Clerion Inc. (“Clerion,” “we,” “us,” or “our”), a Delaware corporation, operates the website clerionai.com and provides a Canvas-native academic intelligence platform for higher education (the “Service”). This Privacy Policy describes the data the Service collects, how it is collected, the purposes for which it is used, the parties with whom it is shared, how long it is retained, and how it may be deleted. It applies to students, staff, and institutional users (“you” or “your”).
Summary
- Data ownership. You and your institution own your academic records. Clerion claims no ownership and receives no licence to use them beyond operating the Service.
- No sale of personal data. Clerion does not sell personal data and does not share it for cross-context behavioural advertising.
- No advertising. The Service displays no advertising, performs no advertising targeting, and permits no third-party advertising trackers.
- Grades are not stored. Grade figures are computed from Canvas on request and held in volatile memory for no more than 30 minutes.
- Read-only integration. Clerion reads from Canvas and does not write to, modify, or delete anything in your Canvas account.
- Deletion on request. All of your data can be permanently deleted at any time, at no cost, with written confirmation.
1. Who we are
Clerion Inc. is a Delaware corporation with its principal place of business at 354 Hurlbutt Street, Wilton, Connecticut 06897, United States. Clerion Inc. is the controller of the personal data described in this policy, except where we process academic records on behalf of an educational institution. In that case the institution is the controller and Clerion acts as its processor and as a “school official” under FERPA, as described in section 17.
This policy covers clerionai.com, the Clerion web application, and the Clerion integration with your institution’s Canvas environment. Privacy enquiries should be directed to the contact in section 22.
2. Changes to this policy
We maintain this policy so that it remains accurate. When it changes:
- The “Last updated” date at the top of this page is revised for every change, however minor.
- For any material change, including a new category of data, a new purpose, a new third party, a change to a retention period, or any reduction in your rights, we notify account holders by email and post an in-app notice at least 30 days before the change takes effect, and we notify the administrative contact at each partner institution.
- Material changes are not applied retroactively to data already collected. Where a change would require a broader use of data already held, we seek consent rather than rely on notice.
- Prior versions of this policy are retained and are available on request.
- If you do not agree to a change, you may request deletion of your account before the change takes effect, as described in section 7.
Change record
Prior versions are available on request, as stated above. Where a revision needs an explanation beyond its date, that explanation is recorded here rather than left for a reader to ask for.
August 23, 2026 — product telemetry added to sections 3, 4, 5, 7, 8 and 18. These sections were revised to describe first-party product telemetry that the Service had already begun collecting. Under the rule above, a new category of data and a new purpose are material changes, so the 30 days’ notice was not given in advance of that collection. We record why, rather than leave the omission unexplained.
No student’s data was collected under the incomplete description. When the collection began, the Service was running only in pre-release environments: the production service had not been stood up, and the accounts in use were Clerion staff together with the demonstration personas they operate, which the system records as staff-driven. There was accordingly no account holder to notify, and no student to whom the omission could have mattered. The notice described above runs in full before the Service admits its first student.
3. Data we collect
The following table lists the data the Service collects in full. Categories not listed here are not collected.
