Skip to policy

Privacy Policy

IVY WATERS INTERNATIONAL LLC

Last Updated: August 15, 2026

Introduction

Welcome to Ivy Waters. Families entrust us with meaningful parts of a learner's story, and we want to handle that trust with care. We are a records-first private school and family workspace for homeschool, expat, and worldschooling families serving Pre-K through Grade 8. Enrollment and official Ivy Waters school records are provided under an active enrollment, on the terms identified at checkout and in any separate enrollment agreement.

Privacy is not an afterthought for us. It is a foundational design principle. We design for data minimization and privacy-first defaults: we limit collection to information used to operate, secure, and support the Services, and we do not sell personal information.

Some data is cached locally on your device, and some is stored in backend services to provide accounts, authorized family access, cross-device records, evidence media, and recordkeeping. This policy explains what we collect, why we process it, the categories of service providers involved, how long we keep it, and the choices available to you. We have written it in plain English because you should not need a law degree to understand how your data is handled.

This policy applies to the current public Ivy Waters services, including:

  • IvyTracks: parent-led learning-evidence capture and recordkeeping;
  • the Parent Portal: the family learning journey, standards coverage, portfolios, and account services;
  • the Ivy Waters website and desktop app shell; and
  • any pre-release, Labs, beta, early-access, or private-testing experience we make available to you, whether or not it carries a separate name.

Where a testing experience processes information differently from the released Service, we describe the difference in a just-in-time notice before you opt in, and that notice sits alongside this policy rather than replacing it. Taking part in testing never lowers the protections described here below what applicable law requires.

Ivy Words and Ivy Numbers are internal Labs and are not part of the current public offer. Our public services use Ivy Waters backend systems and trusted infrastructure providers for hosting, authentication, relational records, private media storage, billing when enabled, and legacy-data migration.

For the processing described in this policy, IVY WATERS INTERNATIONAL LLC ("Ivy," "Ivy Waters," "Ivy Waters International," "we," "us," or "our") is the data controller unless a checkout, enrollment agreement, or feature notice identifies another entity or role. Section 12 explains how to contact us.

1. The Short Version

Our aim is simple: collect what helps provide and protect the service, explain meaningful choices before they happen, and do not use family educational data to build advertising profiles.

Depending on the product and features you use:

  • Some information is stored locally on your device (for example, device-specific preferences or local progress in certain experiences).
  • Some information is stored in our backend services so it can be available across devices and authorized family members (for example, your account, learner profiles, enrollment or billing status, and IvyTracks recordkeeping data you choose to enter).

We chose this approach deliberately. Family and children's data is sensitive, so we focus on collecting the minimum needed for the Services to work, keeping access tightly controlled, and being transparent about what is stored where.

The whole policy on one page

If you read nothing else, read this table. It summarizes the principal categories we process. The sections that follow provide the more specific feature, recipient, retention, and rights details.

What we holdWhy we hold itLegal basis (GDPR)How longWho can see it
Account information (email, hashed password, guardian or display name)To create, secure, and operate your accountContract performanceWhile the account is active, closed out with itYou, and authorized Ivy staff for support or security
Learner profiles (name, year or grade, academic calendar)To organize records against the right studentContract performanceWhile the account is activeYou and adults you authorize
Learning evidence you create (moments, photos, audio, dictated text, notes, drafts, portfolio items)To provide recordkeeping and the learning journeyContract performanceUntil you delete it, or account closure, completed within 30 days including backupsYou and adults you authorize. Ivy staff have no routine access
Sensitive information you choose to add (for example a diagnosis or accommodation note)Only because you chose to record it for your own useExplicit consent, given by entering itSame as other evidence you create, deletable at any timeYou and adults you authorize
Minimum verification set for issued records (legal name, record reference, document title, issue date, enrollment dates, printed academic content)So a transcript or enrollment letter stays checkable years laterLegitimate interests in maintaining a reliable school record, and legal obligation where applicableIndefinitely, by design, see Section 9Anyone you hand the document to, via our verification page
Billing and payment statusTo take payment and manage enrollmentContract performanceWhile required for the enrollment and for tax and accounting periodsYou, authorized Ivy staff, and our payment processor
Technical and security logsTo keep the Services working, secure, and free of abuseLegitimate interests in security and reliabilityOnly as long as reasonably needed, subject to provider settingsAuthorized Ivy staff and infrastructure providers
Product analytics (signed-in flows)To understand and improve how features are usedLegitimate interests, or consent where requiredAs configured for the analytics serviceAuthorized Ivy staff and product-analytics infrastructure
Optional public-site analyticsTo see which public pages are usefulConsentAs configured, stops when consent is withdrawnAuthorized Ivy staff and public-analytics infrastructure

