Privacy Policy
Last updated: February 26, 2026
1. Introduction
Education Management Studio (d/b/a “EMStudio Pro,” “we,” “us,” or “our”) operates the EMStudio Pro platform, an education management application for teachers, private tutors, and educators. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform.
By accessing or using EMStudio Pro, you agree to the terms of this Privacy Policy. If you do not agree, please do not use the platform.
2. Information We Collect
2.1 Account Information
When you create an account, we collect your email address, name, and authentication credentials. Accounts are managed through our authentication provider (Supabase Auth).
2.2 Student and Education Data
As an educator, you may enter student information into the platform, including:
- Student names and identifiers
- Class enrollment and schedule information
- Grades, assignments, and assessment scores
- Attendance records
- Report cards and progress reports
- Lesson plans and instructional materials
This information constitutes “education records” under the Family Educational Rights and Privacy Act (FERPA). You are responsible for ensuring you have the authority to enter this data into the platform. See our FERPA Compliance page for more details.
2.3 File Uploads
You may upload files such as PDFs, images, and documents to attach to lessons, assignments, and other entities. These files are stored securely in Cloudflare R2 object storage. We store metadata about each file, including file name, size, content type, and the entity it is associated with.
2.4 Usage Data
We may automatically collect certain information about your device and how you interact with the platform, including IP address, browser type, operating system, pages visited, and timestamps. This data helps us maintain and improve the service.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the EMStudio Pro platform
- Authenticate your identity and manage your account
- Enable you to create and manage classes, students, lessons, grades, attendance records, and report cards
- Store and serve your uploaded files securely via presigned URLs
- Send transactional communications related to your account (e.g., password resets, security alerts)
- Monitor and analyze usage patterns to improve the platform
- Detect, prevent, and address technical issues and security threats
- Comply with legal obligations
4. Data Storage and Security
We take the security of your data seriously and implement industry-standard measures to protect it:
- Database: All structured data (profiles, classes, students, grades, attendance, etc.) is stored in a PostgreSQL database hosted by Supabase with encryption at rest.
- Row-Level Security (RLS): Every database table enforces Row-Level Security policies, ensuring that each user can only access their own data. No user can view, modify, or delete another user's records.
- File Storage: Uploaded files are stored in Cloudflare R2, an S3-compatible object storage service with encryption at rest. Files are accessed through time-limited presigned URLs.
- Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS/SSL (HTTPS).
- Authentication: User authentication is managed through Supabase Auth with secure session management.
While we strive to use commercially acceptable means to protect your data, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
5. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information or student data to third parties. We may share information only in the following circumstances:
- Service Providers: We use trusted third-party services to operate the platform, including Supabase (database and authentication) and Cloudflare (file storage and content delivery). These providers process data solely on our behalf and are contractually obligated to protect it.
- Legal Requirements: We may disclose your information if required to do so by law, regulation, legal process, or governmental request.
- Safety: We may disclose information when we believe in good faith that disclosure is necessary to protect the rights, property, or safety of our users or the public.
- Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
6. Student Data and Children's Privacy
EMStudio Pro is designed for use by educators, not directly by students. Students do not create accounts or interact with the platform. Educators enter student data into the platform as part of their professional duties.
FERPA Compliance: We recognize that student education records are protected under FERPA. We act as a “school official” with a legitimate educational interest as defined by FERPA when processing student data on behalf of educators. See our FERPA Compliance statement for full details.
COPPA: EMStudio Pro does not knowingly collect personal information directly from children under the age of 13. All student data is entered by authorized educators. If you believe a child has directly provided us with personal information, please contact us immediately so we can remove it.
Educator Responsibility: As the educator, you are responsible for ensuring you have proper authorization (e.g., directory information designation, parental consent, or school official exception) to enter student data into EMStudio Pro.
7. Data Retention and Deletion
We retain your data for as long as your account remains active or as needed to provide you with our services. Specifically:
- Account Data: Retained until you delete your account.
- Education Records: Retained until you delete them or delete your account. You can delete individual students, classes, grades, attendance records, and other data at any time through the platform.
- Uploaded Files: Retained until you delete them or delete your account. Files are permanently removed from Cloudflare R2 upon deletion.
- Usage Data: Retained in aggregate form for analytics purposes. Individual usage logs are automatically purged after 90 days.
To delete your account and all associated data, please contact us at info@emstudio.pro. Upon receiving a verified deletion request, we will delete your data within 30 days. Some data may be retained in backups for up to 90 additional days before being permanently purged.
8. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal information:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete data. You can also update most information directly through the platform.
- Deletion: Request deletion of your personal information, subject to legal retention requirements.
- Data Export: Request a machine-readable export of your data.
- Opt-Out: Opt out of non-essential communications at any time.
- Restriction: Request that we limit the processing of your data in certain circumstances.
To exercise any of these rights, please contact us at info@emstudio.pro. We will respond to your request within 30 days.
9. Cookies
EMStudio Pro uses cookies for essential platform functionality, primarily for authentication and session management. For detailed information about what cookies we use and how to manage them, please see our Cookie Policy.
10. International Data Transfers
Your information may be transferred to and processed in countries other than the country in which you reside. Our service providers, including Supabase and Cloudflare, operate data centers in multiple regions. These providers maintain appropriate safeguards for international data transfers in compliance with applicable data protection laws. By using EMStudio Pro, you consent to the transfer of your information to these facilities.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by posting the updated policy on this page with a revised “Last updated” date. For significant changes that affect how we handle student data, we will also notify you via email. Your continued use of EMStudio Pro after any changes constitutes acceptance of the updated policy.
12. Contact Information
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
Education Management Studio
d/b/a EMStudio Pro
Email: info@emstudio.pro