CreativeTrail High School Privacy Policy
- Effective Date
- Effective Date: August 28, 2026
- Operator
- Operator: Benton Growth Labs LLC, doing business as CreativeTrail
- Contact
- Contact: [email protected]
1. Overview
CreativeTrail is an educational writing-process platform operated by Benton Growth Labs LLC. This Privacy Policy describes how CreativeTrail collects, uses, stores, and shares information in connection with its High School product mode.
CreativeTrail High School/K–12 Mode is designed for institution-administered use by K–12 schools, school districts, educators, and other K–12 educational organizations, including public and private institutions. It helps teachers and students document the writing process, including planning, source work, drafting, revision, reflection, and process evidence.
CreativeTrail is not an AI detector and must not be used as the sole basis for grading, discipline, or academic-integrity decisions. CreativeTrail provides process evidence and teacher-facing support, but teachers and schools remain responsible for educational decisions.
2. Scope of This Policy
This policy applies to CreativeTrail High School/K–12 Mode.
High School/K–12 Mode uses an institution-administered student-data and privacy relationship. CreativeTrail's separate College/General Mode is intended for individual, general, and postsecondary use. The distinction is based primarily on deployment context, not solely on whether a user is under 18.
It does not apply to a separate research study or future product unless that use expressly references this policy.
CreativeTrail may also display demo or presentation materials, including founder-provided sample writing. Demo or presentation pages are not intended for student use and must not be used to enter real student data.
2.1 Current Pilot Notice
The current school-specific pilot has a separate Current School Pilot Data Notice. That notice, together with the applicable school agreement, describes the pilot's current account, process-record, and retention practices.
Links to this Policy and the Terms of Use are presented during account creation.
3. High School Eligibility
CreativeTrail High School/K–12 Mode is currently available only to students age 13 or older who access CreativeTrail through a school, teacher, district, or other authorized K–12 educational organization.
Students under 13 may not use the service.
4. Information We Collect
4.1 Teacher and School Account Information
For teachers and school users, CreativeTrail may collect:
- Name
- Email address
- Account login credentials or authentication information
- School, class, or course information
- Role, such as teacher or administrator
- Class names, assignment names, prompts, due dates, and classroom settings
- Communications with CreativeTrail, including pilot requests or support messages
Teachers may sign in using standard account authentication and, where enabled, Google OAuth.
4.2 High School Student Identity Information
The intended standard High School student flow uses pseudonymous access and does not require students to provide an email address. This design applies only after it is activated for a school under the applicable school agreement; it does not describe the current pilot.
For High School students, CreativeTrail may collect or generate:
- Student name, encrypted in the browser before being stored
- Pseudonymous student code
- Student PIN hash
- Class code
- Enrollment record
- Confirmation that the student is 13 or older
- High School access session information
In the intended standard High School student flow, student names are encrypted before storage. CreativeTrail's servers store encrypted identity data, not plaintext student names. The teacher can unlock student names locally using the teacher's roster passphrase. CreativeTrail does not store the teacher's roster passphrase. This identity design applies only after it is activated for a school under the applicable school agreement.
Although student names are encrypted, High School student work and activity may still be linked to a student code, class, assignment, teacher, and enrollment record.
4.3 Student Writing and Classroom Work
CreativeTrail may collect and store student work created in the platform, including:
- Assignment responses
- Drafts
- Final writing submissions
- Revision history
- Autosaved writing content
- Source work
- Source annotations
- Uploaded or processed source materials, including extracted PDF text where applicable
- Mind map or planning work
- Reflection responses
- Responses to Socratic or process prompts
- Teacher comments, annotations, and feedback
- Immutable versions of submitted Trail work, including proposal submissions and teacher approval or revision-request decisions
- Feedback receipts and acknowledgement records connected to the exact Trail occurrence or submitted version
- Teacher-provided instruction attachments, including the uploaded original and any normalized text needed to display the document
- Teacher-entered academic component scores, assignment weights, release records, and the resulting assignment percentage
- Generated writing-process reports
This information is treated as student educational content.
Academic grades are separate from writing-process and authenticity evidence. CreativeTrail does not automatically turn process evidence, grammar-review information, or an authenticity indicator into academic credit.
4.4 Process and Activity Information
CreativeTrail records information about the student writing process.
Where a teacher enables the optional grammar-review step before final submission, CreativeTrail records the student-declared review boundary, the frozen pre-review version, the returned version, and an objective change summary. This is a CreativeTrail workflow, not monitoring of activity outside CreativeTrail and not an integration with a particular grammar tool. It does not by itself determine whether work is authentic or academically acceptable.
The intended standard High School design is to store aggregate or sanitized process-event information, such as counts and general activity metrics, instead of raw input logs such as raw typed text, raw pasted text, raw key names, or raw selected text in process-event rows. This derived-only design applies only after it is activated for a school under the applicable school agreement; it does not describe the current pilot.
High School aggregate process information may include:
- Writing activity counts
- Typing, deletion, paste, and revision counts
- Large insertion counts
- Focus and selection counts
- Mouse and keyboard activity counts
- Timing and sequence information
- Document length and cursor-position related aggregate information
- Replay or undo-related counts
- Flags indicating that raw input logs were not stored
Important: limiting raw input logs does not remove the student's educational content. CreativeTrail may still store drafts, final writing, revisions, source work, prompt responses, reports, and other student-created content.
4.5 AI Processing Information
CreativeTrail may use approved AI services to support educational features such as:
- Generating Socratic writing prompts
- Selecting or ranking reflection questions
- Categorizing or interpreting student responses
- Summarizing writing-process evidence
- Evaluating process evidence
- Generating teacher-facing report elements
For High School mode, CreativeTrail uses Anthropic as its AI provider for student-content AI processing.
