Privacy Policy

Last Updated: September 19, 2026

1. Introduction

PushPad is owned and operated by Cosaint, Inc., an Arizona corporation. This Privacy Policy explains how Cosaint, Inc., through PushPad, collects, uses, discloses, and safeguards information when educators and learners use our platform. References to "PushPad," "we," "us," or "our" mean Cosaint, Inc. operating through the PushPad brand.

PushPad is a supplemental learning tool. Educators create lesson pads and assign them to learners they invite. This policy applies to both educator accounts and learner accounts, including accounts for learners under 13, since PushPad creates and stores learner account data directly (see Section 6).

2. Information We Collect

2.1 Educator Account Information

  • Full name and email address
  • Password (hashed by Supabase Auth; PushPad never stores plaintext passwords)
  • Subscription tier, billing details processed by Stripe, and Stripe Connect payout information for sellers

2.2 Learner Account Information

Learner accounts are created only when an educator sends an invitation and it is accepted. PushPad does not allow learner self-registration or self-enrollment. When a learner account is created, PushPad collects and stores:

  • A learner-chosen or educator-assigned username and display name
  • A system-generated internal identifier (in the form learner_[username]@pushpad.internal) used only to operate account authentication; this is not a real, reachable email address and is never used to contact the learner
  • A 6-digit PIN, hashed before storage, used in place of a password for learner sign-in
  • The identity of the inviting educator
  • Assignment, attempt, score, and progress data tied to the learner's account

This is a direct collection of information from and about the learner by PushPad, not solely by the educator. Because of this, PushPad, not only the inviting educator, has direct compliance obligations for learner accounts, including for learners under 13. See Section 6.

2.3 Content Created On The Platform

  • Lesson pads, courses, units, and lessons created by educators
  • Media files educators upload to the media library (images used in lesson pad content)
  • Learner-submitted answers and work product for assigned lesson pads

2.4 Usage Data

  • Pages visited and features used
  • Pad completion, attempt history, and time spent per section
  • Browser type, device information, IP address, and approximate location

2.5 Payment Information

  • Payment card information (processed by Stripe; PushPad does not store full card numbers)
  • Billing address, transaction history, and marketplace purchase records
  • Payout details for educators selling pads on the marketplace

3. How We Use Information

  • Provide the Service: create and manage accounts, deliver assignments, grade submissions, process payments
  • PushPad Generation and Grading: process educator inputs through Anthropic's Claude models to generate lesson pad content, and grade learner submissions server-side against stored rubrics and correct answers
  • Course Outline Assistance: process educator course-outline requests through OpenAI's API for structured outline generation only
  • Notifications: in-platform notifications for both educators and learners; account-critical emails (password reset, security alerts, payment receipts) to educators; PushPad does not send marketing email to learner accounts
  • Analytics: understand platform usage and improve features
  • Security: detect fraud, abuse, and unauthorized access
  • Legal Compliance: comply with FERPA, COPPA, applicable state student-data-privacy laws, and other regulations

We do not use learner data to build advertising profiles, for targeted advertising, or to train PushPad's own AI models. Learner data is used only to operate the educational service the educator assigned.

4. Third-Party Services

4.1 Supabase (Database, Authentication, and File Storage)

  • Stores account data, lesson content, and uploaded media files
  • Handles authentication for both educator and learner accounts
  • Subject to Supabase's Privacy Policy and Data Processing Agreement

4.2 Anthropic Claude (Lesson Pad Generation and Grading)

  • Generates lesson pad content from educator inputs
  • Grades learner submissions against educator-defined rubrics and correct answers
  • Learner submissions sent for grading contain only the submitted answer text and the grading rubric; no learner name, internal identifier, or other persistent identifier is included
  • Subject to Anthropic's Privacy Policy and Commercial Terms; data retained per Anthropic's standard API retention policy

4.3 OpenAI (Course Outline Generation)

  • Used only to help educators generate structured course outlines
  • Subject to OpenAI's Privacy Policy and API data retention terms

4.4 Stripe and Stripe Connect (Payments)

  • Processes subscription billing and marketplace transactions
  • Processes payouts to educators selling pads on the marketplace (85% of sale price; PushPad retains 15%)
  • PushPad does not store full payment card numbers
  • Subject to Stripe's Privacy Policy and PCI DSS compliance

4.5 Vercel (Hosting)

  • Hosts the PushPad web application
  • Collects standard server logs (IP addresses, access times)
  • Subject to Vercel's Privacy Policy

We do not use any of these third-party services to collect, share, or process learner data for purposes outside operating the educational service. We do not sell learner or educator personal information to any third party.

