Security & Data Practices
This page is maintained by Aluma to answer common security and privacy questions for students, parents, and schools. It describes the controls currently in place, not a third party certification. See also the Privacy Policy and Terms of Service.
- What do we collect?
- Your account info, the content you create in Aluma, and — only for platforms you connect — the assignment, grade, and schedule data your school account exposes.
- What do we never do?
- We never sell your data, never use private conversations to train models, and never complete or submit schoolwork on your behalf.
- Who can see conversations?
- You. A small number of Aluma support staff may access a conversation only to investigate a bug or a report you send in — never for browsing or marketing.
- How do I delete my data?
- Delete your account anytime from Settings → Data & Privacy, or email privacy@aluma.fun. This removes your data from our primary storage; see Deletion timing below for backups.
Authentication
- Passwords are hashed with PBKDF2 and never stored in plain text.
- Sessions use signed cookies with expiry.
- Account deletion removes account data from our primary storage.
Connected school and productivity accounts
Aluma connects to school and productivity platforms in a few different ways, depending on the platform. We're specific here rather than making one blanket claim:
- OAuth connectors (Google Classroom, Google Calendar, Microsoft 365, Outlook, OneNote, Blackbaud): you sign in with the provider. Aluma never sees your password. The resulting OAuth tokens are stored on Aluma's servers, encrypted at rest.
- Personal-token connectors (Canvas, Schoology, Notion, Slack, Todoist, Linear, Trello, Asana, ClickUp): you paste a token you generate yourself. It is stored on Aluma's servers, encrypted at rest, so web sync can run. It is never shown back to you after saving, and it is deleted when you disconnect.
- Lumi Anywhere school-tab sync (Blackboard today; Edgenuity, PowerSchool, Moodle, Brightspace, Sakai, Edsby, ClassDojo, Seesaw, Gmail, Google Drive, Docebo, TalentLMS, Thinkific, Teachable coming): runs inside a tab in your own Chrome through the Lumi Anywhere extension. That school sign-in stays on your device.
- Machine-local services (Anki, Apple Reminders): unavailable. Their data only exists on your own machine, and neither the web app nor the Chrome extension can reach it.
- Chrome extension: Lumi Anywhere stores an Aluma sign-in token in the extension's local storage, and sends page context to Aluma only when you explicitly attach it.
- Encryption keys: stored tokens are encrypted at rest with encrypt-then-MAC (scrypt-derived key, HMAC-SHA256). Aluma holds the key, so our servers can decrypt them to run sync. We do not claim otherwise.
- Read-only by default: syncing your assignments, grades, and schedule is read-only. Aluma does not edit or submit your schoolwork automatically. The Lumi Anywhere Chrome extension is read-only too: it can read a page to build the snapshot you choose to share, and it cannot type into a page, fill a field, or submit anything.
- The one write-permission exception: only the Autopilot feature can type a drafted answer into a Google Doc, but only after you turn it on for that task and only into a document it has confirmed is your own editable copy. It is opt-in per use, not automatic, and you can turn it off in Settings.
- You can disconnect any connector at any time from Settings.
Hosting and transport
- Application hosted on Render, with Cloudflare in front for DNS, CDN, and DDoS protection. TLS in transit.
- Application data stored in SQLite on an encrypted disk.
AI providers and content handling
- Tutoring replies are generated using third party model providers, currently Anthropic's Claude API. Your messages are sent to the provider to produce responses, subject to their terms. Aluma does not train its own foundation models — Hermes, Athena, and Zeus are tutoring modes built on top of Claude.
- Aluma does not use your private conversations to train models.
Internal analytics
We collect basic product usage data (such as feature usage counts and message volume) to run the Service, enforce plan limits, and understand which parts of the product are working. This is operational analytics, not advertising tracking, and it is not sold or shared with third parties for marketing.
Support staff access to conversations
A small number of Aluma staff can access individual conversations when needed to investigate a bug report, a support ticket, or a safety concern you or a parent raises. Routine, unprompted browsing of student conversations is not part of our process.
Deletion timing
Deleting your account removes your data from our primary, live database immediately. Not currently offered: a published fixed timeline for purging data from encrypted backups. Contact us for current status if you need a specific backup deletion timeline for a school or district agreement.
Incident response
We monitor for and respond to security incidents as part of normal operations. Not currently offered: a published formal incident response SLA or notification timeline. Contact us for current status.
School data processing agreements
Aluma does not currently have standard data processing agreements (DPAs) or state student-data-privacy addenda published for schools and districts. Contact us for current status if your school or district requires one.
Independent security testing
Aluma has not undergone independent third-party penetration testing or security audits at this time. Contact us for current status.
Academic integrity
Aluma is built to coach students through their work, not to complete or submit it for them. Guided walkthroughs start with a diagnostic question, hints are revealed one step at a time, and understanding is checked with follow-up questions rather than accepted on an explanation alone. Aluma does not submit assignments on a student's behalf; the one exception, Autopilot drafting text into a student's own Google Doc, is opt-in per task and always leaves the final submit action to the student. Using Aluma to violate your school's academic integrity policy is against our Terms of Service.
Subprocessors
- Anthropic — model inference (Claude API).
- Stripe — payment processing.
- Render — application hosting.
- Cloudflare — DNS, CDN, DDoS protection.
- Resend — transactional email.
- School and productivity platforms you connect (Google, Canvas, Schoology, Blackboard, PowerSchool, Blackbaud, Notion, and others) — scoped to what you authorize.
Shared responsibility
Aluma is responsible for the platform controls above. Students and families are responsible for the accounts they choose to connect, the content they upload, and keeping their login credentials safe.
Reporting a vulnerability
Please report suspected security issues to security@aluma.fun. We aim to acknowledge reports within a few business days.
Certifications
Aluma does not currently hold independent security certifications such as SOC 2, ISO 27001, or education-specific approvals (e.g. FERPA/COPPA certification programs — note that FERPA and COPPA are laws, not certifications a vendor can hold). As the company grows we plan to pursue relevant compliance work and will publish updates here. Contact us for current status.