College legal document · 13+ only
CreativeTrail College (13+) Privacy Policy
- Effective Date
- Effective Date: August 28, 2026
- Operator
- Operator: Benton Growth Labs LLC, doing business as CreativeTrail
- Contact
- Contact: [email protected]
1. Scope and our role
This Privacy Policy explains how CreativeTrail handles personal information when people visit creativetrail.ai, use the CreativeTrail writing platform, contact us, or participate in an institution-sponsored pilot.
CreativeTrail College/General Mode is available to users age 13 and older, subject to applicable law and any requirements or policies of the user's educational institution. Student accounts require a 13+ self-attestation at account creation; an existing student without that confirmation cannot enter the student workspace until completing it.
College/General Mode is intended for individual, general, and postsecondary use. K–12 schools and districts seeking institution-administered use should use CreativeTrail's High School/K–12 offering. The distinction is based primarily on deployment context, not solely on whether a user is under 18. For an institution-sponsored use, the institution determines the educational purpose, eligible users, course configuration, and authorized users. CreativeTrail processes institution-controlled student records only to provide the service under the institution's instructions and applicable agreement.
CreativeTrail does not operate a student-data research program or a model-improvement program. Normal product use does not enroll a student in research, and student data is not used to train general-purpose AI models.
2. Information we collect
Account, institution, and course information
We collect account and authentication information, such as name, email address, profile image, role, account dates, password hash, authentication-provider identifiers, verification/reset records, and session information. We also process institution, course, instructor, enrollment, assignment, roster, and feature-configuration information needed to provide the service.
Student-created educational content
CreativeTrail stores student-created and institution-provided content, including assignment instructions, sources, annotations, mind maps, planning materials, uploaded or imported document text, drafts, revisions, final writing, peer-review materials, prompt responses, teacher feedback, reports, teacher-entered academic scores, and process indicators.
Writing-process information
CreativeTrail is designed to help students and instructors understand how writing develops, not merely evaluate final text. In a college writing activity, the platform records raw writing-process (keystroke-level) events from within the CreativeTrail workspace. These events include timestamps, keyboard inputs, inserted text, deletions, replacements, pasted text, cursor and selection changes, revision activity, editor-focus changes, and stage transitions.
This collection is limited to the CreativeTrail workspace and the applicable course activity. CreativeTrail does not record activity elsewhere on a student's device. Links to this Policy and the Terms of Service are presented during account creation.
Writing-process data is context, not a conclusive finding. A paste, deletion, pause, or other single event must not by itself be treated as proof of misconduct, authorship, or unauthorized AI use.
AI-assisted writing features
CreativeTrail sends only the content necessary to operate approved AI-assisted features, which may include an assignment, relevant draft excerpt, revision context, prompt response, or process-evidence excerpt. CreativeTrail uses Anthropic for configured writing analysis, Socratic questions, question ranking, and response categorization. CreativeTrail accesses Anthropic through a commercial API organization account under terms that do not permit provider training on CreativeTrail's submitted content.
OpenAI is optional and disabled by default for college pilots. If an institution separately approves and CreativeTrail enables voice transcription or a classifier fallback, CreativeTrail accesses OpenAI through a commercial API organization account under terms that do not permit provider training on CreativeTrail's submitted content. Commercial API terms may permit limited provider retention, typically up to 30 days, for abuse monitoring; CreativeTrail does not represent that AI providers retain no data.
CreativeTrail does not use student information for advertising, unrelated profiling, or training general-purpose AI models. It does not operate a research or model-improvement program using student data.
Communications and technical information
If someone contacts us or requests a pilot, we collect name, email, organization, role, message, and correspondence. We also collect information needed to operate and secure the service, such as IP address, browser and device information, timestamps, session and security events, and diagnostic logs.
3. How we use information
We use information to:
- provide accounts, courses, assignments, writing tools, reports, and authorized AI-assisted features;
- authenticate users, maintain security, prevent misuse, and respond to support requests;
- allow authorized instructors and institution personnel to review student work and approved process evidence;
- maintain and troubleshoot the service;
- comply with institution instructions, contracts, valid legal process, and legal obligations; and
- maintain audit records and investigate security incidents or misuse.
