LYNTRA PRIVACY POLICY
Last Updated: July 16, 2026
1. Scope and Purpose
Lyntra, Inc. (“Lyntra,” “we,” “us,” or “our”) provides an academic execution platform that helps students turn assignments, deadlines, instructions, rubrics, course materials, available time, progress, and changing circumstances into clear next steps, adaptive weekly plans, guided study sessions, and recovery plans.
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when students, educators, support professionals, administrators, or other authorized users access Lyntra’s websites, applications, integrations, pilots, and related services (collectively, the “Service”).
The Service may be provided directly to individual students or through universities, colleges, tutoring and learning centers, accessibility or academic support programs, executive-function coaching organizations, instructors, or other educational organizations (each an "Educational Organization"). If you use Lyntra through an Educational Organization, additional agreements, privacy notices, or data processing terms may apply.
2. Roles, Educational Records, and FERPA
2.1 Direct Student Accounts
When a student creates and uses an account independently, Lyntra generally determines how information is processed to provide, secure, and improve the Service, subject to this Policy and applicable law.
2.2 Educational Organization-Sponsored Use
When an Educational Organization authorizes or provides access to student education records, the organization remains responsible for those records, and Lyntra processes them under the organization's instructions and written agreement. The agreement may control data access, permitted uses, reporting, retention, deletion, security requirements, and student rights.
2.3 FERPA
Lyntra may be treated as a "school official" under the Family Educational Rights and Privacy Act ("FERPA") only when the educational institution determines that Lyntra meets the applicable conditions, including performing an authorized institutional service, remaining under the institution's direct control regarding the use and maintenance of education records, using the records only for the authorized purpose, and meeting the institution's criteria for a legitimate educational interest.
Requests concerning institution-controlled education records should generally be directed to the institution. Lyntra will assist the institution with access, correction, export, deletion, and other valid requests as required by the applicable agreement and law.
2.4 Organizations Not Covered by FERPA
Some tutoring, coaching, and other education-related organizations may not be subject to FERPA. In those deployments, Lyntra processes information under this Policy, the applicable service agreement, and other privacy laws that may apply.
3. Information We Collect
3.1 Account and Identity Information
This may include your name, email address, authentication identifier, institution or program affiliation, role, and account settings. When you sign in through an external provider, Lyntra may receive an account identifier and basic profile information. Lyntra does not receive the password used with that provider.
3.2 Connected Academic Information
When a student or Educational Organization connects a supported learning platform, calendar, course feed, browser extension, or other integration, Lyntra may receive course names and identifiers, assignment titles, instructions, descriptions, rubrics, course materials, due dates, points possible, calendar events, and connection metadata needed to maintain the integration.
Lyntra's learning-platform connections request only the minimum permissions necessary and operate in read-only mode by default. Lyntra does not write grades, submissions, messages, or activity records back to an official learning platform unless a future feature is separately authorized, tested, and disclosed.
Lyntra is not designed to request complete gradebooks, full student rosters, peer communications, disability diagnoses, accommodation records, or unrelated course information. The exact information available depends on the connection method and permissions approved by the student or Educational Organization.
3.3 Schedules, Commitments, and Preferences
Students may provide class schedules, work shifts, commute time, activities, meetings, personal commitments, available study time, task preferences, priorities, and preferred working patterns so Lyntra can help fit academic work into the student's actual week.
3.4 Academic Execution and Activity Information
Lyntra may create or record weekly plans, next academic steps, task breakdowns, time estimates, concepts to apply, rubric checkpoints, study-session goals, completed and unfinished steps, progress updates, blockers, rescheduling actions, reminders, recovery plans, and related activity needed to provide the Service.
3.5 Questions, Course Content, and Student Work
Students may provide questions, assignment text, course materials, draft excerpts, notes, or other content when using guided explanation, reasoning support, rubric review, understanding checks, or feedback features. Students should share only the content needed for the requested assistance.
3.6 Support and Communications
We collect information included in feedback, surveys, support requests, interviews, pilot communications, and other messages sent to Lyntra.
3.7 Technical and Usage Information
We may collect your IP address, browser and device type, operating system, application version, access time, diagnostic logs, error reports, security events, and interactions with Service features. We use essential cookies or similar technologies for authentication, security, preferences, and core functionality. We do not use advertising pixels or cross-site behavioral tracking for targeted advertising.
