OPIUS PRIVACY POLICY
Opius EdTech, Inc.
Effective Date: August 14, 2026 | Last Updated: August 22, 2026 | Version 1.1
Applies to opiusedu.com and the Opius service
Opius EdTech, Inc. ("Opius," "we," "our," or "us") provides an AI-powered service that helps parents and legal guardians access, understand, and stay on top of their children's school information. This Privacy Policy explains what personal information we collect, why we collect it, how we use and disclose it, how long we keep it, and the choices and rights you have.
This Policy applies to our website at opiusedu.com, our marketing activities, and our hosted service and related features, including SMS text messaging (together, the "Service"). It does not apply to third-party products or websites — including the school platforms the Service accesses on your behalf — which are governed by their own privacy policies.
Because the Service exists to help parents manage information about their children, much of the information we handle relates to students, including students under the age of 13. Section 4 (Student Data and Children's Privacy) describes how we protect that information and the special commitments we make about it. We never sell personal information, we never use student information for advertising of any kind, and we never use identifiable personal information to train artificial intelligence models.
Summary of Key Points
This summary is for convenience only. It is not a substitute for the full Policy below.
| Topic | In short |
|---|---|
| Do you sell our data? | No. We do not sell personal information, and we do not share it for targeted or cross-context behavioral advertising. Student information is never used for advertising of any kind. See Sections 4.5 and 7.1. |
| Do you train AI on our data? | No. We do not use your or your children's identifiable information to train, fine-tune, or improve any AI or machine-learning model, ours or a third party's, and we contractually require our AI model provider to do the same. Only fully de-identified, aggregated data may be used to improve the Service. See Section 5. |
| What about my children's information? | The Service collects student information only at your direction and with your consent, uses it only to provide the Service to you, and deletes it when you ask. Section 4 describes our COPPA, FERPA-related, and student-data commitments in detail. |
| What about my school passwords? | School-platform credentials you provide are encrypted using industry-standard encryption before storage, are decrypted only server-side to log in on your behalf, are never written to logs, and can be deleted by you at any time in Settings. See Section 6. |
| What about text messages? | Your mobile number and SMS consent are never shared with third parties or affiliates for marketing or promotional purposes, and are never sold. Reply STOP to opt out, HELP for help. See Section 9. |
| Who can see our content? | Access by Opius personnel is restricted to the limited circumstances in Section 5.4 — with your authorization, to meet a legal obligation, to address a security incident, or to enforce our agreements. |
| Where is data processed? | In the United States, on U.S. cloud infrastructure, plus the service providers described in Section 7. |
| How do we reach you? | privacy@opiusedu.com. See Section 12 for rights requests and Section 17 for all contact routes. |
1. Scope of This Policy and Our Role
Opius is a consumer service: our customer is you, the parent or legal guardian who subscribes. We decide how the personal information described in this Policy is collected and used in order to provide the Service, and we are the "controller" (under laws that use that term) or "business" (under California law) for it.
One aspect of our role is different from most services, and this Policy is written around it: when you provide your school-platform credentials, you authorize Opius to act as your agent — logging into the school platforms associated with your account on your behalf, retrieving the student information you already have the right to see, and helping you understand it. We access only the school platforms you connect, only with the credentials you provide, and only to provide the Service to you.
Where you have accepted our Terms of Service, that agreement and this Policy together govern the Service. If this Policy conflicts with the Terms of Service, the Terms of Service control.
2. Information We Collect
2.1 Information you provide to us
Account and contact data — your name, email address, and authentication information (we support sign-in through Google or an email magic link; we do not store passwords for your Opius account in plaintext).
Student and family information — the information you provide about your household and students, such as a student's name, school, and grade level, used to set up and organize your account.
School-platform credentials — the usernames and passwords for the school platforms you choose to connect. Section 6 describes how these are protected.
Chat and query data — the questions, messages, and instructions you submit to the Service, and the responses generated for you.