We do not sell personal information, share personal information for cross-context behavioral advertising, use student information for targeted advertising, or create commercial profiles unrelated to education.
4. Who receives information
Access is limited by role and legitimate educational or operational need. Information may be available to the student who created it; the student's authorized instructor and institution personnel; assigned peer reviewers for materials specifically made available to them; CreativeTrail personnel with approved support, security, privacy, or operational access; and approved subprocessors.
CreativeTrail limits privileged application access through founder allowlists, developer mode, TOTP multi-factor authentication, role-based authorization, verified browser sessions, and logged access events. Railway account MFA separately controls access to the production database. These access controls are separate from the encryption that protects stored data and data in transit.
We may disclose information when directed by the institution or user, to approved service providers, in response to valid legal process, to protect the security of the service or people, or in connection with a business transaction subject to applicable student-data restrictions and contractual obligations. Where legally permitted, we notify the controlling institution before disclosing institution-controlled student information in response to legal process.
5. Public-site analytics and cookies
Google Analytics and Microsoft Clarity operate only on CreativeTrail's public landing page and public White Paper. They are not loaded in authenticated student or teacher workspaces. Public-site events use stable interface and content identifiers; they do not include names, email addresses, school names, form-entry contents, or student work. Pilot-request measurement records only that the public call to action was opened or that a request was successfully submitted. Public pages use necessary browser storage for site operation. See the College (13+) Cookie Notice.
6. Retention and deletion
CreativeTrail applies a fixed lifecycle to college writing-session data:
| Data category | Standard retention |
|---|---|
| Raw college writing-process events | Deleted 180 days after capture. |
| Session content, including drafts, revisions, prompt responses, report content, and AI request/output content | Purged one year after the session starts. |
| Remaining derived session evidence and session-linked records | Deleted two years after the session starts. |
The production retention job runs daily at 09:15 UTC and records non-content deletion-ledger entries. This schedule does not prevent a documented legal hold or a different written requirement accepted in an institution contract. Account, billing, security, and contract records may be retained for the active relationship and as needed for legal, security, and accounting purposes.
For institution-controlled education records, students should ordinarily direct access, correction, export, or deletion requests to their institution. CreativeTrail assists the institution as required by the applicable agreement. For non-institution information, contact us below. We may verify identity and authority before acting.
Information deleted from the production database may remain temporarily in a previously created encrypted backup. While retained, that information remains protected and is not restored or used for ordinary product purposes except where necessary for disaster recovery or security. It is removed through the normal backup expiration and rotation process.
7. Security
CreativeTrail uses reasonable administrative, technical, and organizational safeguards appropriate to the service. Production data and encrypted backups in Railway Postgres are encrypted at rest, and application/database connections are encrypted in transit. Separate safeguards include password hashing, role-based access controls, TOTP multi-factor authentication for privileged application access, Railway account MFA for production-database access, protected secrets, access logging, input validation, rate limiting, and the daily retention workflow. No system is perfectly secure. If a security incident affects institution-controlled student information, CreativeTrail notifies the institution as required by the applicable agreement and law.
8. Privacy rights
Depending on the law and context, individuals may have rights to request access, correction, deletion, portability, restriction, or information about disclosures. California residents may have additional rights under the CCPA/CPRA, including rights to know, correct, delete, and receive equal treatment for exercising applicable rights. Institution-controlled education-record requests may be referred to the institution.
CreativeTrail recognizes applicable browser privacy signals for public-site tracking where required by law. Because CreativeTrail does not sell personal information or share it for cross-context behavioral advertising, there is no current sale/share opt-out to exercise.
9. Changes
We may update this Policy to reflect changes in law, technology, features, vendors, or practices. If a change materially affects institution-controlled student information, we provide advance notice to affected institutions where required by contract or law. We do not materially expand use of institution-controlled student information without the institution's authorization and any required notice or consent.
10. Contact
Benton Growth Labs LLC d/b/a CreativeTrail
[email protected]
588 El Camino Real, Santa Clara, CA 95050, United States