Last updated: August 20, 2026
This Privacy Notice explains how Athens AI Technologies Inc. (“Athens,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal information through the Athens web application, related course workspaces, and associated services (together, the “Service”).
Please read Section 1 first. It describes how Athens is actually being used today, and several parts of this notice only make sense in that light.
1. How the Athens pilot works today
Athens is currently offered as a limited, instructor-led pilot. An individual instructor (a “Instructor”) creates a course in Athens, uploads their own course materials, and invites their students (each a “Student”). Instructors and Students together are “Users.”
An Instructor's participation does not by itself establish that their school, district, college, or university (an “Institution”) has authorized, sponsored, endorsed, or contracted for the Service. Whether an Institution has approved a given pilot is a matter between the Instructor and their Institution.
Some pilots may involve an Institution directly, under a separate written agreement (an “Institution Agreement”). Where such an agreement exists, it governs Athens' handling of that Institution's data and controls over this notice to the extent of any conflict. Where no such agreement exists, this notice governs Athens' handling of the information described here.
Athens is an early-stage product under active development. It is not a finished or generally available service, and the features described here may change.
Secondary-school pilots require prior coordination with Athens. Athens
distinguishes two models. In higher education a pilot may be instructor-led,
subject to the Instructor's own authority and their Institution's policies. If a
course is offered through a K–12 school or district, the Instructor must contact
Athens at admin@athenslabs.ai and receive written confirmation before
entering Student information, importing a roster, sending invitations, or
uploading course materials. Appropriate school or district authorization is required for every K–12
pilot. Athens may additionally require a school-appropriate pilot agreement
or data-protection addendum depending on applicable law, district policy, and
the pilot's data scope. An individual
Instructor's acceptance of the Terms, and any written confirmation from Athens,
do not replace the school's or district's own authorization. Section 12 has more
detail.
2. Information instructors provide about students
This section describes the collection most likely to be unexpected, so it comes first.
An Instructor can enter a Student's information into Athens before that Student has any contact with Athens. In either path below, Athens may receive and store the Student's email address, the Student's name where the Instructor provides one, the Student's role in the course, such as student or teaching assistant, and the course and section the Student is associated with. Where no name is provided, Athens may derive a display name from the email address.
There are two paths, and they behave differently.
Invitations
An Instructor may send an emailed invitation or generate a copyable invitation link. This creates a pending invitation record holding the information above, together with who issued it, when it was created, its status, and its expiry date.
An invitation does not by itself create an Athens account or a course enrolment, but the two are not created at the same moment either:
- Account setup happens first. When the invited person opens the invitation and sets a password, Athens creates or updates their sign-in identity with the identity provider and sets that password. This happens before they sign in and before the invitation is accepted, and the invitation remains pending at that point.
- Course enrolment happens later. The enrolment is created only when the person then signs in and accepts the invitation while authenticated, at which point the invitation is marked accepted.
So an invited person may have a working sign-in identity while still having no enrolment, and the pending invitation record continues to exist between the two steps.
Direct roster entry and roster import
An Instructor may instead add Students directly to a course roster, one at a time or by importing a roster file such as a CSV.
This path is more immediate: it can create an Athens user record and a course enrolment for the Student straight away, before the Student accepts anything, signs in, or interacts with Athens at all. The user record holds the email address, the name or a name derived from the email address, and the role, and the enrolment associates that record with the course section. A Student may therefore already exist as a user and be enrolled in a course in Athens without having taken any action.
Both paths
Athens relies on the Instructor for the authority to hold this information. The Athens Terms of Service require an Instructor to represent that they are permitted to provide their Students' contact information. Athens does not independently verify that an Instructor has that authority, is authorized by their Institution, or has told Students in advance.
If you are a Student who received an Athens invitation you did not expect, or who believes a record about you exists in Athens that should not, you may contact Athens under Section 11.
3. Other information we collect
Account and identity information
If you accept an invitation and create an account, Athens collects your name, email address, and authentication and session security information. Where a sign-in provider is used, Athens receives the identity attributes needed to authenticate you and provision your account.
Course materials that instructors upload
Instructors upload course materials, which may include syllabi, lecture notes, slides, readings, assignments, problem sets, and similar instructional documents, along with course, section, schedule, and policy settings. Athens extracts text from these files so they can be searched and cited.
These files may contain other people's personal information or third-party copyrighted material. Athens does not inspect uploads to determine what they contain. The Terms of Service place responsibility for uploading appropriate material on the person who uploads it.
Student-submitted content
Depending on which features are enabled, Athens may process content a Student creates or submits, including chat messages and questions, notes and notebook pages, uploaded files, flashcards, practice attempts, study activity, saved course context, and other workspace content. Athens treats this as student-private content, described in Section 6.
