CreativeTrail Security & Student Privacy Overview
- Date
- Date: September 21, 2026
- Operator
- Operator: Benton Growth Labs LLC, doing business as CreativeTrail
- Contact
- Contact: [email protected]
Service, intended users and information collected
CreativeTrail helps students age 13 and older plan, write, revise and reflect. Educators can review how a piece of writing developed alongside the finished work. Benton Growth Labs LLC operates the service.
We process account and sign-in information; class, enrollment and assignment records; student writing and revision history; sources, annotations and uploaded files; prompts and responses; teacher or peer feedback; relevant scores; and writing-process evidence and reports. Technical records support authentication, service operation and security. The features used determine which information is collected.
Writing-process collection occurs inside CreativeTrail's writing workspace, including editing, paste, cursor, focus and timing events. It is not monitoring of other applications or the entire device. Process indicators and AI outputs require human interpretation; they are not conclusive proof of misconduct, authorship or unauthorized assistance.
School-specific data processing terms and service requirements are addressed in the applicable agreement.
Access controls, encryption and production security
Access depends on a user's role and relationship to the relevant class, assignment or session. Passwords are hashed; configured Google sign-in is also available. We have verified multi-factor authentication and recovery arrangements for both founders' administrative accounts.
The service uses HTTPS for browser connections and certificate-verified encrypted database connections. Railway provides hosting and storage protection, including provider-managed encryption at rest for storage and backups. These protections do not imply identical encryption or key-management arrangements across every provider. Processing locations vary by provider; we do not promise that all processing stays in the United States.
Production runs Node 24 LTS, and the relevant dependency fixes have been deployed. We track security issues and remediation.
We use NIST Cybersecurity Framework 2.0 to organize security risk management, not as a certification. Kelan and Chris completed and recorded the first security review, assigned remaining actions and scheduled the next review.
AI processing, analytics and service providers
Student content sent to Anthropic supports authorized CreativeTrail features. We have verified the applicable no-training protections and retention terms. Other AI providers remain disabled unless separately reviewed and authorized. We have reviewed providers receiving school information and recorded their purposes, data categories, processing locations, applicable terms and retention/deletion arrangements.
Microsoft Clarity has been removed. We verified that it neither loads nor sends requests on the homepage, sign-in pages or authenticated student and teacher pages, including navigation between them. Removal does not establish deletion of historical Clarity-held information. Google Analytics is restricted to public marketing pages and does not receive student writing, account identifiers or private-page activity.
| Provider and status | Role and relevant information |
|---|---|
| Railway - active | Application/database hosting and backups; accounts, educational records, writing, process evidence, uploaded files and operational logs. |
| Cloudflare, including Insights - active | DNS, web delivery and technical measurement; network requests, proxied application traffic, and browser, page and performance metadata. |
| Anthropic - active | AI features; relevant writing, assignment, response and process-context excerpts under reviewed terms. |
| Google sign-in - optional | Identity/profile identifiers and sign-in/authorization metadata when a user chooses this method. |
| Resend - active; AWS/SES - indirect | Transactional email; recipient details, verification/reset messages and delivery data. AWS/SES supports the upstream email service. |
| Google Analytics - marketing only | Public-page browser/device and event information, subject to the exclusions above. |
| Google Fonts - active | Font delivery; IP address and browser/request metadata. |
| Google Workspace - active | Support and business communications; contact details, messages and restricted operational records. Support messages may contain information users provide. |
| GitHub - active, operational | Source control and development/deployment records; source code, change history and contributor metadata. Student writing is not needed for this purpose. |
| Other AI providers, including OpenAI - disabled | No feature processing while disabled; separate review and authorization are required before enablement. |
Providers have different roles and do not all receive student writing. Their retention and location arrangements are service-specific; this overview makes no blanket zero-retention or universal retention-period claim.
Retention, export and deletion
Scheduled content expiry is different from complete account or school deletion. The schedules below cover specific records, not all information associated with a person or institution. A daily scheduled sweep handles eligible records; the periods are thresholds, not exact-to-the-second deletion guarantees.
| Information | Schedule and starting point |
|---|---|
| Covered raw writing-process events | 180 days after first storage by the service, which may be later than browser capture. |
| Ordinary writing-session content: drafts, revisions, reflection responses, reports and AI input/output | 365 days from session start. Content removal can leave a non-content evidence record until the later stage. |
| Covered ordinary writing-session derived or linked evidence | 730 days from session start. This is not an account-wide expiry. |
| Related phase work, process artifacts, annotations and feedback | Generally 365 days for content and 730 days for covered remaining records, from session start where linked or the applicable creation, submission or event time. |
| Student PDF/source uploads | Covered content/bytes at 365 days from asset creation and retired records at 730 days from asset creation, subject to live/shared-reference checks. Referenced teacher materials are separate. |
| Accounts, identity links, classes/enrollments, released numeric grades and referenced teacher materials | General maximums and complete end-of-account deletion are not yet established. |
| Security/administrative records, support email and browser-local recovery data | Category-wide limits and complete cleanup are not established by the writing-data schedule. |
| Backups | Daily copies: six days; weekly copies: 27 days. Two older snapshots have no confirmed expiry, so 27 days is not a maximum for every copy. |
| Provider-held copies | Governed by the relevant provider arrangements. Deleting application records does not itself confirm provider erasure. |
Some historical records need verification of their original retention deadlines. The schedules do not establish complete deletion across every category or device.
For access, correction, export or deletion requests, contact [email protected]. We verify identity and school authority, agree the scope and return format, and communicate actions taken and remaining copies. Families may need to request school-controlled records through their school. Complete account/school export and deletion coverage has not been validated end to end; no self-service account-deletion workflow is established.
Backups, incident response and security contact
We maintain daily and weekly production-database backups. In a recovery exercise, we restored a backup into an isolated environment and verified login, saved writing and uploaded files. Recovery took 36 minutes, and the temporary environment was removed afterward.
That result describes this exercise; it is not a guaranteed recovery time for every incident or a guaranteed maximum data-loss period. Production and backups depend on the same provider account. Recovery independent of that account has not been demonstrated.
Backup and provider copies may remain after active data is deleted. Before restored records return to ordinary use, prior deletions, corrections and access revocations must be reconciled. The recovery exercise does not establish that complete deletion or deletion replay has been tested. Requests needing a special preservation hold or a school-specific automatic retention override require an agreed, validated process; those capabilities are not established by the standard schedules.
Incident response
Our incident process covers assessment, evidence preservation, containment, investigation, recovery and follow-up. We tested incident escalation through a documented tabletop exercise.
Kelan leads security, privacy and customer communications; Chris leads technical response. Each serves as the other's backup. Kelan monitors the support inbox, with Chris covering absences. The acknowledgement target includes weekends and holidays but does not imply continuous human staffing.
For an incident involving school information, notifications follow the applicable agreement and law, using the relevant trigger, deadline and designated contacts. The ordinary support target does not replace a shorter incident-notification obligation. Communications distinguish established facts from unresolved questions and are updated as the investigation develops.
Contact us
Our targets are acknowledgement within 48 elapsed hours of receipt and active-system deletion within 72 elapsed hours after verification and acceptance, including weekends and holidays. Backup and provider copies require separate handling. These targets do not override applicable legal or contractual deadlines or guarantee immediate deletion of every copy.
Send security concerns and privacy, export or deletion enquiries to [email protected]. Include a description and a way to reach you. Please avoid sending passwords, authentication codes or unnecessary student content.
This overview describes CreativeTrail's practices and their stated limits. It is not an independent audit, a certification or a guarantee that every possible school requirement is satisfied.