| Category | Data collected | Purpose |
|---|---|---|
| Identity | Name, institutional email address, institution domain, and an internal Clerion user identifier. For staff users, the access role granted by the institution. | Authentication, separation of each institution’s data, and determination of the institutional policies that apply to the account. |
| Canvas academic data | Courses and enrollments; assignments, quizzes, and due dates; submission status and timestamps; syllabus files and their extracted text; announcements; calendar events; course-related messages; and assignment scores as returned by Canvas at the time of viewing. | Delivery of the core Service: reconciling syllabus and Canvas records and producing the resulting plan. |
| User-provided content | Academic goals, reported effort on assignments, questions submitted to the advisor, and the content of support requests. | Personalisation of the plan to your stated goals, and response to your enquiries. |
| Technical and security data | IP address, browser type and version, request timestamps and paths, error diagnostics, and an audit record of each access to academic records. | Operation, diagnosis, and security of the Service, and the access accountability FERPA requires. |
| Product usage and interaction quality | Which screen of the application you are on, how long it was open and attended, and which screen preceded it; whether you have used any of four named features (the what-if grade lab, course comparison, sending a message to the advisor, and opening an assignment drawer); which step of setting up your account you have reached; and signals that the interface is failing you — a control clicked repeatedly, a click that produced no effect, a loading state that never settles, a page reloaded again and again, a form re-entered, an interaction that ran slowly, the application briefly freezing, and the error or empty states it displayed. The error diagnostics listed under Technical and security data above are sent by the same mechanism and held on the same terms; together the two are referred to below as product telemetry. Each record carries the name of the screen, a timestamp, the release of Clerion you are running, and an identifier issued to your browser tab. Every field is either a value from a fixed published list, a whole number, or the developer-assigned name of the control involved. No grade, no coursework, and nothing you type can be carried: text you enter is never read by this mechanism, and error messages have digits, e-mail addresses, identifiers, and quoted text removed in your browser before they are sent, and are truncated to 200 characters. | Diagnosis of failures a student would otherwise have to notice and report, and measurement, in aggregate, of where students are unable to finish a task — above all how many complete the connection to Canvas. Usage records may be switched off in the application at Settings → Privacy; section 4 states exactly what that stops and what it does not. |
| Waitlist (marketing site only) | Name, email address, and the institution provided. | Notification when the Service becomes available at that institution. |
Records written before you sign in
One product-usage record is written before you sign in: the first step of the setup journey is your arrival at the welcome screen, which necessarily happens before there is an account to attach it to. That record carries no name, no e-mail address, and no account identifier. It is nonetheless not anonymous, and we would rather say so than describe it more favourably than it behaves. The browser-tab identifier described above is replaced after thirty minutes of inactivity, but it is not replaced when you sign in — so the arrival record shares one with the records written afterwards in the same tab, and those do identify you. The two can therefore be connected by anyone able to read those records.
That connection is deliberate rather than an oversight: it is the only thing that makes the setup journey measurable as a journey rather than as a pile of unrelated counts. It is also the reason the usage-analytics setting cannot suppress the arrival — the arrival happens before there is an account whose setting could be consulted. Because the record carries no account identifier, deleting your account does not reach it either; it is discarded with the rest of these records within 30 days, as described in section 8.
Data we do not collect
We do not collect Social Security numbers, government identifiers, financial or payment data, health data, biometric data, precise geolocation, advertising identifiers, or behavioural data from any site other than Clerion. We do not construct advertising or marketing profiles, and we do not knowingly collect data from any child under 13. Grade figures are not stored: they are computed from Canvas at the time of the request and held in volatile memory for no more than 30 minutes.
4. How data is collected
Data reaches Clerion through five mechanisms, and no others:
- Directly from you. Information you enter into the Service, including goals, effort reports, advisor questions, support messages, and the waitlist form.
- From Canvas, with your authorisation. When you connect Clerion, your institution’s Canvas server issues an OAuth 2.0 access token scoped to your account. We use that token to call the Canvas API and read the items listed in section 3. This access is read-only. Clerion does not write to, modify, or delete any content in Canvas. You may revoke the token from your Canvas account settings, or disconnect from within Clerion, at any time.
- From Canvas, when you open Clerion from within it. If your institution has installed Clerion in Canvas, opening it from a course sends us a signed message from Canvas identifying you — your name, your institutional email address, and an identifier for your Canvas account. What that message contains is configured by your institution when it installs Clerion, not chosen per student. It grants no access to your data. It establishes who you are, and nothing more; reading your coursework still requires the separate authorisation described above.
- Automatically from your browser. Our servers record the technical data described in section 3, and the Service sets the four strictly necessary cookies listed in section 11.
