Privacy policy
Version 1.1 · August 2026
Soar is a personal planner and study coach for one student's schoolwork. It is in early access: there is no public sign-up, and accounts exist only by family invitation. For a student under 18, the parent or guardian is the contracting party. This policy says plainly what Soar holds, where data can go, and what is still being built. Where something is planned rather than built, we say so.
What Soar collects
Everything Soar holds sits in one database. It comes to five things:
- Account basics. A display name, an email address, and a password stored only as a one-way scramble (a "hash"), never as text.
- Classes and teachers. Class names and details like a teacher's name or a late-work policy, entered by the family.
- Assignments and grades. Tasks, due dates, and grades. These are typed in by the family or read from a calendar feed the family already has. Soar only reads from that feed; it never writes back to it.
- Uploaded screenshots. A family member can choose to upload a photo or screenshot of a grades page or a syllabus so the app can read the details off it. Nothing is captured automatically.
- Encouragement activity. Small "keep going" signals like streaks and gentle nudges, generated inside the app from what the student does in it.
The only three ways data leaves Soar
We have inspected the code for ways information can travel outside Soar's database and found exactly three.
- A screenshot you choose to upload. That one image is sent to Anthropic, the company that makes the AI called Claude, so its software can read the words and numbers off it. This happens only because a person pressed a button. Soar sends the image and a class label, not the student's name or account identity. The image travels under Anthropic's commercial terms, which do not permit Anthropic to use it to train its AI models.
- Technical error reports. If the app breaks, a fault report goes to Sentry, an error-monitoring service. Its screen-recording feature ("session replay") is switched off on purpose because the users are students. Tightening exactly what these reports may contain is planned before beta.
- Nothing else. No advertising, no analytics, no third-party trackers, and no selling of data. Student data is not sold, ever. Even the app's fonts are served by Soar itself rather than fetched from an outside company.
The truth about AI
The part of Soar that plans the work (what is urgent, what to do tonight) is ordinary, predictable computer code with no AI in it. AI appears at exactly two moments, both started by a person pressing a button to read their own uploaded screenshot: reading assignments off a grades page, and summarizing a reference document like a syllabus. No AI runs on its own, in the background, or over a student's data without someone asking. AI-assisted coaching is a hope for the future, not a feature today, and it will not be built without its own privacy review first.
What happens to uploaded screenshots
A grades screenshot is held only long enough for you to check what the app read off it. The moment you confirm the results, or if the reading fails or you cancel, the image is deleted from the database. Only the numbers you approved are kept. One honest exception: reference screenshots, like a photo of a syllabus, are currently kept and are not yet deleted on a schedule. Scheduled deletion for those is planned before beta.
On Anthropic's side, the commercial API deletes inputs and outputs within 30 days by default. Content flagged by Anthropic's automated safety systems can be held longer, and legal holds can override deletion. Soar plans to move to Anthropic's stricter zero-data-retention setting, which is arranged per organization, before beta.
How accounts are protected
Nobody can sign up off the street. Accounts come only from a single-use family invitation code that expires after seven days. Passwords are stored with bcrypt, a long-standing industry-standard one-way scramble, at a strong setting. Sign-in attempts are rate-limited. The app re-checks what each person is allowed to see on every single request, so removing someone's access takes effect on their next click. A coach or tutor can view and add notes, and nothing more: the server itself refuses their edits. All traffic runs over HTTPS. None of this makes a breach impossible, and we will not claim that; it names the specific mechanisms in place.
Where data lives
Soar's app and its single database run on Railway, a hosting company, in the United States.
Ages: 13 and older
Soar is a 13-plus service. It is not directed to children under 13, and the invite-only door means a stranger of any age cannot create an account. If we learn that a user is under 13, we will either obtain verifiable parental consent or delete that child's data, following a documented process. For any student under 18, the parent or guardian is the contracting party.
Your choices: seeing, correcting, exporting, deleting
- See who has access. The team screen in the app lists every person with access to a student and their role. Access can be revoked there, and revocation takes effect immediately.
- Correct. Planner data can be edited directly in the app. For anything you cannot reach, email us.
- Export and delete. Today, a family asks by email and we handle deletion or export by hand, promptly. An in-app "download my data" export and a "delete my account" button with a short undo window are planned before beta. After a deletion, copies can linger for a short while in routine backups and in crash reports, for their normal retention periods, before disappearing from those too.
The forms on this website
Two forms on this website collect information from adults, not from students. They are separate from the app and touch none of a student's planner data.
- Asking for an invite. Your name, email address, phone number, the school your student attends, how many students would use Soar, and anything you choose to add. We use it to reply to you and to set up an account if you go ahead.
- Sending feedback. What happened, what you expected instead, and an email address only if you want a reply.
What you send travels by email through Resend, a message-delivery company listed on the subprocessors page. It is never sold, never used for advertising, and never used to build an audience anywhere. We keep it only as long as it takes to answer you and get you set up. Ask us to delete it at any time and we will.
The companies that touch data
Soar relies on a small number of outside companies to run: the host, the AI provider, and the error monitor. Each one, and exactly what it sees, is listed on the subprocessors page. That list is updated before any new company is added. For example, when a password-reset feature ships it will need an email provider, and that provider will be named there first.
If something goes wrong
No honest service claims zero risk. If a breach of student data is confirmed, we commit to prompt, plain-language notification of affected families. Our reporting plan is written to line up with the 72-hour notice standard used in school data agreements and with Ohio's breach-notification law. A written incident-response plan is part of the work scheduled before beta.
If Soar ever winds down
If Soar were ever to stop operating, families would not be left stranded: we commit to advance notice, a window to export your data before any shutdown, and verified deletion of student data afterward.
Changes to this policy
This policy is versioned and dated at the top. If it changes in a way that matters, families with accounts will be told directly, not just by a quiet edit.
Contact
Questions, corrections, export or deletion requests, or a concern about a child's account: email ceo@executive-os.ai.