3.8 Sensitive Information Not Required by Lyntra
Lyntra does not require biometric information, precise geolocation, government identification numbers, financial account information, medical information, disability diagnoses, or accommodation records to provide its core academic-execution functions. Please do not include this information in free-text fields. If sensitive information is submitted unintentionally, it may be processed as part of the submitted content until it is removed.
4. How Information Is Collected
We collect information through the following sources:
- Directly from the student or another authorized user.
- Through an institution-authorized learning platform, calendar, single sign-on, or other integration.
- Through an iCalendar feed, browser extension, manual upload, or manual entry selected by the student.
- From an Educational Organization when permitted by its agreement and applicable law.
- Automatically through the student's interaction with the Service for security, reliability, and product operation.
Lyntra does not infer permission merely because information is technically accessible. Data access is limited to the connection scopes, user actions, institutional instructions, and product functions that have been authorized.
5. How We Use Information
We use information to:
- Synchronize authorized coursework, deadlines, rubrics, course materials, and calendar commitments.
- Identify clear next academic steps using deadlines, progress, available time, and user choices.
- Create and adapt weekly plans when work is completed, delayed, missed, or reprioritized.
- Break assignments into manageable steps and guided study sessions.
- Connect steps to relevant course concepts and rubric checkpoints.
- Provide explanations, reasoning prompts, understanding checks, feedback on user-selected work, reminders, and recovery support.
- Maintain accounts, integrations, preferences, and support communications.
- Operate, troubleshoot, secure, test, and improve the Service.
- Analyze aggregated or de-identified information to evaluate reliability, usability, and educational support outcomes.
- Comply with applicable law, enforce agreements, and protect users, Educational Organizations, Lyntra, and others.
We do not sell personal information. We do not use student information for targeted advertising or cross-context behavioral advertising. We do not use identifiable student information or identifiable course content to train general-purpose foundation models.
6. Artificial Intelligence and Model Routing
Lyntra's core production application is hosted on Amazon Web Services ("AWS"). For approved academic-execution features, Lyntra may route a limited request either to an approved model through Amazon Bedrock or directly to an approved Google Gemini model through the paid Gemini API. Google therefore acts as an AI subprocessor for requests routed to Gemini, even though Lyntra's core application infrastructure is hosted on AWS. Lyntra maintains an internal model and endpoint allowlist and reviews changes before a new route may process student information.
AI may be used to generate next steps, task breakdowns, adaptive plans, time estimates, concepts to apply, rubric-linked checkpoints, explanations, reasoning prompts, understanding checks, or feedback on student-selected work.
6.1 Minimum Necessary Context
For each AI request, Lyntra is designed to send only the content reasonably needed for the requested function. Depending on the feature, this may include an assignment title or instruction, a relevant rubric section, a limited course-material excerpt, the student's question, progress information, available time, or a draft excerpt. Unrelated account information and direct identifiers should be excluded or replaced with pseudonymous references when they are not needed.
6.2 No General-Purpose Model Training
Lyntra does not authorize identifiable student information, identifiable course content, prompts, or responses to be used to train general-purpose models. Requests to the Gemini API use a paid, billing-enabled service configuration, under which Google states that prompts and responses are not used to improve Google products. Requests through Amazon Bedrock are governed by AWS and the selected model's approved terms and settings.
6.3 Provider Retention, Logging, and Storage
Lyntra is designed not to place raw student prompts, course content, or model responses in general application logs. Amazon Bedrock retention must be configured according to Lyntra's approved policy, and model invocation logging must not capture raw student content unless separately approved and protected.
Google's standard paid Gemini API service may retain prompts and responses for abuse monitoring for a limited period unless Lyntra's project has been approved and configured for zero data retention. Optional Gemini request logging, datasets, feedback sharing, file storage, conversation storage, grounding, and explicit context caching remain disabled for student content unless separately reviewed, documented, and authorized.
6.4 Accuracy and Human Responsibility
AI output can be incomplete or incorrect. Students should review outputs, verify important information, and follow course, instructor, institution, and academic-integrity requirements. Lyntra does not make decisions about grades, admissions, accommodations, eligibility, discipline, financial aid, or other high-impact educational matters.