- Sent by the application, as product telemetry. Distinct from the mechanism above,
because here the application running in your browser assembles the product-telemetry records
described in section 3 and posts them to us, rather than our servers observing
a request you made. They are sent in small batches, including as a page is closing, to a
single endpoint on our own servers (
/api/telemetry). No analytics provider, advertising network, or third-party tracker receives them, and none is present in the application. Each batch is sent with your existingclerion_sessioncookie, which is how a record is attributed to your account rather than to nobody; this mechanism sets no cookie of its own, and none of the cookies in section 11 is an analytics cookie. You may switch off the usage half of it at Settings → Privacy: we then stop recording which screens you view, which features you use, and which setup steps you reach. The records that tell us the Service is failing you — errors, controls that do not respond, loading that never settles — continue, because they are how we learn that the product is broken for a student who has not told us. You were never offered a choice about those, and we would rather say so than imply one. The pre-sign-in arrival described in section 3 is likewise unaffected, for the reason given there.
We do not purchase personal data, obtain it from data brokers or advertising networks, collect it by scraping, or receive it from social networks. We collect no information about you from any website other than Clerion.
5. How data is used
Personal data is used solely to operate the Service, specifically to:
- Reconcile academic data across Canvas, syllabus documents, and course announcements, and identify discrepancies between those sources.
- Generate prioritised plans, daily briefings, deadline tracking, and grade projections.
- Respond to questions submitted through the Clerion advisor.
- Maintain the security, availability, and correctness of the Service, including diagnostics, abuse prevention, and the access audit trail.
- Establish, in aggregate, how the Service is used and where students are unable to finish what they started — in particular the steps of connecting Canvas — so that failures nobody reports can still be found and repaired. This analysis is performed on counts across all students. It is not used to evaluate, rank, or draw conclusions about any individual.
- Respond to support requests.
- Comply with our legal and institutional obligations, including FERPA.
6. Data ownership
You own your data. As between you and Clerion, you and your institution own all academic records, submissions, goals, and content that you provide or that we read from Canvas on your behalf. Clerion acquires no ownership interest in that data.
Clerion does not take a broad, perpetual, or irrevocable licence to your data. We process it solely as your service provider, solely to deliver the functions described in section 5, and solely for the duration of your account. That permission is limited in scope, revocable by you at any time, and terminates on deletion of your data. We do not use your data for our own purposes, do not commercialise it, and retain no rights in it following deletion.
Where Clerion serves an institution, the institution’s written agreement with us governs, and any records constituting education records under FERPA remain under that institution’s direct control.
7. Deleting your data
You may request permanent deletion of all of your data at any time, at no cost, without providing a reason, and without any effect on your access to the Service before deletion is carried out.
How to request deletion
- In the application. Settings → Delete my account. The deletion is carried out immediately on confirmation, your session is revoked, and a confirmation record is written.
- By email. Write to alex@clerionai.com from your institutional email address. We verify the request, carry out the deletion, and confirm it in writing. Deletion is completed within 30 days of receipt and is typically processed on the same business day.
- Through your institution. An institutional administrator may request deletion on behalf of an individual student, or for all of the institution’s users on termination of an agreement.
- To halt further collection immediately, revoke Clerion’s authorisation from your Canvas account settings, or use Settings → Disconnect Canvas. Synchronisation stops at once, and you may then request deletion of the data already collected.
- Before deleting, you may export a copy of your data from Settings, so that nothing is lost that you wish to keep.
What deletion does
Deletion is a permanent removal, not a status flag. Every record associated with your account is deleted from the production database, including courses, enrollments, assignments and calendar items, submissions, syllabus items and extracted syllabus data, course resources and metadata, messages, advisor conversations, goals, effort reports, progress records, the product-telemetry records described in section 3, staff access grants, and your Canvas connection together with its access token. Your identity record is stripped of all personal information in the same database transaction.
One record is beyond the reach of the deletion, and is deleted anyway. The pre-sign-in arrival described in section 3 carries no account identifier, so an erasure keyed to your account has nothing by which to find it. It is not kept on that account: it is discarded, with every other record of its kind, within 30 days of the day it was written (section 8). We state this rather than let “every record” stand unqualified.
