Privacy Policy

What we collect,
and why.

Meletema collects the minimum data required to deliver adaptive flashcards inside your LMS. We don't sell student data, we don't run ads, and we don't share information with brokers.

Last updated · June 3, 2026
Scope

Who this applies to

This policy applies to anyone who interacts with Meletema — instructors who author decks, administrators who manage an organization, and students who play decks directly or through their LMS. When Meletema is launched from a school's LMS, the school remains the data controller and Meletema acts as a service provider.

What we collect

Categories of data

  • Account data. Name, email address, hashed password, and optional second-factor enrollment material for users with their own login.
  • Authored content. Deck titles, descriptions, tags, folder structure, prompts, answers, and explanations created by instructors.
  • Play activity. Card-by-card responses, mastery scores, attempt timestamps, and per-session scores. This data drives the adaptive engine and the instructor reports.
  • LMS launch claims. When a student arrives through an LTI launch, we receive their LMS-provided user identifier, name, roles, and the section/course context. We do not request profile fields beyond what's necessary to map the launch to the right deck and grade column.
  • Billing data. Subscription tier, seat count, and Stripe customer/subscription identifiers. Card details are handled by Stripe and never reach our servers.
  • Operational telemetry. IP addresses, user-agent strings, and request paths captured in application logs for security monitoring and debugging.
Why we collect it

Purposes

Data is used to deliver the service: authenticate users, render the right decks to the right students, adapt the queue based on prior performance, return grades to the LMS, bill organizations for usage, and investigate misuse or outages. We do not use student data to train models, target advertising, or build profiles for any third party.

Who can see it

Access inside Meletema

  • Students see their own progress and the decks assigned to them.
  • Instructors see their authored decks, their linked LMS sections, and the aggregate and per-student progress of students enrolled in those sections.
  • Organization administrators see organization-wide statistics and may manage members, billing, and the LMS connection.
  • Meletema staff may access organization data only for support requests you initiate, for billing reconciliation, or in response to a confirmed security incident. All such access is logged.
Third parties

Service providers

We use a small number of vendors to run the service:

  • Laravel Cloud — application and database hosting.
  • Stripe — subscription billing and payment processing.
  • Transactional email provider — sending invitations, password resets, and notifications.

We do not sell or rent personal data to anyone. We do not include advertising trackers on the application. The marketing site is intentionally free of third-party analytics and ad-tech.

Student privacy

FERPA and COPPA

For US K-12 and higher-education customers, Meletema is designed to handle student records as a "school official" under FERPA's school-official exception. We use student data only for the educational purpose for which it was provided, do not disclose it without the school's authorization, and provide schools with the means to inspect, export, or delete records on request.

Meletema is intended for users aged 13 and over when self-registered. Students under 13 may use Meletema only when launched from an LMS by a school that has provided the parental consent required by COPPA on our behalf. We do not collect more personal information from these students than is necessary to deliver the educational activity.

Retention

How long we keep data

Authored content and play activity are retained for as long as the owning organization maintains an active account. When an organization cancels, we retain data for 60 days in case of restoration requests, then delete production records. Backups containing the data roll off according to the schedule in our security statement.

Your rights

Access, correction, deletion

Users may export or delete their own account data from the in-app settings page. Organization administrators may export or delete data for any member of their organization. For LMS-launched students, requests should be routed through the school, which is the data controller. Where you have rights under GDPR, CCPA, or similar laws — including access, correction, deletion, portability, and objection — we will honor them within the statutory timeframe.

Cookies

What's set in your browser

Meletema sets a session cookie for authentication, a CSRF token cookie for form protection, and a small number of preference items in localStorage for the read-aloud toggle and theme preference. We do not set advertising or cross-site tracking cookies.

Changes

Updates to this policy

When we make material changes to this policy, we will update the "Last updated" date at the top of this page and notify organization administrators by email. Continued use of Meletema after the effective date constitutes acceptance of the revised policy.

Contact

Get in touch

Questions about this policy, privacy requests, or data-protection inquiries can be sent through our support page.