Math Mini-Lessons
Privacy notice
Version 0.9, last updated 2026-09-05. This notice describes the platform as built. For a school district, the executed Data Privacy Agreement and its Parents’ Bill of Rights supplement govern and take precedence over anything here.
Who we are
Math Mini-Lessons (MML) provides a licensed K-12 mathematics curriculum, school onboarding tools and school-level progress analytics to schools that hold a license. Questions about this notice go to sarah@mathminilessons.com.
What we collect
Educator accounts. Name, school email address, role (teacher, school leader, district administrator) and school affiliation, supplied by the school when it adds staff to its roster. Sign-in events and, for administrators, an authenticator enrolment are held by our authentication provider.
Student information supplied by a school. When a school uploads benchmark results, each student is stored under a one-way keyed hash of the identifier the school supplies, together with a first name and last initial, grade level, class period and the scores. We do not store student email addresses, student identification numbers or names in readable form, dates of birth, or any contact information. Students do not have accounts and never sign in.
Professional development requests. The contact name, email address, school, requested date and any notes an educator enters when requesting a workshop.
Technical records. Every access to curriculum material is recorded with the educator’s email, the lesson and the time so that abnormal use can be detected. Our hosting providers keep request logs, including IP addresses, for a short period for security.
How we use it
To deliver licensed curriculum to the right school and grade, manage rosters and licenses, produce analytics at the school and class level, schedule professional development, and keep the service secure.
We do not sell personal information, use it for advertising, share it with third parties for their own purposes, use identifiable student information to improve the product, or send it to artificial-intelligence services.
Who processes it on our behalf
Supabase (database, authentication and file storage, United States); Vercel (application hosting, United States); Google (optional Google sign-in, and Google Drive as the source of some curriculum files); the transactional email provider that delivers sign-in links; and, when enabled, Cloudflare Turnstile to protect the sign-in form from automated abuse. Each provider is bound by written terms that prohibit using the data for any purpose other than providing its service. The current list is available on request and is attached to every district agreement.
How long we keep it
Educator records are kept for the term of the school’s license and removed on the school’s request or at contract end. Material-access records are kept for up to 400 days and security alerts for up to two years. Student information is kept for the period the district agreement specifies and is deleted, including from backups as they expire, at contract end; a certificate of destruction is provided on request.
How we protect it
All traffic is encrypted in transit and all stored data is encrypted at rest. The database denies access by default and is reached only through the application’s own server. Student identifiers are stored as keyed hashes that cannot be reversed. Administrator actions require a second authentication factor. Access to curriculum material is logged and rate-limited. The controls are reviewed against the NIST Cybersecurity Framework and New York Education Law 2-d.
Your rights
Parents and eligible students exercise their rights to see, correct or challenge student information through their school or district, as New York Education Law 2-d provides; the district’s Parents’ Bill of Rights explains how. Educators can ask their school leader to update or remove their account. We answer district requests within ten business days.
Children
The platform is used by educators. We collect no information directly from children, and children under 13 cannot create accounts, so the Children’s Online Privacy Protection Act does not apply to our collection.
Security incidents
If student, teacher or principal information is accessed or released without authorization, we notify the affected educational agency in the most expedient way possible and without unreasonable delay, and within seven calendar days of discovery, so that it can inform families as the law requires.
Changes
We will update the version and date above whenever this notice changes and will tell licensed districts before a change takes effect.