Billing data — billing contact and subscription information. Payment card numbers are collected and stored by our payment processor, not by Opius.
Mobile telephone number and SMS consent data — where you choose to use the Service by text message, the mobile number you provide, the record and date of your opt-in, any opt-out request, and the content and delivery status of text messages exchanged with the Service. See Section 9.
Support and communications data — the content of your messages to us, support requests, and survey or feedback responses.
2.2 Student Data retrieved from school platforms
At your direction, the Service retrieves information about your students from the school platforms you connect — for example, homework assignments and due dates, grades and academic progress, class schedules, attendance records, school account balances, and teacher messages and school communications (collectively, with the student information you provide directly, "Student Data"). Student Data is personal information about your children. Section 4 describes the special protections that apply to it.
2.3 Information collected automatically
Usage data — features used, queries submitted, timestamps, session duration, and error events.
Device and technical data — IP address, browser type and version, operating system, device identifiers, and language settings.
Cookies and similar technologies — as described in Section 10.
Security and audit logs — authentication events, account actions, and the audit records the Service maintains, as described in Section 11 and our Terms of Service.
2.4 Information from third parties
School platforms — the Student Data described in Section 2.2, retrieved as your agent using the credentials you provide.
Google sign-in — if you sign in with Google, we receive your name, email address, and profile picture, solely to authenticate you and operate your account. See Section 8.
Payment processor — confirmation of payment status and subscription events.
We do not purchase personal information from data brokers, and we do not collect information about you or your children from advertising networks.
3. How We Use Personal Information
We use personal information for the following purposes, and for no incompatible purpose without notice to you.
| Purpose | What this means |
|---|---|
| Provide and operate the Service | Authenticate you, retrieve Student Data from the school platforms you connect, process your questions, generate responses, and deliver them by web chat or SMS |
| Support and account management | Respond to requests, troubleshoot, and manage subscriptions and renewals |
| Billing | Invoice and collect subscription fees through our payment processor |
| Security, integrity, and abuse prevention | Detect and investigate unauthorized access, fraud, and abuse; maintain backups and audit logs |
| Service improvement and analytics | Understand aggregate feature usage, reliability, and performance. Performed on usage and technical data and on de-identified, aggregated data — never by training AI models on identifiable information (see Section 5) |
| Communications about the Service | Send administrative, security, billing, and change notices |
| Marketing to parents | Send product news to the account email you provide, with an unsubscribe link in every message. We do not use Student Data for marketing, and we do not send marketing text messages |
| Legal compliance and defense | Meet legal, tax, and regulatory obligations; establish, exercise, or defend legal claims |
4. Student Data and Children's Privacy
This Section is the heart of this Policy. The Service is designed for parents and legal guardians; it is not directed to children, and children cannot create accounts. But the information the Service handles is largely information about children — and a student under 18, including a student under 13, may use the Service under your account with your consent and supervision. The commitments below apply to all Student Data and to any personal information of a child processed by the Service.
4.1 Parental consent and control
You — the parent or legal guardian — are in control of all Student Data in the Service:
Consent. We collect and process Student Data, including information about children under 13, only with your consent, which you provide when you create your account, connect a school platform, and accept our Terms of Service. Consistent with the Children's Online Privacy Protection Act ("COPPA") and its implementing Rule, we obtain your verifiable consent before collecting personal information from or about your child, and we provide this notice of our practices.
Review. You can review the Student Data the Service holds at any time by using the Service or by contacting privacy@opiusedu.com.
Deletion and revocation. You can delete stored school credentials at any time in Settings, disconnect any school platform, direct us to delete your child's information, and refuse to permit further collection — at any time, without needing to give a reason. If you revoke consent or request deletion, we will stop collecting and delete the child's information as described in Section 12, subject only to legal retention requirements.
No conditioning. We do not condition a child's ability to benefit from the Service on the child providing more personal information than is reasonably necessary to provide the Service.
