Melaa™

Privacy Policy

Effective Date: September 29, 2026

1. Introduction

Melaa ("the Service") is operated by IncluSend LLC ("we," "us," or "our"). We are committed to protecting the privacy and security of all users, including educators, administrators, and the student data they manage through our platform. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information.

By using Melaa at melaa.app, you agree to the practices described in this policy. If you do not agree, please do not use the Service.

This policy is designed to comply with the Family Educational Rights and Privacy Act (FERPA), the Children's Online Privacy Protection Act (COPPA), and applicable state privacy laws, including the Colorado Student Data Transparency and Security Act (C.R.S. §§ 22-16-101 et seq.) and the Colorado Privacy Act (C.R.S. § 6-1-1301 et seq.).

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Full name
  • Email address
  • Organization/district name
  • User role within the organization (owner, admin, school admin, teacher, or read-only)
  • Authentication is handled through single sign-on (Google, Microsoft, or ClassLink), managed securely via Supabase Auth. We do not store passwords.

2.2 Student Data

Educators may enter the following student information into the Service:

  • First and last name
  • District student ID (external identifier)
  • Grade level
  • Native/home language
  • School assignment
  • WIDA ACCESS domain proficiency scores (Listening, Speaking, Reading, Writing)
  • Computed composite scores (Overall, Oral, Literacy, Comprehension)
  • English language learner status (derived from scores)
  • IEP and Section 504 support indicators (optional; off unless your district turns it on). An administrator may record whether a student has an IEP and/or a 504 plan and, where your district also enables notes, a short note about the supports that affect instruction. That note is written by your district's administrators and may identify a disability or diagnosis where your district considers it instructionally relevant, so we treat it as health-related information about a student. We do not collect the IEP or 504 plan document itself, evaluation reports, or eligibility determinations.
  • WIDA Alternate ACCESS results and scale scores (only if your district supplies them). Alternate ACCESS is administered to multilingual learners with significant cognitive disabilities as determined by the IEP team, so an Alternate ACCESS record indicates that a student receives special education services; we treat it as a special-education record regardless of whether support indicators are enabled. Scale scores are WIDA's growth measure and are stored alongside proficiency levels when a score file includes them.
  • Interim language assessment results (only if your district supplies them): in-year language measures your district already gives, such as WIDA MODEL, LAS Links, or writing and speaking samples scored on a named rubric, with the date, instrument, and scale as reported. These are stored beside the official ACCESS record and are never compared with ACCESS levels, never used to evaluate exit criteria or project growth, and never included in the context sent to the AI assistant.
  • Service delivery records: the English language development services a student receives, entered by staff either as a weekly total of minutes or as individual sessions. A session record holds the date, an optional start time, the minutes, the service model and setting, the grouping, the language domains addressed, the provider's name, whether the session was delivered or missed (and why), each student's attendance, and a short staff-written focus and note. These records are written by your district's staff, used to compare the services planned with the services delivered, and never included in the context sent to the AI assistant.
  • Differentiation records (part of the program service records): when an educator generates a material for a student or group with the AI assistant (a graphic organizer, worksheet, or assessment), Melaa may ask whether they used it. Only if the educator answers do we record which saved material was used with which students, whether it was used or only planned, the date it was used, the language domains and proficiency level it targets, the educator who recorded it, an optional short staff-written note, and, where the educator also logs a service session for it, a link to that session. A differentiation record documents differentiated instruction and is never counted as service minutes. These records are written by your district's staff; no AI is involved in creating them, and they are never included in the context sent to the AI assistant.
  • Student work samples (optional; off unless your district turns it on). Only your district's account owner can enable this, by accepting the Student Work Samples Addendum in Settings. When it is on, administrators (and teachers, for students on their roster, only if your district also allows it) may upload examples of a student's work as evidence for exit decisions and monitoring: a PDF, an image such as a photo of a worksheet, or a Word document (up to 15 MB each), with a title, the date of the work, the language domains it shows, the class or assignment, a description, and an optional note on what it shows. We also record the file name, type and size, who uploaded it, and when. Melaa does not read or analyze the contents of the file, which may include names written on it. Files are private: each view goes through an access check, is recorded in your audit log, and uses a link that expires after 60 seconds.

Student data may be entered manually, uploaded via CSV file (up to 5,000 records per upload), or imported automatically through roster sync integrations (see Section 2.6). We do not independently collect data from or about students. In demo mode, no student data is stored.

