Loading Ownly Academy...
Loading Ownly Academy...
Version 2026-08-17.1
Ownly Academy is operated by Adodesign LLC ("Ownly Academy", "we", "us", "our"), a company based in the United States.
Ownly Academy is a homeschool planning, organization, and record-management platform. It lets parents, legal guardians, educators, and other authorized adults maintain attendance, lessons, activities, expenses, receipts, portfolio evidence, documents, reports, and related homeschool records.
This policy explains what information we collect, why we collect it, which service providers receive it, how uploaded content is handled, how long information is retained, and what choices you have.
Ownly Academy accounts are intended only for adults who are at least 18 years old. Student profiles are records managed by adults — they are not independent user accounts.
Children and students may not create accounts, receive their own login credentials, independently access the platform, or directly use AI-assisted features. Content about a child is uploaded under the supervision and authorization of the adult account holder.
By creating an account, you confirm that you are an adult and that you are authorized to create and manage the student records you enter.
Account information: your name, email address, password (stored only in hashed form), household or homeschool name, account role, time zone, notification preferences, subscription status, registration and sign-in dates, and records of accepted policies and consents (including the policy version, the wording shown, and the request's IP address and browser identifier).
Student and homeschool information you choose to enter: student names, preferred names, grade levels, birth dates, a photograph if you add one, the state used for compliance, school years, subjects, courses, lesson plans, attendance, activities, goals and milestones, skills and progress notes, assessments and grades, transcripts and certificates, reading logs, field trips, portfolio entries, compliance records and evidence, expenses and receipts, reports, and reminders.
Some fields invite information about how a child learns — learning-style notes, educational goals, and special accommodations. Families often use these to record accessibility needs, an IEP, or similar arrangements. Enter only what you need for your records: this is a homeschool planner, not a medical or clinical system, and we ask you not to store diagnoses, treatment records, or other health information here.
Uploaded content: documents, worksheets, photographs, images, receipts, portfolio evidence, and other homeschool-related files. You are responsible for having permission to upload what you store.
Please do not enter information that is unnecessary for homeschool record keeping. Ownly Academy is not intended to store Social Security numbers, government identification numbers, full payment-card numbers, bank credentials, medical or clinical records, or nude or sexually suggestive images.
Billing information: payments are processed by Stripe, which collects your card and billing details directly on its own systems. We never see or store your card number, card brand, or the last four digits. What we receive back is your subscription status and interval, plan and price identifiers, invoice records (amount, currency, status, and links to Stripe's hosted invoice and PDF), and the Stripe customer and subscription identifiers.
Technical and security information: IP address, browser and device type, session identifiers, sign-in and sign-out events, password-reset requests, request logs, error diagnostics, file-upload metadata, and administrative audit records. We also record the date and time each member was last active, updated at most once an hour while signed in, so we can tell whether an account is still in use.
How you found us: when you first arrive on our public pages we record the site that referred you and any campaign tags in the link you followed, and if you then create an account we store that on your workspace record. This is described in full in section 16.
Support communications: if you contact us, we keep the correspondence and the account details needed to help. Please never send passwords or full payment-card numbers through support messages.
Optional Google Calendar connection: when the workspace owner connects Google Calendar on a paid plan, we store the Google account identifier and email address, the identifier of the dedicated calendar Ownly creates, encrypted access and refresh tokens, the last sync time and health, and mapping identifiers for the Ownly schedule items sent there. The calendar receives only the event title, student first name, subject, time, location, and a minimal Ownly source label. Lesson objectives, planner notes, parent observations, student feedback, reminders, files, expenses, attendance, and other records are not sent.
We use information to create and manage accounts; provide planning and record-keeping features; store and organize records; generate reports and exports; process subscriptions; send requested reminders and account, billing, security, and service notices; provide support; authenticate users and prevent unauthorized access; detect fraud and abuse; operate optional AI-assisted features you have enabled; maintain reliability and security logs; enforce our Terms of Use; comply with legal obligations; and protect users, children, Adodesign LLC, and the public.
