Pearl Education Product Privacy Policy
This policy covers Pearl Education’s Products. The deep, district- and parent-facing detail about student records is in the companion Student Data Privacy Notice. Marketing websites are covered by a separate Website Privacy Policy.
1. Who We Are and What This Covers
Pearl is operated by Trilogy Mentors Inc., DBA Pearl (“Pearl,” “we,” “us”), a Virginia corporation located at 1717 E Cary St, Richmond, VA 23223. This Privacy Policy explains how Pearl handles personal information in connection with the Pearl Products: our web application (used by students, instructors/tutors, parents, and administrators) and our mobile application (for instructors and administrators only). Students are not given mobile app accounts.
This policy does not change any agreement between Pearl and a school, district, or other customer. Where a customer agreement, Data Privacy Agreement (DPA), or executed national/state student data privacy agreement (NDPA) applies, that agreement governs student data.
2. Our Role: Service Provider and FERPA “School Official”
Pearl provides the Products to schools, districts, state education agencies, and program operators (our “customers”). For most personal information processed in the Products — especially student information — the customer is the controlling party and Pearl acts as a service provider on the customer’s behalf and at its direction, as a “school official” with a legitimate educational interest under FERPA (34 C.F.R. § 99.31(a)(1)).
This means:
- Administrators, instructors/tutors, and program staff (adults) are addressed directly by this policy.
- Students and parents/guardians: the substance of how student records are handled, and the way to exercise access, correction, and deletion rights, runs through the student’s school or district. See the Student Data Privacy Notice and contact your school. Pearl will refer parent or student requests it receives directly back to the school.
3. Information We Process
The specific fields are configured by each customer. Categories may include:
- Account and contact data (administrators, instructors/tutors, staff): name, email/username, role, organization.
- Student data (provided by or on behalf of the school): identifiers (name, email/username, local/student ID, school/district); optional demographics the customer elects to provide; program enrollment, scheduling, attendance/dosage, and tutor assignments; assessment and outcome measures (Pearl Insights / Data Hub).
- Usage and device data: access logs, IP address, device/browser and operating system, and session attendance/completion — collected through limited first-party analytics used to operate, secure, and improve the Products.
- Content and communications: instructional files; messages between authorized users (for example, a student and their instructor); and, where a customer enables it, online classroom session recordings.
Please do not submit excluded sensitive data (such as Social Security numbers, financial account numbers, government ID numbers, or biometric records) unless expressly agreed in writing (MSA § 3.2; DPA Schedule 1, Part C).
4. How We Use Information
We use information to:
- provide, maintain, and support the Products;
- secure the Products and prevent fraud, abuse, and technical issues;
- improve and develop the Products; and
- provide AI-enabled features that operate solely on the customer’s behalf to deliver the Services — for example, administrator insights and alerts, natural-language analytics over the customer’s own data, and product help experiences (see the AI Use Disclosure).
Pearl may also create and use de-identified and aggregated data for research, benchmarking, and educational-improvement purposes, using a documented de-identification methodology, as permitted by its customer agreements (MSA § 6). De-identified data does not identify any individual, school, or organization.
5. What Pearl Does Not Do
- We do not sell student data or other personal information.
- We do not use student data for targeted or behavioral advertising, and we do not build commercial profiles of students except as needed to provide the Products.
- We do not use identifiable student data or customer content to train AI models, and we do not use identifiable student data to develop unrelated commercial products without the customer’s separate written authorization (MSA § 5.7; DPA Art. IV). (This does not restrict the use of de-identified or aggregated data described in Section 4.)
6. How We Share Information
- Subprocessors: we use vetted service providers (for example, cloud hosting) to deliver the Products. Each is bound by obligations no less protective than our customer commitments, and we remain responsible for their performance. A current list is available on request (MSA § 4.4; DPA 2.5). See the Subprocessorspage.
- At the customer’s direction or as the customer configures the Products.
- For legal reasons: to comply with law or valid legal process. If law enforcement or a government entity requests student data, Pearl will notify the customer in advance unless legally prohibited (DPA 2.4).
- Business transfers: in a merger, acquisition, or sale, subject to the commitments in this policy and applicable customer agreements.
7. Children Under 13 (COPPA) and Student Consent
Pearl’s Products are used in schools. COPPA applies to children under 13. Consistent with FTC guidance and FERPA, the school or district provides or authorizes any required disclosures and consent for students’ use of the Products, and Pearl processes student information for the educational purposes the customer directs. Where a customer asks, Pearl can make available an in-product mechanism to obtain and record verifiable parental consent (MSA §§ 5.4–5.5). Parents should direct consent and records questions to their school.
8. Data Retention and Deletion
Pearl retains data only as long as needed to provide the Products or as required by law. On request during the service period and for 30 days after it ends, Pearl makes customer data available for export. Unless an earlier deletion is requested, Pearl deletes customer data no later than 60 days after that export period, and will certify deletion in writing on request. Disaster-recovery backups are encrypted, used only for recovery, and overwritten on a rolling schedule not to exceed 7 days. De-identified data is excluded (MSA § 4.6; DPA Art. VIII). See Data Retention & Deletion.
9. Security
Pearl maintains a written information security program with administrative, technical, and physical safeguards, including encryption in transit and at rest and least-privilege access controls (MSA § 4.3). See the Security Overview for details and how to request documentation.
10. Your Choices and Rights
- Administrators, instructors/tutors, and staff may access, update, or correct account information through the Product or by contacting us.
- Students and parents/guardians should contact their school or district, which controls student records; Pearl supports the school in fulfilling these requests and responds to a school’s request regarding a student’s data within 45 days (DPA 2.2).
11. U.S. State Privacy Rights
Several U.S. states (for example, California under the CCPA/CPRA, and Virginia, Colorado, and Connecticut) provide residents with privacy rights regarding personal information. Note that personal information governed by FERPA and used for educational purposes is generally exempt from these consumer-privacy laws; the rights below apply primarily to non-student personal information, such as the account information of adult users and inquiries from prospective contacts.
Subject to applicable law, you may have the right to: know and access the personal information we hold; request correction; request deletion; and appeal a decision. Pearl does not sell personal information and does not share it for cross-context behavioral advertising, so there is no “opt out of sale/sharing” to exercise. We will not discriminate against you for exercising these rights. To make a request, contact privacy@poweredbypearl.com; we will verify your request and may work through your school where the information relates to student records. Authorized agents may submit requests with proof of authorization.
12. International Users
Pearl is based in the United States and stores data in the United States. Coverage of Canadian requirements (PIPEDA, Quebec Law 25, and provincial laws) is being added and will be in place before Pearl serves Canadian customers or users.
13. Changes to This Policy
We may update this policy to reflect changes in the Products or the law. If we make material changes, we will provide notice through the Products or by other reasonable means before they take effect.
14. How to Contact Us
Privacy questions: privacy@poweredbypearl.com. Postal: Trilogy Mentors Inc., DBA Pearl, 1717 E Cary St, Richmond, VA 23223. Students and parents: please contact your school or district first.
