Trust Center

How we handle student data

This page summarizes our Data Security Overview in plain language, for district curriculum leaders and IT reviewers. Questions are welcome athello@yilmazeducation.com.

Data minimization

Student data is limited to first name, last name, grade level, class assignment, and assessment scores — nothing else. We collect no demographic data, and students never create accounts or log in.

Student data is never sold, never used for advertising, and never used to train AI models.

Infrastructure

Literacy Assessments runs on Google Cloud/Firebase in U.S. data centers. Data is encrypted in transit with TLS 1.2+ and at rest with AES-256.

Access controls

Access is role-based — Administrator, Teacher, Teaching & Learning Specialist, and Educational Assistant — and enforced server-side by security rules. An automated test suite runs against those rules on every deployment.

The AI narrative feature

The AI narrative feature is optional and off by default, pending district sign-off. When a district enables it, assessment data is de-identified server-side before any of it reaches the AI provider, and the provider does not train on the data.

Compliance documents

Our Data Privacy Agreement is structured to mirror the A4L National Data Privacy Agreement (NDPA) v2.2 and is available on request:request the DPA.

Everything in the Trust Center