Security & Trust

This page is maintained by Taleemy to answer common security and privacy questions about Taleemy Inquiry. It describes enabled platform controls; it is not an independent certification.

The reflection-privacy invariant

The single most important guarantee we make: private reflections are visible only to their author. This is enforced at the database layer with row-level security policies — not by application code that could be bypassed. Even our own operational staff cannot read private reflections in the ordinary course of service.

Authentication

  • Google sign-in for all users; passwords are never stored by us.
  • Session tokens are short-lived and refreshed automatically.
  • Role-based access (teacher, school admin, super admin) checked server-side on every request.

Data protection

  • Encryption in transit (TLS 1.2+) for all traffic.
  • Encryption at rest for the database and object storage.
  • Row-level security policies on every table containing user content.
  • Uploaded evidence (images and documents up to 20 MB) stored in access-controlled object storage.

Hosting

Taleemy Inquiry runs on Lovable Cloud, which provides a managed Postgres database, authentication, object storage, and edge compute. Infrastructure is operated by established cloud providers with their own security programs.

Sharing model

  • Private: only you.
  • Team: members of your PLC team.
  • School: members of your school community.
  • Public: the Research Commons — you opt in per inquiry.

AI features

AI is used only for brainstorming inquiry questions and topics. AI requests are routed through our gateway; we do not use your content to train third-party models. School accounts have a pooled monthly AI quota.

Shared responsibility

We protect the platform; you protect what you upload. Please avoid uploading identifiable student data. Use pseudonyms and aggregated data when documenting classroom evidence.

Vulnerability reporting

Found a security issue? Please email security@taleemy.org. We appreciate coordinated disclosure and will acknowledge reports within two business days.

Incident contact

For urgent security incidents, contact security@taleemy.org.