4.2 What we collect about children, and how we use it
The Student Data we collect is described in Sections 2.1 and 2.2. We use it solely to provide the Service to you — to answer your questions about your child's schooling and to deliver the notifications you request. We do not use Student Data for marketing or advertising of any kind, we do not build advertising or commercial profiles of students, and we do not use identifiable Student Data to train AI models (Section 5).
Third parties that receive children's information. The only third parties that receive children's personal information are the categories of service provider listed in Section 7 — our AI model provider, text messaging provider, cloud infrastructure and database providers, and payment processor — and each acts solely to provide the Service on our behalf, under written agreements limiting its use of the information to that purpose. We do not disclose children's personal information to any third party for any purpose beyond the operation of the Service, and for that reason no separate consent for third-party disclosure is required or requested. If that ever changed, we would obtain your separate, verifiable consent first.
4.3 Student data commitments
We make the following commitments with respect to all Student Data, consistent with COPPA, California's Student Online Personal Information Protection Act (SOPIPA), and similar state student-privacy laws. We make these commitments as a matter of policy for all users regardless of state:
We will never sell Student Data. We will never use Student Data for targeted, behavioral, or interest-based advertising, or permit any third party to do so, and we will never display advertising to students through the Service. We will not create profiles of students except in furtherance of providing the Service you have requested. We will collect only the Student Data reasonably needed to provide the Service. We will delete Student Data at your request and upon account termination, as described in Section 12. We will maintain reasonable security procedures appropriate to the sensitivity of Student Data, as described in Section 11, including a written information security program. We will not retain children's personal information longer than reasonably necessary for the purpose for which it was collected, and we will not retain it indefinitely. In any merger, acquisition, or sale of assets, we will require any successor to honor these commitments or give you notice and the opportunity to delete your data before any material change applies.
4.4 A note about FERPA
The Family Educational Rights and Privacy Act ("FERPA") gives parents the right to access their children's education records held by schools that receive federal funding. Opius does not receive education records from schools and is not a party to any agreement with your school or district; instead, the Service acts as your agent to exercise the access you already have through the parent and student portals your school provides. Your school and district remain responsible for their own handling of education records under FERPA. If your school's terms of use restrict how portal access may be exercised, you are responsible for ensuring your use of the Service is consistent with them, as described in our Terms of Service.
4.5 If we learn of unauthorized collection
If we learn that we have collected personal information from a child under 13 without parental consent — for example, if a child creates an account misrepresenting their age — we will delete that information promptly and terminate the account. If you believe a child has provided us personal information without consent, contact privacy@opiusedu.com.
5. Artificial Intelligence and Your Data
The Service uses artificial intelligence to understand your questions and generate answers from the Student Data it retrieves. This Section describes how that processing works.
5.1 How the Service uses AI
When you submit a question, the Service transmits the relevant portion of your question and the necessary Student Data to our third-party AI model provider (currently Anthropic's Claude models, accessed through a commercial API) for processing, and returns the result to you. The AI provider processes this data on our instructions to generate your response.
5.2 We do not train AI models on your identifiable data
Opius does not use your account information, chat content, Student Data, or any identifiable personal information to train, fine-tune, retrain, or otherwise develop or improve any large language model, machine-learning model, or other artificial intelligence system, whether our own or a third party's. We do not sell, license, or otherwise make such information available to any party for AI training purposes. We use our AI model provider under commercial terms that prohibit it from training its models on the content we transmit, with retention limited to what its terms permit for abuse monitoring. We will not route your data to any AI provider that will not commit to a no-training basis.
5.3 De-identified and aggregated data
We may create and use de-identified, aggregated data derived from use of the Service — for example, generalized statistics and trends about how families use AI to track homework, grades, and school communications. To qualify, data must be stripped, using industry best practices, of every characteristic that would identify any individual, family, student, or account, and must contain no confidential information. We maintain it in de-identified form, do not attempt to re-identify it, and require the same of any recipient. We may use de-identified, aggregated data to operate, analyze, and improve the Service and our other products, including the algorithms and models underlying them. Because this data cannot be traced to any person, this does not qualify the commitment in Section 5.2: identifiable information is never used to train any model.
