Classroom video is sensitive. We treat it that way.

These commitments are enforced in code, not just stated here.

Protections built into every project

Blur every face by default

Every detected face starts blurred. Yours appears only after you identify it yourself.

Require your manual review

You check blurs, add mutes, and redact names. Sharing waits until review is complete.

Keep deletion in your hands

Delete a project, or just the original recording, at any time. Organizations can automate retention.

Share on your terms only

Reviewers see only what you share, always privacy-enhanced. Every grant is revocable and logged.

What we never do

Enforced by the AI prompt policy, an output filter, and automated tests.

  • Identify students or recognize and compare student identities
  • Infer race, ethnicity, disability, gender, age, or other sensitive traits
  • Interpret facial expressions or infer emotions
  • Score attention, infer engagement, identify off-task behavior, or analyze compliance
  • Rank students or produce student profiles
  • Score teacher effectiveness or produce punitive teacher ratings

Privacy-enhanced, not anonymous

We call the blurred render privacy-enhanced, never anonymous. Voices, spoken names, clothing, and classroom context may remain. The transcript flags likely names for one-click redaction and muting.

Residual-risk honesty

Detection can miss faces, which is why manual review cannot be skipped. Recording consent remains your institution's responsibility.
  • Media lives in private storage behind authorization-checked, short-lived links
  • Reviewers can never stream the original unblurred video
  • Nothing goes to an external AI provider unless explicitly configured
  • Audit logs can never contain transcripts, reflections, or filenames