If the workspace owner chooses automatic Google Calendar sync, we use the limited calendar permission they grant to create and maintain a dedicated Ownly Academy calendar. Sync is one-way from Ownly to Google: Ownly remains authoritative, and edits made directly to managed Google events may be replaced during reconciliation. Free-plan manual export opens a pre-filled Google event in the user's browser; the user reviews and saves it themselves, and Ownly receives no Google credential from that flow.
We also measure how the product is doing as a business. That means counting things: how many households and students exist, how many accounts were active in a period, how plans are distributed, and which channels new families arrived from. These are aggregate figures kept in our own database, and we removed Google Analytics rather than send them to anyone else. Our internal dashboards deliberately answer whether a family is using the app, never what they wrote in it — no student names or record contents appear there.
Adodesign LLC does not sell, rent, trade, or license personal information or student records to data brokers, advertisers, marketing companies, or any other third party for their own commercial use.
We do not use student records for behavioral advertising or cross-site targeted advertising, and we receive no compensation for providing student records or account information to anyone.
Using service providers to host, process, secure, or deliver the platform is not selling — those providers receive information only to perform services for Ownly Academy, as described in section 8.
Student and homeschool records are not publicly searchable, are not shown in public profiles, are not shared with other families, and are not used to build advertising profiles.
Records may be accessed by the primary account holder; adults the account holder has authorized; a limited number of Adodesign LLC personnel when there is a legitimate support, security, technical, or legal need; the service providers in section 8 acting on our behalf; and authorities when disclosure is legally required or reasonably necessary to address a serious safety threat.
Authorized does not have to mean full access. The account owner decides, per member, which children a co-parent or tutor can see and which areas — expenses, resources, compliance, and reports — they can open. A tutor added to the workspace sees no children at all until the owner assigns them.
Account holders are responsible for removing household members or educators who should no longer have access.
AI assistance is off by default for every household and nothing is sent to any AI provider until an adult in your household explicitly turns it on. You can turn it off again at any time in Settings, which stops all AI processing immediately.
When AI assistance is on and you ask the assistant a question, your message, recent messages from that conversation, and a summary of your household's records — student names and grade levels, subjects, recent lessons, attendance, goals, field trips, and expenses — are sent to the Google Gemini API to generate the answer.
When AI assistance is on and you choose to scan a receipt, the receipt image you selected is sent to the Google Gemini API, which reads back five things — vendor, date, amount, category, and a short note describing the purchase — so the expense form can be pre-filled. This happens only when you press the scan button, never automatically, and only the image you picked is sent. Bear in mind that whatever is visible on the receipt is in that image, so avoid scanning receipts that show a card number or other details you would not want to send.
We access Gemini through Google's paid API service. Under Google's terms for paid services, prompts and responses are not used to improve Google's products, though Google may temporarily log requests for abuse prevention, security, and legally required purposes, and may process them in countries where Google operates.
AI-generated answers and extracted receipt fields can be incomplete, inaccurate, or otherwise wrong. Review them before relying on them or saving them into your records — we do not guarantee the accuracy of AI output.
If we add further AI-assisted features (such as automated upload screening), they will follow the same rule: disclosed here, and never processing your content beyond what the feature needs.
We use the following providers. We do not send every category of information to every provider, and each receives only what its role requires.
DigitalOcean — the application and its PostgreSQL database run on DigitalOcean cloud servers in the New York (United States) data center region, managed by Adodesign LLC.
Cloudflare — two roles, and it is worth being clear about both. First, Cloudflare sits in front of the site as our network edge, so every request you make passes through it: it sees your IP address, the address of the page you asked for, and your browser type, and it filters malicious traffic before it reaches us. Second, Cloudflare R2 is our private storage for uploaded images, documents, receipts, and portfolio files — a private bucket, served only through signed links that expire within minutes, never public URLs.
Google Gemini API — optional AI-assisted features, only for households that have turned them on (section 7).
Google Calendar API — optional one-way schedule sync, only after the workspace owner connects a Google account. Automatic sync uses the narrow permission for calendars created by Ownly; manual export requires no Google access token.
Stripe — subscription billing, payment processing, invoices, and refunds.
Resend — delivery of verification, password-reset, billing, reminder, security, and service emails.
