Glimmer Platform Privacy Policy

Last Updated: October 2025

Welcome to Glimmer! Glimmer Labs, Inc. ("Glimmer," "we," or "our") operates the Glimmer platform ("Platform") to support teachers and students in delivering and personalizing instruction.

We take privacy seriously and are committed to protecting the information shared with us through the Platform. This Privacy Policy explains how we collect, use, and safeguard personal and student data in accordance with applicable laws, including the Family Educational Rights and Privacy Act (FERPA), the Children's Online Privacy Protection Act (COPPA), and the Health Insurance Portability and Accountability Act (HIPAA).

1. Information We Collect

When you use the Glimmer Platform, we may collect information in the following categories:

A. Student and Classroom Information

Information may be entered by teachers or administrators, or directly provided by students as part of their learning experience. This may include:

  • Student names or identifiers (first name, last initial, or ID number)
  • Grade level and classroom enrollment
  • Learning progress, work submissions, and in-platform responses (from students)
  • Reflections, goals, interests, or other self-reported inputs (from students)
  • Teacher feedback and notes on assignments or performance
  • Information related to IEPs, 504 plans, or learning supports

B. Educator Information

Information used to manage accounts and communication, such as:

  • Name, role, and school email address
  • Teaching preferences or instructional content created on the Platform

C. Technical Information

Automatically collected, non-personal data used to maintain the Platform, such as:

  • Browser type, device type, and IP address
  • Login timestamps and usage analytics

Glimmer does not collect biometric, financial, or unrelated personal data.

2. How We Use Information

We use collected information solely to:

  • Provide and improve Glimmer's educational tools and insights
  • Support teaching, learning, and student goal-setting
  • Maintain and secure the Platform
  • Communicate about service updates or technical issues

We do not sell personal data, use it for targeted advertising, or share it for marketing purposes.

3. Data Security

We maintain industry-standard administrative, technical, and physical safeguards to protect information from unauthorized access, disclosure, or destruction. This includes:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access controls and authentication
  • Regular security monitoring and vulnerability testing
  • Employee confidentiality training

4. FERPA Compliance

Glimmer complies with the Family Educational Rights and Privacy Act (FERPA) to protect the privacy of student education records and personally identifiable information (PII). We handle all data on behalf of schools and educators solely for educational purposes and never disclose student information without authorization or consent as permitted under FERPA.

5. COPPA Compliance

In compliance with the Children's Online Privacy Protection Rule (COPPA):

Because Glimmer limits the use of personal information collected from users under the age of 13 ("Child" or "Children") to the educational context authorized by a school or educator, by signing up for Glimmer on behalf of a school or classroom, the educator represents that this authorization is based on verified parental consent to disclose data under COPPA for each Child registered within the Platform.

With the noted exception above, Glimmer does not knowingly collect personally identifiable information from anyone under the age of 13. However, we may unknowingly collect and retain information about Children on our servers if such data is submitted by users over the age of 13. For example, if a teacher uploads class materials containing a student's name and age, this information may be stored as part of that content.

If you believe that we have inadvertently collected information from a child without proper authorization, please contact us at support@learnwithglimmer.com, and we will delete the data promptly.

6. HIPAA Compliance

We take your privacy seriously. In compliance with the United States Health Insurance Portability and Accountability Act of 1996 (HIPAA), we take all steps reasonably necessary to ensure that your data is treated securely.

The HIPAA Privacy Rule protects the privacy of individually identifiable health information, known as protected health information (PHI). PHI may include student information related to health, accommodations, or disabilities (such as IEP or 504 plan details).

To learn more about your rights under HIPAA, please visit the U.S. Department of Health and Human Services website: https://www.hhs.gov/hipaa/for-individuals/index.html

7. Data Breach Response

In the event of an unauthorized release, disclosure, or acquisition of personal or student data that compromises its security, confidentiality, or integrity, Glimmer will:

  • Notify affected users and/or partner schools within 72 hours of confirming the incident, unless law enforcement requests a delay.
  • Provide available details including the nature of the incident, the types of information involved, the estimated date of occurrence, and steps taken to address it.
  • Comply with all applicable federal and state laws regarding breach notification and mitigation.
  • Maintain a written Incident Response Plan consistent with industry standards and provide a summary upon request.

8. Data Retention and Deletion

We retain information only as long as needed to provide educational services or as required by law. Upon request from a school or user, Glimmer will permanently delete or return personal or student data within 60 days.

9. OpenAI Processing

Glimmer may use OpenAI OpCo, LLC as a data processor to generate educational insights, recommendations, or feedback.

No personally identifiable information (PII) is ever sent to OpenAI. All PII is decoupled from other data before any processing occurs. Only anonymized or de-identified data necessary to generate the requested output is transmitted.

OpenAI does not retain or use this data to train its models, and all processing occurs under strict data protection and confidentiality standards.

10. Children's Privacy

Students cannot independently create Glimmer accounts. Educators manage all access for minors, and parents or guardians may request access to or deletion of their child's data by contacting us directly.

11. Updates to This Policy

We may update this Privacy Policy periodically to reflect product or legal changes. The "Last Updated" date will always indicate the current version, and we will notify users of any significant updates.

12. Contact

Glimmer Labs, Inc.
New York, NY
support@learnwithglimmer.com