Privacy Policy
Last updated August 17, 2026 ยท Pilot-program draft โ the practices described here are implemented and verified; final legal wording is pending review by counsel.
The short version
PodiumAI turns a student's practice speech into text as they speak, has an AI judging panel score it against their league's rules, and keeps only the text, numbers, scores, and written feedback. The voice itself is never recorded or stored โ not by us, and not as a recording anywhere. Students sign in with a username, never an email address. There are no ads, no trackers, no marketing profiles, and no selling or renting of data โ ever. Coaches see a student's work only when the student chooses to share it, and the student can take that back at any time.
Who this covers
PodiumAI is a speech-and-debate practice service provided to school and club programs for students roughly ages 10โ18, plus their coaches, school administrators, and parents. There is no open signup: schools are onboarded by the operator, coaches are invited by their school, and students join only with a short-lived invite code from their coach (or are added by the coach directly). This policy covers the PodiumAI application and this website. Each participating school's service agreement identifies the contracting parties; questions can always start with your school's program administrator.
What we collect, exactly
Student accounts: a display name, a username, a birthdate, and the team they belong to. The birthdate exists to enforce the under-13 parental-consent lock and is stored encrypted, as is the display name. Students never provide an email address at any age โ internally their login is a synthetic identifier on a reserved, non-routable domain, so no student mailbox exists anywhere in the system.
Adult accounts (coaches, school administrators): name, work email address, and a password stored only as an irreversible hash.
Parent contact: for students under 13, the coach provides a parent or guardian's email address โ students never enter it themselves. It is stored encrypted and used only for the consent and deletion round-trips described below. When a parent responds to a consent request, we keep evidence of that decision (timestamp, IP address, browser identifier), sealed and encrypted.
Practice content: the live transcript of what the student said; debate speeches and cross-examination exchanges; the AI judges' scores, grades, written feedback, and debate ballots; and coach feedback notes on shared reports. Transcripts, debate text, and coach notes are all encrypted at rest.
Delivery measurements โ numbers, never audio: speaking time, words per minute, filler-word counts, pause counts and lengths, and pitch/loudness variation figures (for example, "pitch range: 5 semitones") computed while the student speaks. If a school enables optional camera coaching (currently offin production), the video is analyzed entirely on the student's own device and never transmitted; only a handful of numeric posture/eye-contact aggregates would be saved.
School configuration: league rulesets, rubrics, topics, and judging-philosophy text that schools configure or import. If a school uploads a rulebook document, its text is processed once by our AI provider to draft the ruleset and is not retained as a document.
Operations: an append-only audit log of sensitive actions (sign-ins, consent changes, shares and revocations, coach report views, roster and ruleset changes โ recorded as actions and account IDs, never content); per-school usage counts and AI cost totals; short-lived rate-limiting counters; and a single session cookie. Server error logs are structured to contain no student content, no names, and no free-text.
Things we relay but do not keep: messages typed into the help assistant are answered from a fixed knowledge base and are not stored; submissions to the public contact form are emailed to the operator and not written to our database.
What never exists on our side
No audio or video recordings, by architecture.The microphone stream travels directly from the student's browser to our speech-to-text provider and is transcribed in real time; the audio never touches PodiumAI's servers, and PodiumAI has no upload path for it. Our browser security policy technically prevents the app from sending audio anywhere else, model-training on our audio is disabled at the provider (a setting our automated test suite permanently enforces), and an automated test verifies on every release that zero audio bytes reach our servers.
Also not present anywhere: student email addresses, advertising, third-party analytics or tracking scripts, cross-site cookies, marketing profiles, sale or rental of data, student photos, or location data. The only cookie is the session cookie that keeps you signed in; the only things kept in your browser are small preferences like sidebar state.
How the AI works with student data
When a speech is judged or a debate round is played, the transcript and the numeric delivery measurements are sent to our AI provider (Anthropic) with the league's rules, and the model returns scores, feedback, or the opponent's next argument. Overall grades are then computed by fixed arithmetic in our own code from the category scores โ the AI never does the math. Our API traffic is not used to train the provider's models. AI feedback is practice guidance: it is designed to be encouraging, honest, and age-appropriate, and the exact rule text and prompt version used for every report are stored permanently so a past report can never silently change meaning.
Who can see what
Students own their work. A coach can read a practice report or debate ballot only after the student shares it; the student can revoke that share at any time, and every coach view is written to the audit log. When a student shares, the coach receives a notification email that deliberately contains only the student's name and the event type โ never grades, topics, or content, which stay inside the app. On a shared report the coach may leave feedback notes, visible to the student.