Sentry — error monitoring. When something in the app breaks, a technical error report (the error message, stack trace, and the page or action involved) is sent to Sentry so we can find and fix the problem. These reports are configured not to include your IP address, cookies, or the contents of your records, and record identifiers are stripped from the page address before the report is sent — so a report says a student page failed, not which student.
These providers may use their own subprocessors, so information may be processed in the United States or other countries where they operate. We may replace a provider when reasonably necessary; when a change materially affects how personal or student information is processed, we will update this policy.
Every upload is validated before it is accepted: only expected file types are allowed (images, and PDF where appropriate), size limits apply, and the server checks the file's identifying byte signature against its declared type. Verified images may preview in the app; PDFs and other documents are delivered as attachments. Files are stored in private storage reachable only through short-lived signed links that expire within minutes.
Photos you upload are re-encoded in your browser before they leave your device, which strips camera metadata such as GPS location from the stored copy. In the rare case a photo cannot be processed, or for PDFs, the original file is stored as-is.
We want to be precise about what we do and do not do here. File-signature validation is a technical format check; we do not currently run content classification, image matching, or malware scanning. Your files are private to your workspace: they are not shared with other households, not made public, and not used to train anything. If we introduce content or malware screening we will update this policy and say so plainly before it starts.
We do act on what we learn. If we become aware of prohibited material — because someone reports it, because law enforcement contacts us, or because we encounter it while providing support — we investigate and take action, including removing content, restricting or terminating accounts, and preserving records.
Content that violates our Terms may be blocked, removed, or referred for review, and accounts may be warned, restricted, suspended, or terminated. Serious violations may result in immediate action without notice. Where required or permitted by law, we preserve relevant records and report suspected illegal activity to the National Center for Missing & Exploited Children (NCMEC), law enforcement, or other appropriate authorities. Child sexual abuse material is reported as United States law requires.
When records must be preserved for a report, an official request, or a dispute, we place the account on hold. While a hold is in force the account cannot be deleted and its files are not removed, including by the inactivity schedule in section 13.
Because file-signature validation cannot determine what a document or image depicts and is not malware scanning, you remain responsible for everything uploaded through your account. If you believe prohibited content is stored in Ownly Academy, email [email protected] and we will act on it.
Your records are not routinely viewed by Adodesign LLC personnel. Authorized human review may occur when reasonably necessary to respond to a support request, investigate a security event or moderation flag, investigate suspected fraud or abuse, restore or troubleshoot data, comply with a legal request, or protect a person from credible harm.
Access is limited to personnel who need it for the specific task, and administrative changes are recorded in an audit log.
To authorized account users: adults invited or authorized by the account owner.
To service providers: the vendors in section 8, as needed to operate the platform.
For safety and legal compliance: when we reasonably believe disclosure is necessary to comply with a valid legal requirement; respond to a court order, subpoena, or lawful government request; investigate fraud or abuse; report suspected child exploitation; prevent death, serious injury, or another immediate threat; or protect the rights and safety of users, Adodesign LLC, or the public. Where legally permitted, we may challenge requests that appear excessive or invalid.
During a business transaction: if Adodesign LLC is involved in a merger, acquisition, financing, restructuring, or sale of assets, information may be transferred as part of that transaction. Any successor must continue to protect it under this policy unless users are notified of a replacement policy as required by law.
We use reasonable administrative, organizational, and technical safeguards appropriate for a platform handling homeschool and student information, including password hashing, encryption in transit, private file storage with signed time-limited access, encryption at rest for Google Calendar OAuth tokens using a dedicated application key, one-use OAuth state, role-based permissions, authentication and session controls, rate limiting on sign-in and other sensitive endpoints, security and audit logging, upload validation, and limited administrative access.
No online service can guarantee absolute security. Risks outside any provider's full control include criminal attacks, unknown software vulnerabilities, compromised user email accounts, stolen devices, and weak or reused passwords.
If we discover a security incident, we will take reasonable steps to investigate, contain it, protect affected systems, and notify affected users or authorities when required by law. Nothing in this section waives rights you hold under applicable law.
