Privacy Policy
Overview
DistrictWise is a governance intelligence tool for California school districts, operated by Synergy Media Group. This policy explains what data we collect, how we use it, and the protections we put in place.
1. What data we collect
Query text. When a user submits a policy question, the text of that question is processed to generate an answer.
User identifiers. We collect the email address of each licensed staff user to operate their access seat, and issue a short-lived session token. We do not collect student names or student personal identifiers — those are masked on the user's device before any text is transmitted (see §2).
Usage metadata. For operational monitoring, billing, and quality, we log per-query records: the masked question text, the policy citations returned, token and cost counts, and the staff seat that made the request.
What we do not collect:
- Student records, grades, or personally identifiable student information
- Staff personnel records
- Financial account information
- Any data from pages a user visits outside of DistrictWise
2. PII masking
DistrictWise masks personally identifiable information on the user's device, in the browser, before any text is transmitted. Detected and masked types include names, email addresses, phone numbers, street addresses, and cued student ID numbers. Identifiers are replaced with placeholders (for example, [Student 1]); the map needed to restore them never leaves the browser.
The masking is fail-closed: if it cannot verify success, the request is blocked and nothing is sent. As a result, un-masked student identity does not reach our servers or the AI model.
This is a core architectural feature, not an afterthought. Two honest caveats: masking is a guarantee of the staff interface (a separate public embeddable chat widget does not mask and should only receive non-identifying text); and automated name detection, while robust, is not perfect for uncommon names — the interface shows what was masked so users can correct it, and staff are advised not to paste full rosters.
3. How we use data
Query text is used solely to generate a policy answer and is not:
- Sold to third parties
- Used to train AI models
- Shared with advertisers
- Used to build user profiles
4. Data storage and retention
- Because PII is masked on-device (§2), records we retain contain masked query text only — no un-masked student identity.
- Per-query operational logs (masked question, citations, cost) are retained for monitoring, billing, and quality. A user's saved research threads ("incidents") persist until that user deletes them. A formal retention and purge schedule is being finalized as part of go-live.
- All data is encrypted in transit (TLS). Server-side files are held with restricted OS-level permissions, and signing keys and secrets are stored off the application tree; broader at-rest encryption is a hardening item on the go-live checklist.
- Data is stored on U.S.-based cloud infrastructure (AWS).
5. California-specific compliance
FERPA (Family Educational Rights and Privacy Act)
- We operate as a school official under the legitimate educational interest exception
- A signed Data Processing Agreement is required with each district before go-live
- Because student PII is masked on-device before transmission, we do not retain identifiable student education records; any stored research threads are de-identified
SOPIPA (Student Online Personal Information Protection Act)
- We do not use student information for advertising or to build commercial profiles
- We do not sell student information
- We do not disclose student information to third parties except as required by law
AB 1584 (Education Code 49073.1)
- Our Data Processing Agreement meets AB 1584 minimum contract requirements
- Districts retain ownership of all their data
- We will not use district data for any purpose other than providing the DistrictWise service
6. Chrome extension permissions
The DistrictWise Chrome extension requests the following permissions:
| Permission | Purpose |
|---|---|
storage | Store the session token, the on-device un-mask map, and UI state — all local to the browser |
contextMenus | Provide a right-click entry to send selected text to the side panel |
sidePanel | The entire interface is a Chrome side panel |
Host access: https://districtwise.ai/* | The backend the extension communicates with |
The extension does not request tabs, broad host access, or the ability to read or modify the pages you visit. We request only the permissions necessary to deliver the service.
7. Data sharing
We do not sell, rent, or share user data with third parties except:
- As required by applicable law or valid legal process
- To our infrastructure providers (AWS), who are bound by their own privacy commitments
- As explicitly authorized in writing by the district
8. District data ownership
Each district's policy corpus, query logs, and any district-specific configurations belong to that district. SMG acts as a data processor, not a data controller, with respect to district data. Districts may request deletion of their data at any time.
9. Security measures
- TLS encryption for all data in transit
- On-device, fail-closed PII masking before any transmission (the primary control)
- HMAC-hashed access PINs (never stored in plaintext) and short-lived, tamper-evident session tokens
- Application server not directly internet-reachable (bound to localhost behind an HTTPS reverse proxy)
- Secrets stored off the application and code tree; server-side files held with restricted OS permissions
- Access controls limiting data access to authorized SMG personnel
10. Contact
For privacy-related questions, data deletion requests, or to report a concern:
Synergy Media Group
Jason Price
jason@gainsynergy.com
Lincoln, CA