Monarch AI Logo

Legal

Student Privacy Policy

Effective: September 8th 2026 · Last updated: September 8th 2026 · Version: 1.0

Monarch AI Technologies Inc. (“Monarch”) provides a student-safety platform to schools. Our extension is installed by school administrators on school-managed Chromebooks. This policy explains what it processes, why, who can see it, and how long we keep it.

At a glance

  • We read what a student types and images they add, and only on a short, named list of sites the school has approved.
  • We look for six kinds of safety risk: self-harm, violence, sexual exploitation or grooming, substance use, mental-health crisis, and bullying.
  • We do not capture audio or video, do not read pages the student didn’t write in, and do not read what an AI assistant writes back.
  • We never train AI models on student data — us or any company we work with, without exception.
  • We never sell or rent student data and never use it for advertising.
  • Content is pseudonymized by default. Only authorized school staff — never Monarch employees — can link it to a named student, and every time they do, it’s logged.
  • We delete raw captured content after 30 days.
  • Monarch raises signals. The school decides what happens next.

1. Our role

We work for the school, not for students directly. The school decides whether to use the Service, how to configure it, who may review content, and what to do about anything surfaced. We process student data only on the school’s documented instructions.

Where FERPA applies, the school designates Monarch a School Official with a legitimate educational interest: we perform a function the school would otherwise perform itself, stay under its direct control, use records only for the authorized purpose below, and do not redisclose them.

Because the school holds the records, requests to see, correct, or delete data go to the school (Section 10).

2. What the Service does

Safety detection. We analyze text a student types and images a student adds, on school-approved sites, and flag possible early indicators of risk across the six areas above. Indicators go to authorized school staff for human review.

Site restriction — optional, off unless the school turns it on. A school may enable enforcement of its own restricted-site list and school-hours window. Rules come from the school’s administrator and are applied by the browser. We never inspect network traffic and cannot read the content of blocked sites. Where enabled, we record only per-domain daily counts of blocked attempts — not individual page requests or timestamps.

What it is not. Monarch is a detection and alerting tool. It does not make decisions, is not a mandated reporter, does not discharge the school’s legal duties, and does not guarantee that every risk is detected. It does not replace trained staff.

3. What we process

Student-created content. Only what the student types or adds. Content they did not create is not read, and AI assistant replies are not read.

Where. Content scripts run only on sites named in the manifest: Google Docs, Google Slides, Gmail, Google Search, and the AI assistants Gemini, ChatGPT, and Character.AI. Students increasingly type the things this Service exists to notice into a chatbot rather than a document, where a conventional filter cannot see them. There is no wildcard or all-sites access, and no way to widen the list without a new version Google re-reviews.

When. The extension is active whenever the device is in use, including outside school hours if the device goes home.

Risk assessments. Signals inferred across the six areas, with a confidence score and trend. These belong to the school.

School account address — once, at enrollment only. Read solely to match the device to the school’s roster. The address is never stored; we keep only a keyed one-way hash (HMAC). Never used for email or marketing.

Device identifier. The enterprise directory device ID, so a re-imaged Chromebook keeps a stable identity in the school’s inventory.

Blocked-site counts. Only where site restriction is enabled, as described above.

Access log. A tamper-proof, append-only record of who accessed or re-identified what, and when. Contains no captured content.

4. What we never do

These are contractual obligations in the agreement we sign with every school, and each flows down by written contract to every company handling student data for us.

  • No AI training. We do not use student data — and permit no service provider to use it — to train, test, develop, fine-tune, evaluate, or improve any model, algorithm, or dataset, ours or anyone’s. Every model performs classification only. This is unconditional.
  • No sale or rental. Not to advertisers, data brokers, or anyone.
  • No advertising and no commercial use of student data.
  • No secondary use. We process for one authorized purpose — surfacing safety indicators for human review — and no other.
  • No excess collection. We do not condition participation on more information than is reasonably necessary.
  • No offshore processing. All processing and storage is in United States regions.

5. Pseudonymity and who can see content

Student data is handled by device and serial identifiers and cannot be attributed to a specific student without information the school controls. Re-identification is possible by design — the Service exists to alert staff about a specific child at risk — but only authorized school personnel (typically a principal or vice principal) can perform it, and every re-identification is logged. We do not represent this data as anonymous.

Monarch personnel do not access identifiable content. This is enforced by role-based access controls, and every access is logged.

6. FERPA, COPPA, and consent

The Service processes personal information of children under 13. Consistent with FTC guidance permitting a school to authorize collection of students’ personal information for a school-authorized educational purpose, the school — acting in place of the parent — provides any verifiable parental consent required under COPPA.

We use children’s personal information only for the authorized purpose, never for commercial purposes, and provide access and deletion on authenticated request routed through the school.

Parents: to learn whether your child’s school uses Monarch, how it is configured there, or whether opting out is available, contact the school.

7. Service providers

Each is bound by written contract to protections no less strict than our school agreements, including the no-training prohibition and deletion obligations. All process data in United States regions only.

