Privacy
Built like a teacher’s private notebook.
Last updated: July 16, 2026 · v1.3 (alpha)
Plain English first, lawyer language second. Greta is a personal tool teachers buy for themselves. Your notes are yours. We’ll never sell student context, train models on your data, or hand it to anyone you didn’t direct it to.
The five commitments
- Recording is a button.Greta only listens when you press record. There is no ambient mic, no background capture, no “always-on” mode.
- Drafts stay drafts. Nothing leaves Greta — no email, no parent message, no shared document — until you click send. You review every draft.
- No ads. Ever. Student context will never be used for advertising or sold to anyone, full stop.
- No model training. Your notes, voice memos, and drafts are not used to train AI models. The API-provider terms and dates are listed in the service-provider section below.
- Records requests.From Settings → Account data, Greta can prepare a JSON copy of your account records or begin full account deletion. You can also email privacy@teachgreta.com for privacy help. You can delete individual kids, notes, and class memories from live storage yourself.
The trust page gathers these commitments, the security controls, and the service-provider details in one place.
What we collect
From you, the teacher
- Email address and password (for login)
- Optional: grade band, school name (so Greta can write in your context)
- Voice memos and text notes you record
- Optional mobile phone number and text-message consent when you connect Greta’s text-message capture channel
- Drafts Greta generates for you
- Photos you capture of student work (only if you opt in per kid)
- Optional connector reads you approve, such as Gmail sent-message style signals, Microsoft connector status, or Google Drive documents you choose to summarize
About students
Only what you tell Greta. Greta’s schema actively rejects sensitive fields:
- No Social Security Numbers
- No full dates of birth (month + day only, for the birthday card)
- No government IDs or student ID numbers
- No free-text medical diagnoses (use your district’s SIS for that)
- No financial information
Greta rejects SSNs, full dates of birth, and student ID numbers as data fields. Greta is for the kind of context teachers already keep in personal notebooks: who needs a gentle check-in, who had a breakthrough, what to mention at conferences.
How we use it
- To run Greta for you — turning your voice memos into kid cards, drafting emails, generating sub binders, and surfacing context when you ask.
- To send you the product emails you opt into (weekly summaries, conference reminders). Never marketing emails about other products.
- To improve Greta’s reliability and prevent abuse (anonymous error logs, no content).
We do not use it to train AI models, sell to advertisers, share with data brokers, or hand to law enforcement absent a valid court order.
Who we share it with
We use the service providers below only to operate Greta. They may not use mobile information, SMS opt-in data, or messaging consent for marketing or promotional purposes.
- Anthropic — Claude drafts and other language-model features. Data touched: Teacher-provided notes, memos, and the minimum context needed for the requested draft. Per Anthropic's commercial documentation, as of 2026-07-15, API inputs and outputs are not used to train models by default. Verified 2026-07-15. Vendor documentation.
- OpenAI — Whisper transcription and text embeddings for search. Data touched: Voice recordings for transcription and the text needed to create search embeddings. Per OpenAI's API data-controls documentation, as of 2026-07-15, API inputs and outputs are not used to train models by default; default abuse-monitoring logs may be retained for up to 30 days. Verified 2026-07-15. Vendor documentation.
- Convex — Database, file storage, and backend functions. Data touched: Teacher account data, notes, records, drafts, and files stored for the teacher. Convex is an infrastructure provider; encryption and storage controls are attributed to the provider rather than presented as a Greta-operated facility. Verified 2026-07-15. Vendor documentation.
- Vercel — Web application hosting and delivery. Data touched: Requests needed to serve the Greta web application. Vercel hosts and delivers the web application; infrastructure encryption is attributed to Greta's infrastructure providers. Verified 2026-07-15. Vendor documentation.
- Twilio and participating mobile carriers — Optional SMS/MMS capture, verification, and compliance messages. Data touched: Verified teacher phone number, message text, images, delivery metadata, and consent signals. SMS/MMS content and phone numbers pass through Twilio and downstream carriers; carrier retention, inspection, and jurisdictional handling are outside Greta's control. Verified 2026-07-15. Vendor documentation.
- Composio — Optional Gmail, Calendar, Drive, Outlook, and OneDrive connector actions. Data touched: Only the connector context and permissions needed for the action a teacher requests. Connector data passes through Composio only when a teacher connects a service and requests that action; Greta does not require connectors for core use. Verified 2026-07-15. Vendor documentation.
- Learning Commons Knowledge Graph — Optional standards grounding for class/week planning context. Data touched: Structured academic standard codes plus subject, jurisdiction, and grade-band metadata; no raw classroom notes, student names, or parent communications. Greta sends only structured standard lookups. Learning Commons' public privacy documentation describes MCP integrations as receiving minimal query parts or parameters rather than the entire prompt, input, or query. Verified 2026-07-16. Vendor documentation.