Files attached to AI chat. An educator may attach a file to an AI chat message (PDF, image, or Word document), either from their device or from their Google Drive. Melaa receives only the specific file the educator selects. Attached files are sent to our AI provider to answer that request and are not retained by Melaa afterward; content an educator chooses to save is stored in the Materials Library (see Section 8). Because an attachment is supplied by the educator rather than generated from your roster, Melaa cannot reliably detect or redact student names inside it - see Section 4.

2.3 Usage Data

We automatically collect:

  • AI message counts and token usage (input/output tokens, estimated cost) for billing and rate limiting
  • IP address (for demo usage tracking and security purposes)
  • Browser type and device information (via standard HTTP headers)

AI chat messages are not stored on our servers. Chat content is processed in real time and exists only within your active browser session. When you close or refresh the page, chat history is cleared.

2.4 Website Visitor Data

When you visit our marketing pages (before signing in), we collect:

  • An anonymous visitor identifier (UUID stored in your browser's localStorage as cdn_visitor_id)
  • Page paths visited and referrer URLs
  • UTM campaign parameters (source, medium, campaign) if present in the URL
  • Approximate geographic location (country, region, city) derived from Vercel edge network headers

This data is stored in our site_visits table and is used to understand how visitors find and interact with our marketing pages. It is not linked to student data or authenticated user accounts.

We also use Google Analytics to measure aggregate traffic on our public marketing pages and demo only. Google Analytics is not loaded inside the signed-in application - we do not run third-party analytics over the dashboard, admin, or any page that displays student data. Engagement inside the app is measured with our own first-party analytics. See Section 6 for Google's role as a subprocessor.

2.5 Cookies and Local Storage

  • Authentication cookies: Supabase session cookies are used to manage your login session. These are essential for the Service to function.
  • Demo cookie: Demo visitors receive a demo_id cookie (httpOnly, secure, sameSite=lax, 1-year expiry) to track their demo message allowance. This cookie contains only a random identifier.
  • Demo invitation cookie: Visitors who open an invitation link to the demo district receive a melaa_demo_invite cookie (httpOnly, secure, sameSite=lax, expiring with the invitation) that proves the invitation is valid. It contains only the invitation's identifier and expiry, signed by our server.
  • Visitor identifier: An anonymous UUID is stored in localStorage (cdn_visitor_id) for marketing analytics. This identifier contains no personal information.
  • Google Analytics cookies: Google Analytics sets first-party analytics cookies (e.g. _ga, _ga_*) to measure aggregate, non-advertising site and product usage. These are not used to build advertising profiles.

We use Google Analytics for aggregate usage measurement, as described above. We do not use advertising cookies or retargeting technologies, we do not run behavioral advertising, and we do not sell personal information.

Do Not Track: Some browsers offer a "Do Not Track" (DNT) signal. Because there is no widely accepted standard for how to interpret DNT signals, the Service does not currently respond to DNT browser signals. However, we do not engage in cross-site tracking, targeted advertising, or selling personal information regardless of DNT settings.

2.6 Roster Sync Data

If your organization connects a roster provider (Clever or ClassLink/OneRoster), we receive the following data through their APIs:

  • School names and identifiers
  • Student names, grade levels, and provider-assigned IDs
  • Teacher names, email addresses, and provider-assigned IDs
  • Section/course information (name, subject, grade, term)
  • Student-teacher enrollment relationships

OAuth tokens used to access roster provider APIs are encrypted at rest using AES-256-GCM encryption. Sync operations are logged in our roster_syncs table for auditing purposes.

2.7 Sensitive Information

Please do not submit sensitive personal information through the Service, including Social Security numbers, government-issued identification numbers, financial account numbers, biometric data, health or medical information, religious beliefs, or criminal background information. The Service is designed to process only the educational data categories listed above. If we become aware that sensitive information has been submitted, we will take steps to delete it.

2.8 Payment Information

Payment processing is handled entirely by Stripe, Inc. We do not store credit card numbers, bank account details, or other financial information on our servers. We receive only a Stripe customer identifier and subscription status.

