Skip to content

Privacy Policy

Effective Date: May 15, 2026 · Last Updated: May 15, 2026

Phareon LLC ("Phareon," "we," "us," or "our") operates LessonDeck (the "Service"), an AI-powered lesson planning platform for K-12 educators, available at www.lessondeck.org. This Privacy Policy describes how we collect, use, disclose, and protect your information when you use the Service.

By creating an account or using LessonDeck, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Service.

1. Information We Collect

1.1 Information You Provide

  • Account Information: Name, email address, and password (hashed with bcrypt; we never store plaintext passwords).
  • Profile Information: School or district name, grade level(s), subject area(s), and state (used to align lesson plans with state standards).
  • Payment Information: Billing details processed by our payment processor. We do not store credit card numbers on our servers.
  • Lesson Content: Topics, objectives, and preferences you provide when generating lesson plans.
  • Support Communications: Messages you send to our support team.

1.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, lesson plans generated, exports created, and session duration.
  • Device & Browser Data: IP address, browser type, operating system, device type, and screen resolution.
  • Analytics Data: Collected via our analytics provider with consent mode defaults (see Section 10).
  • Log Data: Server logs including request timestamps, URLs, and response codes.

1.3 Information We Do Not Collect

  • Student personally identifiable information (PII). LessonDeck is a tool for teachers; students do not create accounts.
  • Social Security numbers, government-issued IDs, or biometric data.
  • Precise geolocation data.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the LessonDeck Service.
  • Generate AI-powered lesson plans tailored to your grade level, subject, state standards, and preferences.
  • Process payments and manage subscriptions through our payment processor.
  • Send transactional emails (account verification, password resets, subscription confirmations, and usage alerts).
  • Provide customer support and respond to inquiries.
  • Analyze usage patterns to improve features, fix bugs, and optimize performance.
  • Detect, prevent, and address technical issues and security threats.
  • Comply with legal obligations.

We do not sell your personal information to third parties. We do not use your personal information for third-party advertising.

3. AI-Generated Content & Data Processing

LessonDeck uses third-party artificial intelligence services to generate lesson content. When you request a lesson plan, we send the following to our AI provider:

  • Grade level, subject area, and state you selected.
  • Topic, objectives, and any custom instructions you provide.

Your inputs are transmitted to our AI provider's API for processing. We do not send your name, email address, or other personal identifiers to our AI provider.

We encourage you to review our AI provider's data practices and to avoid including sensitive or personally identifiable information in AI prompts.

4. Sub-Processors & Third-Party Services

We use the following categories of third-party services to operate LessonDeck:

Provider CategoryPurposeData Categories Shared
Cloud hosting and database providersApplication hosting and database storageAccount data, lesson plan content, user-generated text
Payment processorsSubscription billing and payment processingBilling name, email address, payment method details
AI service providersAI-powered lesson plan generationLesson topics, grade level, subject area, state, custom instructions
Email delivery servicesTransactional email deliveryEmail address, message content
Content delivery and security providersPerformance, DDoS protection, and asset deliveryIP address, request metadata
Application hosting providersWeb application deployment and servingApplication code, environment configuration (no user PII directly)
Analytics servicesUsage analytics and product improvementAnonymized/aggregated usage data, page views, session data (with consent)

Each provider is bound by their own privacy policies and data processing agreements. We only share the minimum data necessary for each service to function.

5. Data Storage & Security

We implement industry-standard security measures to protect your data:

  • Encryption in transit: All data is transmitted over TLS 1.2+.
  • Encryption at rest: Database and file storage are encrypted at rest using AES-256.
  • Password hashing: Passwords are hashed with bcrypt and never stored in plaintext.
  • Row-level security: Database RLS policies ensure users can only access their own data.
  • Access controls: Administrative access is restricted to authorized Phareon personnel with multi-factor authentication.
  • Vulnerability monitoring: We monitor dependencies for known vulnerabilities and apply patches promptly.

While we take reasonable steps to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.

