Legal

Privacy Policy

Effective date: September 5, 2026

Updated September 5, 2026.Three corrections after an internal audit, all in your favor. Section 6 now names two more companies we use behind the scenes (Anthropic and Slack), neither of which receives any student information. Section 8 now lists every feature that sends data to Google's Gemini models, not just four of them, including the optional AI study assistant and the safety screen that protects it. And assignment notification emails no longer carry your student's name, so of the emails we write, a student's name now reaches our email provider only in the optional weekly progress email, exactly as this policy says.

Updated August 26, 2026. Two changes. We now use Google Ads to measure which of our ads bring families to the site, on our public marketing pages only, and section 7 says exactly what that involves and how to turn it off. We also removed two tools this policy described but which we had not actually switched on, because a policy that lists things we do not do is not worth much. Nothing about student data changed, and nothing new is collected from a student. Sections 6 and 7 carry the detail.

1. Who We Are

Genesis Education Solutions operates the Genesis K-12 Academy learning platform ("the Platform"). We teach hands-on engineering to homeschool students in grades 6 through 8 from a Biblical worldview. Our students are children, so this policy is written to be read by their parents. Contact us at team@gk12academy.com with any privacy question.

2. Information We Collect

We collect only what the course needs to work:

  • Parent account: your name, email address, and password.
  • Student account: the student's first name or display name, grade level, and the login email and password you create for them.
  • Progress data: which lessons are complete, quiz and assignment scores, notebook and workbook entries, and answers saved inside interactive activities.
  • Student work: photos of hands-on builds and assignment files (PDFs or images) that a student uploads for feedback or grading.
  • Course feedback: some lessons end with a short form asking how the lesson went, and after certain lessons a short pop-up asks the student to rate how the course is going (1 to 5 stars) with an optional note. We store the answers with the lesson, the course version, the student's grade level, and the state the lab kit ships to, so we can tell which version of a lesson needs work. We do not store the student's name, their login, or any identifier that would let us or you link an answer back to one student, so we cannot tell you what your own student answered.
  • Purchase records: what was bought, the amount, and the shipping address for the lab kit. Card numbers are handled entirely by Stripe and never reach our servers.
  • Website usage on public pages: page views, clicks, and advertising measurement on our marketing pages. See section 7. None of this runs on student pages.
  • Support messages: anything you email us.

We do not collect birth dates, phone numbers, home addresses beyond kit shipping, photographs of faces for identification, or location data.

3. Children's Privacy (COPPA)

Genesis K-12 Academy is built for middle school students. Every student account is created by a parent or guardian and stays linked to that parent's account. We comply with the Children's Online Privacy Protection Act (COPPA):

  • We do not knowingly collect personal information from a child under 13 without verifiable parental consent.
  • Student accounts require a parent account and cannot be created independently by minors. There is no way for a student to sign up on this site.
  • A parent may review, correct, or request deletion of their child's data at any time, and may withdraw consent at any time.
  • We do not serve advertising of any kind to students, targeted or otherwise.
  • No website analytics and no advertising pixel of any kind runs on the pages students use. Our advertising tools are on our public marketing pages only, where the audience is parents. See section 7.
  • Once a browser has been used to sign in to a student account, we delete the analytics and advertising cookies on it and stop loading those tags on that browser entirely, including on our public marketing pages. If your student has ever signed in on a device, that device is out.
  • Our free lesson preview and our student dashboard demo carry no analytics and no advertising tag either, because those are pages a student may reasonably be looking at.
  • We do not condition a child's participation on giving us more information than the course needs.

How we verify that you are the parent

Every family reaches us through a purchase before any student account exists. You buy the course, our payment processor (Stripe) charges your card and emails you a receipt for that transaction, and only then do you receive a code to create your account. A payment card transaction that notifies the account holder is one of the methods the Federal Trade Commission recognises for verifying parental consent, and it is the method we rely on.

Before you create a student account, we also show you a plain-language notice of exactly what we collect from your student, how we use it, who else receives it, and how you can review or delete it. You confirm you are the parent or guardian and agree to that notice. We keep a record of both halves: the transaction that verified you, and the notice you agreed to, including its version and date.

You can withdraw your consent at any time from your account settings, or by emailing us. See section 11.

4. How We Use Your Information

We use what we collect to:

  • Run the Platform and deliver the course and the lab kit.
  • Track student progress and build gradebook and transcript reports for parents.
  • Grade submitted assignments and give feedback on hands-on builds. See section 8.
  • Send enrollment confirmations, account notices, and the optional weekly progress email.
  • Understand how people find and use our public marketing pages so we can improve them.
  • Answer support requests.