3. How We Use Your Information

We use collected information to:

  • Provide and operate the Service, including generating WIDA CAN DO Descriptor profiles and AI-powered instructional recommendations
  • Authenticate users and manage account access via role-based permissions
  • Synchronize student roster data from connected providers (Clever, ClassLink)
  • Process payments and manage subscriptions via Stripe
  • Send transactional emails (invitations, trial reminders, notifications) via Resend
  • Enforce usage limits, student capacity limits, and prevent abuse
  • Maintain audit logs of data access events for FERPA compliance
  • Improve the Service through aggregated, de-identified analytics. When we create de-identified or aggregated data, we remove information that makes the data identifiable to any individual, and we do not attempt to re-identify such data. De-identified data derived from Student Data is never shared for advertising or unrelated commercial purposes.
  • Respond to support requests. When troubleshooting requires seeing what a specific user sees, an authorized IncluSend administrator may open a support session that renders that user's screens. Support sessions are read-only, expire automatically after 30 minutes, require a written reason, cannot export data or use AI features, and replace student names and student identifiers with temporary pseudonyms while hiding staff-written notes, plans, and letters. Each session is recorded in the institution's own audit log with the reason and the administrator's identity. Support sessions remain access to Student Data under our role as a school official, and are limited to what is necessary to resolve the issue.

We do not use Student Data to market or advertise to students, parents, or educators. Student Data is used exclusively to provide the Service as described herein.

4. AI Processing

When you use the AI Thought Partner feature, your messages and the associated student context (proficiency levels, grade, CAN DO Descriptors) are sent to Anthropic's Claude API to generate instructional recommendations. This data is transmitted securely via encrypted connections.

  • No training on your data: Anthropic does not use API inputs or outputs to train their AI models, per their API Terms of Service.
  • Zero Data Retention (ZDR): On the fully managed plan, AI requests run through IncluSend's Anthropic account, which is covered by a Zero Data Retention agreement with Anthropic: all data sent to and received from Anthropic's API has a zero-day retention period-data is not stored on Anthropic's servers beyond the duration of each API request. Chat content is processed in real time and is not persistently stored by Anthropic or by Melaa. Chat exists only in your browser session.
  • Bring Your Own Key (BYOK): If your district supplies its own Anthropic API key, AI requests run through your district's own Anthropic account under that account's terms, not IncluSend's Zero Data Retention agreement. Your district controls retention and any data-handling arrangements on its own Anthropic account. Melaa still redacts student names before sending context to the model, exactly as on the managed plan.
  • Student names are removed from student data and messages before they reach the AI. The application automatically replaces student names with anonymous identifiers (Student A, Student B, etc.) before sending student data to the AI. Additionally, our server enforces name redaction as a secondary safeguard-all student names from your organization's roster are matched and stripped from message text, and from the student context assembled on our server, before it reaches Anthropic. One exception applies to files an educator attaches. Word documents and PDFs with a text layer, whether attached to a chat message or uploaded to import a language plan, are converted to text on our server and pass through the same name redaction. An image, or a scanned PDF with no text layer, is transmitted to the AI as supplied, and we cannot detect or remove names inside it; the AI is instructed not to repeat any name it contains. Educators should not attach images or scanned documents containing student names unless they intend for that content to be processed.
  • Support indicators and AI. If your district enables both support indicators and their use in AI guidance, the indicator and any note are included in the context sent to Anthropic so that suggested strategies account for supports already in place. Names are removed first: the note passes through the same roster-wide redaction described above, and that redaction always runs, regardless of any warning an administrator acknowledged when saving the note. Because the note may identify a disability or diagnosis, that information does reach Anthropic when your district turns this on. Redaction removes names, not the clinical content, and the clinical content is the part that makes the suggestion useful. We never send the IEP or 504 plan document itself, because we do not collect it. A district that wants to record indicators without any disability-related information reaching the AI can record them and leave AI use switched off; whether teachers can see indicators and whether the AI uses them are separate settings.
  • Student work samples are never sent to AI. No work sample file, and none of the details staff type about it, is ever included in any request to Anthropic or any other AI model, whatever your district's settings. We enforce this in code with an automated check that fails if any part of Melaa that prepares AI requests uses the work samples feature. If a staff member downloads a work sample and attaches it to an AI chat message themselves, the attached-file rules above apply to that file.
  • No AI-driven profiling: Student data is not used to train, fine-tune, or improve any artificial intelligence or machine learning models, and is not used to create student profiles or make automated decisions about students.
  • No automated decision-making: The Service does not engage in automated decision-making or profiling that produces legal or similarly significant effects on students. All AI outputs are advisory and require educator review before implementation.
  • AI fairness: We recognize that AI-enabled features may perform differently across individuals and groups, and may produce unintended or disparate impacts. We take reasonable steps to evaluate and reduce the risk of unfair outcomes, including monitoring AI responses across diverse student populations and language backgrounds. If you observe biased or inappropriate AI outputs, please report them to info@melaa.app.

