Readflexes

Data Security and Privacy Plan

Effective date: July 13, 2026
Back to Readflexes

This Data Security and Privacy Plan describes how Readflexes protects the personally identifiable information ("PII") of students and educators that it receives when a school or district uses the Readflexes service (the "Service"). It is provided as the "Data Security and Privacy Plan" referenced in student data privacy agreements, including the SDPC National Data Privacy Agreement (NDPA), and should be read together with the Readflexes Privacy Policy and any signed Data Privacy Agreement ("DPA"). Where a signed DPA and this Plan conflict, the signed DPA controls.

Our role. When a school, district, or teacher uses Readflexes with students, the school owns and controls the student data and Readflexes acts as a school official / service provider under the school's direction, processing student data only for legitimate educational purposes and only as authorized.

1. Compliance with applicable data privacy and security laws

Readflexes designs its handling of student and educator data to comply with the data privacy and security requirements that apply to its school and district customers, including:

2. Technical safeguards and controls that protect PII

Readflexes runs on Google Cloud / Firebase infrastructure in the United States and applies administrative, technical, and physical safeguards designed to protect PII, including:

3. Alignment to a cybersecurity framework

Readflexes aligns its security practices with the NIST Cybersecurity Framework (CSF) — organizing controls around Identify, Protect, Detect, Respond, and Recover — and operates on Google Cloud infrastructure that is independently certified to ISO/IEC 27001 and SOC 2. Readflexes reviews and improves its safeguards over time as the Service and the threat landscape evolve.

4. Compliance with the LEA's Parents Bill of Rights

Readflexes supports and will comply with each customer LEA's Parents Bill of Rights for Data Privacy and Security. Consistent with those rights, Readflexes affirms that:

5. Training of personnel with access to data

All Readflexes personnel, assignees, and subprocessors who have access to student data or educator data are required to understand and follow this Plan and the confidentiality and data-protection obligations of any applicable DPA before being granted access, and to handle PII only as necessary to operate and support the Service. Access is granted on a need-to-know basis and removed when no longer required.

6. Subprocessors

Readflexes uses a small number of trusted subprocessors to operate the Service. Each is permitted to use data only to provide services to Readflexes and is bound by confidentiality and data-protection obligations (including, for Google, the Google Cloud Data Processing Addendum). Current subprocessors:

ProviderPurposeData location
Google — Firebase (Authentication, Firestore, Realtime Database, Hosting, App Check) & Cloud FunctionsAuthentication, data storage, real-time multiplayer, hosting, and application backendUnited States
Google — Analytics for FirebaseUsage and performance analyticsUnited States
Google — reCAPTCHABot and abuse preventionUnited States
Google — Classroom APIRoster import (only when authorized by the teacher)United States
Google — Cloud Text-to-SpeechGenerating spoken audio of words and promptsUnited States
UnsplashImage search for vocabulary sets (image queries only; no student identifiers sent)United States

Readflexes maintains this list as its providers change and requires each subprocessor to protect PII received in connection with the Service.

7. Managing data security and privacy incidents

Readflexes maintains an incident response process for events that implicate PII. If Readflexes determines that an unauthorized acquisition, access, use, or disclosure of PII has occurred, it will:

8. Data location, retention, return, and destruction

9. Contact

Questions about this Data Security and Privacy Plan, or requests related to student data, may be directed to:

Email: readflexes@gmail.com