Legal

Privacy Policy

↓ Download PDF

Effective date: June 30, 2025  ·  Last updated: June 30, 2025

PULSE4ED, LLC ("PULSE4ED," "we," "our," or "us") operates a suite of AI-powered coaching and professional development tools for K–12 educators, including Principal PULSE (available at principal.pulse4ed.com) and PLC Pulse (available at plc.pulse4ed.com), as well as this marketing website at pulse4ed.com (collectively, the "Platform").

We take student, educator, and school data privacy very seriously. This Privacy Policy explains what information we collect, how we use it, with whom we share it, and what rights you have — including our obligations under the Family Educational Rights and Privacy Act (FERPA), the Children’s Online Privacy Protection Act (COPPA), and applicable state privacy laws.

By using any part of the Platform you agree to this policy. If you are accessing the Platform on behalf of a school or district ("School Partner"), the School Partner’s agreement with us governs data use to the extent it conflicts with this policy.

1. Who We Are & Which Products This Covers

PULSE4ED, LLC is a U.S.-based educational technology company. Our Platform includes:

  • Principal PULSE — An AI-powered observation, coaching, and development platform for principals and instructional coaches. It enables educators to log classroom observations, record and transcribe coaching conversations, generate PULSE Method™ feedback scripts, track teacher development tiers, and sync coaching events with Google or Outlook Calendar.
  • PLC Pulse — A Professional Learning Community (PLC) oversight and progress-tracking platform for principals, assistant principals, teachers, and instructional coaches. It enables goal tracking, meeting documentation and summarization, attendance monitoring, structured feedback via the PULSE Method™, and admin visit scheduling.
  • This website (pulse4ed.com) — Our marketing and informational site.

Both products are intended for use by adult educators and school administrators. Neither product is directed at students, and we do not knowingly collect information directly from students under 18.

2. Information We Collect

2.1 Information You Provide Directly

Account & Profile Information

  • Full name, email address, job title, and password (stored as a bcrypt hash — we never store your plaintext password)
  • School name, district name, and school type (Elementary, Secondary, or Both)
  • Role selection (Principal, Assistant Principal, Teacher, or Instructional Coach)
  • Profile image (PLC Pulse)
  • Scheduling preferences (preferred observation and debrief time windows)

Observation & Coaching Data (Principal PULSE)

  • Teacher profiles: name, email, subject, grade level, and coaching tier assignment
  • Classroom observation records: notes, observation mode (walkthrough vs. formal), date and time
  • Coaching session data: PULSE scores (P, U, L, S, E), voice ratio metrics, Look-For ratings, focus areas, coaching goals, and session status
  • Audio recordings of observations and feedback conversations, including their transcripts
  • Photos, screenshots, and student work samples attached to observations (uploaded by you)
  • Coach self-reflection entries and PULSE self-assessment scores
  • Custom Look-Fors (instructional practice checklists you define)
  • In-app feedback you submit (bug reports, feature requests, free-text messages)

PLC & Team Data (PLC Pulse)

  • PLC team names, subjects, grade levels, and member rosters (names, roles, grades, subjects)
  • SMART goal text, baseline values, target values, units, target dates, and monthly checkpoint entries
  • Meeting records: date, agenda, notes, attendance matrix, and (in a future release) audio recordings
  • PULSE progress reports: structured five-section feedback (Praise, Unpack Data, Listen & Learn, Suggest, Encourage)
  • Admin visit records: scheduled date/time, notes, and completion status
  • Uploaded goal data files (CSVs, assessment data, PDFs)

2.2 Information We Collect Automatically

  • Standard server logs: IP address, browser type, operating system, referring URL, pages visited, and timestamps
  • Session tokens and authentication tokens (JWT, stored client-side)
  • In-app feedback metadata: the page URL where feedback was submitted and your browser’s user-agent string
  • Calendar OAuth tokens (Google or Outlook) if you connect a calendar — access tokens, refresh tokens, and expiry timestamps are stored encrypted

2.3 Information We Do Not Collect

  • We do not collect payment card details directly (Stripe will handle billing when activated).
  • We do not use third-party session-recording tools (e.g., session replay, heatmap services) on pages that handle educator or student-related data.
  • We do not knowingly collect information directly from students under 18.

3. How We Use Your Information

We use the information we collect to:

  • Provide and improve the Platform — creating your account, authenticating you, delivering features, and fixing bugs.
  • Generate AI-powered coaching tools — sending observation transcripts, teacher context, and classroom data to our AI providers to produce PULSE scores, coaching scripts, follow-up emails, Look-Fors, and meeting summaries (see Section 4).
  • Facilitate calendar integration — syncing observation and feedback events to your connected Google or Outlook Calendar.
  • Send transactional emails — password resets, member invitations, scheduled-observation reminders, PULSE report deliveries, and follow-up coaching emails to teachers (sent on your behalf).
  • Generate reports and exports — producing Word and Excel exports of coaching data, and PDF exports of PULSE progress reports.
  • Maintain an audit trail — logging key actions (observations completed, sessions deleted, reports published) in an immutable activity log for accountability and compliance.
  • Enforce our Terms of Service and protect the safety and security of the Platform.
  • Contact you about your account — service announcements, security notices, and (with your consent) product updates.