AI interaction information
When you use an AI feature, Athens processes your prompt or question, the course excerpts retrieved to answer it, the model's response, the citations shown, and operational metadata such as the provider and model used, token counts, latency, status, and errors.
Product usage, device, and security information
Athens automatically collects IP address, browser and device type, request time, pages and features used, session and authentication events, diagnostic records, and security and audit events. Athens uses cookies and similar browser storage that are necessary for sign-in, session security, cross-site request forgery protection, preferences, and core functionality.
Support and pilot feedback
If you contact Athens, report a problem, or give pilot feedback, Athens collects your contact details, your message, and the surrounding context. Please do not include another person's private information in a support message unless it is necessary and you are permitted to share it.
4. How we use information
| Category | Primary purposes |
|---|---|
| Invitation information instructors provide | Deliver and validate the invitation, associate the right person with the right course and section, prevent invitation misuse, and show the Instructor roster status |
| Account and identity | Authenticate you, provision and secure your account, and maintain sessions |
| Instructor-uploaded course materials | Extract and index text, ground AI answers in course sources, show citations, and give the Instructor control over what is released to Students |
| Student-submitted content | Provide the study features the Student uses, keep their work available to them, and maintain their course history |
| AI interactions | Generate responses, apply course policy and usage limits, debug and improve reliability and safety, and monitor cost |
| Product usage, device, and security | Operate and secure the Service, diagnose faults, prevent abuse, and maintain audit and security records |
| Support and feedback | Answer you and improve the pilot |
Across all categories, Athens also uses information to comply with law, respond to lawful requests, and establish, exercise, or defend legal claims.
Athens does not sell personal information. Athens does not use Student or course data for advertising or cross-context behavioral advertising. Athens does not train or fine-tune AI models on Student or course content, and Athens configures its approved AI providers so that content sent for a request is not used by them to train their models.
5. Our role, FERPA, and other privacy laws
Athens does not claim a settled legal characterization of its role, and this notice should not be read as one.
In an instructor-led pilot with no Institution Agreement, it is often unclear whether an education-records framework such as FERPA applies to a given course, whether the Institution has designated Athens as a “school official” with a legitimate educational interest, and whether Athens is acting as a controller, a processor, a service provider, or on its own behalf for a given activity. Those determinations depend on the Institution's own policies, the Instructor's authority, and facts Athens cannot establish on its own. Athens therefore does not represent that it is a school official for any course, that any Institution has approved its use, or that any particular privacy statute applies to or is satisfied for every pilot.
Athens will work with an Institution that wishes to formalize an arrangement, and will honor an Institution Agreement where one exists.
Instructors are strongly encouraged to check their own Institution's policies on third-party educational tools, student data, and instructional materials before inviting Students or uploading course content. Athens cannot make that assessment for you.
6. Student-private content and what instructors can see
Athens separates Student workspace content by user, course, and section.
By default, Instructors do not see a Student's individual conversations, prompts, answers, notes, notebook pages, flashcards, practice attempts, or other private workspace content. Where course analytics are available, they are designed to show aggregate patterns rather than individual content, and Athens suppresses aggregate values derived from fewer than five distinct learners. The current threshold is five.
Instructors do see roster and course administration information, including invitation status and enrollment, and the materials they themselves uploaded.
Changing these boundaries would require a deliberate product decision and, as appropriate, notice or consent. Athens will not quietly expose Student-private content to Instructors.
7. When we disclose information
Athens discloses personal information in these circumstances:
- To service providers. Athens uses providers for cloud hosting, storage, databases, authentication, email delivery, queueing, and AI model inference. They may process information only to provide services to Athens. Athens' infrastructure runs on Amazon Web Services, and AI features use approved model providers. The current list of provider categories is available on request.
- To the Instructor and course. Roster, enrollment, and course administration information is visible to the Instructor and any teaching assistants they authorize, subject to Section 6.
- At your direction. When you use a feature that shares or exports information, or you authorize a connection.
- For legal, safety, and security reasons. Where Athens reasonably believes disclosure is required by law or valid legal process, or is necessary to protect rights, safety, security, Users, or the Service.
- To an Institution. Where an Institution Agreement or applicable law requires it, or where an Institution makes a lawful, verified request concerning its own records. Athens may direct a request concerning Institution-controlled records to the Institution.
- In a corporate transaction. In connection with financing, due diligence, a merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to applicable law and confidentiality obligations.
Athens may also disclose aggregated or de-identified information that is not reasonably linkable to an individual. Athens does not disclose personal information to data brokers or for third-party targeted advertising.
8. Where information is processed
The pilot is intended for Users in the United States, and Athens' default infrastructure and approved provider paths are intended to use U.S. regions. Providers and support operations may process information in other locations where disclosed. This notice is not an international privacy supplement, and Athens should be contacted before the Service is used for people or data subject to requirements outside that scope.
9. Retention
Athens retains information for as long as needed to provide the Service and for the purposes described above, and then for legitimate business, security, audit, and legal reasons.
In practice:
- Invitation records persist until they are deleted or the course or section is removed. Two things that may look like deletion are not: an invitation that expires can no longer be used, and an invitation that an Instructor revokes is disabled and marked revoked. In both cases the record, and in the revoked case the revoked status, are retained rather than erased.
- User records and enrolments created by direct roster entry or import persist until they are deleted or the course or section is removed, whether or not the Student ever signs in.
- Account, course, material, and Student content persist while the account and course remain active, and are removed through the deletion paths available in the Service or on request.
- Security, audit, and operational records are retained on their own schedules, in minimized form.
- Backups and recovery points expire on their own schedule. Deleting something from the active Service does not immediately remove it from backups. If a backup is restored, Athens may need to reapply completed deletions.
Athens has not yet finalized a published retention schedule with specific periods for each category. Section 11 below describes how to request deletion in the meantime. Athens will publish defined retention periods as the pilot matures.
10. Security
Athens applies administrative, technical, and organizational safeguards to protect personal information, described in the Athens Security Statement, which also states plainly which controls are implemented today and which are not yet in place. No online service can eliminate all risk, and Athens does not guarantee absolute security.
11. Your choices and requests
You may ask Athens to access, correct, export, or delete personal information
about you by contacting admin@athenslabs.ai. You do not need an Athens account
to make a request. A Student who never accepted an invitation, or who was added
to a roster without signing in, may ask Athens about the record and request its
deletion.
Athens does not yet provide a complete self-service export or account-deletion workflow. Requests are handled through the tools available in the Service together with manual processes operated by Athens. That means a request may take longer than it would with a mature product, and Athens will tell you what it can and cannot do for your request.
Athens may need to verify your identity before acting, and will not disclose one person's information to another. A request may be limited by applicable law, the rights of others, security needs, legal holds, backup expiry schedules, and the technical scope of the pilot. Where information is controlled by an Institution under an Institution Agreement, Athens may need to refer the request to that Institution.
Students may also ask their Instructor to remove them from a course.
Depending on where you live, you may have additional rights under applicable privacy law, such as rights to know, access, correct, delete, or appeal a decision. Athens will comply with applicable law and will evaluate a verified request under the law that applies to it. This notice does not attempt to list every law that might apply or to state that any particular statute governs a given pilot.
12. Students under 18, and school-led pilots
Athens may be used in secondary schools as well as in higher education, so some Students may be minors.
Athens is responsible for the obligations that apply to Athens. Athens does not treat a school, a district, or an Instructor as responsible for Athens' own compliance, and nothing in this notice shifts Athens' legal obligations onto them.
Secondary-school pilots require prior coordination. If a course is offered
through a K–12 school or district, the Instructor must contact Athens at
admin@athenslabs.ai and receive written confirmation before entering Student
information, importing a roster, sending invitations, or uploading course
Appropriate school or district authorization is required for every K–12
pilot. Athens may additionally require a school-appropriate pilot agreement
or data-protection addendum depending on applicable law, district policy, and
the pilot's data scope. Authorization must come from the school or
district rather than from an individual teacher. Such an agreement would cover
authorization, permitted use, subprocessors, security, retention and deletion,
incidents, and student and parent rights. Where a school authorizes Athens, that
authorization is limited to the school-authorized educational purpose it
describes.
Children under 13 may not use the Service, and their information should not be entered into it. Athens has not implemented a verified school or parental consent process, so under-13 participation is prohibited rather than conditionally permitted. Athens does not currently prevent an Instructor from entering a younger student's details through roster entry or import, which is why this is stated as a rule here and why Athens is working to enforce it in the product. If Athens learns it holds personal information about a child under 13, Athens will delete it and contact the Instructor and, where appropriate, the school.
An Instructor should still confirm their own school's or district's requirements before using any third-party tool. That is a statement about the Instructor's own duties, not a transfer of Athens' duties to them.
13. Changes to this notice
Athens may update this notice as the pilot, the Service, or the law changes. When a change is material, Athens will provide notice through the Service, by email, or by another reasonable channel. The date at the top shows when this notice was last updated.
14. Contact
Questions or requests concerning this notice may be sent to:
Athens AI Technologies Inc.
1007 N. Orange Street, 4th Floor, Suite 1382
Wilmington, DE 19801
Email: admin@athenslabs.ai