We retain records while your account is active. Free accounts follow one of the two schedules below. Accounts with an active paid subscription are not deleted under either schedule.
Empty-account cleanup: a free workspace is considered empty when it contains only account and setup information, including the household profile, user account, student profiles, school years, enrollments, subjects, preferences, sessions, and automatically generated operational rows. A student profile, school year, or subject by itself is not a homeschool record for this purpose. Adding a lesson, activity, attendance entry, course, portfolio item, goal, assessment, grade, transcript, certificate, file, document, expense, receipt, field trip, reminder, resource, compliance item, support request, or another deliberate record removes the workspace from empty-account cleanup.
Unverified registrations: the initial verification link is sent at signup. If the owner email remains unverified and the free workspace still has no homeschool records, we send a fresh verification link not before day 3. We send a second and final fresh link not before day 6 and at least three full days after the first reminder. Not before day 7, at least four full days after the first reminder and 24 hours after the final reminder were accepted by our email provider, the registration may become eligible for permanent deletion. Verifying the owner email or adding any real record cancels this path.
Verified empty accounts: not before day 7 after the workspace was created, we send the owner a service email warning that the account may be deleted in seven days. Not before day 13, and at least six full days after the first warning, we send a second and final service email warning that deletion may occur after 24 hours. Not before day 14, at least seven full days after the first warning and 24 hours after the final warning were accepted by our email provider, and only after checking again that the workspace still has no homeschool records, the account and its setup information may become eligible for permanent deletion. Signing in without adding a real record does not cancel verified empty-account cleanup; adding any real record does.
A delayed or failed email delays deletion; no warning period is shortened. Internal workspaces, legal holds, paid accounts, and accounts with a subscription reference are excluded. The unverified, verified-empty, and record-bearing deletion paths each require a separate internal authorization flag.
For a free workspace that contains homeschool records, activity means signed-in use of the service by any household member. Opening an email or visiting a public page does not count.
The longer schedule below is a limit on us, not a countdown against you: it sets the earliest point at which each step may happen, and every step is preceded by an email. No account with records is ever hibernated or deleted without the notices described here.
Not before 180 days of inactivity: a friendly check-in email — nothing changes on the account. Not before 240 days: a second email, sent at least 30 days before hibernation. Not before 270 days: hibernation, meaning the account is marked dormant and new uploads are paused, while every record is preserved and the account is restored automatically the moment any member signs in.
Not before 18 months of continuous inactivity: a final email with at least 30 days' warning and instructions for signing in and downloading your records. Not before 19 months, and only if the account has not been reactivated and is not subject to a legal hold: the account and its data are deleted. Deletion for inactivity requires a separate internal authorization on top of everything above, so it can never follow automatically from a missed email.
For an account that contains homeschool records, signing in at any point before deletion stops the longer inactivity schedule, restores full access, and resets the clock. We keep those periods deliberately long because homeschool records are often needed for state compliance, and a normal school year includes months when families do not log in.
You can also delete the workspace yourself at any time, from Settings. Only the account owner can do this. We ask you to download your records first, re-enter your current password, and type the workspace name to confirm, because the deletion is immediate and cannot be undone: every student, lesson, attendance record, goal, portfolio entry, receipt, and report is removed for every member, uploaded files are deleted from storage, and any active subscription is cancelled. The limited information described in the next section is kept.
Account holders are responsible for keeping their email address current and downloading records they wish to keep.
Deleting an account does not necessarily erase every related record immediately. We may retain limited information when reasonably necessary for tax and accounting obligations, payment and refund records, fraud prevention, security investigations, consent records, legal disputes and preservation requirements, abuse and child-safety reports, and enforcing account restrictions.
Concretely, after a workspace is deleted we keep four things, and nothing else. Your consent history: the wording you agreed to, when, and the IP address and browser it came from. A deletion record: that a workspace on a given plan was deleted, with counts of what it held, the identifiers used by our payment processor, and no names or email addresses. A plan history: the dates a workspace moved between plans, identified only by its former workspace identifier. And, if a staff member ever took an action on the account, the administrative audit entry recording what they did and when — kept so that staff activity remains accountable after the fact.
