Privacy policy
Version 1.3 · September 2026
Soar is a personal planner and study coach for one student's schoolwork. It is in early access, and Soar controls how accounts are created, and what is required right now is shown on the sign-up page itself. For a student under 18, the parent or guardian is the contracting party. This policy says plainly what Soar holds, where data can go, and what is still being built. Where something is planned rather than built, we say so.
What Soar collects
Almost everything Soar holds sits in its own database, and this is what it comes to. It is thirteen things. Some copies also sit with the outside companies listed further down, and that section says what each one sees.
- Account basics. A display name, an email address, and a password stored only as a one-way scramble (a "hash"), never as text.
- Classes and teachers. Class names and details like a teacher's name or a late-work policy, entered by the family, and when each class meets.
- Terms and the school week. Your semesters and quarters, which days are which kind of school day, when the bells go, and the days off.
- Assignments and grades. Tasks, due dates, and grades. Some are typed in by the family. Others are read from a calendar feed you added, off a screenshot somebody uploaded, or from a connected Canvas account. Soar only reads from a calendar feed and from Canvas coursework; it never writes back to either.
- Calendar feeds and events. Calendar addresses the family adds, and the events on your calendar: ones entered in Soar, ones read from those addresses, and ones read from a connected school account. A repeating event is kept as the pattern it follows.
- School account connections. If you connect a school account like Canvas, Soar keeps the connection itself: the school's Canvas address, your Canvas user id, the sign-in tokens needed to stay connected (stored encrypted, and never shown to anyone), when they expire, and how the last sync went. For a parent's connection it also keeps which Canvas child maps to which Soar student, and whether grades are included.
- Uploaded screenshots. A family member can choose to upload a photo or screenshot of a grades page or a syllabus so the app can read the details off it. Nothing is captured automatically. Soar keeps the record of the upload and everything it read off the picture.
- Work plans and how the work went. The plan for a piece of work and its stages. The check-ins recorded against a piece of work: the answer given, who gave it (the student, a parent, or Canvas), and when it was asked and answered. And timer sessions: what was planned, how long it ran, any pauses, how it ended, and whether a parent asked to be told.
- Getting to know you. The questions Soar asks about how a student works, and the answers. Every answer is stored with who gave it, because a student’s own answers and a parent’s answers about the student are kept apart and never merged. The questionnaires Soar shows today ask the student. Soar also keeps, for each set of questions, whether it was finished or passed on.
- Encouragement activity. Small "keep going" signals like streaks, journey progress, rewards and celebrations. Most are generated inside the app from what the student does in it; some come from a parent acting on the student's behalf, or automatically from a connected Canvas account. Soar also keeps whether a reward was approved and any note left with it, records of quiet stretches and returns, and the settings that control how much encouragement to give.
- Alerts and reminders. Rules for when Soar should say something, and the reminders it has sent, including whether the student started a timer, dismissed the reminder, or ignored it. Alerts when a grade crosses a number you chose, and alerts when a student has been quiet for a while. And whether the person who should see an alert has seen it.
- Who has access. Every person invited to see a student's Soar, their role, and whether that invitation is pending, accepted or removed.
- Agreement records. When a grown-up sets up a child's account, Soar keeps a dated record of what they agreed to: who agreed, who it was about, when, and the exact sentences they were shown. A record like this is kept so that months later, either side can say plainly what was agreed. It is never used for anything else. The same kind of record is kept when somebody signs themselves up, and when an account close is requested: who asked, who it was about, when, and the exact sentences they were shown. Because their whole purpose is to survive a disagreement, these are kept even after the account itself is deleted.
The five ways data leaves Soar
We have inspected the code for ways information can travel outside Soar's database and found five. Three are things Soar sends. Two are places Soar fetches from, at your request, using an address or an account you gave it.
- A screenshot you choose to upload. That one image is sent to Anthropic, the company that makes the AI called Claude, so its software can read the words and numbers off it. This happens only because a person pressed a button. Soar sends the image and a class label, not the student's name or account identity. The image travels under Anthropic's commercial terms, which do not permit Anthropic to use it to train its AI models.
- Technical error reports. If the app breaks, a fault report goes to Sentry, an error-monitoring service. Soar also sends Sentry a small sample of ordinary performance traces, and occasional notes about unusual conditions that are not crashes. Its screen-recording feature ("session replay") is switched off on purpose because the users are students. Tightening exactly what these reports may contain is planned before beta.
- Messages from the forms on this website. What you send through the invite and feedback forms travels by email through Resend.
- Your school's Canvas, if you connect it. When you link a Canvas account, Soar reads your courses and assignments from your school's own Canvas site. There are two ways to link one. If you paste a Canvas access token, that token is what Soar keeps and it is sent to your school's Canvas site with every read. If you connect through Canvas's own sign-in instead, connecting sends an authorization code and Soar's own credentials to that Canvas site's sign-in endpoint, staying connected sends the stored refresh token to the same place, and the access token Canvas gives back is sent with every read. Soar never changes your courses, assignments, submissions or grades.