5.4 Human access to your data
Opius personnel and contractors do not read your chat content or Student Data except where: you explicitly authorize access (for example, to resolve a support request); access is necessary to comply with a legal obligation or valid legal process; access is necessary to detect, prevent, or respond to security incidents, fraud, abuse, or technical problems; or access is necessary to enforce our agreements. Access under these exceptions is limited to the minimum necessary and is logged.
5.5 AI accuracy and automated decisions
AI-generated responses may contain errors. The Service provides information to help you stay informed; it does not make decisions about you or your child, and we do not use personal information for profiling in furtherance of decisions that produce legal or similarly significant effects (including decisions about education enrollment or opportunity). Always verify important information — a grade, a deadline, a balance — against the school platform itself before acting on it.
6. School-Platform Credentials and Access
Encryption. School-platform credentials you provide are encrypted using industry-standard encryption (currently AES-256-GCM) before storage, and are decrypted only server-side, only at the moment they are needed to log in on your behalf.
No logging. Your plaintext credentials are never written to logs and are never exposed to client-side code.
Your control. You may delete stored credentials at any time through Settings. Upon termination of your subscription, we cease access to your school platforms and delete your stored credentials within a reasonable period.
How access works. The Service uses secure browser automation to log into the school platforms you connect, in substantially the same way you would as a user. Opius has no partnership or affiliation with, and no special access rights to, these platforms, and their availability to the Service may change. Each school platform is governed by its own terms and privacy policy.
Caching. To improve performance and reduce login frequency, the Service temporarily caches retrieved Student Data. Cached data is stored securely, refreshed periodically, and handled as Student Data under this Policy.
7. How We Disclose Personal Information
We disclose personal information only as described below. We engage the following categories of service provider, each bound by a written agreement limiting its use of the information to providing services to us and requiring appropriate security:
| Category | Function | Data involved |
|---|---|---|
| Cloud infrastructure and database | Hosting, storage, and backup on U.S. infrastructure | All categories, encrypted at rest and in transit |
| AI model provider | Generate responses to your questions, under no-training terms | The portions of your questions and Student Data necessary for the request |
| Text messaging provider | Transmit SMS messages to and from users who have opted in | Mobile number and message content only; never used for marketing (see Section 9) |
| Payment processing | Subscription billing and payment card handling | Billing contact and payment data (card data held by the processor) |
| Communications and support | Transactional email and support tooling | Contact data and support correspondence |
| Analytics and security | Aggregate usage measurement, logging, and threat detection | Usage, device, technical, and log data |
We also disclose personal information: at your direction, when you ask the Service to take an action; to professional advisors (attorneys, accountants, auditors, insurers) under duties of confidentiality; in corporate transactions (merger, acquisition, financing, reorganization, or sale of assets), subject to confidentiality protections, continued application of this Policy or a materially equivalent policy, and the successor commitments in Sections 4.3 and 9; for legal and safety reasons, where we believe in good faith that disclosure is required by law or valid legal process, or is reasonably necessary to protect the rights, property, or safety of Opius, our users, or the public — and where legally permitted, we will notify you before disclosing your content in response to legal process; and with your consent, for any other purpose disclosed to you when consent is requested.
7.1 We do not sell or share personal information
Opius does not sell personal information, and does not share personal information for cross-context behavioral advertising or targeted advertising, as those terms are defined under the California Consumer Privacy Act and other U.S. state privacy laws. We have not sold or shared personal information in the preceding twelve months, including the personal information of individuals we know to be under sixteen years of age.
8. Google User Data and Limited Use
If you sign in with Google, we access your name, email address, and profile picture solely to authenticate you and operate your account. We do not access Google Drive, Gmail, Calendar, or other Google account data.
