Legal
Privacy notice for Veritas Quest learning accounts.
The privacy notice explains what Veritas Quest collects, why it is collected, who can see it, how long it is kept, and how to make requests.
Last updated: August 14, 2026
At a glance
This notice covers the Veritas Quest learning platform: the learner app, the teacher and author consoles, the guardian portal, and the public pages you are reading now. The cards above are the short version; the sections that follow are the whole of it.
We never sell your data.. No advertising networks, no data brokers, no third-party tracking pixels on the learning surfaces.
Under-16 accounts are supervised.. They are always attached to a school, or to a guardian who has completed the consent flow.
Schools stay in charge of their data.. For school-issued accounts the school directs what happens to learner records; we act on its instructions.
You can erase your account.. Settings, then Account, then Erase - from inside the product, without asking anyone for permission.
Who this notice covers
Veritas Quest is multi-tenant. An account belongs either to a school workspace or directly to an individual learner or guardian, and the two are treated differently.
For school-issued accounts, the school decides what learning data is collected and why; we hold and process it on the school's instructions under the agreement it signed with us. If your school has its own privacy notice or data processing agreement, that agreement governs and takes precedence over this page wherever the two differ.
For accounts created directly on this site, we make those decisions ourselves and this notice is the whole answer.
What we collect
We try to hold as little as the product can run on. This is the inventory:
Account data. Display name, email address or phone number, role, the school or class you belong to, and a hashed password. Passwords are never stored in a readable form.
Learning data. Quest and exam attempts, answers, time on task, mastery and streak state, XP, league standing, and the cosmetics you have earned.
Technical data. Device and browser type, IP address, and diagnostic records from crashes and errors - used to keep the service running and to investigate abuse.
Support messages. The contents of support tickets and feedback you send us, and our replies. Only what you choose to write.
What we do not collect. Precise location, contacts, photo libraries, microphone or camera access, social graphs, advertising identifiers. The product asks for none of them.
Why we collect it
Account data exists so you can sign in and so the right learner sees the right work. Learning data is the product: mastery tracking, adaptive routing, streaks, leagues and teacher reporting are all computed from it, and without it the platform has nothing to teach against.
Technical data keeps the service available and secure - finding crashes, rate-limiting abuse, investigating incidents. Support messages are used to answer you.
We do not profile learners for advertising, and we do not use learning data to train models that are sold or shared outside the platform.
Under-16 safeguards
A learner under 16 cannot hold a free-floating account. They are attached either to a verified school workspace, whose staff administer the account, or to a guardian who has completed the consent flow we send by email before the account becomes usable.
Guardians keep a portal of their own: they can see the learner's progress, review what was consented to, and withdraw that consent, which suspends the account.
Class and school leaderboards are scoped to the learner's own workspace, and workspaces are isolated from one another at the database level. A learner in one school cannot be enumerated, ranked against, or messaged by a learner in another.
Who we share it with
A short list, and only where the service cannot run without it. We do not sell personal data, and we do not share it for anyone else's marketing.
Your school. For school-issued accounts, teachers and workspace administrators see the learning data for the learners they are responsible for.
Your guardian. Where a guardian link exists, that guardian sees the learner's progress and account state through the guardian portal.
Infrastructure providers. Hosting, database and email delivery services that run the platform and send transactional mail such as password resets and consent requests.
Error and usage monitoring. Where a deployment enables them, Sentry receives crash diagnostics, and PostHog and Google Analytics receive product-usage events. Google Analytics runs with advertising signals and ads personalization disabled. All of them stay off unless the operator configures them.
Legal obligation. Where the law requires disclosure, or where disclosure is necessary to protect a child from harm.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, or stop processing it. You can also object to processing and, where a data protection regulator covers you, complain to it.
Two of those you can exercise yourself, immediately: correct your profile from Settings, then Profile; and erase the account entirely from Settings, then Account. Erasure is deliberately hard to do by accident - it asks you to type a confirmation phrase - because it cannot be undone.
For anything else, contact us using the details below. If your account was issued by a school, send the request to the school as well: the school decides, and we act on its instruction.
How long we keep it
Account and learning data is kept while the account is active, because a learning record deleted mid-course takes the learner's progress with it.
When an account is erased, the personal data attached to it is removed, and any records we are required to keep - billing records, safeguarding reports, security logs - are separated from the identity that produced them. School-issued accounts follow the retention schedule in the school's agreement.
Diagnostic and error records are short-lived and expire on the monitoring provider’s retention schedule.
How we keep it safe
Traffic is encrypted in transit. Passwords are hashed, and are never stored or logged in readable form. Sessions can be listed and revoked from Settings, then Account, and multi-factor authentication is available to accounts that want it.
Workspace isolation is enforced in the database itself rather than only in application code, so a bug on one screen cannot spill one school's learners into another's. Administrative access to production data is restricted and logged.
No system is perfect. If a breach affects you, we will tell you and, where required, the regulator.
Changes to this notice
When this notice changes materially we update the effective date shown at the top of this page and, for changes that affect how learner data is handled, notify account holders inside the product.
Contact us
Privacy questions, data requests and complaints all go to the same place, and we answer them in the order they arrive.
If your account was issued by a school, your school's data protection contact is the faster route for anything about learning records - they hold the decision, we hold the data.