Legal

Privacy Policy

Effective August 16, 2026 · Last updated: August 16, 2026

HUSH is a class hub for large higher-education courses: AI tutoring grounded in course materials, live questions, class chat and study rooms, attendance, in-class activities, and notifications. This policy explains exactly what we collect, how it is used, who it is shared with, and the privacy limits we enforce.

1. Summary (plain English)

  • Both instructors and students create accounts (email and password, or Google sign-in).
  • Students can still ask questions anonymously to the instructor when the class is set that way.
  • Instructors, teaching assistants, and institution administrators cannot read students' Class Chat, Study Rooms, or Direct Messages.
  • We do not sell personal data, and our AI providers do not train models on your data.
  • Data is encrypted in transit (HTTPS) and at rest by our cloud provider.
  • You can request access to or deletion of your data at any time through our contact form.

2. Who this policy covers

"HUSH" (also "we," "us," "our") means the HUSH service and the people who operate it. This policy applies to instructors, teaching assistants, department and institution administrators, and students who use HUSH ("Users"). It covers the HUSH web and installable (PWA) application, the marketing site, push notifications, and support communications (collectively, the "Service").

3. Information we collect

3.1 Instructor, TA, and administrator accounts

  • Name, email address, and a hashed password — or an OAuth identifier if you sign in with Google.
  • Institution, department, course, and section names you enter, plus staff roles you assign.
  • Billing information processed by Stripe. We store only the last four digits of the card and a Stripe customer ID — never full card numbers.

3.2 Student accounts

  • Name, email address, and a hashed password — or an OAuth identifier if you sign in with Google.
  • The classes you join by code, your enrollment records, and your role in each class.
  • For students on the student-pay plan, billing information processed by Stripe (last four digits and Stripe customer ID only).

3.3 Student-generated content

  • Class Chat messages, replies, reactions, @mentions, and pinned messages.
  • Direct messages between classmates and messages in student-created Study Rooms.
  • Polls you create and your poll votes.
  • Images and files you upload to chat, rooms, or class spaces.

3.4 Live Questions and AI tutor conversations

  • The text of questions submitted to the instructor, their timestamps, votes, and the class they were submitted to. Where the instructor has enabled anonymity, your identity is hidden from classmates and, in fully anonymous mode, from the instructor as well — but the submission is still stored and linked to your account internally for abuse prevention.
  • Your conversations with the Course Assistant (AI tutor), including your prompts, the answers returned, and the course materials cited.
  • AI-generated lessons, challenges, and confusion maps derived from class activity.

3.5 Educational records

  • Attendance records created when you check in with a rotating class code.
  • Responses to in-class activities, quizzes, and polls, along with any scores or grades produced from them.

For US institutions, these are typically "education records" under FERPA and are handled as described in section 12.

3.6 Course materials uploaded by instructors

  • Slides, documents, links, announcements, deadlines, and private staff notes uploaded by course staff, plus text extracted from them so the Course Assistant can cite sources.

3.7 Notifications and technical data

  • Push notification device tokens and subscription endpoints, plus your notification preferences.
  • Basic request logs (IP address, user agent, page or endpoint requested) retained for up to 30 days for security and debugging.
  • Product analytics events (for example, "created a class" or "opened a lesson") to understand feature usage. We do not send message or question content into analytics.

4. How we use information

  • Operate the Service: display questions, run chat and rooms, deliver lessons, record attendance and activity responses, and generate confusion maps.
  • Ground the Course Assistant in your course's own materials and published answers.
  • Send transactional email and push notifications (announcements, deadlines, mentions, billing receipts).
  • Provide support when you contact us.
  • Detect and act on abuse, spam, harassment, and safety issues.
  • Bill and manage subscriptions and seats.
  • Comply with legal obligations.

5. AI processing — what is actually sent

HUSH uses third-party large-language-model providers through an AI gateway. Different features send different data, and we want to be precise rather than reassuring:

  • Course Assistant (AI tutor): your question text, recent conversation turns, and relevant excerpts of the course materials for that class are sent to the provider. This content is not anonymized in the sense of being stripped of everything identifying — if you type identifying details into a question, they are sent.
  • "Catch Me Up" room summaries: the student chat messages you missed in that room, including author display names, are sent to the provider to produce the summary.
  • Lessons, challenges, and confusion maps: course materials and aggregated question or activity content are sent to the provider.

We do not send account passwords or payment data to AI providers. Our providers are contractually prohibited from using this data to train their models. Providers may retain inputs for a short abuse-monitoring window (typically up to 30 days) under their own policies, after which they are deleted.

