Cerebra Learning, LLC — Privacy Notice
Last Updated: July 10, 2026 · Effective Date: July 10, 2026
Preamble
Cerebra Learning, LLC ("Cerebra," "we," "us," or "our"), an Illinois limited liability company, has prepared this Privacy Notice ("Notice") to describe how we collect, use, disclose, and safeguard personal information in connection with our online educational services (the "Services") made available through our website located at cerebra.academy (the "Site").
We are committed to protecting the privacy of all users, including children, parents, and schools. This Notice explains our practices in accordance with applicable federal and Illinois privacy laws, including the Children's Online Privacy Protection Act of 1998 ("COPPA"), 15 U.S.C. § 6501 et seq.; the Family Educational Rights and Privacy Act ("FERPA"), 20 U.S.C. § 1232g; and the Illinois Student Online Personal Protection Act ("SOPPA"), 105 ILCS 85/1 et seq.
By using our Site or Services, or by permitting your child to use our Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Notice and our Terms of Service. If you are providing verifiable parental consent for a child under 13, or if you are a school or district authorized representative, you confirm that you have the authority to agree to this Notice on behalf of the child or the school. Capitalized terms not defined in this Notice have the meanings set forth in our Terms of Service.
Article 1 — Definitions
- "Child" or "Children" means an individual or individuals under the age of 13.
- "COPPA" means the Children's Online Privacy Protection Act of 1998, 15 U.S.C. § 6501 et seq., and its implementing regulations at 16 C.F.R. Part 312.
- "Education Records" means records that contain information directly related to a student and are maintained by an educational agency or institution or by a party acting for the agency or institution, as defined by FERPA.
- "FERPA" means the Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g, and its implementing regulations at 34 C.F.R. Part 99.
- "Operator" means a person who operates an internet website, online service, online application, or mobile application where such service is used for K–12 school purposes, as defined by SOPPA, 105 ILCS 85/5.
- "Parent" means a parent or legal guardian of a Child.
- "Personal Information" means information that identifies, relates to, describes, or is reasonably capable of being associated with or linked to a particular individual, including but not limited to name, email address, telephone number, physical address, online identifier, IP address, unique device identifier, persistent identifier, account credentials, Education Records, and any other information collected in combination with such identifiers.
- "School" or "Educational Agency" means a public or private elementary or secondary school, school district, or educational institution that uses the Services for educational purposes.
- "School Official" means a contractor, consultant, volunteer, or other party to whom an educational agency or institution has outsourced institutional services or functions that it would otherwise use employees to perform, and who meets the criteria set forth in 34 C.F.R. § 99.31(a)(1)(i)(B).
- "SOPPA" means the Illinois Student Online Personal Protection Act, 105 ILCS 85/1 et seq.
- "Student Data" means personal information contained in Education Records or information collected by an Operator through the provision of services to a School for K–12 school purposes, as defined by SOPPA.
- "Usage Information" means information collected automatically through your use of the Site and Services, including but not limited to device type, operating system, browser type and version, IP address, approximate geographic location derived from IP address, pages visited, time and date of access, referring and exit URLs, clickstream data, and other technical data regarding your interaction with the Services.
- "User" means any individual who accesses or uses the Site or Services, including Children, Parents, educators, school administrators, and other visitors.
- "Verifiable Parental Consent" means any reasonable effort, taking into consideration available technology, to ensure that before Personal Information is collected from a Child, a Parent receives notice of our Personal Information practices and authorizes such collection, use, and disclosure, in accordance with the methods permitted under 16 C.F.R. § 312.5.
Article 2 — Information We Collect
I. Categories of Personal Information Collected from Users Age 13 and Older.
A. Identifiers. When you create an account, we collect your first name, last name, and email address. For school-based accounts, we may also collect a unique student identifier assigned by the School.
B. Account Credentials. We collect username, password (stored in hashed and encrypted form), and authentication tokens necessary to secure your account.
C. Usage Information. We automatically collect information about your use of the Site and Services, including: device and browser information (device type, operating system, browser type and version); network and connection data (IP address, approximate geographic location derived from IP address); interaction data (pages viewed, features accessed, time spent on pages, clickstream data, search terms entered, referring and exit URLs); and session identifiers and cookies as described in Section IV below.
D. Educational Progress and Performance Data. We collect and maintain records of lessons completed, quiz and assessment results, learning progress, review schedules, skill mastery indicators, and related educational performance metrics generated through your use of the Services.