5. We Do Not Sell Your Data

We do not sell, rent, or trade personal information. We do not share it with anyone for their own marketing. The only outside companies that touch your data are the service providers listed in section 6, and they handle it only to do the job we hired them for.

6. Third-Party Services

These are every outside company that receives data from the Platform, and what each one gets:

  • Firebase (Google): accounts, sign-in, our database, file storage, and web hosting. Firebase holds essentially everything described in section 2, because it is where the Platform lives.
  • Stripe: payment processing. Stripe receives the buyer's name, email, card details, and the kit shipping address. We never receive the card number. Stripe's own privacy policy governs that data.
  • Google Gemini: the AI models behind the features listed in section 8 — assignment grading, project photo feedback, review sheets, checkpoint reviews, the optional AI study assistant and its safety screen, support-message sorting, and the weekly progress email. Section 8 describes exactly what is sent.
  • Bunny Stream: hosts and delivers the course videos. Bunny receives the viewer's IP address and standard video playback requests. Videos play through a signed link that expires, and Bunny does not receive a student's name or account.
  • Resend: sends our email. Resend receives the recipient's email address and the contents of the message. Of the emails we write, the optional weekly progress email is the only one that includes a student's first name, alongside how many lessons they finished; our other notices, such as an assignment submission notice, name the assignment but not the student. Two exceptions carry text a student typed themselves: if you or your student write to our support address, the message reaches us exactly as it was typed and our reply is addressed to the name on the account that sent it, and if the AI study assistant's safety screen flags a student's message as a possible crisis, that message is included, as typed, in the safety notice we send to you and to our team.
  • Google Analytics: measures traffic on our public marketing pages only. It does not run on student pages. See section 7.
  • Google Ads: tells us which of our ads brought a family to the site, on our public marketing pages only. Google receives the page visited, the browser and device type, the IP address, and an identifier stored in a cookie on those pages. When someone buys, it also receives a scrambled (SHA-256 hashed) form of the buyer's email address, so Google can match the sale to the ad that led to it; we never send the address itself, and this only ever involves the adult who paid. It does not run on student pages, on our free lesson preview, or on our student dashboard demo, and it never receives a student's name, account, grade, or schoolwork. See section 7.
  • Anthropic (Claude): the AI models we use for our own internal work — drafting and checking course material, admin tooling, and back-office bookkeeping. Anthropic receives no student information of any kind: no names, no accounts, no schoolwork, no grades, no uploads.
  • Slack: our internal team chat. It receives operational alerts about the business, such as a bookkeeping summary or an internal task update. It receives no student information of any kind.
  • YouTube and Vimeo: not used for course content today, and no lesson currently contains a video from either. If a lesson ever does, it is embedded through YouTube's no-cookie player and Vimeo's do-not-track option, so neither can set advertising cookies on a student's browser.

Advertising and marketing tools run on our public marketing pages only. None of them run on the dashboard, on a course page, or on a lesson page. If we add another one, it goes on the public pages under the same rule and this policy is updated to name it.

7. Cookies and Website Analytics

On student pages we use no analytics and no tracking cookies at all. The dashboard, every course page, and every lesson page load without Google Analytics. No analytics tag is loaded there and no analytics cookie is set there.

On our public marketing pages (the homepage, course pages, the store, and similar) we use Google Analytics to count visits and understand which pages people read. It sets two first-party cookies, named _ga and _ga_ followed by a property code. They tell a returning visitor from a first-time visitor and group page views into a single visit. They expire on their own after two years, and you can delete them at any time from your browser settings.

We configure Google Analytics with Google Signals turned off, and we do not use it to build advertising audiences.

On those same public marketing pages we also run Google Ads conversion tracking, so we can tell which of our ads actually led to a purchase or a signup rather than guessing. It sets cookies whose names begin _gcl_, which record that you arrived from one of our ads. That is genuinely advertising, not just measurement, so we want to be plain about it: it lets Google connect your visit here to the ad you clicked. You can manage what Google does with it at myadcenter.google.com, you can block or delete the cookies in your browser, and you can switch the whole thing off on this browser using the control below.

We honor the Global Privacy Control signal. If your browser sends it, we turn advertising storage off automatically and you do not have to do anything else.

None of this runs on student pages. The dashboard, course pages, lesson pages, our free lesson preview, and our student dashboard demo load no analytics tag and no advertising tag of any kind. A student is never added to an advertising audience. And once a browser has been used to sign in to a student account, we delete the analytics and advertising cookies on it and stop loading those tags on that browser everywhere, including here.

Separately, the Platform uses ordinary sign-in storage to keep a signed-in user signed in and to remember a browser tab's session. That is not tracking and it is not shared with anyone.