What is not in this table is as important as what is. We do not hold advertising profiles, we do not sell personal information, and we do not use a child's learning history to target anyone with anything.

2. What We Collect

We collect only the minimum information necessary to provide you with an account and keep our services running.

2.1 Account Information

When you create an Ivy Waters account, we collect:

  • Email address: used for authentication, account recovery, essential service communications, and optional marketing messages when an adult explicitly joins a list.
  • Password: processed for authentication and stored only in hashed form. We do not store plaintext passwords.
  • Guardian name or display name (if provided): used to identify the adult account holder and personalize the workspace.

2.2 Service Data (What You Choose to Store)

To provide core features of the Services, we store certain information in our backend database when you choose to use those features. This may include:

  • Learner profiles: such as a student name, age, grade, and other details you choose to provide to organize the family workspace.
  • Account and settings data: such as timezone, notification preferences, family membership and permissions, enrollment status, and billing status.
  • Learning and recordkeeping data: such as notes, activities, attendance, resources, parent-approved standards matches, curriculum plans, academic-record fields, and portfolio content you choose to create.
  • Evidence media: such as photos, audio and, where a feature supports it, video; editable dictation or transcription drafts; captions; and related metadata that you deliberately upload or record through a feature. Media files may contain information about other people or embedded device, date, or location metadata.
  • Generated and issued-document data: such as portfolio exports and, once operating and approved, the information needed to prepare a school record and the minimum set needed to confirm that a document we issued is genuine. Section 9 explains how long each is kept.

2.3 Automatically Collected Technical Data

When you use our apps, our hosting infrastructure may automatically collect limited technical information:

  • IP address: temporarily processed for security and abuse prevention.
  • Browser type and version: used for compatibility and troubleshooting.
  • Device type (desktop, tablet, mobile): used to optimize your experience.
  • General geographic region (country level): may be derived from IP address for aggregate service analytics and security. We do not request GPS location as part of ordinary account telemetry, although media you choose to upload may contain embedded location metadata.

2.4 Cookies and Similar Technologies

Our apps use cookies and similar storage technologies:

  • Authentication cookies: essential cookies that keep you logged in to your account. These are strictly necessary for the service to function.
  • Security cookies: used to prevent cross-site request forgery and other security threats.
  • Product analytics storage: when product analytics is enabled, the current signed-in app configuration keeps its identifier and event state in browser memory rather than durable cookies or local storage. Selected events may be associated with an adult account identifier and, for some IvyTracks events, a yes/no learner-context flag. We use this to understand and improve product flows, not for advertising.

After a visitor chooses Allow insights, public pages may use cookie-free public-site analytics for aggregate page and performance measurement. Ivy removes query strings and URL fragments and excludes verification, password-reset, and email- preference routes before pageview delivery. The same choice permits one bounded, first-party first-touch record on the device. Our Cookies Policy explains how to withdraw the choice. We do not use child learning activity to build advertising profiles, and signed-in learning experiences do not contain child-directed advertising.

2.5 Sensitive Information You Choose to Add

Family notes, records, or media may reveal information that is sensitive under some laws, including a learner's health, disability, support needs, beliefs, or family circumstances. Please provide only what is useful for the feature you choose. Ivy Waters does not provide medical or psychological services, and the ordinary family workspace is not intended to replace a professional health record. Where a feature requires a separate legal basis or consent for sensitive information, we will ask for it before enabling that processing.