Two records are retained by design, and neither can identify you. The security audit trail is de-identified during the erasure so that its entries can no longer be associated with an individual, and a non-personal record of the fulfilled deletion request is kept as evidence that the request was completed. Deleted data is removed from encrypted backups as those backups expire, within 30 days.
8. Data retention
Data is retained only for as long as it is required for the purpose for which it was collected. Each category below carries a defined retention period; no category is retained indefinitely.
| Data | Retention period |
|---|---|
| Grades and score figures | Not stored. Computed from Canvas on each request and held in volatile memory for a maximum of 30 minutes. |
| Canvas academic data (courses, assignments, syllabi, calendar, messages) | Retained while the account is connected and in use, and purged 60 days after the last sign-in. Canvas remains the system of record, so purged data is restored by reconnecting. |
| Goals, effort reports, advisor conversations | Retained while the account is active and deleted with the account. Advisor conversation history is held in your browser and is removed when you clear it or the account is deleted. |
| Identity and account record | Retained until deletion is requested, then erased within 30 days, including from backups. |
| Server request logs (IP address, user agent, request path) | 30 days, then deleted. |
| Product telemetry (section 3) | 30 days, then deleted — each day’s records are discarded whole. Deleted sooner if you delete your account, with the single exception of the pre-sign-in arrival described in section 7, which no account-keyed erasure can reach and which is therefore removed at the 30-day limit. The daily totals derived from these records — how many views, how many failures, how many students reached each step of setup — carry no identifier of any kind, are not personal data, and are kept as the Service’s record of its own behaviour over time. |
| Security audit records of access to academic records | Retained for accountability under FERPA, and de-identified on erasure so that they cannot be associated with an individual. |
| Waitlist entry | Retained until the Service launches at the institution provided or removal is requested, whichever occurs first. Removal is completed within 30 days of a request. |
| Canvas OAuth access token | Retained only while the connection is active, and destroyed on revocation or deletion. |
On termination of an institutional agreement, institutional data is deleted or returned within 30 days, at the institution’s election.
9. How data is protected
The following controls are in place:
- Encryption in transit. All connections to the Service, including browser to server, server to Canvas, and server to database, use TLS 1.2 or later. HTTP requests are redirected to HTTPS and the site is served with HTTP Strict Transport Security.
- Encryption at rest. All stored data, including database contents, backups, and logs, is encrypted at rest using AES-256.
- Secrets management. Credentials and API keys are held in a managed secret store and are not present in source code, configuration files, logs, or support records.
- Tenant isolation enforced in the database. Each institution’s data is isolated by row-level security policies in PostgreSQL, so that a query scoped to one institution cannot return another institution’s records. An automated test verifies this isolation under a restricted database role on every change.
- Least privilege. The application connects using a restricted database role limited to the permissions it requires, and production access is limited to authorised personnel.
- Audit logging. Access to academic records is recorded in an append-only audit log capturing the accessing account, the record accessed, and the time of access.
- Redaction prior to AI processing. Personal identifiers are removed from course and message text at the network boundary before any content is transmitted to our AI provider.
- Read-only integration. Clerion’s Canvas authorisation cannot modify your Canvas account, so a compromise of Clerion cannot alter grades or submissions held there.
- Secure development. Every change passes automated type, lint, architecture, and test gates together with dependency vulnerability scanning before release, and is reviewed prior to merge.
No system can be guaranteed secure. These controls are maintained, tested, and enforced through automated gates rather than procedure alone.
10. Accounts, sign-in, and passwords
Clerion does not create, store, or manage passwords. There is no Clerion password that can be guessed, phished, or reused.
- Authentication method. Clerion is reached by LTI launch from within Canvas, or by single sign-on with your institution’s identity provider over SAML or OIDC, delegated to our identity provider WorkOS. Google Workspace sign-in is offered where the institution permits it. Clerion receives only the resulting authentication assertion.
