Trust & Security
This page is maintained by Docentia to answer common security and privacy questions about the platform. The statements below describe Docentia's current practices and platform capabilities. They are not independent legal verification or certification by a third party.
Privacy by design
Docentia is built around the idea that student learning data should be protected by default: collect only what is needed, limit access by role, encrypt data, and keep the student, parent, and educator in control.
Minimum data collection
We only ask for information needed to provide learning features and classroom management.
No advertising use
Student data is never sold or used to target advertising.
Role-based access
Students, teachers, district admins, and platform admins see only what their role requires.
Encrypted infrastructure
Data is encrypted in transit and at rest on our backend infrastructure.
Compliance and safeguards
Educational data stays educational
Docentia is designed to support FERPA-aligned educational data practices. Student information is used only to deliver learning and progress features within the platform. We do not sell student data, use it for advertising, or share it with unrelated third parties. For district deployments, we work with schools under terms that reflect a school official or educational-purpose relationship where applicable.
Built for grades 8–11, with young learners in mind
Docentia is primarily used by students in grades 8–11. For any student under 13, we follow applicable COPPA requirements and rely on the school or district to obtain the necessary parental consent and to manage age-appropriate access. We minimize the personal data we collect and only ask for what is needed to support the learning experience.
Working toward SOC2 examination
Docentia is in the beginning stage of SOC2 readiness and audit preparation. We are documenting controls, tightening access policies, and preparing for an independent SOC2 examination. This page will be updated as we complete milestones. SOC2 is a compliance framework, not a guarantee of security; we treat it as one part of our ongoing commitment to protecting student data.
Data is encrypted and access-controlled
Docentia encrypts data in transit and at rest. The platform uses authenticated sessions, role-based access control, and Row-Level Security (RLS) policies so users can only access the data they are authorized to see. Admin, teacher, and student views are separated by role, and sensitive operations are handled by privileged server-side code.
AI supports learning, not surveillance
Docentia uses AI to generate explanations, feedback, and adaptive practice recommendations. Student prompts and responses are processed to provide educational support, not to build advertising profiles or train unrelated models. AI-generated content is filtered for safety and age-appropriateness, and teachers and administrators retain control over classroom use.
Minimal cookies, clear choice
Docentia uses essential cookies to keep users signed in and to remember display preferences (like theme). We present a consent banner on first visit so visitors can choose between essential-only and all cookies. We do not use advertising or cross-site tracking cookies.
Access, correction, and deletion
Students, parents, and district administrators can request access to, correction of, or deletion of student data by contacting info@docentia.ai. We process requests in coordination with the school or district that owns the student relationship, because many records are managed under district agreements.
Shared responsibility
Docentia is hosted on the Lovable Cloud platform, which provides backend infrastructure, managed authentication, and security features. Docentia configures and operates the application layer on top of that platform. Security and privacy are a shared responsibility: Lovable Cloud manages the platform, while Docentia manages application permissions, data handling, and user-facing practices. The controls described on this page are implemented by Docentia in the application layer.
Request data deletion
Students, parents, teachers, and district administrators can request deletion of a Docentia account and its associated learning data. For district-managed students, we coordinate with the district that owns the student relationship before completing deletion.
Trust Center updates
Get an email when Docentia publishes material updates to compliance, security, or privacy practices. Low volume — only when this page materially changes.
Security contact form
Report a vulnerability, suspected incident, or privacy concern. The form goes to our security inbox at info@docentia.ai.
Trust center changelog
Material changes to our practices, controls, and this page.
July 2026 (later)
Added data deletion request form, cookie preferences page, downloadable PDF privacy policy, and a Trust Center updates email list.
July 2026
Added cookie consent banner, downloadable privacy policy, and a dedicated security contact form.
June 2026
Consolidated privacy and security inquiries to info@docentia.ai for a single point of contact.
May 2026
Published Trust & Security page covering FERPA-aligned practices, COPPA, SOC2 readiness, and encryption.
April 2026
Began SOC2 readiness engagement; started documenting controls and access policies.
Contact us
For privacy requests, security reports, or questions about this page, email us directly.
Privacy & security
Data access, correction, deletion, vulnerability reports, and incidents.
Last updated: August 2026. This page is a living document and will be updated as Docentia's practices and compliance posture evolve.