7. Academic Integrity and Learning Boundaries
Lyntra is designed to support learning and academic execution, not to impersonate a student or complete graded work on the student's behalf. The Service may explain concepts, guide reasoning, suggest a structure or next step, connect work to rubric criteria, check understanding, and provide feedback on student-selected drafts. Students remain responsible for their own work and for following all applicable academic integrity policies.
Lyntra may use safeguards, usage limits, or review processes to reduce misuse. A student's access may be restricted when use violates Lyntra's Terms or creates a material security or academic integrity risk.
8. Student Control and Educational Organization Reporting
8.1 Student Control
Students can control the information they enter, the supported integrations they connect, and the content they choose to submit for AI assistance. Disconnecting an integration stops future synchronization. Students may request access, correction, export, or deletion as described below.
8.2 Organization-Level Reporting
For organization-sponsored use, Lyntra may provide authorized personnel with aggregated or appropriately de-identified information about adoption, engagement, assignment friction, completed steps, recovery behavior, or where support may be useful. Lyntra applies role-based access and seeks to avoid reporting that could reasonably identify an individual when aggregate reporting is sufficient.
8.3 Student-Approved Context Sharing
A student may choose to share a limited context report with an authorized coach, tutor, accessibility professional, adviser, instructor, or support provider. Such a report may include completed steps, a current blocker, a question to ask, or a session outcome. Individual-level sharing occurs when the student directs it, when the Educational Organization has an authorized educational purpose and legal basis, or when disclosure is otherwise permitted by law and agreement.
8.4 No Disability Inference
Lyntra is not designed to diagnose a disability, infer accommodation eligibility, or make accommodation decisions. Educational Organizations should not use Lyntra activity as a substitute for an individualized accommodation process or professional judgment.
9. How We Disclose Information
9.1 Educational Organizations
We may disclose information to an Educational Organization only as permitted by the applicable deployment, agreement, student direction, institutional authorization, and applicable law. We do not provide identifiable student information to an organization for unrelated advertising, employment, disciplinary, or commercial purposes.
9.2 Service Providers and Subprocessors
We use service providers for AWS cloud hosting and application operations, AI processing through Amazon Bedrock and the paid Google Gemini API, authentication, communications, analytics, customer support, and security. These providers may process information only to provide contracted services and are subject to contractual, confidentiality, access, retention, and security requirements appropriate to their role. Lyntra maintains a current AI and cloud processing notice for institutional review.
9.3 Legal, Safety, and Security Reasons
We may disclose information when we reasonably believe disclosure is required by law or valid legal process, or is necessary to protect the rights, safety, security, or integrity of users, Educational Organizations, Lyntra, or others; investigate fraud, abuse, or a security incident; or enforce our agreements.
9.4 Business Transactions
If Lyntra is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be disclosed as part of the transaction under appropriate confidentiality protections and applicable law. We will provide notice if a transaction materially changes how personal information is handled.
10. Research, Evaluation, and Product Improvement
Lyntra may use aggregated or de-identified information to evaluate service quality, reliability, student engagement, and academic-execution patterns. Lyntra does not use identifiable student information for a separate research study unless the student or Educational Organization receives additional notice and any required consent, institutional approval, or ethics review for that study.
Lyntra does not attempt to re-identify information that has been de-identified for evaluation. Contracts with recipients of de-identified information prohibit re-identification.
11. Data Security
Lyntra's core production application and operational data are hosted on Amazon Web Services. Approved AI requests may also be processed by the paid Google Gemini API when that route is selected.
Safeguards include, as appropriate to the deployment, encryption in transit and at rest, least-privilege and role-based access, multi-factor authentication for privileged access, managed secrets and credentials, environment separation, logging and monitoring, secure software development practices, dependency and vulnerability management, backups, vendor review, personnel confidentiality obligations, and incident-response procedures.
Lyntra's application, job, queue, event, and model-routing systems are designed to use pseudonymous identifiers and minimum-necessary payloads. Raw course content, draft text, names, email addresses, disability information, and secrets should not be placed in log messages, resource names, tags, tracing fields, metric labels, queue attributes, or other operational metadata. Sensitive content remains in approved encrypted storage and is referenced by protected identifiers whenever practical.
No system can guarantee absolute security. Users should protect their credentials and promptly report suspected unauthorized access to cloud@lyntra.net
Lyntra is not currently represented as SOC 2 certified. Lyntra is implementing and documenting security, availability, confidentiality, and privacy controls as part of its readiness efforts and will claim certification only after an independent examination has been completed and an applicable report has been issued.