School administratorssee aggregate activity for their school โ team sizes, session counts, staff names โ never student work or transcripts. If an administrator also coaches a team, they see that team's shared reports under exactly the same student-controlled sharing rules as any coach. The platform operator's management view is limited to school-level usage counts and costs; it contains no student content. These separations are enforced by the database itself (row-level security), not just by application screens.
Children under 13 โ parental consent (COPPA)
For a student under 13, nothing is collected until a parent approves.The coach provides the parent's email; the parent receives a private link describing exactly what PodiumAI collects and doesn't; and until they approve, the student's account exists but every collection point is locked โ no practice session can start, no transcription can run, no judging can happen. This lock is enforced on the server at every entry point, not just hidden in the interface.
The same private link remains the parent's standing portal: they can revoke consent at any moment (practice locks immediately, and anything in flight is discarded rather than saved), approve again later, or permanently delete everything. If a birthdate correction reveals a student is younger than recorded, collection re-locks automatically. We never require more information from a child than the service needs โ and participation is never conditioned on providing more.
Parents' and schools' rights
Review: a parent can see their child's work by reviewing it with their child, or request a copy of the child's stored information through the school or the operator. Correction: display names can be corrected in-app; birthdate corrections run through the coach so the age lock stays honest. Revocation: consent can be withdrawn at any time from the parent portal. Deletion: described below โ available to parents directly and to school administrators for parents who contact the school instead.
Deletion & retention
Data is kept while the account is active in its school program. A parent can permanently erase a child's account โ transcripts, reports, ballots, progress, everything โ from their consent link, confirmed by a second emailed link that expires in 30 minutes. A school administrator can perform the same erasure from the team roster (with a type-the-name confirmation) for any student on their team, which is also the path for students 13 and older. Erasure is immediate in live systems; encrypted backup copies rotate out within roughly 30 days. What remains afterwards is a single anonymous log line proving the deletion happened โ it contains no personal information.
Short-lived records expire on their own: student invite codes within hours, password recovery codes in 15 minutes (stored only as hashes), consent links after 60 days (renewable by the coach), and rate-limit counters within minutes to hours. Audit log entries are retained for accountability and contain no content. When a school's participation ends, the school may request deletion of its program's data.
How data is protected
Names, birthdates, parent emails, consent evidence, transcripts, debate text, coach notes, and team names are encrypted at rest (AES-256-GCM) with the key held outside the database โ a stolen copy of the database or its backups alone is unreadable. Access rules are enforced by row-level security in the database itself: one student's rows simply do not exist for anyone else's queries, and the application's own database role cannot bypass those rules. The few privileged operations that must cross those lines run through a short, fixed allowlist, and every such use is audited.
In transit, everything is TLS-only with strict transport security; the database and cache have no public network endpoints at all. Passwords are stored with scrypt (irreversible). Session cookies are secure, HTTP-only, and same-site. Sign-in, judging, token, consent, and erasure endpoints are all rate-limited. Backups are encrypted and run daily. If a breach affecting personal information ever occurred, we would notify affected schools and parents without undue delay, as required by law (including Florida's Information Protection Act).
Service providers (all of them)
Four processors, each receiving the minimum needed to do its one job โ none may use student data for their own purposes:
- Deepgramโ live speech-to-text (the student's audio is transcribed in real time; PodiumAI never receives or stores the audio, and training on it is disabled) and the AI opponent's synthesized voice.
- Anthropic โ the AI judging panel and debate opponent read transcripts, delivery numbers, and league rules to produce scores and arguments; API traffic is not used to train models.
- Resend โ delivery of transactional email only: parent consent and deletion links, staff invitations, share notifications, and contact-form relay.
- Railway โ cloud hosting for the application, database, and cache, with encrypted storage and private networking.
There are no analytics providers, no advertising partners, and no data brokers. We disclose personal information beyond these processors only if required by law, and would notify the school unless legally barred.
Schools, FERPA, and agreements
When PodiumAI is adopted by a school or district, we operate as a service provider to that school: student records are processed only to provide the service, under the school's direction, consistent with FERPA's school-official framework. A data-processing agreement with each school documents this; the inventory in this policy is the complete enumeration of what that agreement covers.
Changes & contact
If this policy changes in a way that matters, participating schools are notified before the change takes effect, and the date above always reflects the current version. Questions or requests: start with your coach or your school's program administrator โ they can see account status, resend consent emails, correct records, and reach the operator directly for anything else, including data requests.
A dedicated privacy-contact mailbox for direct parent inquiries will be published here before the pilot begins.