We do not sell your personal information or the information of the teachers and students referenced in your data. We do not use your data to serve third-party advertising.

4. AI-Powered Features & Third-Party AI Services

Both products use OpenAI’s API to power intelligent coaching features. This is a core part of what makes PULSE4ED work, so we want to be transparent about how it operates.

4.1 Principal PULSE — AI Features

FeatureWhat we send to OpenAIWhat we receive back
Transcript AnalysisCoaching conversation transcript, teacher name/subject/grade/tier, Look-Fors, classroom photos or screenshotsPULSE scores, voice ratio, coaching feedback narrative, model coaching script, suggested teacher next step, Look-For results
Script GenerationTeacher context, Look-For results, data set summary, identified strength/growth areasReady-to-use PULSE-structured coaching conversation script
Follow-Up Email GenerationTeacher name, subject, grade, and PULSE feedback fieldsEmail subject and body for the coach to review and send
Audio TranscriptionAudio file (MP3/WAV)Text transcript of the recording
Look-For GenerationTeacher context, initiative or focus areasSuggested list of instructional Look-Fors
Coach Self-Reflection SummaryCoach’s PULSE self-assessment scoresParagraph and bulleted summary of coach’s growth areas

4.2 PLC Pulse — AI Features (Planned Phase 1.5)

FeatureWhat we send to OpenAIWhat we receive back
Meeting Transcription (Whisper)Meeting audio recordingText transcript of the meeting
Meeting Summary (GPT-4o-mini)Meeting transcript, agenda, notes, and active PLC goal descriptions (no student PII — only aggregate metrics)Summary of key topics, goal progress, action items, decisions, and celebrations

4.3 OpenAI Data Handling

We use OpenAI’s API under a data processing agreement. Data sent to OpenAI is governed by OpenAI’s API data usage policies, which state that API inputs and outputs are not used to train OpenAI models by default. For the most current information on OpenAI’s data practices, please visit openai.com/policies/api-data-usage-policies.

We recommend that users avoid including student-identifying information (full names, ID numbers, Social Security numbers, or other FERPA-protected identifiers) in free-text fields that are sent to AI features. Teacher names and instructional context are necessary for the coaching tools to function; student data beyond aggregate performance metrics is not.

5. How We Share Information

We do not sell personal information. We share data only in the following circumstances:

5.1 Service Providers (Sub-processors)

ProviderPurposeData Shared
OpenAIAI coaching features, transcription, summarizationTranscripts, teacher context, classroom media, meeting data (as described in Section 4)
Amazon Web Services (S3)File storage — audio recordings, photos, screenshots, PDFs, uploaded data filesUploaded files; presigned URLs used so files transfer browser-to-S3 without passing through our servers
Amazon Web Services (SES)Transactional email deliveryRecipient email addresses and message content
MongoDB AtlasDatabase hostingAll structured data described in Section 2
Google / Microsoft (Calendar OAuth)Calendar sync (only if you connect your calendar)Event details (date, time, notes) synced to your own Google or Outlook Calendar
Stripe (future)Billing and subscription managementPayment information; we will not store card details ourselves

All service providers are contractually bound to use data only to provide the specified service to us and are prohibited from using it for other purposes, including advertising.

5.2 School Partners

If you access PULSE4ED through a school or district agreement, your school or district administrator may have access to data generated within their campus or district instance, consistent with their administrative role and applicable law (including FERPA).

5.3 Legal Requirements

We may disclose information if required by law, court order, or government authority, or to protect the rights, property, or safety of PULSE4ED, our users, or the public.

5.4 Business Transfers

In the event of a merger, acquisition, or sale of all or a portion of our assets, user data may be transferred as part of that transaction. We will provide notice before personal information is transferred and becomes subject to a different privacy policy.

6. FERPA & Student Data

PULSE4ED products are used by school officials — principals, assistant principals, instructional coaches, and teachers — to support educator coaching and professional development. To the extent that any data on the Platform constitutes "education records" under FERPA (for example, aggregate assessment data attached to a PLC goal or student work samples uploaded as observation evidence), we act as a school official with a legitimate educational interest under FERPA, as determined by the School Partner.

Our FERPA commitments:

  • We use education records solely to provide the Platform services; we do not use them for advertising or sell them to third parties.
  • We maintain reasonable security safeguards appropriate for the sensitivity of education records.
  • We will notify School Partners if we discover a security breach affecting education records and will cooperate with their response efforts.
  • We will delete or return education records upon request or when a School Partner relationship ends, subject to our data retention practices (Section 7).
  • We do not re-disclose education records except as directed by the School Partner or as permitted by FERPA.

School Partners are responsible for obtaining any required parent or eligible student consent before uploading education records to the Platform, and for ensuring their use of the Platform complies with FERPA and applicable state law.