E. User-Generated Content. We collect content that you voluntarily submit through the Services, including written responses, uploaded files, and communications with educators or support personnel.
F. Payment Information. If you purchase a subscription or paid feature, we collect payment card information (cardholder name, card number, expiration date, CVV code), billing address, and related transaction details. Payment card data is processed and stored by our third-party payment processor and is not stored on Cerebra servers. See Article 4, Section II.D below.
II. Categories of Personal Information Collected from Children Under Age 13.
A. Information Collected for Parental Consent (Individual Accounts). For individual (non-School) accounts, before we collect any Personal Information from a Child, we collect a Parent's email address for the sole purpose of providing direct notice of our information practices and obtaining Verifiable Parental Consent. We do not condition a Child's participation in the Services on the Child disclosing more Personal Information than is reasonably necessary to participate in the Services.
B. Information Collected After Verifiable Parental Consent or School Authorization. After obtaining Verifiable Parental Consent (for individual accounts) or relying on School consent (for School accounts), we collect the Child's first name, username, and password (hashed and encrypted); the same categories of educational progress and performance data described in Section I.D; the same categories of Usage Information described in Section I.C, limited to what is necessary to provide and secure the Services; and responses, submissions, and other content created by the Child, limited to what is reasonably necessary for the educational purposes of the Services.
C. Data Minimization. We collect only the minimum Personal Information from Children that is reasonably necessary to provide the Services and do not require Children to disclose more information than necessary to participate.
III. Sources and Methods of Collection.
- Directly from Users when creating an account, using the Services, or communicating with us.
- Automatically Through Technology via cookies, web beacons, log files, and similar technologies as described in Section IV.
- From Schools, who provide limited student information (such as first name, username, and student identifier) necessary to provision access.
- From Parents, for individual accounts of Children under 13.
- From Service Providers that perform functions on our behalf, such as hosting, security monitoring, and fraud prevention.
- Payment Information collected directly by our third-party payment processor. Cerebra does not receive, access, or store complete payment card numbers; we receive only transaction confirmations, partial card identifiers (last four digits), and billing contact information necessary for account administration and customer service.
IV. Cookies and Tracking Technologies.
A. Use of Cookies. We use cookies (small text files stored on your device) and similar technologies to authenticate users and maintain secure sessions; remember user preferences and settings; analyze usage patterns and improve the Services; and protect against fraud and enhance security.
B. Types of Cookies. We use Strictly Necessary Cookies (essential for operation, including authentication and security), Functional Cookies (enhanced functionality and personalization), and Analytics Cookies (understanding how Users interact with the Services).
C. First-Party Only. All cookies and tracking technologies are deployed and controlled by Cerebra. We do not use third-party advertising cookies, third-party analytics services, or third-party behavioral tracking technologies. All site assets, including scripts, fonts, media files, and maps, are served from Cerebra-controlled servers.
D. Cookie Controls. You may refuse or delete cookies through your browser settings. If you disable cookies, some features of the Services may not function properly. Disabling cookies does not prevent the collection of Usage Information through other means such as server logs.
E. Do Not Track Signals. Because there is no common industry standard for recognizing or responding to "Do Not Track" signals, we do not currently respond to such signals from browsers. We do not engage in cross-site tracking or behavioral advertising.
Article 3 — How We Use Personal Information
We do not sell personal information, show advertising, or use third-party advertising or analytics trackers.
I. General Uses for Users Age 13 and Older.
A. Account Administration — to create, maintain, and secure your account; verify your identity when you sign in; and provide customer support.
B. Service Delivery — to provide access to educational content, lessons, and assessments; track learning progress and generate performance reports; schedule and deliver personalized review sessions; and customize educational content based on learning patterns and skill mastery.
C. Communications — to send transactional communications regarding your account (security alerts, password resets, billing notices); respond to your inquiries and support questions; notify you of changes to the Services, this Notice, or our Terms of Service; and send educational content, progress updates, and service-related information that you have requested or that is reasonably expected in connection with your use of the Services.
D. Service Improvement and Analytics — to analyze usage patterns and trends; improve and develop new features, content, and educational methodologies; enhance user experience through personalization; and conduct research and testing.
E. Security and Fraud Prevention — to detect, investigate, and prevent fraudulent, unauthorized, or illegal activity; monitor and enhance the security and integrity of the Services; and enforce our Terms of Service and other policies.