Limited Use. Opius' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer or sell Google user data to third parties; do not use it for advertising; do not use it to determine creditworthiness or for lending; do not use it to train generalized AI or machine-learning models; and do not permit humans to read it except in the circumstances described in Section 5.4.
Disconnecting. You may revoke access at myaccount.google.com/permissions or by contacting privacy@opiusedu.com. Following disconnection or a deletion request, we delete Google user data within thirty (30) days unless a longer period is required by law.
9. Mobile Information and SMS
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent are not shared with any third party, and are not sold, rented, or licensed to anyone.
If you choose to use the Service by text message, we collect and use your mobile number, your SMS consent record, and the content of messages you exchange with the Service solely to operate the messaging program — to deliver the messages and notifications you request, honor your opt-out, provide customer care, and keep records demonstrating your consent. We disclose mobile numbers and message content only to the vendors that operate the messaging program on our behalf (our messaging service provider and cloud infrastructure providers), solely so they can transmit messages for us, under written contracts prohibiting any other use, and where required by law. We do not send marketing or promotional text messages, and we do not use text message content to train AI models. Any successor in a corporate transaction remains bound by this Section.
How to stop. Reply STOP (or END, CANCEL, UNSUBSCRIBE, or QUIT) to any text from us to opt out, HELP or INFO for help, or START to rejoin. You can also turn off SMS in Settings or contact privacy@opiusedu.com. Consent to receive texts is not a condition of using the Service — everything available by text is also available through the web chat. Message and data rates may apply; message frequency varies.
10. Cookies, Analytics, and Tracking
We use cookies and similar technologies on our website and in the Service: strictly necessary cookies (authentication, session management, security — the Service will not function without these); preference cookies (remember your settings — you can disable these in your browser); and analytics cookies (measure aggregate usage and performance — you can disable these through your browser, a universal opt-out signal, or a request to privacy@opiusedu.com). We do not use advertising cookies, we do not participate in cross-context behavioral advertising, and we do not disclose personal information to advertising networks or data brokers. We never place advertising or tracking technologies in the portions of the Service a student may use.
Universal opt-out signals. We honor the Global Privacy Control and similar browser-based universal opt-out signals recognized under applicable state law, treating them as a valid opt-out of any sale, sharing, or targeted advertising for that browser or device (activities we do not engage in regardless). Signals must be enabled on each browser and device you use; see globalprivacycontrol.org.
Do Not Track. Browser "Do Not Track" headers have no uniform standard, and we do not respond to them; we do respond to universal opt-out signals as described above.
11. Data Security
We maintain a written information security program with administrative, technical, and physical safeguards appropriate to the sensitivity of the information we handle — which, because it includes children's information and school credentials, we treat as high-sensitivity across the board. Current measures include: encryption of data in transit (TLS) and at rest; encryption of school-platform credentials with industry-standard encryption, decrypted only server-side at time of use; access controls and least-privilege provisioning, with multi-factor authentication for personnel with production access; logical separation of each family's data; centralized logging, monitoring, and vulnerability management; encrypted, access-controlled backups with documented recovery procedures; personnel confidentiality obligations and security training; and a documented incident response plan.
Incident notification. If we determine that a security incident has compromised personal information, we will notify you and, where required, regulators, without undue delay and within the timeframes required by applicable law. Because compromised school credentials could affect accounts outside our Service, we will also tell you which credentials were affected so you can change them at the school platform.
No system is perfectly secure. Use a strong, unique password for each school platform, and notify us promptly at security@opiusedu.com of any suspected compromise.
