Privacy Policy
Effective Date: August 2026
LectraScan AI is operated by Cien Rios LLC.
Information We Collect
- Account information (email, name).
- Uploaded documents (images of student work).
- OCR and AI-generated text.
- Usage data (feature usage, scans count).
- Device information (for performance and security).
How We Use Information
- Provide handwriting transcription services.
- Improve readability using AI.
- Enable document organization and export.
- Maintain security and prevent abuse.
Student Data
LectraScan AI may process student-submitted work uploaded by lecturers. We do NOT claim ownership of this data.
Data Storage
- Documents are stored securely using encrypted storage.
- Access is restricted to authorized users only.
- We do not make documents publicly accessible.
Data Residency
LectraScan AI's primary database, object storage, and edge functions are hosted on Supabase in the United States. We do not currently operate EU- or India-resident infrastructure. EU/UK/Swiss data subjects, and customers requiring data residency in their region for institutional procurement, should email institutions@cienrios.com before signing up so we can evaluate a region-specific deployment. Where personal data is transferred to sub-processors outside its origin jurisdiction, transfers are governed by the relevant Standard Contractual Clauses — see the sub-processor list for details.
AI Processing
- AI is used to improve readability and translation.
- AI outputs may contain errors.
- Users must review all results.
Data Sharing
We do NOT sell personal data.
We only share data with:
- Service providers — see our full sub-processor list for the third parties involved in delivering the service, the data each receives, and where they operate.
- Legal obligations when required.
Data Retention
- Account, document, and student-work data is retained until you delete it via "Delete my account" or document-level controls.
- You may delete individual documents at any time.
Audit-log retention exception
We retain a minimal audit log of administrative actions — account-deletion requests, plan changes, export and share-link generations, and AI compliance-guard violations — beyond the deletion of the underlying account or organization. This trail is required to demonstrate compliance, investigate misuse, and respond to lawful requests. Each entry contains a UTC timestamp, the action name, and the organization / actor IDs involved; it does not contain document content. Retained audit-log entries authored by you are included in your self-service export bundle.
Your Data Export
The in-app "Export my data" control produces a ZIP containing:
- Your profiles row.
- A sanitized copy of your authentication record (email, sign-in timestamps, user metadata) — encrypted password and multi-factor secrets are excluded by design.
- Audit-log entries you authored.
- Every owned organization with all org-scoped tables, including documents, OCR results, AI clarity rewrites, translations, corrections, exports metadata, usage events, subscription entitlements, and that organization's audit-log entries.
- Original scanned page images at
pages/<orgId>/<documentId>/<n>.jpg.
Audit-log entries authored by other users in your organization are not included because they contain those users' identifiers.
User Rights
Users can:
- Access their data.
- Export their data.
- Delete their data.
Children's Privacy
This app is intended for educators, not direct use by children.
Contact
Cien Rios LLC, 17113 Miramar Parkway #1027, Miramar, FL 33027, USA