Wanadel · Trust

Student data privacy

Wanadel (Wanadel) is a study app students choose to love — and schools can trust. This page says, in plain language, exactly what we collect, what we never do, and who touches the data. It is written to answer the questions in your district DPA or university vendor review before you ask them.

What we never do

How school dashboards work

Teachers see progress for the students in their own classes — the same relationship FERPA's school-official provision covers. School administrators see aggregates only, and any breakdown covering fewer than 10 students is suppressed automatically in our database layer, not in the browser. Reports that leave the institution are de-identified aggregates, always.

What we collect

CategoryDataWhy
AccountEmail, display name, school (self-reported or via your institution), timezone, persona preferenceSign-in, personalization
Study contentFlashcards, notes, study guides, uploaded materials the student creates or importsThe product itself
Study activityReview ratings and schedule (FSRS), session times, quiz/test scores, focus sessions, streaksProgress, spaced repetition, dashboards
Product eventsFirst-party product events support account progress and reliability. Only when a student allows it, a separate anonymous PostHog subset contains feature and redacted error events, never account identity, study content, or free text.Reliability + aggregate analytics
AI conversationsMessages the student sends the AI study assistantAnswering the student; auto-deleted on account deletion

Retention & deletion

Subprocessors

Every service that can touch student data, and what it does:

ProviderPurposePosture
Supabase (AWS, US)Database, authentication, file storageSOC 2 Type II, HIPAA-capable
AnthropicAI responses (Claude API)No training on our users’ data under commercial API terms; SOC 2
DeepgramOptional voice features (speech-to-text / text-to-speech)Processed per request
ResendTransactional email (welcome, account)Email address only
Expo (EAS)App build + update deliveryNo student data
PostHogOptional anonymous product-use and redacted error reportsNo account identity, study content, replay, or advertising use

We give institutions 30 days' advance notice before adding a subprocessor that would touch student data. To ask about subprocessor change notifications, use our contact form.

Security

Encryption in transit (TLS) and at rest; row-level security on every table; role-gated access enforced in the database; private storage buckets with signed, expiring URLs; least-privilege service keys that never ship in the app. Vulnerability reports: use our contact form (see security.txt).

For your procurement team

Last updated July 2026. Questions: use our contact form.