F. Legal and Regulatory Compliance — as necessary to comply with applicable laws, regulations, legal process, and governmental requests.
G. Payment Processing — solely to process authorized transactions, manage billing, and administer your subscription.
II. Uses for Children Under Age 13.
A. Permitted Uses. We use Personal Information collected from Children solely for the purposes disclosed in the direct notice provided to Parents at the time of collection and for which Verifiable Parental Consent (or School consent under COPPA's school consent provision) was obtained, including providing the educational Services requested; maintaining the Child's account and learning progress; communicating with the Parent or School as permitted by the consent provided; ensuring the security and integrity of the Child's account; and complying with applicable law.
B. No Behavioral Advertising or Profiling. We do not use Personal Information collected from Children for behavioral advertising, marketing, or creating user profiles for non-educational purposes.
C. Internal Research and Improvement. We may use de-identified, aggregated data that does not identify any individual Child to improve the Services and conduct research, provided such data cannot reasonably be used to re-identify any Child.
III. Uses for Student Data (School Accounts).
A. Authorized Educational Purposes Only. When we act as a School Official under FERPA or as an Operator under SOPPA, we use Student Data solely to provide the Services authorized by the School; for purposes directed by the School and disclosed in our agreement with the School; and to maintain, support, evaluate, and improve the Services consistent with the School's authorization and applicable law.
B. Prohibited Uses Under SOPPA. For K–12 Illinois School accounts, we do not sell or rent Student Data; use or disclose Student Data for targeted advertising; create personal profiles of students for purposes other than supporting authorized educational or school purposes; or use Student Data for any purpose not authorized by the School or permitted by SOPPA, 105 ILCS 85/10.
C. De-identified Data. We may use de-identified or aggregated Student Data that cannot reasonably be used to identify any individual student for product development, research, analytics, and improvement, provided such use complies with FERPA, SOPPA, and our agreement with the School.
Article 4 — Disclosure of Personal Information to Third Parties
I. General Policy.
We do not sell, rent, or disclose Personal Information to third parties for their direct marketing purposes.
II. Service Providers.
A. Permitted Disclosures. We disclose Personal Information to third-party service providers that perform business functions on our behalf, including cloud hosting and infrastructure providers; data storage and backup services; security, fraud prevention, and threat detection services; email delivery and communication platforms; customer support and ticketing systems; and payment processing services.
B. Contractual Protections. We require all service providers to use Personal Information only for the specific services they provide to Cerebra; maintain the confidentiality and security of Personal Information through appropriate safeguards; comply with applicable privacy and data protection laws, including COPPA, FERPA, and SOPPA where applicable; and return or securely delete Personal Information upon termination or upon our request, except where retention is required by law.
C. Subprocessors. Service providers may engage subprocessors only with our prior written consent and must impose substantially similar data protection obligations on any subprocessor.
D. Payment Processors. Payment card information you provide to purchase Paid Services is collected and processed by our third-party payment processor FILL IN: name of payment processor and a link to its privacy policy — no payment features are live yet, so this remains a placeholder until you enable payments. ("Payment Processor"). We share with the Payment Processor only the information necessary to process your payment and manage your subscription (payment card information, transaction information, and an account identifier). Cerebra does not store complete payment card numbers on our servers; we receive only transaction confirmations and status, partial card identifiers (last four digits), and billing contact information. The Payment Processor is required to comply with the Payment Card Industry Data Security Standard (PCI DSS) and acts as a service provider that may use payment card information only to process payments, prevent fraud, and comply with card network requirements, and not for its own independent purposes. This Privacy Notice continues to apply to any payment-related Personal Information that we collect or receive.
III. School Disclosures (for School Accounts).
A. Disclosure to Schools. For accounts created under a School's authorization, we disclose Student Data and educational progress information to the School and to authorized School personnel to enable the School to fulfill its educational mission.
B. School Control. Schools retain the right to control access to, review, correct, and request deletion of Student Data in accordance with FERPA, SOPPA, and our agreement with the School.
IV. Parent and Legal Guardian Access (for Individual Child Accounts).
For individual accounts of Children under 13, we disclose the Child's Personal Information and educational progress to the Parent or legal guardian who provided Verifiable Parental Consent, upon verified request.