7. Data Retention & Deletion

  • Active accounts — We retain your data for as long as your account is active or as needed to provide you with the Platform.
  • Coaching sessions and PLC records — Retained until you delete them or your account is closed. Coaches can delete individual sessions; this action is reflected in the activity log.
  • Activity logs (Principal PULSE) — Our activity log is append-only and immutable to preserve accountability. It records metadata (event type, timestamps, teacher name snapshot) but not full content of observations.
  • Audit logs (PLC Pulse) — Time-bucketed quarterly logs. PII-tagged fields (meeting notes, report content, names) are stored as SHA-256 hashes — not raw values — in the audit log. Old quarters may be archived to cold storage.
  • Audio recordings (PLC Pulse) — Default retention of 90 days per campus setting; campus administrators can adjust this.
  • Password reset tokens — Automatically expire after 1 hour.
  • Calendar OAuth tokens — Retained until you disconnect your calendar in Settings.
  • Account deletion — To request deletion of your account and associated data, contact us at privacy@pulse4ed.com. We will process your request within 30 days, except where retention is required by law or legitimate business interests (e.g., audit logs that must be retained for compliance).

Note: PLC Pulse uses soft deletes — records are marked as deleted rather than permanently removed — to maintain audit integrity. Hard deletion upon request is available; contact us.

8. Security

We implement technical and organizational safeguards to protect information against unauthorized access, loss, or misuse:

  • Passwords are hashed using bcrypt with a salt factor of 12. We never store plaintext passwords.
  • Authentication tokens are signed JWTs with a 7-day expiry.
  • Data in transit is encrypted via HTTPS/TLS.
  • File uploads to AWS S3 use presigned URLs, so media files transfer directly from your browser to our storage bucket without passing through our application servers.
  • Security headers (CORS, Content-Security-Policy, etc.) are enforced via Helmet middleware.
  • Input sanitization strips HTML from request bodies to prevent cross-site scripting (XSS).
  • CSRF protection is applied to OAuth calendar flows (time-limited state tokens).
  • Access control — all API endpoints require authenticated sessions; campus-scoped queries prevent cross-tenant data access.

No security system is impenetrable. If you believe your account has been compromised, please contact us immediately at security@pulse4ed.com.

9. Children’s Privacy (COPPA)

The Platform is designed for use by adult educators and school administrators. We do not knowingly collect personal information directly from children under 13. If we learn that we have inadvertently collected personal information from a child under 13 without verifiable parental consent, we will delete it promptly.

If student work or assessment data is uploaded to the Platform as part of a coaching observation, it is the responsibility of the School Partner to ensure that any such upload complies with COPPA, FERPA, and applicable state law — including obtaining required parental consents.

If you are a parent or guardian and believe your child’s information has been collected, please contact us at privacy@pulse4ed.com.

10. Your Rights & Choices

Depending on where you are located, you may have the following rights regarding your personal information:

  • Access — Request a copy of the personal information we hold about you.
  • Correction — Ask us to correct inaccurate or incomplete information. You can also update most profile information directly in your account Settings.
  • Deletion — Request deletion of your account and associated data (subject to legal retention obligations and immutable audit logs).
  • Data portability — Export your coaching data as Word or Excel files at any time from within Principal PULSE. PLC Pulse supports PDF and browser-based exports.
  • Withdrawal of consent — Disconnect your Google or Outlook Calendar integration at any time in Settings. This will revoke our access and delete stored calendar tokens.
  • Recording consent (PLC Pulse) — If your campus requires recording consent, you may withdraw consent at any time within the app. Withdrawing consent will stop new recordings from being captured; prior recordings are subject to the campus’s retention policy.
  • Opt-out of marketing — Unsubscribe from non-transactional marketing emails at any time via the link in any marketing email, or by contacting us.

To exercise any of these rights, contact us at privacy@pulse4ed.com. We will respond within 30 days. We may need to verify your identity before processing certain requests.

California residents may have additional rights under the California Consumer Privacy Act (CCPA/CPRA), including the right to know what categories of personal information we collect and the right to opt out of the sale of personal information. We do not sell personal information.

11. Cookies & Tracking Technologies

The marketing website (pulse4ed.com) uses minimal cookies essential for the site to function (e.g., session state). We do not use third-party advertising cookies or behavioral tracking cookies.

The Principal PULSE and PLC Pulse applications use JWT tokens stored in your browser (localStorage or cookies) to maintain your authenticated session. These are strictly necessary for the apps to function and are not used for advertising purposes.

We do not use session-recording, heatmap, or user-behavior analytics tools (such as Hotjar, FullStory, or PostHog) on pages that handle educator or student-related data, out of an abundance of caution for K–12 privacy.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes that affect how we handle data already collected, we will provide additional notice — for example, by emailing registered users or posting a prominent notice in the app.

Your continued use of the Platform after changes become effective constitutes acceptance of the updated policy.

14. Contact Us

If you have questions, concerns, or requests related to this Privacy Policy or your data, please contact us:

PULSE4ED, LLC
Privacy Team
Email: privacy@pulse4ed.com
General inquiries: info@pulse4ed.com
Security concerns: security@pulse4ed.com

We aim to respond to all privacy-related inquiries within 30 days.