6. Sharing

We share information only with:

  • Subprocessors that operate the Service — listed in section 6.1 below.
  • Your institution, if and when you use HUSH under a department or institution plan. Administrators receive account, roster, seat-usage, attendance, activity/grade, and aggregate engagement data for their own courses. Administrators and instructors do not receive the contents of students' Class Chat, Study Rooms, or Direct Messages.
  • Law enforcement or regulators, where required by valid legal process, and where we may lawfully do so we will attempt to notify the affected user.
  • A successor entity, in the event of a merger or acquisition, subject to this policy.

We do not sell personal data and we do not share it for cross-context behavioral advertising.

6.1 Subprocessors

We use the following providers to operate the Service:

  • Supabase — database, authentication, file storage, and realtime. United States.
  • Stripe — payment processing. United States.
  • Lovable — application hosting and AI request routing (AI gateway). United States.
  • Google (Gemini models, accessed through the gateway) — AI inference for the Course Assistant, summaries, and lessons. United States.
  • Resend (via the Lovable email pipeline) — transactional and notification email delivery. United States.

Push notifications are delivered by HUSH's own server directly to your browser's push endpoint — there is no third-party push subprocessor. An updated list is available on request.

7. Privacy guarantees we enforce

These are binding commitments, enforced in the product and not merely stated here:

  • Instructors, teaching assistants, and institution administrators cannot read student Class Chat, student-created Study Rooms, or Direct Messages between students.
  • Rooms created by an instructor that are visible to course staff are clearly marked as teacher-visible in the interface before you post.
  • Content you report is reviewed by HUSH moderation. Reporting a message does not hand a professor unrestricted access to a private conversation; we share only what is necessary to act on the report or to protect someone's safety.
  • Anonymous Live Questions are presented to the instructor without your identity when the class is in an anonymous mode.

8. Your rights

Depending on your jurisdiction (for example GDPR in the EU/UK, or CCPA/CPRA in California), you may have the right to access, correct, port, restrict, or delete your personal data, to object to certain processing, and to be free from discrimination for exercising these rights. Use our contact form to exercise them. We respond within 30 days. Where your institution controls your account, we may direct your request to them and assist them in fulfilling it.

9. Retention

  • Instructor and student accounts: retained until the account is deleted, then removed within 30 days.
  • Enrollments and rosters: retained while the section exists; removed when the section or account is deleted.
  • Live Questions and instructor answers: retained for the life of the course section unless deleted earlier by course staff.
  • Class Chat, Study Rooms, and Direct Messages: retained while the class is active; deleted with the section, or on request by the account holder for their own messages.
  • Uploaded images and files: deleted with the message, room, or section they belong to.
  • AI tutor conversations: retained for the academic term to preserve your history, then deleted or de-identified.
  • Attendance, activity responses, and scores: retained for the life of the section, or longer where the institution instructs us to retain them as education records.
  • Push tokens: deleted when you disable notifications, uninstall, or the token expires.
  • Billing records: retained as required by tax and accounting law (typically 7 years).
  • Request logs: 30 days. Backups: up to 30 days after deletion, then purged.

10. Eligibility and children

HUSH is intended for higher-education users who are 18 or older, or the age of majority in their jurisdiction. It is not directed to children under 13, and we do not knowingly collect personal information from them. If we learn we have done so, we delete it. An institution that wishes to deploy HUSH to any users under 18 must contact us first and is responsible for obtaining any parental or guardian consents required by law.

11. International transfers

The Service is operated from the United States. If you access it from outside the US, your information will be transferred to and processed in the US. Where required, we rely on Standard Contractual Clauses or another lawful transfer mechanism with our subprocessors.

12. FERPA and institutional agreements

HUSH is currently used by individual instructors and by students who pay for their own access. We do not claim to have institutional agreements in place today.

For institutions that adopt a HUSH institutional plan in the future, a data-processing addendum and FERPA terms are available — under those terms HUSH would act as a School Official with a legitimate educational interest, using student data only for the educational purposes the institution defines and not disclosing education records except as permitted by that agreement or by law. Request them through our contact form.

Regardless of any agreement, we operate on a data-minimization basis consistent with FERPA expectations: we collect only what the Service needs, we do not sell student data, and we do not use it for advertising.

13. Security

We use TLS in transit, encryption at rest by our cloud provider, row-level access controls in the database, server-side authorization on every state-changing operation, and least-privilege service credentials. See our Security Statement for detail.

14. Changes to this policy

We will post material changes to this page and, where practical, notify account holders by email or in-product notice. Continued use of the Service after the effective date constitutes acceptance.

15. Contact

HUSH is the service and the people who operate it; it is not an incorporated entity. Reach us any time through our contact form.

Questions about this document?

Send us a message through our contact form and we'll reply to you directly.