Data Handling & Privacy
Last updated: June 2026
What NOVA+ Will Collect in Production
When deployed to a district, NOVA+ will collect only the minimum data necessary to deliver instructional continuity services:
- Student learning records — mastery levels, session history, and quiz responses, stored in a school-controlled namespace partitioned per district.
- Accommodation delivery logs — timestamped records of which IEP/504 accommodations were active during each session, as required by IDEA.
- Attendance event data — received via SIS webhook to trigger Catch-Up Briefings; used transiently and not stored beyond the session.
What NOVA+ Does Not Collect
NOVA+ is built around a minimum-data principle. The following categories are never collected in any deployment:
FERPA Compliance
NOVA+ will operate as a School Official under FERPA (20 U.S.C. § 1232g). Student education records remain under the exclusive control of the school district at all times. NOVA+ will not sell, share, aggregate, or use student data for any purpose outside of instructional delivery for the contracting district.
COPPA: If a district deploys NOVA+ to students under 13, the district is responsible for obtaining appropriate parental consent under COPPA. NOVA+ will not collect data from students under 13 without district-verified consent on file.
IDEA Accommodation Logging
The NOVA+ Access module will create session-level accommodation delivery logs that distinguish mandated IEP tools from student-elected supports — the exact documentation IDEA requires. These records will be retained for the duration of the district's agreement and deleted upon contract termination or at the district's written request.
The dual-key architecture separates the legal accommodation key (IEP/504-mandated) from the agency key (student-elected supports), each with an independent audit trail. This ensures the legally required IEP log cannot be conflated with general accessibility settings the student chose independently.
Data Storage & Security
- All data in transit encrypted with TLS 1.3.
- Each district's student data stored in a logically isolated namespace — no co-mingling across districts.
- Server-side AI proxy — the Claude API key is never exposed to the browser.
- No student data is used to train AI models, by NOVA+ or any third-party processor.
- Infrastructure hosted on Railway (US region). District data does not leave the United States.
Third-Party Services
NOVA+ uses a small number of sub-processors. Each is disclosed below with the data they access and why:
| Service | Purpose | Student data exposure |
|---|---|---|
| Anthropic (Claude API) | AI content generation for Catch-Up Briefings and learning plans | Session context only. Anthropic does not use API inputs to train models. Anthropic Privacy Policy → |
| Railway | Cloud hosting and deployment | Encrypted at rest. Railway has no access to student-level records. |
| Google Fonts | Typography (Poppins, Lora fonts) | None — font files load from Google CDN. No student data is transmitted. |
Demo Mode
The public demo at nova-plus.org uses entirely simulated data: fictional student names, synthetic academic records, and placeholder accommodation logs. No real student, staff, or district information is collected, processed, or stored at any time. All demo state resets on page reload.
The demo represents a conditional prototype. The first live deployment is planned for Fall 2026 at Opportunity High School, Marshall Public Schools. No students are currently enrolled and no district data agreements are in effect.
Data Deletion
Districts may request deletion of all student data at any time by written request. All data associated with the district will be permanently deleted within 30 days of the request or contract termination, whichever comes first. Individual student deletion requests received from a district will be honored within 10 business days.
Contact
Questions about data handling, FERPA requests, IDEA documentation, or security disclosures:
Jason Raddatz · Founder, NOVA+ · Marshall, Michigan