Trust & Security

Last updated: August 12, 2026

This page is for school and district administrators evaluating Lesson Maker Pro. It describes what data the platform handles, where that data goes, and how it is protected. If you need something we have not covered here, contact us and we will get you an answer.

At a Glance

  • Built for teachers. There are no student accounts, no rosters, and no student logins.
  • Student activity sessions are anonymous: names students type are never stored, and analytics are off on student screens.
  • We do not need student data to work, and we tell teachers not to upload it.
  • Teachers own the content they create.
  • Data is encrypted in transit. Our database provider encrypts data at rest.
  • Payments are handled by Stripe. Card numbers never touch our servers.
  • Images you upload in conversations are stored in a private bucket and served through short-lived signed links.
  • We do not sell personal information.
  • A data processing agreement is available on request.

What We Collect

  • Teacher account information: email address and password.
  • Content teachers create: lesson plans, unit plans, materials, presentations, and chat conversations with the teaching assistant.
  • Files teachers upload to the teaching assistant, such as images of existing worksheets.
  • Billing details for paid plans, processed by Stripe.
  • Product usage data to understand what is working.

Visitors can try the product without an account. Those sessions use an anonymous identifier that is not tied to a name or email address.

What We Do Not Collect

  • Student accounts. Students never log in to Lesson Maker Pro.
  • Student rosters or gradebooks.
  • Student records. The product does not ask for them and does not need them to function.
  • Student personal information. Student activity sessions are anonymous by design.

Student Data, FERPA, and COPPA

Lesson Maker Pro is built for teachers. There are no student accounts and no rosters. Some activities a teacher creates, like digital experiences and escape room sessions, include a student-facing screen: students join with a short code on their own device, with no login and no account.

Here is exactly what happens with student information in those sessions:

  • Students enter a first name so their teacher can see their progress live. That name is displayed to the teacher during the session and is never saved to our servers, our database, or our analytics.
  • Our analytics and advertising tools are switched off entirely on student screens. Session identifiers exist only to run the activity itself.
  • When a student finishes, we record an anonymous completion code and score statistics, with no name and nothing the student typed.
  • The "mission report" a student can save is created on the student's own device and is never uploaded to us.

Because we do not collect or keep student personal information, schools can use these activities without handing us student records. We instruct teachers not to include student names or other personally identifiable student information in prompts, uploads, or lesson content, and we never use anything from a student session for advertising or to train AI models.

If your district has specific compliance requirements, contact us through the district inquiry form and we will work through them with you.

How AI Generation Works

Lesson Maker Pro is not a passthrough to a chatbot. When a teacher generates a lesson plan or material, we build the request: we ground it in our database of over 450,000 verified state and national standards, apply grade and subject constraints, and define the structure the output must follow. Results then run through our own formatting and quality checks before the teacher sees them.

The generation step itself runs on OpenAI models, with Anthropic as a fallback when OpenAI declines a request. We do not permit these providers to use Lesson Maker Pro content to train their models. OpenAI data sharing is disabled, and Anthropic does not use inputs or outputs from its commercial API for training by default.

AI-generated content can contain mistakes. We tell teachers to review everything before using it in a classroom.

Security Practices

  • All traffic is encrypted in transit with TLS.
  • Our database provider encrypts data at rest.
  • Database access is controlled with row-level security, so each account can only read its own data.
  • Images you upload in conversations are stored in a private bucket. They are never publicly reachable and are served through signed links that expire after one hour.
  • All protected API routes go through centralized authentication.
  • Google account access uses the narrowest OAuth scopes available: per-file Drive access, plus Classroom access limited to listing your classes and posting the coursework, classwork materials, and topics you choose to send. We can only see files the app itself creates, and we never read student data.

Subprocessors

We use the following service providers to run Lesson Maker Pro. Each one receives only what it needs for its job.

ProviderPurposeData involved
SupabaseDatabase, authentication, and file storageAccount email, created content, uploaded files
VercelApplication hosting and site analyticsRequest data, anonymized page analytics
OpenAIAI content generationPrompts, content being generated or edited, uploaded files used in generation
AnthropicBackup AI provider for lesson generationLesson prompts, only when the primary provider declines a request
StripePayment processingPayment details and billing email. Card numbers never touch our servers.
ResendTransactional and product emailEmail address
PostHogProduct analytics and error reportingUsage events, error reports, and teacher session replays. No tracking cookies. Never loads on student screens.
GoogleOptional export to Drive, Docs, Slides, Forms, and Classroom; image searchExported files go to the teacher's own Google account, only after they connect it. Image searches send the search text only.
CloudConvertFile format conversion for presentation PDF exportThe presentation file being exported
Unsplash / PexelsLicensed stock images for presentationsImage search text only

Retention and Deletion

  • Teachers can delete individual lesson plans, materials, and conversations from within the app at any time.
  • Student session records are deleted 14 days after creation. Anonymous completion records (no names) are deleted after 12 months. Names students type to join a session are never stored.
  • Deleting a conversation also deletes any images uploaded to it from our storage.
  • Account deletion is handled by request: email support@lessonmakerpro.com and we will delete the account and its data.
  • Created content can be exported as PDF, Word, or PowerPoint files, or sent to Google Drive, Docs, Slides, Forms, or Classroom.

For Districts

A data processing agreement is available on request. We are also happy to complete security questionnaires and answer procurement questions directly.

Start with the district inquiry form or email sales@lessonmakerpro.com.