Algebro

Algebro for Districts

Everything a district IT or privacy office needs to vet Algebro: who touches student data, how it is protected, and how to reach the person responsible. That person is me. I'm Justin Korwin, the founder, and I answer every district privacy email myself.

Last updated: July 24, 2026

The short version:

  • Students sign in with a username only. We never collect student email addresses.
  • We do not sell data, serve ads, or build advertising profiles. Ever.
  • Five vendors process data on our behalf, all in the United States. They are all listed publicly.
  • No personally identifiable information is ever sent to the AI provider.
  • Deletion requests go to a person, not a queue: jkorwin@algebro.ai.

Who processes student data

Algebro runs on five third-party providers. No other company receives student data, and none of them may use it for anything beyond providing their service to Algebro.

Supabase

Primary database. Holds the educational records: student names, usernames, progress, scores, and answers. Hosted in the United States (us-east-1).

Clerk

Authentication. Holds usernames, password hashes, and session tokens. Student accounts have no email address attached.

Vercel

Web hosting and CDN. All platform traffic passes through Vercel infrastructure.

OpenAI

Powers the AI tutor and quiz feedback. Receives math problems, student answers, and lesson context only. No names, usernames, emails, or other personally identifiable information is ever sent. API data is not used to train OpenAI models.

Stripe

Payment processing for parent subscriptions only. No student, teacher, or school account data touches Stripe.

The full list, including exactly what data each provider receives, where it is processed, and links to each provider's data processing and security documentation, is on our Subprocessors page. We give advance notice before adding a subprocessor or changing what one does. If your district needs to be on that notice list, email me and I'll add you.

FERPA and COPPA posture

Student accounts are username-only. We collect a student's first name, last name, username, and password. We do not collect student email addresses, phone numbers, or physical addresses, and we do not condition participation on providing more information than that.

When a school or district uses Algebro, we operate as a “school official” with a legitimate educational interest under FERPA's school-official exception (34 CFR § 99.31(a)(1)). Education records remain the property of the school or district, and we use them only for the purposes the school authorizes.

For students under 13, school-created accounts rely on COPPA's school consent exception (16 CFR § 312.5(c)(4)): the school consents on behalf of parents, for educational purposes only. Parent-created student profiles rely on direct verifiable parental consent instead. Either way, we comply with Florida's student privacy law (FSOPIPA, Fla. Stat. § 1006.1494): no targeted advertising, no profiling outside K-12 purposes, no selling or renting student information.

The complete details, including retention periods and parental rights, are in our Privacy Policy.

Security overview

  • Authorization on every request. Every read and write of user data is authorized server-side in application code. Teachers can see only their own classes; students can see only their own work.
  • Deny-all row-level security. The database enforces deny-all row-level security policies. No browser or client ever queries the database directly; all access goes through server-side code, so a compromised or modified client still cannot read another user's rows.
  • Encryption. All traffic is encrypted in transit (HTTPS/TLS) and data is encrypted at rest in the database.
  • Passwords. Handled by Clerk, never stored in plain text, never visible to Algebro.
  • No analytics on student surfaces. Web analytics load only on public marketing pages and adult (teacher, parent, admin) dashboards, never on student-facing pages.
  • Security audit. I ran a full security audit of the platform in June 2026 and applied its fixes.

If you believe you have found a security issue, email jkorwin@algebro.ai and I will respond promptly.

Rostering and single sign-on

Clever

Live. Students and teachers can sign in with Clever today, and class rosters sync from Clever sections. Available through the Clever Library.

ClassLink

In certification. ClassLink single sign-on is built and is going through ClassLink's certification process now.

Google Classroom

Planned. Teacher sign-in with Google and roster import from Google Classroom are on the roadmap, pending Google's OAuth verification of our app.

If your district uses a rostering setup not listed here, email me. Manual class setup with teacher-generated join codes works everywhere without any integration.

Google OAuth client IDs for district admins

Coming after Google verification.

Once Google finishes verifying our OAuth app, this section will list the exact OAuth client IDs and scopes so your Google Workspace admin can allowlist Algebro before teachers connect their accounts. If you need this information sooner, email jkorwin@algebro.ai.

Data deletion and privacy requests

Schools, districts, and parents can request deletion or export of student data at any time. On a verified request, I delete the covered student information within a reasonable time, subject only to records the law requires us to keep. When a district tells us a student is no longer enrolled, the same deletion applies.

I also sign district data privacy agreements. Send yours over, or ask for our documentation, and you will be dealing with me directly rather than a legal inbox.

Algebro LLC

See also our Privacy Policy, Subprocessors, and Terms of Service.

Algebro for Districts | Student Data Privacy and Security | Algebro