Privacy Policy
Effective date: 2026-06-08
1. What this policy covers
This policy describes what data LMS Bridge collects when you use the Service, why we collect it, how we store it, and your rights. For institutional deployments under a separate Data Use Agreement (DUA) or Data Processing Agreement (DPA), the terms of that agreement control to the extent of any conflict.
2. Data we collect from you (the instructor)
- Account information: name, email address, password (hashed), institution name, role, discipline, the LMS you use, and other onboarding fields you provide.
- Free-text descriptions you provide (e.g., teaching pain points, faculty narrative for reports). Used to improve the product and inform feature priorities.
- Canvas access tokens you paste into the Service. Encrypted at rest with AES-256 using a key stored in our server environment, separate from the database.
- Server logs: IP address, browser, timestamps, and the URL of pages you visit. Used for security monitoring and debugging.
3. Data we read from Canvas on your behalf
When you connect a Canvas access token, we use it to call the Canvas API to read:
- Your course list, assignments, rubrics, quiz questions and quiz statistics
- Per-student submission scores and rubric assessments (used only to compute aggregate outcome attainment — see §4)
We do not write to Canvas without your explicit instruction (e.g., when you click "Push to Canvas"). We do not request admin scopes or institutional API tokens.
4. Aggregation guarantee
When you run "Compute" on an Outcomes Assessment report, we pull per-student grade data from Canvas through our server, but we do not store per-student grade data. We store only the aggregate counts: how many students fell into each of the four attainment levels per Performance Indicator. Per-student data is held only in memory during the computation and discarded immediately after.
5. AI processing
Some features use a third-party AI provider (currently Anthropic Claude) to generate content (lecture material, assessment items, narrative drafts, tag suggestions). The text of these requests includes the prompt you supply and any short metadata needed for the generation (assignment description, criterion text, etc.). Anthropic's data handling is governed by their published policies; we do not transmit per-student identifiable data to AI providers.
6. Cookies and tracking
We set a session cookie when you log in so we can identify you across page loads. We do not use third-party advertising cookies or cross-site tracking.
7. Where data is stored
Application data is stored on servers operated by Amazon Web Services in the United States. Backups are retained for up to 90 days.
8. Retention
- Account data: retained until you delete your account.
- Encrypted Canvas tokens: deleted within 7 days of report deletion or account closure.
- Aggregate outcome counts and narratives: retained for the standard accreditation cycle (typically 6 years for ABET) unless your institution requires shorter retention under a DUA.
- Server logs: retained up to 90 days.
9. Your rights
You can request to access, correct, export, or delete your data at any time by emailing hello@lmsbridge.ai. We will respond within 30 days. If you are in a jurisdiction with specific data subject rights (e.g., California, EU), those rights apply.
10. FERPA
LMS Bridge handles data that may constitute "educational records" under the Family Educational Rights and Privacy Act. For institutional deployments, LMS Bridge can be designated as a "school official with legitimate educational interest" under FERPA via a Data Use Agreement. Until such designation, individual instructors using the Service are responsible for ensuring their use complies with their institution's policies.
11. Sub-processors
We use the following sub-processors:
- Amazon Web Services (hosting)
- Anthropic (AI inference)
- Resend (transactional email)
We will give 30 days' notice before engaging a new sub-processor.
12. Security incident notification
If we determine that a security incident has resulted in unauthorized access to your data, we will notify you without undue delay and in any case within 72 hours of confirmation.
13. Contact
Privacy questions: hello@lmsbridge.ai.