AI inputs may include limited excerpts or summaries of student writing, source work, prompt responses, revision information, or process evidence. AI outputs may include questions, feedback, categorizations, rationales, summaries, or report elements.
CreativeTrail does not use AI outputs as the sole basis for grading, discipline, or academic-integrity decisions, and schools must not do so.
4.6 Technical and Security Information
CreativeTrail may collect technical information needed to operate and secure the service, including:
- Session cookies
- Authentication records
- Device/browser metadata
- Server logs
- Deployment and error logs
- IP addresses or request metadata collected by hosting infrastructure
- Security, debugging, and reliability logs
CreativeTrail is hosted on Railway and uses Railway Postgres for database storage. Railway may process hosting, database, deployment, and operational logs as part of providing infrastructure.
5. How We Use Information
CreativeTrail uses information to:
- Provide the High School writing-process platform
- Allow teachers to create classes and assignments
- Allow students to join classes and complete assignments
- Preserve writing-process evidence
- Generate process reports
- Support teacher review and classroom feedback
- Maintain account security
- Debug, monitor, and improve platform reliability
- Respond to support requests
- Comply with legal, contractual, and school requirements
- Improve CreativeTrail using aggregated or deidentified information where appropriate
6. How We Do Not Use Student Information
CreativeTrail does not use High School student information to:
- Sell student personal information
- Serve targeted advertising to students
- Build advertising profiles
- Market unrelated products to students
- Let third parties use student data for their own advertising purposes
- Make fully automated disciplinary decisions
- Act as a standalone AI detector
CreativeTrail does not knowingly collect High School student email addresses through the High School student flow.
7. School Control and Educational Use
High School/K–12 Mode is intended for institution-administered K–12 use.
When CreativeTrail receives student data through a school, teacher, district, or educational program, CreativeTrail uses that data to provide the educational services requested by the school or teacher and as otherwise described in this policy or the applicable school agreement.
Schools remain responsible for determining how CreativeTrail is used in the classroom and how CreativeTrail outputs are interpreted.
8. Sharing and Subprocessors
CreativeTrail may share information with service providers that help operate the platform. Current or expected service providers for High School mode include:
- Railway: hosting, database infrastructure, deployment logs, and operational infrastructure
- Railway Postgres: database storage
- Anthropic: AI processing for supported educational features
- Google OAuth: teacher or school-user sign-in, where enabled
- Transactional email provider: teacher account, verification, reset, or support emails, where enabled
CreativeTrail may also share information:
- With the teacher, school, district, or authorized educational program responsible for the class
- With authorized CreativeTrail personnel who need access for support, security, debugging, or operation
- If required by law, legal process, or to protect rights, safety, and security
- In connection with a business transfer, subject to appropriate protections for student data
CreativeTrail does not sell High School student data.
9. Internal Access
Access to student data is limited to authorized CreativeTrail personnel with a legitimate operational need, such as support, debugging, security, compliance, or service operation.
Production admin, impersonation, raw audit, and export tools are restricted to authorized personnel and are not used for casual review.
10. Retention for the Intended Standard Service
This public policy describes the intended pseudonymous and derived-only High School service. Its retention and deletion configuration will apply only after it is activated for a school under an applicable school agreement.
Before that activation, the school agreement and the deployed configuration must state the applicable retention and deletion terms. They may include storage of pseudonymous access information and derived process evidence, but this policy does not promise that those future terms are active today. For the current pilot, see the Current School Pilot Data Notice.
11. Deletion and Deidentification Requests
Schools, districts, or authorized teachers may request deletion or deidentification of High School student data.
Parents or students who want to access, correct, delete, or deidentify student data should generally contact the school first, because CreativeTrail is provided through the school-authorized classroom relationship.
CreativeTrail will delete student information upon a valid request from the applicable school, district, or educational institution when required by applicable law or agreement. CreativeTrail will also honor valid deidentification requests when required by applicable law or agreement.
Because High School student names are encrypted, deleting or deidentifying student data may require more than deleting names. It may also require removing or breaking links between student codes, classes, enrollments, assignments, writing records, reports, and process evidence.
12. Security
CreativeTrail uses technical and organizational measures designed to protect information, including:
- High School pseudonymous student access
- Browser-side encryption of High School student names
- PIN hashing
- Signed High School access cookies
- Role-based and class-based access controls
- Route-level authentication and authorization checks for student report and classifier endpoints
- Authentication for teacher accounts
- Server-side storage in Railway Postgres
- Limiting High School raw input-log storage
- Limiting internal access to authorized personnel
No system can be guaranteed completely secure. CreativeTrail will continue to improve its security controls as the product develops.
13. Backups
CreativeTrail maintains encrypted Railway Postgres database backups for security, reliability, and disaster-recovery purposes. The backups are retained and removed under the backup schedule configured with CreativeTrail's infrastructure provider.
Information deleted from the production database may remain temporarily in a previously created encrypted backup. While retained, that information remains protected and is not restored or used for ordinary product purposes except where necessary for disaster recovery or security. It is removed through the normal backup expiration and rotation process.
14. Changes to This Policy
CreativeTrail may update this Privacy Policy from time to time. For school deployments, CreativeTrail will provide notice of material changes to the school, teacher, or other authorized contact.
15. Contact
Questions about this policy or CreativeTrail's privacy practices may be sent to:
Benton Growth Labs LLC / CreativeTrail
Email: [email protected]