Data Sharing & Student Privacy Policy — uThrive Academy LLC

Effective Date: January 1, 2026

Last Updated: June 2026

uThrive Academy LLC ("uThrive," "we," "our," or "us") provides digital personal financial literacy curriculum to K-12 school districts. Because we integrate directly with district learning management systems (LMS) and single sign-on (SSO) providers, we maintain a strict Data Minimization and Zero-Monetization Standard regarding all student and educator data.

This Data Sharing Policy explains what data is shared, how it flows between school districts and our platform, and the strict boundaries we enforce.

1. Our Core Commitment to Districts

  • Data Ownership: All student records, educational data, and rostering information remain the absolute property of the local education agency (school district).

  • Strict Confidentiality: We treat all student data as confidential and comply with the Family Educational Rights and Privacy Act (FERPA).

  • No Commercial Exploitation: uThrive never sells, trades, rents, or commercializes student or educator data. Data is never used for behavioral profiling or targeted commercial advertising.

2. What Data We Receive & Share

We operate on a Data Minimization principle, collecting and processing only what is technologically necessary to deliver our Getting Ahead curriculum and track student course progress.

  • Rostering & Authentication Data: Through district-approved integrations (such as LTI 1.3 endpoints, Google Classroom, ClassLink, or Clever), we receive minimal data required to authenticate users and establish accounts—typically student/teacher names, district email addresses, and school-assigned user identification numbers.

  • Progress Telemetry & Grade Passback: We track course completion, quiz metrics, and module progression to populate the district's LMS gradebook via LTI standards.

  • What We Do NOT Collect: We do not collect social security numbers, home addresses, private financial details of minors, biometric data, or non-educational behavioral history.

3. Third-Party Infrastructure & Subprocessors

To deliver our digital curriculum, uThrive utilizes enterprise-grade, secure cloud infrastructure (such as the MagicBox learning platform).

  • Subprocessor Compliance: Any subprocessor or platform partner utilized by uThrive is bound by strict data protection agreements that prohibit them from accessing student records for any purpose other than maintaining and securing the uThrive learning environment.

  • No Unauthorized Sharing: We do not share district data with any other external third parties, advertisers, or data brokers.

4. Data Security in Transit and at Rest

Data shared between school district systems and uThrive is protected using robust technical safeguards:

  • Encryption: All data in transit is encrypted using industry-standard Transport Layer Security (TLS/HTTPS). Data at rest within our cloud environments is stored using advanced encryption protocols.

  • Role-Based Access Control: Access to institutional accounts and student usage telemetry is strictly restricted to authorized uThrive personnel on a strict "need-to-know" basis for customer success, technical support, and platform maintenance.

5. Data Retention & Deletion Protocol

  • Active Term: Data is maintained securely for the duration of the active Software License Agreement with the school district.

  • Post-Termination Deletion: Upon the expiration or termination of a district agreement, uThrive will, at the district’s discretion, securely return or permanently delete/purge all student educational records and rostering telemetry from our active servers within 30 days, retaining only high-level anonymous historical metrics if explicitly agreed upon.

6. Questions & District IT Inquiries

School district administrators, superintendents, or IT Directors seeking specific vendor security questionnaires, auxiliary compliance documentation (such as Texas-specific data privacy addendums), or data audits can contact our operations team directly: