Privacy Policy

Effective 2026-09-05 · Synergy Media Group (SMG), doing business as DistrictWise

Overview

DistrictWise is a governance intelligence tool for California school districts, operated by Synergy Media Group. This policy explains what data we collect, how we use it, and the protections we put in place.

1. What data we collect

Query text. When a user submits a policy question, the text of that question is processed to generate an answer.

User identifiers. We collect the email address of each licensed staff user to operate their access seat, and issue a short-lived session token. We do not collect student names or student personal identifiers — those are masked on the user's device before any text is transmitted (see §2).

Usage metadata. For operational monitoring, billing, and quality, we log per-query records: the masked question text, the policy citations returned, token and cost counts, and the staff seat that made the request.

What we do not collect:

  • Student records, grades, or personally identifiable student information
  • Staff personnel records
  • Financial account information
  • Any data from pages a user visits outside of DistrictWise

2. PII masking

DistrictWise masks personally identifiable information on the user's device, in the browser, before any text is transmitted. Detected and masked types include names, email addresses, phone numbers, street addresses, and cued student ID numbers. Identifiers are replaced with placeholders (for example, [Student 1]); the map needed to restore them never leaves the browser.

The masking is fail-closed: if it cannot verify success, the request is blocked and nothing is sent. As a result, un-masked student identity does not reach our servers or the AI model.

This is a core architectural feature, not an afterthought. Two honest caveats: masking is a guarantee of the staff interface (a separate public embeddable chat widget does not mask and should only receive non-identifying text); and automated name detection, while robust, is not perfect for uncommon names — the interface shows what was masked so users can correct it, and staff are advised not to paste full rosters.

3. How we use data

Query text is used solely to generate a policy answer. Specifically, and this is an architectural property rather than a policy we promise to keep (see our AI transparency page): your questions are never used to train any publicly available AI model, are never used to answer another district's questions, and never leave the education context. Query text is not:

  • Sold to third parties
  • Used to train AI models
  • Shared with advertisers
  • Used to build user profiles

4. Data storage and retention

Because PII is masked on-device (§2), everything we retain contains masked query text only — no un-masked student identity.

DataRetentionWhat happens at expiry
District policy corpusFor the term of your district's agreement with usDeleted within 30 days of contract termination, with written certification
Per-query logs (masked question, citations, cost)Up to 13 months, rollingAutomatically aged out
Saved research threads ("incidents")Until the user deletes themDeleted on request, immediately

All data is encrypted in transit (TLS). Server-side files are held with restricted OS-level permissions, and application secrets are stored off the application tree. Data is stored on U.S.-based cloud infrastructure. See our security overview for the full architecture.

5. California privacy rights (CCPA/CPRA)

DistrictWise is a business-to-government service: our direct relationship is with your school district, not with individual consumers, and the data we process is governed primarily by FERPA, SOPIPA, and California Education Code §49073.1 rather than the CCPA/CPRA's consumer framework. To the extent the CCPA/CPRA applies to any personal information we hold about a staff user (such as a work email address), that individual may contact us at [email protected] to ask what we hold and to request its deletion, and we will respond within the statutory timeframe. We do not sell personal information and have not sold personal information in the preceding twelve months.

6. Children's data

DistrictWise is a tool for school district staff — administrators, principals, and central-office employees. It is not directed at children, does not create accounts for students, and does not knowingly collect personal information directly from anyone under 18. Any student information that appears is limited to what a staff member incidentally includes in a policy question, and is masked on-device before transmission as described in §2.

7. California-specific compliance

FERPA (Family Educational Rights and Privacy Act)

  • We operate as a school official under the legitimate educational interest exception
  • A signed Data Processing Agreement is required with each district before go-live
  • Because student PII is masked on-device before transmission, we do not retain identifiable student education records; any stored research threads are de-identified

SOPIPA (Student Online Personal Information Protection Act)

  • We do not use student information for advertising or to build commercial profiles
  • We do not sell student information
  • We do not disclose student information to third parties except as required by law

AB 1584 (Education Code 49073.1)

  • Our Data Processing Agreement meets AB 1584 minimum contract requirements
  • Districts retain ownership of all their data
  • We will not use district data for any purpose other than providing the DistrictWise service

8. Chrome extension permissions

The DistrictWise Chrome extension requests the following permissions:

PermissionPurpose
storageStore the session token, the on-device un-mask map, and UI state — all local to the browser
contextMenusProvide a right-click entry to send selected text to the side panel
sidePanelThe entire interface is a Chrome side panel
Host access: https://districtwise.ai/*The backend the extension communicates with

The extension does not request tabs, broad host access, or the ability to read or modify the pages you visit. We request only the permissions necessary to deliver the service.

9. Data sharing and subprocessors

We do not sell, rent, or share user data with third parties except:

  • To the subprocessors who help us provide the Service — see our subprocessor list for who they are and what they touch
  • As required by applicable law or valid legal process
  • As explicitly authorized in writing by the district

If something goes wrong: if we become aware of unauthorized access to district data, we notify the affected district's designated contact without unreasonable delay, consistent with the notice timeline in our Data Processing Agreement.

10. District data ownership

Each district's policy corpus, query logs, and any district-specific configurations belong to that district. SMG acts as a data processor, not a data controller, with respect to district data. Districts may request deletion of their data at any time.

11. Security measures

Summarized here; full detail on our security overview:

  • Only ports 443 and 80 accept inbound connections; SSH is closed to the internet, admin access is over a private network, and the default policy is deny
  • The serving container runs no web browser and no Node runtime, and the server never browses the open web
  • The district's policy corpus is mounted read-only — the application cannot modify or corrupt it
  • Cross-district requests are refused at the API layer with 403; a seat can only ever see its own district's data
  • Sign-in is throttled per account and per source IP; unknown and licensed addresses return byte-identical responses so the system cannot be used to enumerate district staff
  • HSTS, clickjacking protection, MIME-sniffing protection, and a strict referrer policy are enforced
  • Transactional email is sent through a scoped cloud identity; no credential has ever been committed to source control

12. Contact

For privacy-related questions or data deletion requests: [email protected]
To report a security concern: [email protected]

Synergy Media Group
Jason Price
Lincoln, CA