6. Data Retention

When you delete your account, we delete or anonymize your personal data within 30 days, except where retention is required by law (e.g., payment records for tax compliance).

7. Your Rights

Depending on your location, you may have the following rights regarding your personal information:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your account and associated data.
  • Export: Export your lesson plans in PDF, DOCX, or PPTX format at any time through the Service.
  • Opt-out: Opt out of non-essential communications via account settings or email unsubscribe links.
  • Restrict processing: Request that we limit how we use your data in certain circumstances.

To exercise any of these rights, contact us at support@lessondeck.org. We will respond to verified requests within 45 days.

8. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) provides you with additional rights. In the preceding 12 months, we have collected the following categories of personal information:

CategoryExamplesBusiness Purpose
IdentifiersName, email, IP addressAccount creation, service delivery
Commercial informationSubscription tier, payment historyBilling, subscription management
Internet/network activityPages visited, features used, session dataAnalytics, service improvement
Professional informationSchool name, grade level, subject areaLesson plan personalization

As a California resident, you have the right to:

  • Know what personal information we collect and how it is used.
  • Delete your personal information (subject to legal exceptions).
  • Opt out of sale or sharing. We do not sell or share your personal information as defined under the CCPA/CPRA.
  • Non-discrimination. We will not discriminate against you for exercising your privacy rights.

To submit a CCPA request, email support@lessondeck.org with the subject line "CCPA Request."

9. FERPA Considerations

LessonDeck is designed for teachers, not students. We do not collect student personally identifiable information (PII), and students do not create accounts on our platform. Teachers are the sole users of the Service.

While teacher-created lesson plans may reference curriculum topics, grade levels, or general classroom contexts, they should not contain student PII. We advise teachers not to include student names, grades, or other identifying information in lesson plan prompts.

If your school or district requires a Data Processing Agreement (DPA) or Student Privacy Pledge compliance documentation, please contact us at support@lessondeck.org.

10. Cookies & Tracking Technologies

LessonDeck uses the following cookies and tracking technologies:

Cookie/TechnologyTypePurposeDuration
Authentication tokenEssentialAuthentication & session managementSession / 7 days
Payment processor sessionEssentialPayment processingSession
Analytics cookiesAnalyticsUsage analytics & reportingUp to 2 years
Cookie consent preferenceEssentialStores your cookie consent choice1 year

Analytics Consent Mode: Our analytics provider is configured with consent mode defaults set to analytics_storage: denied. This means analytics cookies are not set until you provide explicit consent. Without consent, only cookieless, aggregated data is collected (pings without identifiers).

You can manage cookie preferences through your browser settings. Disabling essential cookies may prevent you from using certain features of the Service.

11. International Users

LessonDeck is operated from the United States. If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States.

We are GDPR-aware but do not currently maintain full GDPR compliance infrastructure (e.g., EU-based data processing, appointed EU representative). If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, please be aware that U.S. data protection laws may differ from those in your jurisdiction.

If we begin to actively target or significantly serve users in the EEA, we will update this policy to reflect full GDPR compliance measures including lawful basis for processing, data protection impact assessments, and appointment of a Data Protection Officer as required.

12. Children's Privacy

LessonDeck is intended for use by teachers and educators who are 18 years of age or older. We do not knowingly collect personal information from children under 13 (or under 16 in certain jurisdictions). Student accounts are not supported.

If we learn that we have collected personal information from a child under 13 without parental consent, we will delete that information promptly. If you believe a child has provided us with personal information, please contact us at support@lessondeck.org.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date at the top of this page and post the revised policy here.

When we make material changes to how we handle your personal data, we will notify you by email.

Your continued use of the Service after the updated policy is posted constitutes your acceptance of the changes.

14. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

Phareon LLC

9111 Cross Park Drive Suite D200

Knoxville, TN 37923

Email: support@lessondeck.org

Website: www.lessondeck.org

For CCPA requests, email support@lessondeck.org with the subject line "CCPA Request."

For FERPA or school district inquiries, email support@lessondeck.org with the subject line "FERPA/District Inquiry."