Last updated 6 September 2026
Bluestift builds Raya, an AI tutor for students, and a companion dashboard for schools. This page explains what we hold, why we are allowed to hold it, how long we keep it, and what you can do about it. It is written to be read, not to be survived.
We ask everyone the year they were born. We store the year, never a full date of birth, and we ask it neutrally rather than as “are you over 13?” — a question phrased that way just tells a child which answer opens the door.
Under 13. We operate no verifiable parental consent mechanism of our own. Where a school adopts Bluestift, it consents on the parent's behalf for school use, which is the exception COPPA provides at 16 CFR § 312.5(c)(6). A child who signs up alone can use Raya, on an account we hold to the strict minimum: no email is required, no analytics ever runs, their work is never used to improve models, they cannot join public study rooms, and nothing can be bought from the account without an adult confirming they are the parent or guardian paying. We do not claim a consent we have not obtained — a parent can see, correct or delete the child's data at any time, below.
Under 18. Optional processing is off and cannot be switched on: no product analytics, and no use of their content to improve models. That is stricter than the law strictly requires in some countries — GDPR art. 8 sets the age of digital consent between 13 and 16 depending on the member state — and we would rather be too careful with a 17-year-old than not careful enough with a 13-year-old.
Parents. You can ask to see, correct or delete your child's data. If they use Bluestift through a school, the fastest route is the school, which can produce their record directly. Either way, write to hello@thebluestift.com and we will help.
“Legal basis” is the GDPR term for what entitles us to hold something at all. Where it says contract, the product cannot work without it. Where it says consent, you chose it and can un-choose it.
| What | Why | Legal basis |
|---|---|---|
| Account — a random identifier, a username, a display name, and an email address or profile picture if you add one | To have an account at all, and to get you back into it | Contract |
| Year of birth | To apply the age rules above | Legal obligation |
| Your conversations, uploads and generated study material | To tutor you, and to let you come back to your work | Contract |
| Learning signals — what you've worked on and where you struggle | To adapt the tutoring, and to show your teachers class-level progress | Contract |
| School enrolment — your real name, class and year, held for your school | So your school can identify you in its own dashboard | Contract (with your school) |
| Product analytics | To see which features actually help | Consent — off until you accept, never for under-18s |
| Using your content to improve our models | To make the tutor better | Consent — on by default on adult accounts, switchable off at any time; off until you switch it on if your account is linked to a school; never for under-18s |
| Sending your progress to your school | So your teachers can see who is stuck and on what | Contract (with your school) — only while your account is linked to one |
| Server logs and a coarse network signal | To stop spam, abuse and runaway automated sign-ups | Legitimate interests |
| Payment records | To take payment and keep the books | Contract / legal obligation |
We do not use your content to advertise to you, and we do not sell or share personal information in the sense US state privacy laws give those words.
To tutor properly, Raya maintains a model of your understanding — which concepts you have grasped, how confidently, and how you tend to approach difficulty. You do not see this model in the interface, which is exactly why it is included in full in the data export below. It is yours to look at.
Product analytics is provided by PostHog and is strictly opt-in. Until you accept the banner, the analytics library is never even downloaded — no events, on your device or on our servers. If you accept, we record page views and a few product actions tied to your account identifier, so we can measure real usage. You can decline and use everything.
You can withdraw that consent whenever you like from your settings, with one switch. It is as easy to withdraw as it was to give, which is what art. 7(3) asks for.
Cookies are minimal: one to keep you signed in, one to remember your analytics choice so we stop asking, one each for your language and theme, one to remember which school you are looking at if you belong to several, and a short-lived one while a school connects Google Classroom. There are no advertising or cross-site tracking cookies.
A short list, each one only for what it is named for. The current sub-processors, with what they hold and where, are on the sub-processors page, which we keep up to date as they change.
Text you send to Raya is processed by large-language-model providers to generate a reply. We use them on their API terms, which do not feed that content into training of their public models.
Some of these providers operate outside the EEA and the UK. Those transfers need to be covered by the European Commission's Standard Contractual Clauses or an adequacy decision, and we are working through that provider by provider as a newly launched company. The sub-processors page says where we are rather than claiming it is finished.
| What | How long |
|---|---|
| Your account and its content | While the account is active |
| Anonymous accounts that go unused (no email added, no school) | Deactivated after 60 days of inactivity, deleted after 180 |
| School records | For the school's contracted term, then returned or destroyed at its instruction |
| Payment records | As long as accounting and tax rules require |
| The log that a data request happened | Kept after the data itself is deleted — it is the proof we deleted it |
When you delete your account, we delete the account, your conversations, your uploads, your results and the cognitive profile — including the parts of it held in systems that no automatic cascade would have reached. Payment records survive, because art. 17(3)(b) requires them to.
If you are in the EU, the UK or a US state with a privacy law, you have rights of access, correction, deletion, portability, and objection to certain processing, and you may withdraw consent at any time. Two of those are wired straight into the product:
For anything else — a correction, an objection, a question about the year of birth on file — write to hello@thebluestift.com. We do not charge for any of this, and we do not treat you differently for asking. If you are in the EEA or the UK you can also complain to your national data protection authority.
When a school adopts Bluestift, the school decides what is collected about its students and we act on its instructions — it is the controller, we are the processor. In US terms we act as a school official with a legitimate educational interest under FERPA (34 CFR § 99.31(a)(1)): we use student data only to provide the service, we do not re-disclose it, and we return or destroy it when the contract ends. The terms are set out in the data processing addendum.
Staff see their own classes, not the school at large. A parent exercising the FERPA right to inspect and review their child's record asks the school, which can produce it from its dashboard.
One thing that record deliberately leaves out: a student's own conversations with Raya. A tutor you believe is being read over your shoulder is a tutor you stop asking real questions of, and the tutoring stops working. Those conversations are available in full through the student's own export.
We will update this page when our practices change and revise the date above. Questions, requests, or concerns: hello@thebluestift.com.