3. Information We Do Not Intentionally Request for the Core Service

For ordinary family-workspace use, we do not intentionally request:

  • Advertising identifiers or ad targeting profiles for children
  • Precise location data as an account or learning-record field, although uploaded media may contain embedded metadata as described above
  • Social media profiles or contact lists
  • Photos, videos, or audio that you have not deliberately submitted through an evidence, profile, capture, or upload feature
  • Government-issued identifiers (like Social Security numbers) or sensitive financial account numbers
  • Financial information directly (payments are processed by third-party providers)

We also do not sell personal information to third parties. The signed-in family workspace does not contain third-party advertising. Selected public marketing pages may use optional, consent-controlled analytics or marketing technologies as described in our Cookies Policy; those technologies are not permitted to use family educational data or signed-in child learning activity.

4. How We Use Your Information

We use the limited information we collect for the following purposes:

PurposeData Used
Create and manage your accountEmail, password (hashed)
Authenticate you when you log inEmail, password (hashed), auth cookies
Send essential service communications (password resets, security alerts, critical updates)Email
Sync and display the family learning journey, portfolios, and recordsLearner profiles, learning data, evidence media, account permissions
Provide optional parent-reviewed standards or model-assisted suggestions when requested and enabledSelected evidence text, bounded task context, and operational request metadata needed for that feature
Store evidence media and, when separately enabled, prepare an editable transcription draftThe submitted media, media metadata, and the portion sent to an approved transcription service for the requested task
Maintain security and prevent abuseIP address, security cookies
Ensure compatibility and fix bugsBrowser type, device type
Understand and improve product flows when product analytics is enabledAdult account identifier, event name, product context, a yes/no learner-context flag where relevant, and technical/device data
Understand which public pages are useful after optional consentPage path without query or fragment, referring site, broad region, browser and device details
Comply with legal obligationsAs required

We do not use family educational data or signed-in child learning activity for:

  • Advertising or marketing profiling
  • Selling to third parties
  • Advertising or marketing profiles based on child learning activity
  • Fully automated academic or enrollment decisions. Model-assisted suggestions require parent review and do not independently determine a student record.

5. Service Providers and Other Recipients

We use service providers to host and operate parts of the platform. The data a provider receives depends on the feature you choose. We review the provider, purpose, data categories, retention behavior, and applicable agreement before activating a new route for learner content. Provider terms and legally required retention may include exceptions, which we disclose when material to the feature.

Recipient categoryPurposeData involved
Legacy identity, database, and storage infrastructureStaged migration, reconciliation, security, and bounded rollback onlyAccount metadata, learner profiles, and Service Data that remain in isolated legacy features or migration copies
Authentication, session, and relational database infrastructureAccounts, sessions, authorized family access, enrollment status, and Platform-backed recordsAccount metadata, family and guardian records, learner profiles, enrollment or billing status, and Service Data
Private object-storage infrastructurePrivate evidence media, avatars, and document assetsUploaded media and the object metadata needed to authorize access
Web hosting, content delivery, and security infrastructureDelivering the Services, reliability, and abuse preventionStandard hosting, delivery, reliability, and security logs
Payment and fraud-prevention servicesEnrollment billing and payment processing when checkout is enabledEmail, billing details, transaction metadata, and payment-method information handled by the processor; we do not store full payment-card numbers
Transactional communicationsAccount, security, lifecycle, and support messages, including messages submitted through the `/contact` formAdult email address, message subject and content, and delivery metadata
Product analytics infrastructure, when configuredUnderstanding product reliability and adult account flowsAdult account identifier, product event and context, technical or device data and, where relevant, a yes/no learner-context flag; not a raw learner identifier, learner notes, evidence media, or record contents by design
Optional public-site analytics infrastructureConsent-based measurement of useful and reliable public pagesPage path without query or fragment, referring site, broad region, browser, and device details
Model or transcription processing, only when reviewed and enabledOptional parent-requested standards, writing, transcription, or other model-assisted suggestionsSelected evidence text or submitted media, bounded task context, and operational request metadata needed for the requested feature
Professional advisers, auditors, insurers, authorities, or transaction counterpartiesLegal compliance, security, claims, professional advice, audit, insurance, or a corporate transaction where lawfully necessaryOnly the information reasonably necessary for that purpose, subject to applicable confidentiality and legal restrictions
Recipients a guardian directs us to contactSending an issued record or other information at the guardian's requestThe information the guardian directs us to send and the destination details they provide

We state recipients by category because the particular vendor may change. Replacing a provider within a category does not authorize a new purpose, a new category of data, or materially longer retention. We update this policy, give a feature-specific notice, or obtain an additional choice before a materially different use where applicable law requires it. You may ask us to identify actual recipients of your personal information. We provide that information after verification where applicable law requires it.