V. Legal and Regulatory Disclosures.
A. Lawful Requests and Compliance. We may disclose Personal Information when required by applicable law, regulation, legal process, or valid governmental request, including in response to a court order, subpoena, search warrant, or other valid legal process issued by a court or governmental authority with jurisdiction; to comply with statutory or regulatory obligations imposed on Cerebra; and in response to lawful requests from public authorities, including to meet national security or law enforcement requirements, where such requests are supported by applicable legal authority.
B. Notice to Users and Schools. Where legally permitted and practicable, we will provide advance written notice to affected Users or, for Child accounts, to the Parent, and for School accounts, to the School, before responding to legal process, and provide sufficient time to seek a protective order or other appropriate relief, unless we are prohibited by law from providing such notice or unless notice would create a risk of injury or harm, interfere with an investigation, or be otherwise counterproductive or futile.
C. Scope Limitation and Challenge. When responding to legal process or governmental requests, we will disclose only the information legally required to be produced; use commercially reasonable efforts to narrow or challenge requests that are overbroad, unduly burdensome, legally defective, or not supported by applicable legal authority; and document the request and our response internally.
VI. Protection of Rights and Safety.
We may disclose Personal Information when we have a good faith belief that disclosure is necessary to protect the rights, property, or safety of Cerebra, our Users, or the public; detect, prevent, or investigate security incidents, fraud, or illegal activity; enforce our agreements; or defend against legal claims. Such disclosures will be limited to the information reasonably necessary to address the identified risk and documented internally.
VII. Business Transfers.
If Cerebra or substantially all of its assets are acquired, or if we undergo a merger, consolidation, reorganization, or sale of assets, Personal Information may be among the transferred assets. We will provide notice to Users by email and by posting a prominent notice on the Site at least thirty (30) days before the transfer takes effect (for Child accounts, notice to the Parent or School), and the successor entity will be required to maintain materially equivalent privacy protections or, if material changes are proposed, provide notice and, where required by law, obtain renewed consent before implementing such changes.
VIII. Aggregated and De-identified Data.
We may disclose aggregated or de-identified data that does not identify any individual User and cannot reasonably be used to re-identify any User, for purposes including research, analytics, and benchmarking. Such data is not considered Personal Information and is not subject to the restrictions in this Article 4.
Article 5 — Data Security
I. Security Measures.
We implement and maintain commercially reasonable administrative, technical, and physical safeguards designed to protect Personal Information from unauthorized access, use, alteration, disclosure, and destruction. These measures include:
A. Technical Safeguards
- Encryption of Personal Information in transit using industry-standard protocols (TLS 1.2 or higher);
- Encryption of sensitive Personal Information at rest;
- Secure authentication mechanisms and hashed password storage;
- Regular security testing and vulnerability assessments;
- Logging and monitoring of access to Personal Information;
- Network security controls appropriate to the Services.
B. Administrative Safeguards
- Role-based access controls limiting access to Personal Information on a need-to-know basis;
- Confidentiality obligations for any personnel or contractors with access to Personal Information;
- Incident response and breach notification procedures;
- Vendor management and due diligence processes for service providers.
C. Physical Safeguards
- Physical access controls at the data center facilities (operated by our hosting providers) where Personal Information is stored;
- Secure disposal and destruction procedures for media containing Personal Information.
II. Limitations.
No security system is impenetrable. We cannot guarantee the absolute security of our databases, servers, or transmissions. Email and other electronic communications sent to or from us may not be secure, and you should exercise caution when deciding what information to send via such channels.
III. User Responsibility.
You are responsible for maintaining the confidentiality of your account credentials. You agree to notify us immediately at info.cerebralearning@gmail.com if you become aware of any unauthorized access to or use of your account.
IV. Security Incident Response.
In the event of a data breach or security incident involving unauthorized access to or disclosure of Personal Information, we will promptly investigate to determine the scope, nature, and impact; provide notification without unreasonable delay to affected Users, Parents (for Child accounts), or Schools (for Student Data), in accordance with applicable law, describing the incident and categories of Personal Information involved, the steps we are taking, contact information for assistance, and recommendations for protective steps; notify applicable regulatory authorities, including the Illinois Attorney General where required; and cooperate with Schools in their investigation, notification, and response obligations under FERPA, SOPPA, and other applicable laws.
Article 6 — Data Retention and Deletion
I. Retention Principles.
We retain Personal Information only for as long as reasonably necessary to fulfill the purposes for which it was collected, to provide the Services, to comply with legal and regulatory obligations, to resolve disputes, and to enforce our agreements.
