. The third parties that process student session data are our infrastructure subprocessors — Railway, Upstash, and Cloudflare — each only to the extent necessary to deliver the service and each bound by their own data processing terms. Betterstack receives operational logs and uptime checks that contain no student names or response content.

Two features on the teacher's session-setup screen contact outside services, and neither one involves student data. If a teacher searches the built-in stock-image library, the search term they type is sent to Pixabay to return matching images. If a teacher generates an image from a description, that description is sent to the Pollinations image-generation service to produce the image. These are optional, teacher-initiated actions performed before any student joins.

We use two tools to understand aggregate usage and to detect and fix technical problems: PostHog (anonymous product analytics — counts of events such as "session created" or "response submitted," plus general feature usage) and Sentry (error monitoring — technical diagnostics such as error messages and stack traces when something breaks). We configure these to minimize data: no student names or response content are ever sent to them. PostHog autocapture is disabled, and Sentry session replay and performance tracing are turned off. PostHog stores an anonymous identifier in your browser (via local storage) to de-duplicate usage counts; it is not linked to any student identity. Both process data in the United States.

11. Data Breach Notification

In the event of a data breach that affects student information, we will notify affected schools and districts without unreasonable delay and no later than 72 hours after becoming aware of the breach. Notification will include a description of the data involved, the date or estimated date of the breach, and the steps we are taking in response.

12. Your Rights

Because no user accounts are required (for teachers or students) and student data is automatically deleted within 24 hours, the practical scope for data access and deletion requests is limited. However, we respect the following rights:

Schools and districts may request confirmation of data deletion, details about our data handling practices, or termination of data processing under an active DPA. Parents may contact their child's school to inquire about how 3XGenre Live is used in the classroom. Because we do not maintain user accounts or retain student data beyond 24 hours, there is no persistent student data for us to provide access to or delete on request.

13. Changes to This Policy

We may update this policy from time to time. If we make material changes to how we handle student data, we will notify schools and districts with active DPAs at least 30 days before the changes take effect. The "Last Updated" date at the top of this page reflects the most recent revision.

14. Contact Us

If you have questions about this privacy policy, our data practices, or if you would like to sign a Data Processing Agreement, please contact us:

Learning Innovation Systems, LLC
20409 Yorba Linda Blvd. Suite K2 225
Yorba Linda, CA 92886
Email: support@eduprotocols.com