Legal
Privacy Policy
Last updated August 20, 2026
Who we are
Beacon Education (“Beacon”, “we”, “us”) provides instructional coaching software for school leaders at beaconcoach.us. This policy explains what we collect, why, how long we keep it, and how to get it back or have it erased. It applies to the Beacon web application and to this website.
Questions, requests and complaints: privacy@beaconcoach.us.
Who the data belongs to
When a school uses Beacon, the school is the owner and controller of the observation record. We are a service provider acting on the school’s instructions. We do not sell school data, we do not rent or share it for advertising, and we do not use it to train artificial intelligence models.
What we collect
- Account information — name, work email address, school, and role. Collected when an invited user creates an account.
- Roster information — the teacher names, departments, grade levels and assignments a school imports so observations can be attributed.
- Observation evidence — notes, photographs, audio and video recorded by an observer during a classroom visit, together with transcripts generated from those recordings.
- Coaching records — the analyses Beacon produces, conversation notes, agreed next steps and goal history.
- Your evaluation instrument — the walkthrough or evaluation form a school uploads, and the structure Beacon reads from it: domains, indicators, descriptors and rating scale. Used only for that school.
- Google account data — only if a user chooses to connect Google Calendar. See the section below.
- Billing information — plan, subscription status and invoices. Card numbers are handled entirely by Stripe and never reach our servers.
- Operational logs — IP address, browser type, timestamps and error traces, kept to keep the service secure and working.
Student data
Beacon is designed around adult professional practice, not student records. We ask observers not to enter student names or identifiers. Evidence captured in a live classroom — a photograph of the board, a recording of a discussion — may nonetheless incidentally include student voices or work.
We treat that material as a school record under the school’s control. We act as a school official with a legitimate educational interest under FERPA (34 CFR § 99.31(a)(1)), we use the material only to deliver the service the school asked for, and we do not disclose it to anyone else except the subprocessors listed below. Audio and video recordings are automatically and permanently deleted 30 days after capture.
Ratings and professional judgment
Where a school has uploaded its own evaluation instrument, Beacon may propose a rating for an indicator and show the evidence and reasoning behind it. That proposal is a draft for the observing principal. It is not stored as the school’s rating, is not disclosed to the teacher, and is not included in any export or report unless a principal has selected a rating themselves.
Beacon does not make employment decisions and is not a system of record for evaluation. Ratings, evaluation outcomes, and any personnel action remain the responsibility of the school and its evaluators under the school’s own collective bargaining agreement, board policy, and state requirements. Where the evidence is thin, Beacon declines to propose a rating rather than guessing.
An uploaded instrument is visible only to the school that uploaded it. It is not shared with other schools and is not used to train artificial intelligence models.
Google user data and Limited Use
Connecting Google Calendar is optional and can be revoked at any time. When a user connects it, Beacon requests read-only access to calendar events through the scope https://www.googleapis.com/auth/calendar.events.readonly . Beacon does not request Google profile or email scopes for this integration.
- We read event titles, times, locations and attendees only to show the user’s upcoming schedule inside Beacon and to match events to teachers on the roster.
- We store the minimum needed for that: an encrypted OAuth refresh token, and the event fields shown in the app. We do not copy the whole calendar into permanent storage.
- We never write to, modify or delete anything in Google Calendar.
- We do not transfer Google user data to third parties, except as necessary to provide the feature, comply with law, or as part of a merger with prior notice.
- We do not use Google user data for advertising, and we do not use it to develop, improve or train generalized artificial intelligence models.
- No human at Beacon reads Google user data except with explicit permission for support, when required by law, or for security investigation.
Beacon’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect Google Calendar in Beacon under Settings, which deletes the stored token and the cached events. You can also revoke access at any time from myaccount.google.com/permissions.
How we use what we collect
- To operate the service: authentication, rosters, observations, analyses and coaching history.
- To generate an instructional read of an observation using the AI providers named below.
- To send transactional email you asked for — confirmations, trial notices, the weekly digest, billing receipts.
- To take payment and manage subscriptions.
- To keep the service secure, debug failures and prevent abuse.
- To read the structure of an evaluation instrument a school uploads, so evidence can be organised under that school’s own indicators.
- To propose a rating against those indicators where the evidence supports one. A proposal is not a rating: it is shown to the observing principal, is not stored as a rating, is not visible to the teacher, and does not appear in any export unless the principal selects a rating themselves.
We do not use school data for marketing to anyone other than the account holder, and we do not profile students.
Subprocessors
Beacon runs on a small, deliberate set of vendors. Each is bound by contract to process data only on our instructions.
- Vercel — application hosting (United States).
- Supabase — database, authentication and file storage (United States).
- Anthropic — generates the coaching analysis from observation evidence. Content sent through the API is not used to train models.
- OpenAI — speech-to-text transcription of recordings. API content is not used to train models.
- Stripe — payment processing and invoicing.
- Resend — transactional email delivery.
- Google — calendar data, only where a user has connected it.
How long we keep it
- Audio and video recordings: permanently deleted 30 days after capture, by an automated sweep.
- Transcripts, notes, analyses and coaching history: kept while the account is active, because their value is the trend over time.
- Account and billing records: kept while the account is active and for as long afterwards as tax and accounting law requires.
- Operational logs: up to 90 days.
- After an account is closed, school data is deleted within 30 days of a written request, and within 12 months otherwise.
Security
Data is encrypted in transit with TLS and at rest by our hosting providers. Access is scoped per school by database row-level security, so one school cannot see another’s records. Internal access is limited to the people who need it to run the service, and is logged.
Your rights
A school administrator may request a copy of their school’s data, correct it, or ask us to delete it. Individual users may request access to, correction of, or deletion of their own account information. Write to privacy@beaconcoach.us and we will respond within 30 days. Deletion requests that conflict with a school’s own record-retention obligations are referred to the school.
Cookies
Beacon sets a session cookie so you stay signed in. That is the only cookie we require. We do not use advertising cookies or third-party trackers on this site.
Children
Beacon is a tool for school employees. We do not knowingly create accounts for anyone under 18 and we do not market to children.
Changes to this policy
If we change this policy in a way that materially affects how school data is handled, we will email account administrators before the change takes effect and update the date at the top of this page.
Contact
Beacon Education — privacy@beaconcoach.us — Nebraska, United States.