12. Data Retention and Deletion
12.1 General Retention
We retain information only for as long as reasonably necessary to provide the Service, secure our systems, maintain required records, comply with an Educational Organization's instructions, resolve disputes, and meet legal obligations. Retention periods may vary depending on the type of information and the applicable deployment.
12.2 Account Deletion
After verifying a valid account deletion request, Lyntra will delete or de-identify personal information from active production systems within 30 days unless retention is required for security, fraud prevention, legal compliance, dispute resolution, or an Educational Organization's lawful instructions.
Residual encrypted copies may remain temporarily in backups and system-recovery media until they expire through normal rotation. These copies are not used for ordinary product operations.
12.3 Connected Academic Data
Disconnecting a learning-platform or calendar integration stops future synchronization. Previously synchronized information remains subject to the student's account settings, the applicable agreement, and verified deletion requests.
12.4 AI Request and Response Content
Lyntra does not intentionally retain raw AI request and response content in general application logs. Content that a student chooses to save as part of a plan, study session, explanation, or feedback history is retained as account content.
Amazon Bedrock and the paid Google Gemini API may apply provider-side processing or retention according to the configured endpoint and current provider terms. Lyntra documents these settings, disables optional content logging and storage for student data, and does not claim zero data retention unless the specific processing route has been verified to provide it.
12.5 Organization Termination
For organization-sponsored deployments, the return, export, retention, and deletion of information are handled according to the organization's agreement and lawful instructions. When required, Lyntra will provide confirmation of deletion.
13. Your Choices and Rights
Depending on your account, deployment, and applicable law, you may be able to:
- Access or correct your account and profile information.
- Review, update, or delete user-entered tasks, commitments, preferences, and progress information.
- Request a portable copy of the personal information associated with your account.
- Request deletion of your account and personal information.
- Disconnect a learning platform, calendar, or other integration.
- Change non-essential notification preferences.
- Submit a privacy question, objection, complaint, or appeal.
If you use Lyntra through an Educational Organization, you should generally contact the organization first regarding education records. Lyntra will work with the organization to support applicable FERPA requirements and contractual obligations.
Direct privacy requests may be sent to cloud@lyntra.net . We may need to verify your identity and may retain limited information necessary to document and complete your request.
14. Children and Younger Students
The Service is designed primarily for postsecondary education and is not directed to children under 13. Lyntra does not knowingly collect personal information online from a child under 13 without the authorization and consent required by applicable law. If we learn that such information was collected without a valid legal basis, we will take reasonable steps to delete it.
Students under 18 may use Lyntra only when permitted by the applicable Educational Organization, program, agreement, and law. Deployments involving minors may require additional notices, consent, age-appropriate design, access restrictions, and contractual protections.
15. United States Operations and International Use
Lyntra is operated from the United States. Information may be stored or processed in the United States and other approved locations where service providers operate. For organization-sponsored deployments, data-location and transfer requirements may be addressed in the applicable agreement and technical configuration.
The Service is currently designed primarily for United States postsecondary institutions, education-related organizations, and students. Contact Lyntra before deploying the Service for a program subject to non-U.S. data protection requirements.
16. State Privacy Rights
Residents of certain states may have additional rights under applicable privacy laws, including the right to know, access, correct, delete, obtain a copy of, or appeal decisions concerning personal information. These rights apply only where the relevant law applies to Lyntra and may be subject to exceptions.
Lyntra does not sell personal information or share personal information for cross-context behavioral advertising. We will not discriminate against users for exercising applicable privacy rights.
Requests may be sent to cloud@lyntra.net
17. Changes to This Policy
We may update this Privacy Policy to reflect changes to the Service, service providers, technology, applicable law, or institutional commitments. We will update the "Last Updated" date and provide additional notice when a material change requires it.
Information collected through organization-sponsored deployments remains subject to the applicable agreements and any required change-control procedures.
18. Contact Us
Privacy, security, access, deletion, or complaint requests may be sent to:
Lyntra, Inc.
Attn: Privacy & Security
4710 Sheboygan Avenue
Madison, Wisconsin, United States
Privacy and Security: cloud@lyntra.net
Support: francopastor@lyntra.net
Students with questions about institution-controlled education records should also contact the applicable Educational Organization. Information about FERPA complaints is available from the U.S. Department of Education's Student Privacy Policy Office.