PylotEDBack to homepage

LEGAL

Privacy Policy

Effective Date: September 16, 2026
Last Updated: September 16, 2026

Overview

PylotED (“PylotED,” “we,” “us,” or “our”) provides a web-based platform designed to help K–12 schools, districts, educators, and education organizations manage and evaluate Pilot programs, vendor relationships, feedback, communications, and related administrative activities.

We are committed to protecting user and organization information and to collecting and processing only the information reasonably necessary to provide PylotED.

PylotED is designed for educators, administrators, district personnel, vendors, and other authorized adult users. PylotED does not provide student accounts and is not intended to collect or process student personally identifiable information or student education records. Schools, districts, vendors, and users should not enter, upload, or otherwise provide student personally identifiable information to PylotED. If we become aware that student personal information has been submitted unintentionally, we may take appropriate steps to remove it.

Information We Collect

Depending on how PylotED is used, we may collect or process the following categories of information:

  • First and last name
  • Email address
  • Organization or district affiliation
  • User role and permissions
  • Account identifiers
  • Optional profile information

Users may enter information necessary to use PylotED, including district and school information; staff and business contact information; vendor information; Pilot-program information; feedback and responses; communications; CRM records; forms and settings; quotes and invoices; and other administrative information.

PylotED may process technical information necessary to operate and secure the service, including authentication information, session information, application requests, timestamps, and security-related records.

Google Authentication and Google Workspace

PylotED supports Google authentication. When a user chooses to sign in with Google, PylotED may receive the user’s verified email address, name, Google account identifier, and profile image when available. This information is used to authenticate the user, establish their PylotED account, and provide appropriate access to the platform.

An authorized district or organization administrator may optionally connect a Google Workspace directory to PylotED. After authorization, PylotED may access staff directory information necessary to provide rostering and organization-management functionality, including staff names and email addresses; organizational unit assignments; account or suspension status; Google Workspace groups; group names and email addresses; and group membership information.

PylotED uses read-only Google Workspace directory permissions appropriate to these functions. Connecting Google Workspace is optional and requires authorization through Google’s OAuth process. PylotED does not intentionally use Google Workspace rostering to obtain student information. PylotED’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including applicable Limited Use requirements.

CSV Roster Imports

Authorized users may also import staff roster information using CSV files. CSV roster imports should contain only appropriate staff or authorized adult-user information needed to establish or manage PylotED accounts. CSV files should not contain student information. Organizations are responsible for ensuring that information uploaded through CSV rostering is appropriate for use with PylotED.

Gmail

Users may optionally connect Gmail to PylotED for communication features. When a user chooses to send an email through PylotED, information transmitted through Gmail may include recipient email address, subject, message body, invitation or account-setup links, and attached quote or invoice PDFs.

PylotED may also access limited Gmail metadata for contact-history functionality, such as sender, recipient, subject, date, and message identifiers. PylotED requests Gmail metadata access rather than permission to read message bodies for contact-history functionality. PylotED may also request permission to send email when the user chooses to use PylotED’s email features. PylotED does not use Gmail information for advertising and does not sell Gmail information.

How We Use Information

  • Provide and operate the PylotED service
  • Authenticate users
  • Manage organizations, accounts, roles, and permissions
  • Manage Pilot programs and vendor relationships
  • Provide feedback and communication functionality
  • Maintain staff rosters
  • Generate administrative documents
  • Provide customer support
  • Protect the security and integrity of the platform
  • Diagnose technical problems
  • Maintain and improve PylotED
  • Comply with applicable legal and contractual obligations

Service Providers and Third Parties

PylotED uses service providers and infrastructure necessary to operate certain portions of the service. These currently include:

  • Hosting and database infrastructure. PylotED’s hosted application environment uses infrastructure that includes Cloudflare D1 for application database storage.
  • Google services. Google may process authentication, Workspace directory, Gmail, and related information when users or organizations choose to use those integrations.
  • Address lookup. OpenStreetMap Nominatim may receive organization or address search information entered into PylotED to return matching address information.
  • Sales-tax lookup. SalesTaxZip may receive a ZIP code to return geographic and applicable sales-tax information.
  • Google Maps. When a user chooses to open an address in Google Maps, the address may be transmitted to Google through the resulting browser request.

These third-party services may process information according to their respective terms and privacy policies.

Disclosure and Advertising

PylotED does not sell personal information. PylotED does not use personal information for third-party behavioral advertising. PylotED currently does not use third-party advertising networks or advertising trackers. If these practices materially change, we will update this Privacy Policy as appropriate.

We may disclose information to service providers that help us operate and secure PylotED, but only as reasonably necessary for them to provide those services. We may also disclose information when required by applicable law, legal process, court order, or governmental request, or when reasonably necessary to protect the rights, security, or integrity of PylotED, its users, or others. Information may also be transferred in connection with a merger, acquisition, financing, reorganization, or sale of some or all of the business, subject to applicable law and contractual obligations.

We do not sell district roster information.

Security

PylotED uses administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, or destruction. Depending on the applicable functionality, these measures include authentication controls, role-based access controls, organization-level access restrictions, session controls, secure communications, credential protection, and other security practices appropriate to the information processed.

No internet-based service can guarantee absolute security.

Retention and Deletion

PylotED retains information for as long as reasonably necessary to provide the service, fulfill contractual obligations, maintain appropriate business and security records, and comply with applicable law.

When a district account is permanently deleted, PylotED deletes the district’s applicable active application data and associated Google Workspace connection credentials from its active systems. When applicable, PylotED also attempts to revoke the district’s Google Workspace authorization before removing its locally stored connection credentials. If a person legitimately belongs to multiple organizations using PylotED, deleting one district does not automatically delete that person’s account or information necessary to maintain their relationship with another organization.