We do not sell, rent, or trade your personal information to any third party. We do not share family educational data with advertisers, data brokers, or social media platforms. Optional technologies on public marketing pages may process adult visitor and campaign data as described in our Cookies Policy and subject to the applicable consent choice.

Before activating a new family-data model or transcription route, we complete a privacy and security review. A just-in-time notice identifies the recipient category, the content sent, the requested purpose, and any material retention or training terms. It also identifies processing regions, transfer safeguards, the actual recipient, or an available non-model path where that information is material to the choice or applicable law requires it. Until the review and any required notice or choice are complete, the route remains unavailable for family data.

6. Children's Privacy and Parent Controls

We take children's privacy seriously. Ivy Waters is a guardian-operated service that stores information adults choose to provide about learners in Pre-K through Grade 8. Children do not create accounts or independently operate the Services. A child may nevertheless appear or speak in a photo, audio recording, or video that an adult chooses to add, so we treat learner media as sensitive child-linked data.

Parent-mediated collection

The Children's Online Privacy Protection Act (COPPA) regulates certain online collection of personal information from children under 13 in the United States. Other child-privacy, biometric, education, and data-protection rules may also apply depending on the family, feature, and jurisdiction. Our current service is designed around adult account holders and parent-mediated choices:

  • Account creation requires a parent or guardian. Only individuals aged 18 or older may create an Ivy Waters account. Children do not create their own accounts.
  • Guardians choose what learner information to add. This can include a child's image or voice when a guardian deliberately uses a supported media feature.
  • Optional processing is a separate choice. Storing a recording does not by itself authorize optional transcription or other model processing. Where offered, the feature explains what is sent and provides a non-AI path.
  • No child accounts or public social features. We do not send account email to children, permit children to create accounts, or provide public profiles, forums, or contact with strangers.
  • No advertising directed at children. The signed-in family workspace contains no third-party advertising, and product analytics is not used to build advertising profiles from child learning activity.
  • Parental control. Parent/guardian accounts govern access to learner workspace data and entitlements. Families can use available export controls, request deletion through the retention-aware process below, and clear local copies on their devices.

Before introducing child accounts, unsupervised child interaction, biometric identification, or another materially different child-directed flow, we will review the collection, notice, consent, retention, and provider requirements for that feature. If you believe information was submitted without appropriate authority or notice, contact us. We will investigate and restrict, delete, or retain it as required by applicable law and the circumstances.

7. International Users and GDPR

We serve families worldwide, including in the United Kingdom, European Union, and Australia. If you are located in the European Economic Area (EEA), the United Kingdom, or another jurisdiction with data protection laws, you have specific rights regarding your personal data.

Under the General Data Protection Regulation (GDPR), we process your data on the following legal bases:

  • Contract performance: processing account and Service Data is necessary to provide the features you request and, once available, any enrollment you purchase.
  • Legitimate interests: we may rely on legitimate interests for security, fraud prevention, service reliability, and limited product improvement where the processing is necessary and proportionate. Before relying on this basis, we assess and document the interest, necessity, and effect on your rights. Where consent is required instead, we ask for consent.
  • Legal obligation: we may process data as required to comply with applicable laws.
  • Consent: where required (for example, for optional analytics or marketing communications, if we introduce them in the future), we will obtain your explicit consent and provide an easy way to withdraw it.

Your Rights Under GDPR

If you are in the EEA or the UK, you have the right to:

  • Access: request a copy of the personal data we hold about you.
  • Rectification: request correction of inaccurate data.
  • Erasure ("Right to Be Forgotten"): request deletion of your personal data. Content you created is erased in full. A document we have already issued and certified is reduced to the minimum set that keeps it verifiable, on the schedule and legal basis set out in Section 9.
  • Restriction: request that we limit how we use your data.
  • Data portability: receive your data in a structured, machine-readable format.
  • Object: object to our processing of your data based on legitimate interests.
  • Withdraw consent: where processing is based on consent, withdraw it at any time.
  • Lodge a complaint: file a complaint with your local data protection authority.

