Trust

Security & Data Practices

This page is maintained by Aluma to answer common security and privacy questions about the product. It describes the controls currently in place, not a third party certification.

Authentication

  • Passwords are hashed with PBKDF2 and never stored in plain text.
  • Sessions use signed cookies with expiry.
  • Account deletion removes account data from our primary storage.

Connected school and productivity accounts

  • Connections use OAuth. Aluma never sees or stores your school password.
  • OAuth tokens are encrypted at rest and used only to read the scopes you authorized.
  • Aluma does not write into your school documents or submit assignments on your behalf.
  • You can disconnect any connector at any time from Settings.

Hosting and transport

  • Hosted on Cloudflare with DDoS protection and TLS in transit.
  • Application data stored in managed Postgres with encryption at rest.

AI providers and content handling

  • Tutoring replies are generated using third party model providers, currently Anthropic's Claude API. Your messages are sent to the provider to produce responses, subject to their terms.
  • Aluma does not use your private conversations to train models.

Subprocessors

  • Anthropic — model inference (Claude API).
  • Stripe — payment processing.
  • Cloudflare — hosting, CDN, DDoS protection.
  • School and productivity platforms you connect (Google, Canvas, Schoology, Blackboard, Notion, and others) — scoped to what you authorize.

Shared responsibility

Aluma is responsible for the platform controls above. Students and families are responsible for the accounts they choose to connect, the content they upload, and keeping their login credentials safe.

Reporting a vulnerability

Please report suspected security issues to security@aluma.fun. We aim to acknowledge reports within a few business days.

Certifications

Aluma does not currently hold independent security certifications such as SOC 2 or ISO 27001. As the company grows we plan to pursue relevant certifications and will publish updates here.