Your billing history lives with Stripe under their own retention rules, because tax and accounting law requires it.
Sign-in history — the record of sign-ins, failed attempts, and password-reset requests, with the email address, IP address, and browser involved — is deleted along with the account. Student names, schoolwork, attendance, portfolio files, receipts, and reports are not kept in any form.
If encrypted infrastructure backups or snapshots contain information that was later deleted, that information may remain until those recovery copies expire under the infrastructure's configured rotation. Recovery copies are used only for disaster recovery, not ordinary business use.
Signed download links for files and exports are time-limited and expire automatically.
Depending on your location, you may have rights to access, correct, export, or delete your personal data. Most of these you can exercise yourself, without asking us.
In the app you can correct any record you entered, delete individual lessons, activities, expenses, portfolio entries, and uploaded files, manage and remove household members, choose what each member is allowed to see, and turn AI-assisted features off. The account owner can disconnect Google Calendar at any time; Ownly then attempts to remove the dedicated Google calendar and deletes its stored tokens and mappings. If Google access was already revoked, Ownly can remove the local connection but may be unable to remove the old calendar from Google. The account owner can also export the whole workspace and can delete the entire account — including every student record and every stored file — from Settings.
Two things are not self-service today. Removing one student while keeping the rest of the workspace, and account deletion by a member who is not the owner, both need us: email [email protected] and we will handle it. We may need to verify your identity, account ownership, and authority over the student records involved, and we may deny or limit a request where necessary to protect another person, preserve security, comply with law, or maintain a valid legal hold.
Correction, 3 August 2026. Until that date this site ran Google Analytics, and an earlier version of this policy said it was limited to our public pages. That was wrong, and we are correcting it here rather than quietly editing it away. The measurement tag was placed in a layout shared by the public site and the signed-in application, so Google also received the addresses of pages viewed inside the app — including /dashboard, /expenses, /records, and student pages, whose addresses contain the internal identifier of a student record. Alongside each page view Google received its usual measurement signals: an analytics cookie identifying the browser across visits, browser and device type, and an approximate location derived from the IP address.
What Google did not receive: student names, dates of birth, record contents, uploaded files, or anything you typed into the app. None of that appears in a page address, and the page title sent with each view was the site's generic title, not a child's name. The internal identifiers that were sent are random strings that mean nothing outside our database.
What we did: we removed the tag from the entire site rather than reconfigure it, and the Google Analytics property was deleted. There is now no third-party analytics or advertising script anywhere on this site, public pages included, and we do not intend to add one.
Cookies we set. Sign-in cookies, named with a better-auth prefix, keep you signed in and protect the session; a signed-in session expires after 30 days without use, and that window is refreshed as you keep using the app. It ends sooner if you sign out. Staff administration uses its own separate cookie prefix. These are strictly necessary — the service cannot work without them.
One cookie is not strictly necessary: oa_src. It is set only when you land on our public home page, lasts 30 days, and holds the referring site and any campaign tags from the link you followed, so that if you later create an account we can record which channel brought you. It stays on our own domain, is read once at signup, and is never sent to anyone. If you would rather not have it, blocking or clearing cookies for this site removes it with no effect on the service.
Your browser also keeps a little interface state in its own local storage — which sections you left expanded, and the light or dark preference in the staff area. That stays on your device; we never read it on the server.
We do not use advertising cookies, we do not share anything with ad networks, and we deliberately discard advertising click identifiers (such as gclid or fbclid) rather than store them. If we ever introduce analytics or advertising technology, we will update this policy and provide any choices the law requires before it starts.
Adodesign LLC is based in the United States, and our providers may process information in the United States and other countries where they or their subprocessors operate. Privacy laws differ between countries; where required, we use appropriate provider agreements or transfer safeguards.
We may update this policy when features, providers, data practices, or legal requirements change, and we will update the version shown above. For material changes we may display an in-app notice, send an email, or require renewed acceptance before continued use. Continued use after a non-material update means the revised policy applies from its stated effective date.
Adodesign LLC — Ownly Academy. Based in the United States.
Privacy requests and general support: [email protected].