Privacy Policy
Plain-language, minimal-collection, education-first. Last updated July 2026.
What we collect
LewisLab collects the minimum needed to run a learning platform: your email, display name, and role (student or teacher) at registration; the structures you build and save; assignment submissions and attempt outcomes used for progress tracking; and per-user preferences (theme, motion, autosave cadence). Guests can use the core tools with no account at all, guest work stays in your browser's local storage until you choose to sign up and claim it.
What we never do
We do not sell personal data, run third-party advertising, or use student work to train external AI models. Analytics used to improve the platform (for example, which chemistry mistakes are most common) are aggregated and de-identified.
Student privacy (FERPA)
Classroom features are designed around FERPA principles: teachers see only their own classes; students see only their own records; educational records are used solely to provide the service; and school-directed deletion requests are honored. Role changes, score overrides, and account unlocks are captured in an append-only audit log.
Your rights (GDPR)
You can access, correct, or export your data at any time from Settings, and you can delete your account, including saved structures, submissions, and progress records, from Settings → Account. Deletion is permanent and takes effect immediately for personal data, with backups purged on a rolling schedule.
Security
Passwords are stored only as salted bcrypt hashes. Sessions live in httpOnly, Secure, SameSite cookies, never in browser storage readable by scripts. All traffic is encrypted in transit, inputs are validated on every request, and repeated failed sign-ins trigger a temporary account lockout.
Contact
Questions about this policy or a data request? Reach the maintainer through the contact details on the About page and we will respond promptly.