To exercise any of these rights, contact us using the information in Section 12 below. Rights can be subject to legal conditions and exceptions. We may need to verify your identity and guardian authority before acting on a request, and we will respond within the period required by applicable law.

International Data Transfers

Our infrastructure and analytics providers may process account and Service Data in the United States and other regions where they operate. For transfers that require a legal safeguard, we use the applicable provider agreement and transfer mechanism. The exact mechanism depends on the provider, entities, and regions involved.

Educational data is transmitted as part of workspace sync and reporting. It is processed with standard protections and transfer safeguards for applicable regions.

Our payment processor may process payment-related information in multiple countries, including outside the EEA or UK. Where applicable, we rely on the processor's contractual safeguards and an appropriate transfer mechanism.

Australian Privacy Act

If you are located in Australia, the Australian Privacy Act 1988 may give you rights including access to and correction of personal information. Contact us to exercise the rights that apply to your circumstances.

California Residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you the rights to know what personal information we collect and why, to access a copy of it, to correct inaccurate information, to delete it subject to the retention rules in Section 9, and to be free from discrimination for exercising any of these rights.

Two disclosures matter most here, and both are simple:

  • We do not sell personal information, and we do not share it for cross-context behavioral advertising. There is no opt-out link because we do not conduct either activity.
  • We do not use a child's learning history to build an advertising profile. Learner evidence is not an advertising input under any circumstances.

We do not knowingly collect personal information directly from children under 16. Learner information reaches us through a parent or guardian operating the account, as described in Section 6. To exercise a California right, contact us at the address in Section 12. We may need to verify your identity and, for a learner record, your guardian authority before we act.

Texas Residents (TDPSA)

Ivy Waters International is a Texas entity. If you are a Texas resident, the Texas Data Privacy and Security Act gives you the rights to confirm whether we process your personal data, to access and obtain a portable copy of it, to correct inaccuracies, to delete it subject to the retention rules in Section 9, and to opt out of targeted advertising, sale, or profiling with legal or similarly significant effects.

We do not conduct targeted advertising, do not sell personal data, and do not profile families in a way that produces legal or similarly significant effects, so those opt-outs have nothing to act on. We honor recognized universal opt-out mechanisms where they apply. To exercise a Texas right, contact us at the address in Section 12. If we decline a request, you may appeal by replying to our decision, and you may contact the Office of the Texas Attorney General.

8. Data Security

We implement appropriate technical and organizational measures to protect your account information:

  • Passwords are stored only in hashed form; we do not store plaintext passwords.
  • Authentication is handled by authentication infrastructure that uses encryption in transit (TLS/SSL) and at rest where applicable.
  • Web hosting uses HTTPS so data is encrypted during transmission.
  • Private evidence media is stored in private object storage and accessed through authorized, time-bounded or server-mediated requests.
  • Access controls and operational processes are designed to limit organizational access to people who need it to operate, secure, or support the Services.
  • Device-stored data (where used) is stored locally in your browser/app environment and remains under your control on that device.

No system is 100% secure. While we take reasonable measures to protect your information, we cannot guarantee absolute security. If we become aware of a data breach affecting your account information, we will notify you and any applicable regulatory authorities as required by law.

9. Data Retention and Deletion

Your data sits in one of two tiers, and which tier it is in decides what a deletion request can reach. The family story and the formal record share one source, but they are not the same thing.

  • Tier 1, content you created. Learning moments, photos, audio and dictated text, notes, unpublished drafts, and portfolio items that are not part of a document we have issued. This is yours. You can delete individual items or all of it at any time, and we complete the deletion within 30 days, including backups.
  • Tier 2, records the school issued. Transcripts, enrollment letters, school-issued portfolios, and records packets we have issued and certified, plus the minimum identity and enrollment data needed to confirm that one of them is genuine. We keep these on the published schedule below, because a school cannot un-issue a document it has certified. While a document is still verifiable, you cannot delete the small set of data that keeps it verifiable.

