Effective July 17, 2026
These Terms of Service and this Privacy Policy (together, the “Terms”) form an agreement between you — the school, district, organization, or individual using the services (“you” or “Customer”) — and K12Smart, a service of the Learning Technology Center (LTC) of Illinois (“K12Smart,” “we,” “us,” or “our”). By creating an account, accessing, or using K12Smart Chat, K12Smart Phish, or any related website or service (the “Services”), you agree to these Terms.
K12Smart is a suite of tools built for K-12 schools and districts by the Learning Technology Center. It includes K12Smart Chat (AI assistants that answer questions on your website or by email) and K12Smart Phish (phishing simulation and security-awareness training). We may update, add, or discontinue features over time.
Access to the Services generally requires an account. You may sign in through single sign-on (for example, the Learning Technology Center’s identity portal or Google Workspace), a magic-link invitation, or credentials issued to you. You are responsible for maintaining the confidentiality of your account and API keys, for activity under your account, and for ensuring the people you invite are authorized. Sessions remain active for up to 30 days unless you sign out.
You agree to use the Services only for lawful, educational, and administrative purposes, and not to:
K12Smart Chat and certain other features use artificial intelligence. AI can make mistakes. Responses are generated from the content you provide (such as your documents and website) and may be incomplete or inaccurate — please verify important information from an authoritative source. The Services do not provide legal, medical, financial, or other professional advice, and AI output should not be relied on as such.
You retain ownership of the documents, knowledge sources, messages, and other materials you or your users provide (“Customer Content”). You grant K12Smart the limited rights needed to host, process, and display Customer Content in order to operate and improve the Services for you (for example, indexing your documents so an assistant can answer from them). You are responsible for having the rights to the content you upload and for the accuracy of information your assistants draw upon.
When you use K12Smart Phish, you authorize us to send realistic but safe, simulated phishing messages to the staff and users you designate within your own organization, and to record engagement with those simulations (see the Privacy Policy). Simulations are designed for training: the decoy sign-in pages used in simulations do not read, store, or transmit any credentials or information typed into them — they record only that a button was pressed. You are responsible for using this feature appropriately within your organization.
The Services are provided on an “as is” and “as available” basis, without warranties of any kind, to the fullest extent permitted by law. To the fullest extent permitted by law, K12Smart and the Learning Technology Center will not be liable for indirect, incidental, special, consequential, or punitive damages, or for loss of data, revenue, or goodwill, arising from your use of the Services.
We may update these Terms from time to time; material changes will be reflected by the “Effective” date above, and continued use of the Services means you accept the updated Terms. Either party may stop using or providing the Services in accordance with any applicable order or agreement. These Terms are governed by the laws of the State of Illinois, without regard to its conflict-of-laws rules.
This Privacy Policy explains what information the Services collect, how we use it, and the choices you have. It applies to the K12Smart Services and this website.
AI responses are generated using Amazon Bedrock, running within our cloud environment in the United States. Your content is processed only to operate the Services for you — for example, to answer a question from your documents. Your content is not sold, and it is not used to train publicly available or third-party AI models. Embeddings of your knowledge sources are stored in a vector database in a collection dedicated to your organization.
Each organization’s data is scoped to that organization. One district’s content, conversations, and knowledge base are not shared with, shown to, or used to answer another district. Knowledge used by your assistants is stored in a per-organization collection, and access throughout the Services is scoped to your account.
We do not sell your personal information. We share information only: (a) with the service providers and subprocessors listed below, who process data on our behalf to run the Services; (b) with integrations you choose to enable (such as your Google Workspace); (c) when required by law or to protect rights and safety; and (d) as part of your own organization’s use of the Services.
The Services use essential session cookies to keep you signed in. Phishing simulations use tracking pixels and links to record opens and clicks for the recipients you designate, as described above. This marketing website may embed the live K12Smart Chat assistant and load fonts and scripts needed to display the site.
We retain information for as long as your account is active and as needed to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements. Some data is purged automatically — for example, the bodies of reported phishing emails are purged after review, and certain inbound processing addresses expire. You may request deletion of your data as described below; we will honor deletion requests subject to our legal and operational obligations.
We use reasonable technical and organizational measures to protect data, including encryption of stored credentials and integration secrets, hashed (never plaintext) API keys, tenant scoping so organizations are isolated, AI-assisted content moderation, and audit logging of key actions. No system is perfectly secure, but we work to protect your information.
The Services are provided to schools and districts for educational and administrative purposes. To the extent the Services process education records on your behalf, we act as a service provider (“school official”) under applicable law and use that data only to provide the Services to you — not for advertising and not to build profiles unrelated to the Services. Your organization remains responsible for its own obligations under FERPA and applicable state student-privacy laws.
You may access, correct, or request deletion of your information, or ask questions about this policy, by contacting us at the address below. If your organization administers your account, some requests may be directed through your organization.
The Services are intended for use by school staff and administrators, not for direct use by children to create accounts. We do not knowingly collect personal information directly from children under 13 through account registration.
Some parts of the Services connect to Google APIs when you or your administrator choose to enable them. Our access to, and use of, information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We request only the access needed for the feature you turn on:
openid, email, profile) — to authenticate you and identify your account.admin.directory.user.readonly, admin.directory.group.readonly, admin.directory.orgunit.readonly) — when a Workspace administrator connects your directory, to import the users, groups, and org units you choose to sync so you can build phishing-simulation audiences. We do not modify your directory.https://mail.google.com/), granted by a Workspace administrator through domain-wide delegation and used only for K12Smart Phish — to (a) locate and read a specific message a user reports as suspicious so it can be analyzed, and (b) when your administrator confirms a message is malicious, remove that message from recipients’ mailboxes (a “recall” to Trash or permanent deletion) that you initiate. We access mailbox content only for those reported or confirmed messages and the recall actions you request.apps.alerts) — to read the alerts that record when your users press Gmail’s native “Report phishing/spam” button, for your simulation reports.gmail.addons.current.message.readonly, gmail.addons.execute) — if you install this optional add-on, it reads only the single message a user has open at the moment they click Report, in order to submit that message for analysis.calendar.readonly) — if a user connects their calendar in K12Smart Chat, to read it so the assistant can answer that user’s scheduling questions.Consistent with the Limited Use requirements, we do not:
We store integration credentials and OAuth tokens in encrypted form, scope all Google data to the organization that connected it, and retain and delete it as described in §2.7. You may disconnect a Google integration at any time through the Services or by contacting us, which revokes our ongoing access.
We use the following third parties to help operate the Services. They process data only as needed to provide their function.
| Provider | Purpose |
|---|---|
| Amazon Web Services — Bedrock | AI response and embedding generation (in-region, within our cloud) |
| Amazon Web Services — SES, S3 | Sending & receiving email; file and document storage |
| Qdrant Cloud | Vector database for per-organization knowledge embeddings |
| Google Workspace | Single sign-on, and (for phishing) authorized mailbox access you enable |
| Stripe | Billing and payment processing, where applicable |
| Amazon Translate / Google Cloud Translation | Optional multilingual translation for chat |
| Twilio (optional, your account) | SMS/voice, when you enable it with your own credentials |
| Porkbun | Sending-domain (DNS) management for phishing simulations |
We may update this list as the Services evolve. Optional integrations run only if your organization enables them.
Questions about these Terms, this Privacy Policy, or your data? Contact K12Smart, a service of the Learning Technology Center, at hello@k12smart.com.