- Postmark — Inbound email capture. Data touched: Inbound message metadata and message content sent to a teacher's Greta capture address. Postmark receives inbound email needed for the capture path; Greta records provider authentication results and avoids putting raw message bodies in application logs. Verified 2026-07-15. Vendor documentation.
- Sentry — Error tracking and performance monitoring. Data touched: Scrubbed error metadata, stack traces, and performance measurements. Greta scrubs classroom content before Sentry receives error events. Verified 2026-07-15. Vendor documentation.
- PostHog — Privacy-conservative product analytics. Data touched: Allowlisted operational fields such as source, surface, status, counts, booleans, and latency. Greta sends only allowlisted operational fields; autocapture and session replay are off. Verified 2026-07-15. Vendor documentation.
We use these providers only to operate Greta. We don’t share your data with marketing networks, analytics resellers, or other recipients for their own marketing or promotional purposes.
Text-message privacy
Greta’s text-message capture channel is optional. If you turn it on, Greta collects the mobile number you enter, the time you verified it, your messaging preferences, and the messages or photos you choose to send. Greta uses this information only to verify your number, receive teacher-initiated classroom captures, send automated confirmations or clarification questions, provide support and compliance replies, and send an optional daily reminder if you separately enable one.
Message frequency varies with your use of Greta. If you enable reminders, Greta sends no more than one scheduled reminder per day. Message and data rates may apply. Reply STOP to unsubscribe or HELPfor help. You can also disconnect text messaging from Settings → Connections. See the Text messaging terms for program details.
Greta does not sell, rent, or share your mobile phone number, SMS opt-in data, or messaging consent with third parties or affiliates for their marketing or promotional purposes. We disclose mobile information only to service providers and mobile carriers that help us operate the messaging service, when you direct us to, or when the law requires it. Those providers may use the information only to provide their services to Greta.
Optional connectors
You can use Greta fully without connecting Gmail, Calendar, Drive, Outlook, or OneDrive. If you do connect them, Greta reads only the context you ask it to read. Conference calendar events and invite emails are created or sent only after explicit teacher confirmation. Connector actions are logged so you can see what Greta accessed or changed.
- Gmail sent mail: used to learn your parent-email writing style. Greta stores a compact style summary, not raw email bodies by default.
- Gmail thread context: used only when you ask Greta to read a specific parent thread for drafting context.
- Google Drive: used only for folders or files you choose to list or summarize.
- Google Calendar: used to import conference events and, when you confirm, create conference events managed from Greta.
- Outlook: connected for account context and future teacher-approved invite sending after Greta pins the exact Composio tool and review flow.
- OneDrive: connected as a read-only account foundation. OneDrive file reads should be enabled only after Greta pins the exact Composio tool and review flow.
- Learning Commons Knowledge Graph: when standards grounding is enabled, Greta resolves structured academic standard codes for class/week planning context. It receives standard codes with subject, jurisdiction, and grade-band metadata — not raw classroom notes, student names, or parent communications. This context is not for grading, placement, or formal student evaluation. Learning Commons data is credited under its CC BY 4.0 license.
You can disconnect a connector at any time. When you disconnect, you can keep what Greta already learned as archived context or ask Greta to forget connector-derived summaries where possible.
Where it lives
Greta uses infrastructure providers with encryption at rest and in transit. Authentication uses the Convex Auth Password provider. Greta’s API keys stay server-side, and signed URLs protect access to stored media.
How long we keep it
- While your account is active: as long as you keep it.
- After an individual kid, note, or class-memory deletion, the selected record is removed from live storage. Provider backups follow a retention window of up to 30 days.
- For full account deletion, use Settings → Account data or email privacy@teachgreta.com with a verified request; Greta will confirm the process.
- Anonymous error logs: 90 days.
- Billing records (legal requirement): 7 years.
Your rights
- Request a JSON copy of your account records from Settings → Account data, or email privacy@teachgreta.com for privacy help.
- Delete any kid, any note, any draft, anytime.
- Request full account deletion from Settings → Account data, or email privacy@teachgreta.com with a verified request.
- Email privacy@teachgreta.comwith any question and we’ll follow up.
California, EU, and UK residents have additional rights (access, rectification, portability, objection). Email us and we’ll honor them within the legally required timeframes.
Children
Greta is for teachers, not students. We don’t collect data directly from children. The notes teachers keep about students in Greta are the teacher’s own observational records — see our FERPA page and trust page for the full picture.
Changes
If we change anything material, we’ll update the date at the top of this page. We won’t apply changes retroactively to data we already hold.
Contact
Privacy questions: privacy@teachgreta.com. General: hello@teachgreta.com.