Privacy Policy and Data Handling
Effective and last updated: July 18, 2026
The short version: Sightline works with two kinds of education data: publicly published, aggregate state data that we preload, and the school-level planning information your team chooses to enter. It is not designed to receive student-level data of any kind. We use no analytics trackers or advertising tools, we do not sell data, and customer information is never sent to an external AI provider or used to train AI models.
The two kinds of education data in Sightline
Public Platform Data. The education data preloaded into Sightline comes from publicly available, aggregate state sources, including California School Dashboard indicator files, CAASPP and ELPAC results, graduation and college/career data, and the CDE's published accountability tables. These files are released by the state at the school and student-group level, already aggregated, with small groups suppressed by the state so that no individual student can be identified. Sightline organizes, combines, calculates, visualizes, and analyzes this information.
Customer Data. Authorized users at your school may also enter school-level or student-group-level aggregate values and planning information: goals, targets, projections, assumptions, planning scenarios, comments and notes, verified aggregate results, settings, and school logos. You own this information. We treat nonpublic Customer Data as your confidential information, use it only to provide and support the service, and never sell it, use it for advertising, or use it to train a general-purpose AI model.
No student-level data
Sightline is designed for use by adult school personnel and is not intended to collect, store, manage, or retrieve pupil records or covered pupil information. Sightline does not connect to your student information system. Customers must not submit student names, student identifiers, rosters, individual assessment results, pupil records, or any information that identifies or could reasonably identify an individual student, including unsuppressed small-group data. Based on its design and permitted uses, Sightline does not function as a pupil-record storage or management service. If a customer proposes a use involving pupil records or student-level data, that use requires separate written approval and appropriate contractual and security terms, and may not be supported. We are glad to walk your team or authorizer through this in detail on request.
What we collect about adult users
- Account information: name, work email address, organization and school affiliation, role, and login credentials (passwords are stored only in hashed form by our authentication provider).
- Activity and technical information: login timestamps, actions within the platform recorded in an audit log, and standard technical information processed by our hosting infrastructure, such as IP address and browser type, in server request logs.
- Support communications: emails and requests you send us.
- Billing information: billing contact details and transaction status. Card and bank account numbers are entered directly with Stripe, our payment processor, and are never stored on edMAJIC systems.
Uploads
When you upload a CSV of verified aggregate results, the file is read and processed in your browser. Only the extracted aggregate values are saved to our database; the raw file itself is not transmitted to or retained on our servers. School logo images you upload are stored as image data in our database as part of your school's settings.
Automated recommendations (Eddie)
Sightline's built-in assistant provides recommendations and guidance using preloaded content, your entered data, and predefined analytical rules that run within the platform. Sightline does not transmit Customer Data or user prompts to an external generative artificial intelligence provider at runtime.
Service providers
Sightline runs on a small set of contracted service providers, each of which processes only what is needed for its role:
- Application hosting (Netlify): serves the application and processes standard web request information such as IP addresses.
- Database and authentication (Supabase, hosted in the United States): stores account data and Customer Data, and manages logins. Data is encrypted in transit and at rest.
- Payments (Stripe): processes billing and payment information.
- Transactional email (Resend): delivers account and notification emails.
- Fonts (Google Fonts): when pages load, your browser requests font files from Google, which involves your IP address, as with any web resource.
We use no analytics or advertising trackers in Sightline, and we do not permit other parties to collect information about users across sites through the service. Because we do not track users across sites, the service does not respond differently to Do Not Track signals. We may disclose information to professional advisers or authorities when legally required.
Security
All traffic is encrypted in transit (HTTPS). Account data and Customer Data are stored in a managed database with row-level security, so each organization's users can only access the schools licensed to that organization. Administrative access is limited to authorized edMAJIC personnel and contracted service providers who require access to provide or secure the service. Account activity is logged.
Backups
We maintain database backups at least weekly to support recovery of the service.
Retention and deletion
Following expiration or termination of a subscription, Customer may request deletion of Customer Data. Unless legally required to retain it, edMAJIC will delete active copies of Customer Data within 60 days after a verified request. Residual copies may remain in access-restricted backups for up to 90 additional days and will not be restored except for disaster recovery. Billing, transaction, security, and legal records may be retained as reasonably necessary for legitimate business and legal obligations. The public state education data that powers Sightline is not Customer Data and remains part of the platform.
Security incidents
If we confirm a security incident resulting in unauthorized access to Customer Data, we will investigate and contain it, notify affected customers without unreasonable delay, reasonably cooperate on remediation, and make any notifications required by law.
Changes to this policy
We may update this policy by posting a revised version with a new date above. Material changes will be communicated to customer billing contacts.
Questions
We are a small team and happy to answer privacy or procurement questions directly: info@edmajic.com