- Password strength and multi-factor authentication. Because authentication takes place at your institution’s identity provider, that provider’s password-strength requirements and multi-factor authentication policies apply to Clerion automatically, including step-up and MFA challenges. An institution that requires MFA obtains MFA on Clerion without additional configuration, and we recommend MFA-enforcing single sign-on for every deployment.
- Sessions. Authenticated state is carried in an encrypted, signed session cookie that is HttpOnly, Secure, and SameSite-restricted, and therefore cannot be read by JavaScript or replayed from another origin. Every state-changing request additionally requires a CSRF token bound to the session. Sessions are revoked on sign-out and on deletion of the account.
- Staff access. Staff may view a student’s data only where the institution has expressly granted that access, and each such access is recorded in the audit log.
11. Cookies
The Service uses four cookies, each of which is strictly necessary for the Service to function or to be secure. No analytics cookies, advertising cookies, or third-party cookies are used, and no cross-site tracking is performed. The marketing site at clerionai.com sets no cookies.
| Cookie | Purpose | Lifetime | Category |
|---|---|---|---|
clerion_session |
Maintains the authenticated session. Contains an encrypted, signed session reference, with no academic data and no content readable by the browser. | Duration of the session; cleared on sign-out or deletion | Strictly necessary, first-party |
clerion-auth-verifier |
Protects the sign-in exchange against interception and login-CSRF attacks. Set at the start of sign-in and destroyed on completion. | 10 minutes | Strictly necessary, first-party |
clerion_view_as |
Records the student whose data an authorised staff member is currently viewing, so that the viewing context cannot be altered from the browser. Set only for staff holding an institutional access grant, and never for students. | Until the staff member exits the view | Strictly necessary, first-party |
clerion_lti_session |
Maintains the session established when you open Clerion from within Canvas, so that the launch signs you in without a separate login. Contains a signed, opaque session reference and no personal data. Set only on an LTI launch, and never during ordinary sign-in. | 12 hours | Strictly necessary, first-party |
Because all four cookies are strictly necessary, no consent banner is presented and there are no optional cookies to disable. Blocking them prevents sign-in. Advisor conversation history is held in your browser’s local storage rather than on our servers, and may be cleared from within the application.
12. Third parties and subprocessors
The following table lists in full the third parties that process data in the course of operating the Service and this website, the function each performs, and the data each receives. Each is necessary to what it supports; one of them, Supabase, serves only the waitlist form on this website and never receives data belonging to an account holder. None is an advertising, analytics, or data brokerage service.
| Third party | Function | Data received | Location |
|---|---|---|---|
| Google Cloud Platform (Google LLC) |
Hosting for the application, database, and secret store. | All data described in section 3, encrypted at rest. Processed solely as our infrastructure provider and not accessed for Google’s own purposes. | United States |
| Instructure (Canvas LMS) |
Your institution’s learning management system and the source of academic data, operated under your institution’s own agreement. | Only the authenticated API requests we make to read your data. No student data is transmitted to Canvas by Clerion, and no content is written there. | As determined by your institution |
| WorkOS (WorkOS, Inc.) |
Authentication and single sign-on. | Name, institutional email address, institution domain, and session metadata. No academic data, grades, or coursework. | United States |
| OpenAI (OpenAI, L.L.C.) |
Syllabus extraction, reconciliation, and advisor responses. | Course, assignment, syllabus, and message text, with personal identifiers removed before transmission. No names, email addresses, account identifiers, or grades. Under our API terms this content is not used to train models. | United States |
| Vercel (Vercel Inc.) |
Delivery of the website and the application’s static assets. | Request metadata only: IP address, user agent, and requested path. No academic or account data is transmitted. | United States |
| Supabase (Supabase, Inc.) |
Storage of waitlist registrations submitted through the marketing site. | Waitlist name, email address, and institution. No academic data, and no data relating to authenticated users of the Service. | United States |
| Slack (Slack Technologies, LLC) |
Internal engineering and operational alerting. | No personal or academic data. Alerts contain system status and non-personal identifiers only. | United States |
Personal data may additionally be disclosed in two circumstances outside the ordinary operation of the Service: where we are compelled to do so by valid legal process, in which case we will notify you in advance unless prohibited by law; and where disclosure is necessary to protect the safety of a user or of the public. In the event of a merger or acquisition, your data remains subject to this policy, and we will provide at least 30 days’ notice before any transfer.