Your privacy choices

We do not show a cookie banner, because we advertise only in the United States and we are well below the size at which an opt-in prompt is required. What we do instead is give you a real switch and honor Global Privacy Control. The switch is per browser and per device.

You can turn off advertising measurement on this browser. We will delete the analytics and advertising cookies already on it and stop loading those tags here. This applies to this browser on this device, so it is a per-device choice, and clearing your browser storage will undo it.

8. Artificial Intelligence

These features send data to Google's Gemini models. We want to be specific about what leaves the Platform:

  • Assignment grading. When a student submits an assignment, the file they uploaded goes to Gemini along with the assignment instructions and the grading rubric. That file is usually their own written work and often has their name on it.
  • Project photo feedback. When a student uploads a photo of a hands-on build, the photo goes to Gemini along with any note they wrote, so it can comment on the build against a rubric.
  • Review sheets. When a parent generates a review sheet, the student's first name, grade level, the topics they struggled with, and their scores go to Gemini.
  • Weekly progress email. Each student's first name and lesson counts go to Gemini to write the short encouragement note at the top. You can turn this email off from your dashboard.
  • Checkpoint reviews. When a student submits a checkpoint review, their written answers and the review's criteria go to Gemini so it can judge whether each section is answered with real evidence.
  • AI study assistant. When the assistant is turned on and a student asks it a question, their message, the lesson text they are reading, any notes in their notebook that the panel has open, and the conversation so far go to Gemini. Every message is also screened first by a Gemini safety check that watches for a student in distress or an attempt to misuse the assistant; if a message looks like a possible crisis, we notify you by email right away. You can turn the assistant off for each student from your dashboard, and when it is off nothing is sent.
  • Support messages. When you or your student send us a support message, its subject and body go to Gemini so it can sort the ticket to the right person. Whatever you type in the message is what gets sent; we do not attach an account or a student record to it.

We use Google's paid Gemini service. On the paid service, Google does not use what we send, or what the model returns, to train or improve its models.

We do not use AI to make decisions about a child outside the course, to build a profile of a child, or for any advertising purpose.

The in-lesson AI study assistant is currently turned off and is not available to students, apart from the anonymous demo on our public lesson preview, which is not connected to any account. When we do turn it on, parents will be able to turn it off for each student individually. Study assistant conversations are saved for 90 days so you can read them from your parent dashboard, and are deleted automatically after that.

9. Data Retention

We keep each kind of record only as long as we need it. This is our schedule:

RecordHow long we keep it
Parent and student accounts, and all progress data24 months after the last sign-in on the account, then deleted
Student work uploaded for feedback or grading (build photos, assignment files)The 18 month course access period, then deleted within 30 days of it ending
Grades and written feedback on that workWith the account, so 24 months after the last sign-in
Answers to the short end-of-lesson course feedback form and the course rating pop-up24 months from the date the answer was sent. These are not linked to a student, so they are not deleted with an account
AI study assistant conversations90 days, visible to you from your parent dashboard, then deleted automatically
Purchase, order, and kit shipping records7 years, which is what tax and accounting rules require
Unredeemed claim codes from a purchase12 months from the date of purchase, then they expire
Website analytics records from our public pages18 months
Advertising measurement data held by Google AdsGoverned by Google\u2019s own retention policy. You can turn this off on your browser at any time using the control in section 7, or manage it at myadcenter.google.com
Ad click identifiers we store with an order record18 months, the same as our other website analytics records
Support email and support tickets24 months
Anything you ask us to deleteDeleted within 30 days of the request

When a record reaches the end of its period we delete it. Where a purchase record has to be kept for tax reasons, we keep the transaction and drop the personal detail attached to it once the account itself is deleted.

10. Security

We use encrypted connections (HTTPS) everywhere, Firebase Authentication for sign-in, and rules on our database that let a parent see only their own family's records and a student see only their own work. Uploaded files are stored with access tokens rather than public links, and course videos play through signed links that expire. No system is completely secure, so please use a strong, unique password on every account.

11. Your Rights

Parents and guardians may, at any time: see the data we hold about their child, correct anything wrong, download or request a copy of it, have it deleted, and withdraw consent for us to collect any more. Withdrawing consent means we close the student's account, because the course cannot run without it.

The fastest way is from your account: sign in and open Account settings, where Your family's data lets you download everything we hold about your family straight away, or send us a deletion request. You can also email team@gk12academy.com from the address on the parent account and tell us what you want. Either way we answer within 30 days and we do not charge for it.

12. Changes to This Policy

We may update this policy as the Platform changes. If a change is material, we will email enrolled families before it takes effect. The effective date at the top of this page always reflects the most recent version, and material changes are summarized there.

13. Contact

For privacy questions, data requests, or anything COPPA related, contact us at team@gk12academy.com.