II. Active Account Retention.
While an account remains active, we retain the Personal Information and educational progress data associated with that account to provide continuous access to the Services and to maintain learning continuity.
III. Account Deletion.
A. User-Initiated Deletion (Ages 13 and Older). Users age 13 and older may delete their own accounts at any time through the Account & Privacy page within the Services. Upon deletion, the account, associated Personal Information, learning progress, and user-generated content will be deleted from our active production systems within a commercially reasonable period, typically within five (5) business days; Personal Information will be deleted from backup systems as those backups are rotated and replaced in the ordinary course, typically within thirty (30) days of the deletion request; and we may retain limited information (such as email address and transaction records) as necessary to comply with legal obligations, prevent fraud, resolve disputes, enforce our Terms of Service, and maintain security and audit logs, with access restricted and not used for operational purposes.
B. Parent-Initiated Deletion (Children Under 13, Individual Accounts). The Parent or legal guardian who provided Verifiable Parental Consent may review, download, and delete the Child's account and Personal Information at any time using the secure link provided in the parental consent email. Deletion timelines are the same as in Section III.A.
C. School-Initiated Deletion. Schools may request deletion of student accounts, classes, and associated Student Data at any time by contacting us at info.cerebralearning@gmail.com or through the mechanism specified in our agreement. We will process such requests within a commercially reasonable period, typically within ten (10) business days, and from backups within thirty (30) days, except as required to be retained by law or our agreement.
D. Automatic Deletion of Unverified Child Accounts. Individual accounts created for Children under 13 for which the Parent does not provide Verifiable Parental Consent within seven (7) days of the consent request will be automatically and permanently deleted.
IV. Retention Exceptions.
Notwithstanding the deletion timelines above, we may retain Personal Information for longer periods where required by applicable law (e.g., tax, accounting, or audit requirements); where reasonably necessary to establish, exercise, or defend legal claims or resolve disputes; where limited information is necessary for security, fraud prevention, and enforcement (with restricted access and not used operationally); or as de-identified or aggregated data that cannot reasonably identify any individual.
V. Data Portability.
Before deleting an account, Users (or Parents for Child accounts, or Schools for School accounts) may download a copy of the associated Personal Information and learning progress data in a commonly used, machine-readable format through the Account & Privacy page or by contacting us at info.cerebralearning@gmail.com.
Article 7 — Rights of Users, Parents, and Schools
I. Rights of Users Age 13 and Older.
You have the right to access your Personal Information; to request correction of inaccurate Personal Information; to request deletion of your Personal Information (subject to the retention exceptions in Article 6, Section IV); and to obtain a copy of your Personal Information in a portable, machine-readable format. You may exercise these rights through the Account & Privacy page or by contacting us at info.cerebralearning@gmail.com. We do not sell or share Personal Information for cross-context behavioral advertising, so no opt-out of such practices is required or provided.
II. Parental Rights (Children Under 13).
Before collecting Personal Information from a Child under 13, we provide the Parent with direct notice of the types of Personal Information we collect, how we use it, our disclosure practices, and the Parent's rights under COPPA and this Notice. For individual accounts, we obtain Verifiable Parental Consent before collecting, using, or disclosing Personal Information from a Child (except for the limited collection of a Parent's email address to obtain consent). At any time, a Parent may review the Child's Personal Information, refuse further collection or use, revoke consent, and direct us to delete the Child's Personal Information (subject to Article 6, Section IV). See Article 8, Section VI for the complete parental access and control workflow.
III. School Rights (School Accounts).
For School accounts, the School retains the right to control access to, review, correct, and delete Student Data in accordance with FERPA, SOPPA, and our Data Processing Agreement; to direct disclosure of Student Data to authorized personnel or parents as permitted by law; to audit our data handling practices on reasonable advance notice; to request deletion as set forth in Article 6, Section III.C; and to receive Student Data in a structured, commonly used, machine-readable format.
IV. Non-Discrimination.
We will not discriminate against any User, Parent, or School for exercising any of the rights set forth in this Article 7.
V. Response Timelines.
We will respond to requests to access, correct, or delete Personal Information without undue delay and in any event within forty-five (45) days of receipt of a verifiable request (extendable by up to an additional forty-five (45) days with notice). For requests from Schools regarding Student Data, we will respond within ten (10) business days or within the timeframe specified in our Data Processing Agreement.