5. How We Share Information

We do not sell personal information. We share data only in these limited circumstances:

  • Published Marketplace Pads: a lesson pad an educator explicitly publishes to the marketplace is publicly visible via its frozen listing snapshot; this never includes learner data
  • Service Providers: the third-party services listed in Section 4, under contract, and only as necessary to operate the service
  • Legal Requirements: when required by law, court order, or to protect rights and safety
  • Business Transfers: in the event of a merger, acquisition, or sale, with notice to affected users
  • With Consent: when a user or an educator (on behalf of a learner they are responsible for) explicitly authorizes sharing

6. Children's Privacy (COPPA)

6.1 Learner Accounts And Direct Collection

PushPad creates a real account for every invited learner, including learners under 13. Because PushPad itself creates and stores this account data, not only the inviting educator, PushPad has direct obligations under the Children's Online Privacy Protection Act (COPPA) for these accounts. We do not rely solely on educator or school authorization to satisfy our own COPPA obligations.

6.2 School / Educator Authorization

Where an educator invites a learner under 13 in an educational context, the educator may act as an authorized intermediary for consent purposes, consistent with COPPA's school-authorization provisions. This authorization covers collection of information reasonably necessary to provide the assigned educational service. It does not extend to:

  • Using a learner's data to build an advertising or marketing profile
  • Using a learner's data to train PushPad's own AI models
  • Sharing a learner's data with any party outside the educational purpose it was collected for
  • Retaining a learner's data after the account is removed and any applicable retention period ends

Educators are responsible for providing any additional notice to parents/guardians required in their jurisdiction, and for confirming they have authority to invite the learner to the platform. See our Parent Notice Template for sample language educators can use.

6.3 Parental Rights

A parent or guardian of a learner under 13 has the right to:

  • Review the information PushPad has collected about their child
  • Request deletion of that information
  • Refuse further collection or use of that information
  • Contact us directly at support@pushpad.com; a parent does not need to go through the educator to exercise these rights

6.4 2025 COPPA Amendments

The FTC's 2025 amendments to the COPPA Rule become fully enforceable April 22, 2026. Ahead of that date, PushPad does not use learner data for targeted advertising or third-party disclosure requiring separate opt-in consent, does not collect biometric identifiers, and retains learner data only as long as reasonably necessary to provide the assigned educational service (see Section 8).

7. FERPA And State Student-Data-Privacy Laws

For educators using PushPad within a school or district that receives federal funding, learner assignment, attempt, and score data may constitute an education record under the Family Educational Rights and Privacy Act (FERPA). PushPad supports FERPA's "school official" exception by limiting our use of that data to providing the contracted educational service, maintaining direct control by the school over that data's use, and not using it for any other purpose.

Several states (including Illinois, California, New York, and others) require a signed Data Processing Agreement (DPA) between a school or district and any vendor handling student data. See our Data Processing Agreement page for how PushPad handles student data against the categories a DPA typically covers, and how to request a signed one. Independent educators, homeschool users, and tutors using PushPad outside of a school/district relationship are not covered by these state laws in the same way, but the learner-data protections in this policy apply to their invited learners regardless.

8. Data Security And Retention

  • Encryption in transit (HTTPS/TLS) and at rest for sensitive data
  • Learner PINs and educator passwords are hashed, never stored in plaintext
  • Access controls, monitoring, and PCI DSS-compliant payment processing via Stripe

Removing a learner from an educator's roster begins a data-deletion process for that learner's account and associated data, subject to a short grace period during which the educator can reverse the removal. When an educator deletes a lesson pad or an uploaded media file, PushPad permanently removes it; we do not retain a copy after deletion. Content still referenced by an active marketplace listing, a completed purchase, or an active learner assignment cannot be deleted until that reference is resolved, so that a buyer's purchased copy or a learner's assigned work is never silently pulled out from under them. Payment records are retained for 7 years for tax and legal compliance. No system is 100% secure; account holders are responsible for keeping login credentials confidential.

9. Your Privacy Rights

  • Access: request a copy of personal data PushPad holds about you or, for a parent, your child
  • Correction: request correction of inaccurate information
  • Deletion: request account and data deletion, subject to legal retention requirements
  • Export: download educator-created lesson content
  • California Residents (CCPA): the specific rights above, plus confirmation that PushPad does not sell personal information

To exercise these rights, contact support@pushpad.com.

10. Cookies And Tracking

PushPad uses cookies for authentication (keeping you signed in), preferences, analytics, and fraud prevention. You can control cookies through your browser or the Cookie Settings link below; disabling some cookies may limit platform functionality.

11. International Users

PushPad's servers are located in the United States. By using the service, you consent to the transfer of your data to the U.S.

12. Changes To This Policy

We may update this Privacy Policy periodically. Changes will be posted here with an updated date; material changes will also be communicated via email or in-platform notification.

13. Contact Us

For privacy questions, requests, or to request a Data Processing Agreement:

  • Support Email: support@pushpad.com

By using PushPad, you acknowledge that you have read and understood this Privacy Policy.