This policy covers all educational products operated by Constraint Layer Research, including the engines listed below. Each engine handles data differently. This policy describes exactly what each engine does and does not do.
| Engine | Data category | Server-side storage |
|---|---|---|
| Curiosity Research Engine | No-storage | None |
| Explorer Reality Engine | No-storage | None |
| Civil War Perspectives | No-storage | None |
| American Revolution | No-storage | None |
| Novus Expedition | No-storage | None |
| Interactive Root Word Inquiry | No-storage | None |
| The Starfall Forest | Limited-storage | Session reports |
| Math Skills Engine | Limited-storage | Session reports |
The history simulations, research engine, and root word inquiry tool collect no personal information, no student data, no usage analytics, and no session records. No account, login, or signup is required. These engines transmit queries to external API services during active sessions and retain nothing on our servers after the session ends. No record of the interaction exists on our infrastructure once the browser tab is closed.
The Starfall Forest and Math Skills Engine store session reports on the server to support skill tracking across sessions and to generate teacher-readable reports. This section describes exactly what is stored.
Student first name — entered by the student at session start. No verification, no authentication. This can be any name the student chooses.
Session date — the date and time each session occurred.
Skill assessment results — which math skills were tested and their status: passed, remediated, in-progress, or failed-foundational.
Session report text — a structured summary of skills tested and results, intended for teacher review.
No email address, no school name, no grade level, no IP address, no device information, no browser fingerprint, no geographic location, and no authentication credentials. The student name field is a free-text input with no identity verification. No mechanism exists to connect a session report to a specific individual beyond the name the student typed.
Session data is stored as flat JSON files on the server, one file per student name. These are not stored in a database. No indexing, no cross-referencing, and no analytics are performed on stored files. Files are accessible only via direct server access.
The Starfall Forest uses the browser's localStorage to enable save and resume functionality within a session. This data is stored locally on the student's device, not on our servers. It persists until the browser's local storage is cleared. No other engine uses localStorage, cookies, or any other browser-side persistence mechanism.
Session report files can be deleted on request. Contact christopher.fi@constraintlayer.ai with the student name used in the engine. Because files are keyed by student name only, we will delete all files matching the requested name. There is no retention requirement — files are deleted upon request with no delay.
All engines transmit queries to external services during active sessions:
A commercial language model API processes questions and generates responses. The query text is sent to the API provider's servers for processing. We use model-agnostic architecture and may change providers. Current API providers process queries under their own data handling policies, which prohibit training on API inputs.
For engines with research capability, a web search service retrieves live sources to support cited answers. The search query is transmitted to the search provider.
These transmissions occur in real time. For no-storage engines, we do not log, store, or retain the queries or responses. For limited-storage engines, only the structured skill results described above are retained — not the full question text, not the AI-generated narrative, and not individual student answers to math problems.
We use no cookies, no analytics tools, no tracking pixels, and no advertising technology. We do not use Google Analytics or any equivalent service. No session identifiers persist between visits. The only browser-side storage used is localStorage in the Starfall Forest engine for save/resume functionality, as described above.
The Children's Online Privacy Protection Act applies to online services that collect personal information from children under 13.
For no-storage engines: no personal information is collected from any user of any age. COPPA compliance is structural — there is no collection mechanism to regulate because none exists. No parental consent is required.
For limited-storage engines: the only data stored is a student-entered first name and math skill results. No email, phone number, physical address, screen name linked to an online contact, or other COPPA-defined personal information is collected. The student name field accepts free text with no identity verification — a student may enter any name. Because no COPPA-defined personal information is collected, no parental consent mechanism is required under the current architecture. If future features introduce collection of COPPA-defined personal information, appropriate consent mechanisms will be implemented before deployment.
The Family Educational Rights and Privacy Act protects student education records maintained by educational agencies or institutions.
For no-storage engines: no education records are created or maintained. FERPA compliance is structural.
For limited-storage engines: session reports containing skill assessment results could constitute education records if the engine is used as part of a school's instructional program and the school directs students to use it. In that context, Constraint Layer Research functions as a school official with a legitimate educational interest under FERPA's school official exception. We maintain these records only for the purpose of supporting instruction and generating teacher-readable reports. Records are deleted on request. No records are disclosed to third parties. Schools and districts may request review or deletion of any stored session data by contacting us directly.
The only third-party services involved in engine operation are the language model API provider and, for research-capable engines, the web search provider. Both receive query text during active sessions only. Neither receives student names, school names, grade levels, or any identifying information. Settings such as reading level and grade level are stored locally and are not transmitted with API queries.
We select API providers whose terms of service prohibit using API inputs for model training. We do not control third-party data handling beyond contractual terms. Current provider policies are available on request.
For no-storage engines: there is no user data to breach. The attack surface for student information exposure is zero.
For limited-storage engines: session report files are stored on the server with standard file-system permissions. Access requires direct server credentials. Files are not exposed through any public URL or API endpoint. No web-accessible directory listing exists for stored files.
All API transmissions use encrypted connections (HTTPS/TLS). No data is stored at rest on our servers for no-storage engines. For limited-storage engines, stored files contain no sensitive personal information beyond a student-entered first name.
Product development may introduce features that involve additional data collection, such as teacher dashboards, authenticated student accounts, or district-level reporting. If and when such features are developed, this policy will be updated before deployment to describe exactly what data is collected, how it is stored, how long it is retained, who can access it, and how it can be deleted. Any feature involving expanded student data collection will include appropriate consent mechanisms and will comply with COPPA and FERPA requirements.
For schools or districts conducting privacy reviews, we can confirm:
No-storage engines collect no student personal information and create no education records. Limited-storage engines store only a student-entered first name and skill assessment results, with no authentication and no identity verification. No data is sold, shared with third parties for marketing, or used for advertising. No persistent tracking exists between sessions for any engine. The products operate through a standard web browser with no installation required.
We are available to complete Student Data Privacy Consortium (SDPC) agreements, state-specific student privacy addenda, or district privacy review questionnaires on request.
If this policy changes, the updated version will be posted at this URL with a revised effective date. Changes involving new data collection will be communicated to active school and district partners before taking effect.
Christopher Finks
Constraint Layer Research LLC
christopher.fi@constraintlayer.ai
302 South Silver, Lamoni, IA 50140