VI. Limitations on Rights.
We may decline to process a request where we cannot verify the identity of the requestor with reasonable certainty; where the request is manifestly unfounded, excessive, or repetitive; where retention is required by law or necessary for the establishment, exercise, or defense of legal claims; where the information is subject to an ongoing investigation or dispute; or where disclosure would compromise the privacy or other rights of another individual.
Article 8 — Children's Privacy (COPPA Compliance)
I. Application.
This Article applies to the collection, use, and disclosure of Personal Information from Children under the age of 13 in connection with individual (non-School) accounts.
II. Verifiable Parental Consent Requirement.
A. Consent Before Collection. Except as provided below, we do not knowingly collect, use, or disclose Personal Information from a Child under 13 without first obtaining Verifiable Parental Consent from the Child's Parent. We may collect a Parent's email address or other online contact information for the sole purpose of providing direct notice and obtaining Verifiable Parental Consent. If we do not receive Verifiable Parental Consent within seven (7) days of collecting the Parent's contact information, we will delete the Parent's contact information and the Child account registration.
B. Verifiable Parental Consent Methods. We obtain Verifiable Parental Consent using one or more of the following methods, selected based on the sensitivity of the Personal Information and available technology:
- Email Plus Additional Verification. We send a consent notice and request to the Parent's email address provided at signup. The Parent completes an additional verification step to provide consent — such as clicking a unique, time-limited, cryptographically signed consent link sent to the Parent's email address, or responding from the same email address with confirming information (such as the Child's username or date of birth).
- Credit or Debit Card Verification (for Paid Services). For paid Services, we may use a credit or debit card transaction as a method of obtaining consent, in accordance with 16 C.F.R. § 312.5(b)(2).
- Other FTC-Approved Methods. Any other method approved by the Federal Trade Commission under COPPA.
C. Content of Parental Consent Notice. The parental consent notice includes the name and contact information of Cerebra Learning, LLC; the categories of Personal Information we will collect from the Child; how we will use it; whether and to whom we will disclose it; a link to this Privacy Notice; a statement that the Parent's consent is required before collection (except for limited collection permitted under COPPA); the Parent's rights under COPPA (to review, delete, refuse further collection, and revoke consent) with instructions on exercising them; and a statement that if the Parent does not provide consent within seven (7) days, the Child account registration and the Parent's contact information will be deleted.
D. Verification of Consent. Before granting access to a Child under 13, we confirm completion of the verification step and maintain records of the consent provided, including the date and method.
III. Data Minimization.
We collect from Children only the Personal Information reasonably necessary to provide the Services and do not condition a Child's participation on providing more than is reasonably necessary.
IV. No Sale or Disclosure for Marketing.
We do not sell or disclose Personal Information collected from Children to third parties for their direct marketing purposes, and we do not use it for behavioral advertising or non-educational profiling.
V. Knowledge of Unauthorized Collection.
If we learn that we have collected Personal Information from a Child under 13 without Verifiable Parental Consent, or that a Child has provided Personal Information beyond what we requested, we will delete that information as quickly as possible, typically within five (5) business days of discovery. If you believe a Child under 13 has provided us Personal Information without consent, contact info.cerebralearning@gmail.com.
VI. Parental Access and Control Rights.
Parents of Children under 13 with individual accounts have the following rights at any time:
- Right to Review — by logging in to the Child's account, using the secure parental access link provided in the consent email, or contacting us with "COPPA Parental Review Request" in the subject line and completing identity verification.
- Right to Delete — using the secure parental access link's "Delete Account" option, or by contacting us with "COPPA Deletion Request" in the subject line. Upon a verified request, we delete the Child's account and Personal Information in accordance with Article 6, Section III.B.
- Right to Refuse Further Collection or Use — using the secure parental access link or contacting us with "COPPA Refusal of Further Collection." Because the Services cannot be provided without collecting necessary account and progress information, exercising this right will disable the Child's account.
- Right to Revoke Consent — at any time, with the same effect as a deletion request.
- Right to Download — a copy of the Child's Personal Information and learning progress in a portable, machine-readable format via the secure link or by contacting us with "COPPA Data Download Request."
Parental Identity Verification. The secure link sent to the Parent's email at the time of consent is unique, time-limited, and cryptographically signed; a Parent who uses this link is deemed verified. For direct contacts, we may require the request to come from the same email address provided at consent, information matching that provided at account creation, and/or additional confirming information. We will respond to verified parental requests within five (5) business days, or within the timeframe required by applicable law.
