Wanadel · Trust
Student data privacy
Wanadel (Wanadel) is a study app students choose to love — and schools can trust. This page says, in plain language, exactly what we collect, what we never do, and who touches the data. It is written to answer the questions in your district DPA or university vendor review before you ask them.
What we never do
- We never sell or share identifiable student data. Not to advertisers, not to brokers, not to anyone. What we sell schools is software and aggregate reporting.
- No advertising to students and no profiling for any non-educational purpose.
- No AI training on student data. Student content sent to our AI provider is governed by commercial API terms that prohibit training on it.
- No advertising or replay tracking. First-party analytics are PII-free by design. Optional PostHog analytics begins only after a student allows it and receives a narrow anonymous event list, never study content or account identity.
How school dashboards work
Teachers see progress for the students in their own classes — the same relationship FERPA's school-official provision covers. School administrators see aggregates only, and any breakdown covering fewer than 10 students is suppressed automatically in our database layer, not in the browser. Reports that leave the institution are de-identified aggregates, always.
What we collect
| Category | Data | Why |
|---|---|---|
| Account | Email, display name, school (self-reported or via your institution), timezone, persona preference | Sign-in, personalization |
| Study content | Flashcards, notes, study guides, uploaded materials the student creates or imports | The product itself |
| Study activity | Review ratings and schedule (FSRS), session times, quiz/test scores, focus sessions, streaks | Progress, spaced repetition, dashboards |
| Product events | First-party product events support account progress and reliability. Only when a student allows it, a separate anonymous PostHog subset contains feature and redacted error events, never account identity, study content, or free text. | Reliability + aggregate analytics |
| AI conversations | Messages the student sends the AI study assistant | Answering the student; auto-deleted on account deletion |
Retention & deletion
- Students can delete their account in-app; deletion cascades through content, activity, analytics events, and files.
- Raw behavioral events are kept at most 13 months, then destroyed automatically. Long-term records are de-identified aggregates.
- On contract end, an institution's organizational data is purged or returned on request, with written confirmation.
Subprocessors
Every service that can touch student data, and what it does:
| Provider | Purpose | Posture |
|---|---|---|
| Supabase (AWS, US) | Database, authentication, file storage | SOC 2 Type II, HIPAA-capable |
| Anthropic | AI responses (Claude API) | No training on our users’ data under commercial API terms; SOC 2 |
| Deepgram | Optional voice features (speech-to-text / text-to-speech) | Processed per request |
| Resend | Transactional email (welcome, account) | Email address only |
| Expo (EAS) | App build + update delivery | No student data |
| PostHog | Optional anonymous product-use and redacted error reports | No account identity, study content, replay, or advertising use |
We give institutions 30 days' advance notice before adding a subprocessor that would touch student data. To ask about subprocessor change notifications, use our contact form.
Security
Encryption in transit (TLS) and at rest; row-level security on every table; role-gated access enforced in the database; private storage buckets with signed, expiring URLs; least-privilege service keys that never ship in the app. Vulnerability reports: use our contact form (see security.txt).
For your procurement team
- DPAs: we sign the SDPC National DPA v2 (Standard, incl. the Exhibit E General Offer) and state equivalents.
- HECVAT 4: completed workbook available on request.
- Security whitepaper and incident-response summary (72-hour breach notification): available on request.
- Accessibility: WCAG 2.1 AA self-assessed ACR (VPAT 2.5) available on request; third-party audit planned.
- All of it: use our contact form.
Last updated July 2026. Questions: use our contact form.