ProviderRoleNote
Google Cloud (Vertex AI)Hosting and Gemini classificationPaid enterprise tier; provider contractually commits not to train on submitted inputs. Classification only.
Google Gemini (via Vertex AI)Secondary classificationSame enterprise terms and no-training commitment.
RunPodGPU compute for our self-hosted safety modelBound by contractual flow-down obligations.
Meta Llama Guard (self-hosted by Monarch)Safety classificationMonarch-operated instance. Not trained or fine-tuned on student data.

We give schools 30 days’ notice before adding or replacing any provider that processes student data. No AI or inference provider may use student data to train or improve its models.

8. Security

Encryption in transit and at rest · role-based access control with least privilege · multi-factor authentication · tamper-proof audit logging · personnel confidentiality obligations and training · encrypted backups with restore testing · documented incident response · code-review gates and dependency-vulnerability monitoring.

We will not materially reduce security during a school’s term.

9. Retention, deletion, and incidents

  • Raw captured content: deleted after 30 days.
  • Alerts and risk assessments: retained for the term of the school’s agreement, exportable at any time.
  • On termination: full export in a machine-readable format, then certified deletion of all captured content, flagged content, and risk assessments within 30 days.
  • Individual deletion on the school’s request, as state law requires.
  • Exception: the access log is preserved, so the school retains proof the Service was used properly. It contains no captured content.

Security incidents. We notify the school’s designated contact within 72 hours of confirming a breach affecting student data, describing the incident, scope, likely consequences, and measures taken. We do not notify parents or regulators on the school’s behalf except at its written direction or as required by law — if your child’s data were affected, you would hear from the school.

10. Parent and student rights

Parents and eligible students may inspect, review, correct, and in some cases delete student data. Because the school holds the records and can verify identity, requests go to the school. We assist the school in responding, refer any direct request to it, and do not alter or delete data except on the school’s written instruction or as law requires.

Ownership. The school owns raw student data, alerts, flagged content, and identifiable risk assessments. Monarch owns its models and software, developed without training on any school’s student data.

If you’re unsure who to contact at your school, write to us and we’ll point you to the right office.

11. School staff and administrative information

Administrator accounts: name, work email, role, and authentication identifiers — used to operate and secure the account and to contact administrators about the Service. Not used for marketing without consent.

Support communications: correspondence and anything you include in it.

12. Browser extension disclosures

Installed by school administrators via Chrome Admin Console policy on school-managed ChromeOS devices. Not offered for personal installation.

Single purpose: the extension enforces the school’s student-safety policy on school-managed devices — surfacing early indicators of risk in what a student writes for staff review, and, where the school enables it, applying the restricted-site rules the school sets.

PermissionWhy it is required
storageReads the school’s policy from managed storage; holds the outbound queue and device credential locally so captured content isn’t lost while offline.
alarmsFlushes the outbound queue, renews the device credential, and re-evaluates the school-hours window. MV3 service workers terminate between events, so an alarm is the only way to run periodic work.
identity, identity.emailReads the signed-in school account address once, at enrollment only, to match the device to the school’s roster. Admin Console policy applies per organisational unit and is identical across devices in it, so no per-student identifier can be distributed by policy. Address never stored — only a keyed one-way hash. Never used for email or marketing.
enterprise.deviceAttributesReads the enterprise directory device ID so a re-imaged or reassigned Chromebook keeps a stable identity in the school’s inventory. Chrome grants this only to policy-installed extensions on managed ChromeOS, the sole deployment context.
declarativeNetRequestEnforces the school’s restricted-site list and school-hours window where the school has enabled it. Rules come from the school’s authenticated administrator and are applied by the browser. The extension never inspects network traffic and holds no host permission to read blocked sites. declarativeNetRequestFeedback is deliberately not requested.
Content script matchesRuns only on manifest-named sites: Google Docs, Google Slides, Gmail, Google Search, Gemini, ChatGPT, Character.AI. Only what the student types or adds is read; content they did not create is not read, and assistant replies are not read.

Host scope. These sites appear in content_scripts.matches only, not in host_permissions — the service worker holds no fetch or cookie access to them. There is no <all_urls> or wildcard access anywhere in the manifest, and no runtime mechanism to widen the list.

Limited Use. Collection is limited to what is strictly necessary for the single purpose above. We do not sell user data or transfer it for advertising, creditworthiness, or lending. We do not use or transfer it for any unrelated purpose. We do not use or transfer it to train generalized AI models. Human access to identifiable content is limited to authorized school staff. Data is encrypted in transit and at rest.

13. State laws and changes

Our data processing agreement aligns with the National Data Privacy Agreement published by the Student Data Privacy Consortium, and we execute state-specific addenda schools require, which prevail over inconsistent standard terms.

If we materially change how we handle student data, we update this policy, revise the effective date, and notify schools as our agreements require. Adding a service provider requires 30 days’ advance notice.

14. Contact

Monarch AI Technologies Inc.
1178 Broadway, 3rd Floor #1501
New York City, NY 10001

Privacy & Support email: support@monarchai.io

Parents: for records about your own child, contact your school first; they hold the records.