VII. School Exception.
The Verifiable Parental Consent requirement does not apply to School accounts. When a School authorizes a Child's use of the Services, we rely on the School's consent under the school consent exception, 16 C.F.R. § 312.5(c)(3), and Article 9 below.
Article 9 — School Use, FERPA, and SOPPA Compliance
I. School Official Status (FERPA).
A. Direct Control. When a School engages Cerebra to provide Services to its students, Cerebra acts as a "School Official" under FERPA, 34 C.F.R. § 99.31(a)(1)(i)(B). The School retains direct control over Cerebra's use and maintenance of Education Records through our Data Processing Agreement (the "School DPA"), available upon request by contacting info.cerebralearning@gmail.com; the School's contractual right to audit, direct disclosure, and require deletion; and the School's ability to terminate access and require return or deletion of Education Records.
B. Use Limitation. We use Education Records solely to provide the educational Services authorized by the School; for purposes directed by the School in writing; and as permitted by FERPA, 34 C.F.R. §§ 99.31 and 99.33 — and not for any other purpose.
C. Prohibition on Unauthorized Disclosure. We do not disclose Education Records except on documented written instruction from the School; to authorized School personnel; to parents of students as directed by the School and permitted by FERPA; to our service providers acting on our behalf and subject to the restrictions in Article 4, Section II; as required by law or legal process in accordance with Article 4, Section V; or in connection with a health or safety emergency in accordance with 34 C.F.R. § 99.36.
D. No Re-Disclosure. Education Records disclosed to us will not be re-disclosed without prior written consent of the School (or the student's parent where applicable), except as permitted by FERPA, and we require service providers to be subject to substantially similar obligations.
E. Data Processing Agreement Integration. The terms governing our processing of Student Data and Education Records are set forth in the School DPA, available upon request. In the event of any conflict between the School DPA and our Terms of Service regarding the handling of Student Data, the School DPA shall control solely with respect to that School's Student Data.
II. School Consent Under COPPA.
For School accounts of Children under 13, we rely on the School's consent under the school consent exception, 16 C.F.R. § 312.5(c)(3). The School is responsible for providing any required notices to parents, obtaining any required parental consents where the School's authorization does not satisfy legal requirements, and ensuring its use of the Services complies with applicable law. We use Personal Information collected through School accounts solely for authorized educational purposes and do not sell such information or use it for behavioral advertising or non-educational profiling.
III. Illinois SOPPA Compliance (K–12 Illinois Schools).
For K–12 Illinois School use, Cerebra acts as an "Operator" under SOPPA, 105 ILCS 85/5. This Section applies solely to Student Data collected in the K–12 context; it does not apply to general website visitor information or individual (non-School) accounts.
A. Prohibited Practices. We do not and will not: sell or rent Student Data to any third party for any purpose (105 ILCS 85/10(1)); use or disclose Student Data to target advertising to students (105 ILCS 85/10(2)); create personal profiles of students except in furtherance of K–12 educational purposes authorized by the School in writing (105 ILCS 85/10(3)); or use or disclose Student Data for any purpose not authorized by the School or permitted by SOPPA.
B. Permitted Uses. We use Student Data solely to provide the Services authorized by the School; to maintain, support, and improve the Services consistent with the School's authorization; for purposes expressly directed by the School in writing; as required by law or valid legal process (subject to notice to the School where permitted); and to enforce our Terms and protect the rights, safety, and security of the Services and Users, consistent with SOPPA and our agreement.
C. Data Security. In accordance with 105 ILCS 85/10(4), we implement and maintain reasonable security procedures and practices appropriate to the nature of the Student Data, as described in Article 5, including encryption in transit (TLS 1.2+), encryption of sensitive data at rest, hashed password storage, access logging and monitoring, role-based access controls, documented incident response, and vendor due diligence.
D. Breach Notification. In the event of a breach involving Student Data, we will notify the affected School without unreasonable delay after confirming the breach, and in no event later than the sooner of the timeframe required by our DPA or the timeframe necessary to enable the School to fulfill its own notification obligations under Illinois law; provide the School with sufficient information (description, dates, categories and number of students affected, types of data involved, remediation steps, and contact information); and cooperate with the School's investigation, response, and notification efforts.
E. Deletion Rights. Illinois K–12 schools may request deletion of school-created student accounts, classes, and associated Student Data at any time by contacting info.cerebralearning@gmail.com with "SOPPA Deletion Request" in the subject line. Upon a verified request, we delete from active production systems within ten (10) business days and from backups within thirty (30) days, subject to legal retention exceptions.