- A calendar feed you add. When you add a calendar address, Soar fetches that address on a schedule to read what is on it. The address itself is what travels. For Canvas and Google calendars that address contains a private token, so it is worth treating like a password. Soar only reads from the feed; it never writes back to it.
Nothing else. No advertising, no analytics, no third-party trackers, and no selling of data. Student data is not sold, ever. Even the app's fonts are served by Soar itself rather than fetched from an outside company.
The truth about AI
The part of Soar that plans the work (what is urgent, what to do tonight) is ordinary, predictable computer code with no AI in it. AI appears at exactly two moments, both started by a person pressing a button to read their own uploaded screenshot: reading assignments off a grades page, and summarizing a reference document like a syllabus. No AI runs on its own, in the background, or over a student's data without someone asking. AI-assisted coaching is a hope for the future, not a feature today, and it will not be built without its own privacy review first.
What happens to uploaded screenshots
A grades screenshot is held only long enough for you to check what the app read off it. The moment you confirm the results, or if the reading fails or you cancel, the image itself is deleted from the database. What the app read off the picture is kept, including any rows you chose not to use. One honest exception: reference screenshots, like a photo of a syllabus, are currently kept and are not yet deleted on a schedule. Scheduled deletion for those is planned before beta.
On Anthropic's side, the commercial API deletes inputs and outputs within 30 days by default. Content flagged by Anthropic's automated safety systems can be held longer, and legal holds can override deletion. Soar plans to move to Anthropic's stricter zero-data-retention setting, which is arranged per organization, before beta.
How accounts are protected
Soar controls how accounts are created, and what is required right now is shown on the sign-up page itself. Passwords are stored with bcrypt, a long-standing industry-standard one-way scramble, at a strong setting. Sign-in attempts are rate-limited. The app re-checks what each person is allowed to see on every single request, so removing someone's access takes effect on their next click. A coach or tutor can view and add notes, and nothing more: the server itself refuses their edits. All traffic runs over HTTPS. None of this makes a breach impossible, and we will not claim that; it names the specific mechanisms in place.
Where data lives
Soar's app and its single database run on Railway, a hosting company, in the United States.
Ages: 13 and older
Soar is a 13-plus service. It is not directed to children under 13, and Soar controls how accounts are created, and what is required right now is shown on the sign-up page itself. If we learn that a user is under 13, we will either obtain verifiable parental consent or delete that child's data, following a documented process. For any student under 18, the parent or guardian is the contracting party.
Your choices: seeing, correcting, exporting, deleting
- See who has access. The team screen lists every person with access to a student and their role. A student removes a coach or tutor from that screen, and a coach or tutor can never remove anybody. Once removed, the next time that person's browser asks Soar for anything of the student's, Soar checks the link again and refuses.
- Correct. Planner data can be edited directly in the app. For anything you cannot reach, email us.
- Export and delete. A "Download my data" link is in the app today, on your own account page, and on the family screen beside a child whose account you are able to close. It hands back one file holding your planner, and it says in the file what it does and does not include. To close an account, you raise a request in the app; we tell you we have it and roughly when it will be done, and we complete it on a written procedure. You can still ask for either by email instead. After a deletion, copies can linger for a short while in routine backups and in crash reports, for their normal retention periods, before disappearing from those too.
The forms on this website
Two forms on this website are for grown-ups getting in touch. They are separate from the app and touch none of a student's planner data.
- Asking for an invite. Your name, email address, phone number, the school your student attends, how many students would use Soar, and anything you choose to add. We use it to reply to you and to set up an account if you go ahead.
- Sending feedback. What happened, what you expected instead, and an email address only if you want a reply.
What you send travels by email through Resend, a message-delivery company listed on the subprocessors page. It is never sold, never used for advertising, and never used to build an audience anywhere. We keep it only as long as it takes to answer you and get you set up. Ask us to delete it at any time and we will.
The companies that touch data
Soar relies on a small number of outside companies to run: the host, the AI provider, the error monitor, and the company that delivers email from the forms on this website. Each one, and exactly what it sees, is listed on the subprocessors page. That list is updated before any new company is added. For example, when a password-reset feature ships it will need an email provider, and that provider will be named there first.
If something goes wrong
No honest service claims zero risk. If a breach of student data is confirmed, we commit to prompt, plain-language notification of affected families. Our reporting plan is written to line up with the 72-hour notice standard used in school data agreements and with Ohio's breach-notification law. A written incident-response plan is part of the work scheduled before beta.
If Soar ever winds down
If Soar were ever to stop operating, families would not be left stranded: we commit to advance notice, a window to export your data before any shutdown, and verified deletion of student data afterward.
Changes to this policy
This policy is versioned and dated at the top. If it changes in a way that matters, families with accounts will be told directly, not just by a quiet edit.
Contact
Questions, corrections, export or deletion requests, or a concern about a child's account: email hello@soar-ef.com.