12. Data Retention
We retain personal information only as long as necessary for the purposes described in this Policy, or as required by law. Children's personal information is never retained indefinitely, and is kept only as long as reasonably necessary for the purpose for which it was collected.
| Data | Retention period |
|---|---|
| Account and contact data | Life of the account, then up to twenty-four (24) months after closure |
| Student Data and chat content | Life of the account. Deleted upon account deletion or your deletion request, as described below |
| School-platform credentials | Life of the connection. Deleted immediately upon your deletion in Settings, and within a reasonable period after subscription termination |
| Cached Student Data | Expires automatically within four (4) to twenty-four (24) hours of retrieval, depending on data type (assignments within 4 hours; grades within 12 hours; attendance and full-page data within 24 hours). Raw page snapshots used for quality calibration are deleted within seven (7) days. Handled as Student Data at all times; never retained indefinitely |
| Usage and technical data | Up to twenty-four (24) months, then deleted or irreversibly de-identified |
| Security and audit logs | Up to eighteen (18) months in live production and up to seven (7) years archived, used only for security, audit, compliance, legal, and regulatory purposes, consistent with our Terms of Service |
| Billing and transaction records | Seven (7) years, as required by tax and accounting rules |
| SMS consent and opt-out records | Life of the account plus four (4) years after the last message as evidence of consent; STOP records retained indefinitely so we can honor them |
| De-identified, aggregated data | Retained indefinitely in de-identified form |
| Backups | Purged on a rolling cycle not exceeding ninety (90) days |
Deletion requests. Upon a valid deletion request, we begin removal within thirty (30) days and complete deletion from active systems within ninety (90) days. Residual copies in encrypted backups are purged on their normal rolling cycle and are not restored to active use in the interim. Deletion may be delayed only where retention is required by law, necessary to establish or defend legal claims, or necessary to complete a transaction you requested. This Section does not apply to security and audit records (retained on the schedule above) or to de-identified, aggregated data.
13. Your Privacy Rights
13.1 Rights available to you
Depending on where you live, you may have some or all of the rights below. We extend these core rights to all U.S. residents regardless of state, as a matter of practice. As the parent or legal guardian, you may exercise all of these rights on behalf of your child with respect to Student Data.
| Right | What it means |
|---|---|
| Know / Access | Confirm whether we process personal information about you or your child and obtain a copy, including categories, sources, purposes, and recipients |
| Correct | Correct inaccurate personal information we maintain (note that Student Data retrieved from a school platform reflects the school's records — corrections to school records must be made with the school) |
| Delete | Request deletion of personal information, subject to legal exceptions |
| Portability | Receive a copy in a portable, machine-readable format where technically feasible |
| Opt out of sale, sharing, and targeted advertising | We do not engage in these activities; the right is preserved for you regardless |
| Opt out of profiling | Opt out of profiling in furtherance of decisions producing legal or similarly significant effects. We do not conduct such profiling |
| Limit use of sensitive personal information | Limit use of sensitive personal information to permitted purposes. We do not use it beyond those purposes |
| Non-discrimination | Exercise your rights without being denied service or charged differently |
| Appeal | Appeal a denial of a rights request |
| Withdraw consent | Withdraw any consent you previously gave — including consent to collection of your child's information (Section 4.1) — without affecting processing already carried out |
13.2 How to exercise your rights
Email privacy@opiusedu.com with the subject line "Privacy Rights Request." You can also manage most information directly: update account information in Settings, delete school credentials in Settings, unsubscribe from marketing email via the link in any message, and stop text messages by replying STOP (Section 9). To request full account deletion, contact privacy@opiusedu.com.
13.3 Verification, timing, and appeals
We will acknowledge your request promptly and respond within forty-five (45) days, extendable once by forty-five (45) days where reasonably necessary, with notice to you. We must verify your identity before acting — particularly important here, because rights over Student Data belong to the parent or guardian on the account; we will verify requests against the account email and may require additional verification for sensitive requests. We do not charge a fee for the first two requests in a twelve-month period, and may charge a reasonable fee for, or decline, requests that are manifestly unfounded, excessive, or repetitive. If we decline your request, we will explain why, and you may appeal by emailing privacy@opiusedu.com with the subject line "Privacy Rights Appeal." We will decide appeals in writing within forty-five (45) days. If your appeal is denied, you may contact your state attorney general.