What this means for verification trust. Records in Tier 2 are issued by Ivy Waters International, which operates as a private school in Texas under Leeper v. Arlington Independent School District, 893 S.W.2d 432 (Tex. 1994). Texas does not license, register, approve, or accredit private schools. A verification therefore confirms that Ivy Waters issued the frozen record, and nothing more. It is not a claim of state licensure, state approval, or third-party accreditation, and it does not commit any receiving school or authority to accept the record.

How Long We Keep Your Data

WhatHow longWhy
Tier 1 content: learning moments, photos, audio, dictated text, notes, drafts, and portfolio items not part of an issued documentUntil you delete it, or until your account closes. Either way the deletion is completed within 30 days, including backups.It is yours, and you decide.
Account information (email, hashed password, display name)While the account is active; closed out with the account.Needed to operate and secure the account.
Legacy migration and rollback copies: Tier 1 or Tier 2 information that remains in legacy identity, database, or storage infrastructure during staged reconciliationNo longer than the schedule for the underlying Tier 1 or Tier 2 information. The Tier 1 30-day deletion boundary applies to legacy copies. Redundant copies are deleted or de-identified after reconciliation and the documented rollback need ends, except where a legal hold or other non-waivable rule requires restricted retention.A migration copy must not become a second, longer retention schedule.
Tier 2 minimum verification set: the student's legal name, the record reference, the document title, the issue date, the enrollment dates, and the academic content printed on the issued documentIndefinitely. We mean indefinitely: there is no scheduled deletion date for this set.An issued transcript has to stay checkable years later, for a placement meeting, an admissions office, or a border crossing. If we deleted this, every document we ever issued you would quietly stop verifying.
Tier 2 supporting material: issued enrollment letters, school-issued portfolios and records packets, their retained artifacts, and superseded issuance snapshots7 years after the student withdraws.Long enough to answer questions about a record we issued, and no longer, because it is not the part that makes a document verifiable.
Verification attempt log: an identity-free record of checks made at our verification page, holding no name, no account link, and no stored IP address30 daysRate limiting and abuse prevention only. It is never joined to a family and never shown as family activity.
Native private-record download attempt log: a pseudonymous, secret-keyed record of a desktop PDF redemption attempt, holding no name, raw account or media ID, file name, object key, IP address, or record content30 daysRate limiting and abuse prevention only. It is not shown as family activity.
Contact and support correspondence: messages sent through the `/contact` form or by email to our published addresses, with the subject and the reply address you give us. The form does not store your IP address: it is processed only in memory for abuse prevention and is not written into the delivered message.Up to 24 months after the conversation is resolved, unless an open legal, safety, or billing matter requires longer. Delivery metadata at the email provider follows that provider's retention settings.Answering you, and keeping enough short-term context that a follow-up does not start from zero.
Server and security logsOnly the period reasonably needed for security, reliability, fraud prevention, and legal compliance, subject to provider retention settings.Operating and protecting the Services.
Product analytics dataThe retention configured for the analytics service, reviewed separately from family records. Material analytics uses and available choices are described in the Cookies Policy.Understanding and improving product flows.
Optional public-site analyticsThe retention configured for the public analytics service. It is separate from family records and stops collecting when consent is withdrawn.Understanding which public pages are useful and reliable.
Device-stored dataOn your device until you clear it (for example, by clearing your browser/app storage).It is not automatically removed when you cancel, and it may be lost if you clear storage, switch devices, or uninstall an app. Server-side deletion does not reach it.

This table describes ordinary retention. We may keep a restricted copy longer where necessary for a legal obligation, fraud or security investigation, dispute, or legal claim. We use it only for that reason and delete it when the exception ends.

Deleting Your Content

You can delete Tier 1 content at any time, a single item, or all of it, through your account controls or by contacting us at the address in Section 12 below. We offer a full export before the deletion runs, and we complete the deletion, including backups, within 30 days.

Deleting Tier 1 content does not alter a document we have already issued. A grade or an attendance figure printed on an issued transcript is a separate, frozen copy made at the moment of issue, and it stays. That is the only way a record can still mean something after the working data behind it is gone.

