Trust Center
How we handle student data
This page summarizes our Data Security Overview in plain language, for district curriculum leaders and IT reviewers. Questions are welcome athello@yilmazeducation.com.
Data minimization
Student data is limited to first name, last name, grade level, class assignment, and assessment scores — nothing else. We collect no demographic data, and students never create accounts or log in.
Student data is never sold, never used for advertising, and never used to train AI models.
Infrastructure
Literacy Assessments runs on Google Cloud/Firebase in U.S. data centers. Data is encrypted in transit with TLS 1.2+ and at rest with AES-256.
Access controls
Access is role-based — Administrator, Teacher, Teaching & Learning Specialist, and Educational Assistant — and enforced server-side by security rules. An automated test suite runs against those rules on every deployment.
The AI narrative feature
The AI narrative feature is optional and off by default, pending district sign-off. When a district enables it, assessment data is de-identified server-side before any of it reaches the AI provider, and the provider does not train on the data.
Compliance documents
Our Data Privacy Agreement is structured to mirror the A4L National Data Privacy Agreement (NDPA) v2.2 and is available on request:request the DPA.
Everything in the Trust Center
Subprocessors
Every third party that touches data, and under what conditions.
Data requests
How districts and teachers request access, correction, or deletion.
Incident response
Our plan, notification commitments, and post-incident reporting.
Privacy Policy
How we collect, use, and protect data.
Terms of Service
The agreement that governs use of Literacy Assessments.
Accessibility Statement
Our conformance target and how to reach us about barriers.