13.4 Authorized agents
You may use an authorized agent to submit a request. We require written proof of the agent's authority and, unless the agent provides a valid power of attorney, direct verification from you.
14. State-Specific Disclosures
14.1 California
This Policy serves as our notice at collection and our full CCPA notice. The categories of personal information we collect, the purposes, and the categories of recipients are set out in Sections 2, 3, and 7; retention periods are in Section 12; and our rights process is in Section 13. We do not sell or share personal information — including, for the avoidance of doubt, the personal information of any consumer under sixteen (16) years of age — and we do not use or disclose sensitive personal information beyond the purposes permitted without an opt-out. Our student-data commitments consistent with SOPIPA are in Section 4.3. California residents may also request information under California's "Shine the Light" law (Civil Code § 1798.83) by emailing privacy@opiusedu.com; we do not disclose personal information to third parties for their own direct marketing purposes.
14.2 Other states with comprehensive privacy laws
Residents of states with comprehensive consumer privacy laws (including Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia) have the rights described in Section 13, including the right to appeal. We recognize universal opt-out signals as described in Section 10. We do not sell personal data, do not process personal data for targeted advertising, and do not profile in furtherance of decisions producing legal or similarly significant effects. Under these laws, personal data about a known child is sensitive data: we process it only with parental consent, as described in Section 4, and only to provide the Service. Consistent with Connecticut law, we confirm that we do not collect, use, or sell personal data to train large language models. Minnesota residents may obtain a list of the specific third parties, and Oregon residents the specific or categories of third parties, to which we have disclosed personal data, by request to privacy@opiusedu.com.
14.3 Nevada and consumer health data
Nevada residents may direct us not to sell covered information; we do not sell covered information as defined by Nevada law. Opius does not collect, process, sell, or share consumer health data as defined by the Washington My Health My Data Act or Nevada SB 370, and does not use geofencing around any healthcare facility. Our Terms of Service prohibit uploading personal health information to the Service.
15. International Users and Data Transfers
Opius is based in the United States and processes personal information on United States infrastructure. The Service is offered to families in the United States, and we do not currently target or market the Service in the European Economic Area, the United Kingdom, or Switzerland. If you access the Service from outside the United States, you understand that your information will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your jurisdiction. If we begin offering the Service in jurisdictions requiring a transfer mechanism, we will implement one and update this Policy before doing so.
16. Third-Party Websites and Services
Our website and the Service may link to, or interoperate with, websites and services we do not control — including the school platforms you connect. This Policy does not apply to them. We encourage you to review the privacy policy of any third-party service, including your school's platforms.
17. Changes to This Policy
We may update this Policy to reflect changes in our practices, technology, or legal requirements. The current version is always posted at opiusedu.com/privacy with the effective date and version number at the top. If we make material changes, we will provide notice by email to your account address, by prominent notice within the Service, or both, at least thirty (30) days before the changes take effect. If a material change would expand how we collect, use, or disclose children's personal information beyond what you previously consented to, we will obtain your renewed consent before the change applies to your account. Your continued use of the Service after the effective date of a change constitutes acceptance, except where consent is required.
18. Contact Us
| Entity | Opius EdTech, Inc., a Delaware corporation |
|---|---|
| Privacy inquiries and rights requests | privacy@opiusedu.com |
| Security incidents | security@opiusedu.com |
| General support | support@opiusedu.com |
| Website | opiusedu.com |
| This Policy | opiusedu.com/privacy |
| Terms of Service | opiusedu.com/terms |
We are committed to resolving privacy concerns directly. If you are not satisfied with our response, you may lodge a complaint with your state attorney general or, for California residents, the California Privacy Protection Agency. Questions about COPPA may also be directed to the Federal Trade Commission.
Accessibility. If you need this Policy in an alternative accessible format, contact privacy@opiusedu.com and we will provide one.