F. Subcontractor Requirements. We require any subcontractor or service provider with access to Student Data to agree in writing to data protection obligations at least as protective as those in this Article and in SOPPA; implement reasonable security measures; comply with SOPPA, FERPA, and other applicable laws; use Student Data only for the services requested; and not sell, rent, or disclose Student Data except as permitted. We maintain a list of subprocessors with access to Student Data and will provide it to Schools upon request.
G. De-identified Data. We may retain and use de-identified or aggregated Student Data that cannot reasonably be used to identify any individual student for product development, research, and analytics, provided such use complies with SOPPA, FERPA, and our agreement, and the data is not re-identified.
IV. Data Processing Agreement.
Our Data Processing Agreement with Schools governs the processing of Student Data and Education Records and includes terms addressing the scope and purpose of processing; categories of Student Data; security and confidentiality obligations; subprocessor management; retention and deletion; breach notification; audit rights; data portability upon termination; liability allocation; and compliance with FERPA, SOPPA, and other applicable laws.
Article 10 — International Data Transfers
The Site and Services are operated in the United States, and Personal Information is processed and stored on servers located in the United States. If you access the Services from outside the United States, you acknowledge that your Personal Information will be transferred to, processed, and stored in the United States, may be subject to laws that differ from those of your jurisdiction, and may be subject to access requests from U.S. governments, courts, and law enforcement. By using the Services, you consent to this transfer.
If you are located in the European Economic Area, United Kingdom, or Switzerland and the GDPR or UK GDPR applies, we process your Personal Information on the legal bases of performance of contract, legitimate interests, compliance with legal obligations, and consent (where required). When we transfer such Personal Information to the United States, we use Standard Contractual Clauses or other recognized transfer mechanisms. You also have the rights to object to processing, request restriction, withdraw consent, and lodge a complaint with a supervisory authority. For GDPR inquiries, contact info.cerebralearning@gmail.com with "GDPR Request" in the subject line; we will respond within one month or within the timeframe required by applicable law.
Article 11 — Third-Party Links and Services
The Site may contain links to third-party websites, applications, or services that are not owned or controlled by Cerebra. This Privacy Notice does not apply to any third party, and we are not responsible for their privacy practices, content, or terms. When you access a third party, you are subject to that third party's policies. Parents are encouraged to supervise their Children's online activities.
Article 12 — Changes to This Privacy Notice
We may update this Privacy Notice from time to time. The "Last Updated" date indicates when the Notice was last revised, and we will update the "Effective Date" when material changes take effect. We will post the updated Notice on the Site and, where required by law, provide prominent notice of material changes through a banner, pop-up, or other conspicuous disclosure. For registered Users, we will send email notice at least thirty (30) days before material changes affecting the collection, use, or disclosure of Personal Information take effect. For individual accounts of Children under 13, we will send email notice to the Parent and obtain renewed Verifiable Parental Consent before collecting, using, or disclosing the Child's Personal Information in a materially different manner. For School accounts, material changes affecting Student Data require the School's written consent before taking effect, or we will provide notice and an opportunity to terminate and retrieve Student Data. By continuing to use the Services after the Effective Date of an updated Notice, you acknowledge that you have read and agree to it. We maintain prior versions and will make them available upon reasonable request.
Article 13 — Contact Information and Requests
If you have questions, concerns, or requests regarding this Privacy Notice, our privacy practices, or the processing of your Personal Information, please contact us at:
Cerebra Learning, LLC
Attn: Privacy Officer
1 North Old State Capitol Plaza, Suite 200
Springfield, Illinois 62701
Email: info.cerebralearning@gmail.com
Please include an appropriate subject line: "Privacy Inquiry" for general inquiries; "COPPA Request" for parental rights; "School Data Request" for Student Data; or "GDPR Request" / "International Privacy Request" for international privacy rights.
Article 14 — Effective Date and Acceptance
This Privacy Notice is effective as of the Effective Date stated at the top. By using the Site or Services, or by permitting your child to use the Services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Notice and our Terms of Service. If you are a Parent providing Verifiable Parental Consent for a Child under 13, you agree on behalf of your Child and yourself. If you are a school or district authorized representative, you represent that you have the authority to agree on behalf of the school or district and its students, and that you have reviewed and agree to our Data Processing Agreement.