13. Opting out of third-party sharing
Each third party listed in section 12 is necessary to the operation of the Service. There is no optional data sharing, and no data is shared for marketing, advertising, or analytics purposes.
You may nonetheless end all third-party processing of your data:
- Disconnect Canvas. Settings → Disconnect Canvas. Synchronisation stops immediately, the stored access token is destroyed, and the synchronised academic data is deleted. Your account remains open.
- Delete your account. Settings → Delete my account, which removes everything as described in section 7.
- Revoke Clerion’s authorisation in Canvas. Your Canvas account settings also allow you to withdraw Clerion’s access directly, at any time.
- By email. Write to alex@clerionai.com and we will carry out either of the above on your behalf within 5 business days.
Institutions that do not permit AI-assisted processing of course content may request that AI-assisted features be disabled for their tenant. We will configure this and confirm it in writing.
14. Subprocessor obligations
Clerion remains responsible for its subprocessors’ handling of your data. We do not disclaim that responsibility.
- Each third party listed in section 12 is engaged under a written data-processing agreement imposing privacy and security obligations at least as protective as this policy and as our agreements with institutions, including FERPA obligations where applicable.
- Each may process your data only on our documented instructions and only to provide the contracted service. Resale, advertising, profiling, and the training of artificial intelligence models on your data are prohibited. Two providers reserve a narrow right over the operational data they hold and nothing more: WorkOS may use the sign-in data described in section 12 to improve the reliability of its own service, and Vercel treats request telemetry and our company contact details as its own. Neither receives academic data, and neither right reaches your coursework, grades, or messages.
- Each is required to maintain appropriate security measures, to notify us promptly of any security incident, and to delete or return data on termination of the engagement.
- Each engages its own subprocessors under a general authorisation from us. It must notify us in advance of any addition or replacement, bind that subprocessor to protections no weaker than those it owes us, and remain liable to us for its acts. Where we object and the objection cannot be resolved, we may end the engagement.
- We assess each provider’s privacy and security posture before engagement, and we remain liable to you and to your institution for its acts and omissions to the same extent as for our own.
The Service may link to external websites, including those operated by your institution. Such sites are not subprocessors and are governed by their own policies.
15. Changes to our third parties
The list in section 12 is maintained as a current record. Before any third party that processes personal data is added or replaced:
- Section 12 is updated before the change takes effect.
- Account holders are notified by email and the administrative contact at each partner institution is notified at least 30 days in advance.
- The incoming provider is bound to equivalent or stronger data-protection obligations before any data is transferred to it. A change of provider does not result in any change to the permitted use of your data.
- Institutions may object to a proposed subprocessor during the notice period. Where an objection cannot be resolved, the institution may terminate and its data is deleted or returned.
- You may request deletion of your account before the change takes effect.
16. Advertising
- No advertisements are displayed, in the application, on the website, before or after sign-in, or in email.
- No user is targeted for advertising. We do not profile, segment, or construct advertising or interest profiles from academic data or user behaviour.
- No third party tracks or collects data for advertising purposes. We use no advertising networks, advertising SDKs, data brokers, or third-party analytics services, and no third party is permitted to collect data about you through the Service.
- No web beacons or comparable tracking technologies are used for advertising. We use no tracking pixels, beacons, device fingerprinting, session-replay tools, or cross-site or cross-device tracking. Interaction measurement is limited to interactions within the Service and is used only for product functionality.