Closing Your Account

You may request account closure through available account controls or by contacting us at the address in Section 12 below. When you request it:

  1. We verify that the request comes from an authorized guardian account.
  2. We offer a complete export of everything we hold about your family, across both tiers, before anything is erased.
  3. We erase Tier 1 content along with account, relational, and private media data, within 30 days including backups.
  4. Private access to Tier 2 ends. We retain Tier 2 supporting material only for its published period, then reduce it to the minimum verification set described above. We tell you in writing what was kept and why.
  5. We may retain limited billing, tax, security, or audit information where the law requires it, and we will tell you if we do.
  6. Data cached locally on your device is not affected by server-side deletion and may need to be cleared separately.

The one thing closing your account does not do is stop an issued transcript from verifying. That is deliberate. It is disclosed here and in the enrollment agreement before you enroll, and it is the reason the record is worth anything to the registrar who eventually reads it.

Why We Can Keep the Tier 2 Set

Under the GDPR, the right to erasure is strong, but it is not unconditional. Article 17(3)(e) preserves processing necessary for the establishment, exercise, or defence of legal claims, and that is the basis we rely on for the Tier 2 verification set: a certified academic record is precisely the kind of document a family, a school, or an authority may later need to rely on. Article 17(3)(b) covers the narrower case of data a law requires us to keep, such as billing and tax records.

We are not hiding behind a statute here. Texas imposes no records-retention period on us, so the schedule above is our own choice, made because the record is useless if it cannot be checked. What the GDPR asks of such a schedule is that it be defined, documented, and disclosed in advance rather than decided after the fact, which is what this section is. None of it limits your erasure rights over Tier 1 content.

10. Your Choices

  • Account information. You can update your email address or password through your account settings at any time.
  • Communications. Essential service messages are required for account operation. Optional newsletters or marketing messages are sent only after an adult asks to receive them and include an unsubscribe or opt-out path.
  • Device-stored data. You have full control over data stored on your device. You can clear it at any time through your browser/app storage settings.
  • Cookies and public-site insights. You can reopen Cookie choices from the site footer and allow or withdraw optional public-site measurement at any time. Essential authentication and security storage may still be required for signed- in features.
  • Media processing. Where transcription or another media-AI feature is optional, you can keep the supported recording without enabling that processing.
  • Model-assisted suggestions. Where model assistance is optional, you can continue without it. Suggestions remain subject to parent review before they become confirmed learner-record information.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our services, or applicable law. When we make changes:

  • We will update the "Last Updated" date at the top of this policy.
  • For significant changes, we will provide prominent notice (such as a banner in our apps or an email to your registered address).
  • Where applicable law requires consent or a particular form of notice, we will use that process before the change applies.

We encourage you to review this policy periodically. The Terms of Service explain how service terms are accepted; privacy consent, where legally required, is handled separately and is not inferred merely from reading this policy.

12. Contact Us

If you have questions about this Privacy Policy, want to exercise your data rights, or have concerns about how we handle information, please contact us:

IVY WATERS INTERNATIONAL LLC Email: privacy (at) ivywaters.com Website: https://ivywaters.com

For GDPR-related inquiries, you may also contact your local data protection authority.

We aim to respond to all inquiries within 30 days.

13. Summary

QuestionAnswer
Does Ivy Waters collect my child's educational data?Yes, when a guardian chooses to provide it. This may include learner profiles, notes, attendance, standards matches, photos, audio, transcripts, portfolio content, and other family records.
What do you collect?Adult account details, the family and learning data you choose to provide, limited billing data, and technical data needed for security and reliability. Passwords are stored only in hashed form by our authentication provider.
Do you sell data?No. We do not sell personal information.
Do you show ads?The signed-in family workspace does not contain third-party advertising.
Do you use learner records for advertising?No. Product analytics may measure signed-in feature use as described above, but it is not used to build advertising or marketing profiles from learner records.
Can I delete my data?Yes, content you created is yours to delete at any time, individually or all at once, completed within 30 days including backups. Closing your account erases the same content plus your account and relational data.
What survives closing my account?Private account access ends. Tier 2 supporting material remains only for the period in Section 9; the minimum set that keeps an issued document verifiable remains indefinitely. Limited billing, tax, security, audit, dispute, legal-claim, or legally required records may also remain for their applicable purpose. Export anything you want to keep first.
Is my data transferred internationally?We may process account, Service Data, and operational data in the US and other countries where our providers operate, subject to the safeguards described above.