Information may remain temporarily in infrastructure backups, security logs, or records that must legitimately be retained for legal, security, accounting, fraud-prevention, or contractual purposes. Messages already sent through Gmail may remain in the sender’s, recipient’s, or Google’s systems according to their respective settings and retention practices.

Users and organizations may disconnect supported Google integrations. When a district is permanently deleted, PylotED removes locally stored Google Workspace roster credentials associated with that district and attempts to revoke the corresponding authorization with Google. Users may also manage third-party application access through their Google account or Google Workspace administration tools.

Children and Student Information

PylotED is designed specifically as an adult administrative platform. PylotED does not provide student accounts, and PylotED is not intended to collect student personally identifiable information or student education records. Organizations using PylotED should not upload student rosters, student education records, student contact information, or other student personally identifiable information. If PylotED becomes aware that such information has been provided unintentionally, we may remove the information and work with the applicable organization to address the issue.

PylotED is not directed to children and is intended for use by authorized adults. PylotED does not knowingly provide accounts to children or intentionally collect personal information directly from children. If we learn that personal information from a child has been provided to PylotED contrary to the intended use of the service, we may take steps to remove it.

Your Privacy Rights

Depending on applicable law and the user’s location, individuals may have rights regarding their personal information, including rights to request access to, correction of, or deletion of certain personal information.

Requests regarding personal information may be submitted to privacy@pyloted.com. We aim to respond to legitimate privacy requests within 30 days and will comply with shorter or different response periods when required by applicable law. We may need to verify the identity and authority of the person making a request before taking action.

Changes to This Policy

We may update this Privacy Policy from time to time as PylotED evolves, our integrations change, or applicable legal requirements change. When material changes are made, we will update the “Last Updated” date above and provide additional notice when appropriate.

Contact

Questions, concerns, deletion requests, or other inquiries regarding this Privacy Policy or PylotED’s privacy practices may be directed to:

PylotED
Privacy: privacy@pyloted.com
Website: PylotED.com

PRIVACY & SECURITY

Privacy & Security Overview

PylotED helps schools and districts manage and evaluate Pilot programs while maintaining a deliberately limited data footprint. The platform is designed for educators, administrators, district personnel, vendors, and other authorized adults—not students.

Students do not use PylotED. PylotED does not provide student accounts and is not designed to collect student personally identifiable information or student education records. Districts and users are instructed not to upload or enter student PII into the platform.

Limited collection and access

PylotED collects only the information necessary to provide and manage the service. For standard educator accounts, this primarily includes first name, last name, email address, organization, and user role. Additional business and administrative information may be stored when users use PylotED’s Pilot-management, feedback, CRM, communication, quote, or invoice functionality.

PylotED supports secure Google authentication. Google Sign-In allows authorized users to access PylotED using their existing Google identity rather than requiring PylotED to handle their Google password. Authentication and authorization are separate: signing in establishes identity, while PylotED’s permissions determine what that user is allowed to access.

PylotED uses role-based access controls to limit functionality and information according to each user’s assigned permissions. Administrative functionality is restricted to appropriately authorized users. Permissions are enforced within the application rather than relying solely on what is displayed in the user interface.

Organization-level separation

PylotED is designed to keep organizations logically separated. Users are granted access according to their organization memberships and permissions. A user associated with one district should not receive access to another district’s information unless that person has been separately authorized for both organizations. When a legitimate user belongs to multiple organizations, PylotED preserves the appropriate relationships independently.

Optional Google Workspace and Gmail connections

Districts may optionally connect Google Workspace to simplify staff rostering. When authorized by the district, PylotED may retrieve limited staff-directory information such as staff names and email addresses, organizational units, account status, groups, and group membership. PylotED uses read-only directory permissions for this functionality and requests only the Google permissions required for the features being provided.

Google Workspace rostering is optional. Districts that do not wish to connect Google Workspace may import authorized adult users through CSV. CSV rostering is intended only for educator, administrator, staff, vendor, and other authorized adult-user information. Student rosters should not be uploaded to PylotED.

Authorized users may optionally connect Gmail for PylotED communication features. PylotED can send messages through the connected user’s Gmail account and can access limited message metadata used for contact-history functionality. PylotED uses Gmail metadata access for this feature rather than requesting permission to read email message bodies.

Deletion and service providers

When a district is permanently deleted, PylotED removes applicable district information from its active application database, including associated roster information and locally stored Google Workspace connection credentials. PylotED also attempts to revoke the district’s Google Workspace authorization when the connection is removed as part of district deletion.

Information legitimately associated with another organization is preserved when necessary. For example, deleting District A does not delete a user’s account if that person is also an authorized member of District B. Limited information may remain temporarily in infrastructure backups, security logs, or records that must be retained for legitimate legal, security, accounting, or contractual purposes.

PylotED uses a limited number of service providers necessary to operate particular functionality, including infrastructure and services associated with Google, Cloudflare, OpenStreetMap Nominatim, and SalesTaxZip. PylotED does not currently use third-party advertising networks and does not sell personal information.

Security approach

PylotED incorporates security controls appropriate to an educator-facing SaaS platform, including:

  • Secure authentication
  • Role-based authorization
  • Organization-level data separation
  • Session controls
  • Protected credentials
  • OAuth permission minimization
  • Data-deletion procedures
  • Limited collection of personal information

Security practices will continue to evolve as PylotED grows and district requirements develop.

PylotED’s approach is intentionally straightforward:
Collect less. Protect what we collect. Keep students out of the system. Give districts control over their information.

For additional details, please review the Privacy Policy. Privacy questions or requests: privacy@pyloted.com