- No data is shared with advertisers, and accordingly there is no advertiser data sharing from which to opt out. Were advertising ever introduced, it would be subject to the 30-day notice in section 2, would not be targeted using student data, and would require opt-in consent.
17. FERPA, COPPA, GDPR, and state law
FERPA
Where Clerion processes education records on behalf of an institution, it acts as a “school official” with a legitimate educational interest under 34 CFR § 99.31(a)(1)(i)(B). Clerion is under the institution’s direct control with respect to those records, uses them only for the purposes the institution authorises, and does not redisclose them except as described in section 12 or as directed by the institution. Requests to inspect or amend an education record are handled through the institution, and Clerion will assist the institution in responding.
COPPA
The Service is designed for higher education and is not directed to children. It is not intended for and may not be used by any person under 13. We do not knowingly collect personal information from a child under 13. If we become aware that we have done so, we will delete the information and close the account promptly. Reports of suspected under-13 use should be directed to the contact in section 22.
State student-privacy laws
Consistent with SOPIPA and comparable state student-privacy statutes, Clerion does not sell student data, does not use it for targeted advertising, does not construct non-educational profiles, and does not permit its vendors to do so. For the purposes of the CCPA and CPRA, Clerion does not “sell” or “share” personal information as those terms are defined, and has not done so in the preceding twelve months.
GDPR and UK GDPR
Where the GDPR or UK GDPR applies, our lawful bases are the performance of a contract with you, our legitimate interests in securing and operating the Service, our agreements with institutions, and consent where consent is sought. The rights described in section 18 apply. Data is stored in the United States; where personal data is transferred from the EEA or the United Kingdom, we rely on the European Commission’s Standard Contractual Clauses together with the UK Addendum. You may lodge a complaint with your supervisory authority, and we ask that you also raise the matter with us directly.
18. Your rights and choices
Clerion honours the following for all users, irrespective of whether a particular statute applies to them:
- Access. Obtain a copy of the personal data we hold about you.
- Portability. Export your data from Settings, or request it from us, in a structured, commonly used, machine-readable format.
- Correction. Have inaccurate data corrected. Data sourced from Canvas is corrected at source and the correction is reflected on the next synchronisation.
- Deletion. Have all of your data permanently erased, as described in section 7.
- Restriction and objection. Request that we cease a particular processing activity.
- Withdrawal of consent. Revoke Clerion’s Canvas authorisation, switch off product-usage records at Settings → Privacy, or request deletion of your account, at any time.
- Complaint. To us, to your institution, or to your data-protection authority.
Requests should be sent to alex@clerionai.com from your institutional email address. We respond within 30 days and make no charge. We do not deny service, charge a different price, or provide a different level of service to any person who exercises these rights. Where FERPA requires that a records request be directed to your institution, we will tell you and will assist the institution in responding.
19. Where data is stored
The Clerion application and database operate in Google Cloud Platform data centres in the United States, and data is stored there. The third parties listed in section 12 operate in the regions indicated. Student data is not relocated to another country without advance notice to institutions.
20. Security incidents
In the event of a confirmed breach affecting your personal data, we will notify you and your institution without undue delay and no later than 72 hours after confirmation. The notification will describe the nature of the incident, the categories of data involved, the measures taken, the measures planned, and any steps you should take. Notification will not be deferred pending completion of our investigation.
Suspected vulnerabilities in the Service may be reported to alex@clerionai.com. We will not pursue legal action against security researchers who report vulnerabilities in good faith and allow a reasonable period for remediation.
21. Accessibility
Clerion targets WCAG 2.1 Level AA. The controls described in this policy, including deletion, disconnection, and access requests, are operable by keyboard and accessible to screen readers. Our Accessibility Statement sets out our current conformance status and the process for reporting a barrier.
22. Contact us
Questions, requests, and complaints concerning this policy, your data, or our security practices, including deletion requests, access requests, and breach notifications, should be directed to our privacy contact.
Privacy contact: Alex Pravia
Email: alex@clerionai.com
Address: 354 Hurlbutt Street, Wilton, CT 06897, United States