5. FERPA Compliance

5.1 School Official Status

We operate under the "school official" exception to FERPA (34 CFR § 99.31(a)(1)), providing services that would otherwise be performed by school employees. As such:

  • We use education records only for the purposes specified in our service agreement
  • We are under the direct control of the educational institution with respect to use and maintenance of education records
  • We do not re-disclose personally identifiable information (PII) from education records without consent, except as permitted under FERPA

5.2 Data Processing Agreement

We offer a Data Processing Agreement (DPA) to all subscribing schools and districts, compatible with the Student Data Privacy Consortium (SDPC) National Data Privacy Agreement framework, including Colorado-specific supplemental terms (Exhibit "G"). Our DPA includes:

  • Specific description of data elements collected and processed (Exhibit B categories)
  • Purpose limitations for data use
  • Security safeguards and technical measures
  • Data breach notification procedures (within 72 hours, per C.R.S. § 6-1-713)
  • Data return and deletion procedures upon contract termination (60-day transfer window, 90-day destruction)
  • Subprocessor disclosure and management
  • Prohibition on using Student Data for AI model training

To request a DPA or our General Offer of Privacy Terms, contact us at info@melaa.app.

5.3 Audit Logging

We maintain comprehensive audit logs of access to student education records and security-relevant events. Our audit trail includes:

  • User identity and timestamp for student record views (opening a student's profile), changes, and exports
  • Type of action performed (view, create, update, delete, export, import)
  • IP address and browser/device information of the request
  • Record of bulk operations (CSV imports, roster syncs, bulk assignments) and every CSV or document export
  • Authentication events: sign-ins, sign-outs (including automatic sign-out after inactivity), and sign-in attempts Melaa refuses, such as a deactivated account
  • Administrative actions (role changes, account deletion, invitation management)

Audit logs are retained for 7 years in compliance with FERPA record-keeping requirements while the organization's account exists. When an organization's account is deleted, a deletion record that includes a copy of its audit trail is kept for 7 years from the date of deletion (see Section 8). Organization administrators can view audit logs through the admin dashboard. Logs are available for inspection by the educational institution upon request.

5.4 Parent and Eligible Student Rights

We support educational institutions in fulfilling their FERPA obligations regarding parent and eligible student rights:

  • Right to Inspect: Parents and eligible students may request access to education records through their school or district
  • Right to Request Amendment: Corrections to student data should be submitted through the educational institution
  • Right to Consent: We do not disclose PII from education records without prior written consent from the parent or eligible student, except as permitted under FERPA

5.5 Data Isolation and Access Control

  • Each organization's student data is logically separated. Every request is scoped to the signed-in user's organization (and, for school-level roles, their assigned schools) by the application before any data is read or written, and database row-level security (RLS), enabled on every table, provides a second layer of defense
  • Users can only access data belonging to their organization
  • Role-based access control limits data visibility:
    • Owner/Admin: Full access to all organizational data and settings
    • School Admin: Access limited to students in their assigned schools (students not yet assigned to a school are visible to district administrators only)
    • Teacher: Access limited to assigned students within assigned schools
    • Read-Only: View-only access across the organization, with no ability to change data
  • Teachers may be assigned specific students, restricting their view to only those students

6. Data Sharing and Third-Party Services

We share information only with the following service providers, solely as needed to operate the Service:

  • Supabase (Supabase Inc.) - Authentication and database hosting. All student data is stored on AWS infrastructure in the us-east-1 (Virginia) region. Data encrypted at rest (AES-256) and in transit (TLS 1.2+).
  • Anthropic (Anthropic PBC) - AI language model API for generating instructional recommendations. Processes only redacted prompts under a Zero Data Retention (ZDR) agreement-no data is stored on Anthropic's servers beyond the duration of each request. Located in the United States.
  • Vercel (Vercel Inc.) - Application hosting and serverless functions. Processes requests in transit only; no Student Data is persisted. Located in the United States.
  • Stripe (Stripe Inc.) - Payment processing. Handles only organizational billing data; no Student Data is shared with Stripe. PCI DSS Level 1 certified.
  • Resend (Plus Five Five Inc.) - Transactional email delivery for invitations, trial reminders, and notifications. Receives only organization admin/teacher email addresses; no Student Data is included in emails.
  • Google (Google LLC) - OAuth authentication when users choose to sign in with Google (we receive only name and email; no Student Data); Google Drive access to the individual files an educator selects in the Google file picker, where Melaa requests only the drive.file scope, which grants access to the chosen files and nothing else in the educator's Drive (this is an inbound integration: the file is retrieved by the educator's browser and no Student Data is sent to Google); and Google Analytics for aggregate usage measurement on our public marketing pages and demo only (not inside the signed-in application). Google Analytics receives page-view and interaction events from those public pages; it does not receive Student Data or WIDA scores.
  • Microsoft (Microsoft Corporation) - OAuth authentication when users choose to sign in with Microsoft. We receive only name and email; no Student Data is shared.
  • Cloudflare (Cloudflare, Inc.) - DNS, content delivery, and network security for our domains. Processes requests in transit only; no Student Data is persisted. Located in the United States.

Google API Services Limited Use. Melaa's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google Drive access is used solely to retrieve the files an educator explicitly selects, and only to fulfill that educator's request. We do not use this data for advertising, we do not sell it, and we do not allow humans to read it except as required for security or to comply with applicable law, or with the user's explicit consent.

If your organization uses roster sync, the following providers may also process data:

  • Clever (Clever Inc.) - Roster data synchronization. Student and teacher data flows from Clever to Melaa based on your district's Clever configuration.
  • ClassLink (ClassLink Inc.) - OneRoster-compatible roster data synchronization. Data flows from ClassLink to Melaa based on your district's configuration.

Data Storage Location: All student data is stored within the United States. Our primary database is hosted on AWS infrastructure in the us-east-1 (Virginia) region via Supabase. Application hosting is provided by Vercel on US-based infrastructure. AI processing occurs on Anthropic's US-based infrastructure under a Zero Data Retention agreement (zero-day retention). A complete list of subprocessors and their DPAs is available at info@melaa.app upon request.

We do not sell, rent, or trade personal information or student data to any third party. We do not use Student Data for advertising, marketing, or any purpose other than providing the Service. We may disclose information if required by law, regulation, or valid legal process.

7. Data Security

We implement the following security measures to protect your data:

  • All data transmitted between your browser and our servers is encrypted using TLS (HTTPS)
  • Data at rest is encrypted in our database (AES-256)
  • Roster sync OAuth tokens are encrypted using AES-256-GCM before storage
  • Organizational data isolation is enforced by the application on every request (each query is scoped to the caller's organization and role), with database row-level security (RLS) enabled on every table as defense in depth
  • Authentication is managed through industry-standard protocols (OAuth 2.0, secure session management)
  • Security headers enforced on all pages: HSTS, X-Frame-Options (DENY), X-Content-Type-Options, strict Referrer-Policy, and Permissions-Policy restricting camera, microphone, and geolocation access
  • Administrative access to production systems is restricted and logged
  • Server-side PII redaction provides defense-in-depth protection before data reaches third-party AI services

We maintain a written Incident Response Plan that defines procedures for detecting, containing, and remediating security incidents. In the event of a data breach involving Student Data, we will notify affected educational institutions within 72 hours, as required by C.R.S. § 6-1-713 and our DPA obligations.

While we take extensive precautions, no method of electronic transmission or storage is 100% secure. If you become aware of a security vulnerability, please contact us immediately at info@melaa.app.

8. Data Retention

  • Account data is retained for as long as your account is active.
  • Student data is retained for as long as the subscribing organization maintains an active account. Organizations may export their student data (CSV or JSON format) and request deletion of student records at any time.
  • AI chat messages are not stored on our servers. Chat history exists only within your active browser session and is cleared when you close or refresh the page.
  • Saved instructional materials (graphic organizers, worksheets, and assessments generated by the AI) are saved to the creating educator's library so they can be reused, exported, or shared with the student's other authorized teachers. These materials store the differentiated content only, not student names. They are retained until the educator deletes them or the organization's account closes; materials that are never opened, shared, edited, or recorded as used with a student are automatically purged after 12 months.
  • Usage logs (AI message counts, token usage, estimated costs) are retained for billing and analytics purposes and are automatically purged after 12 months.
  • Demo usage data (cookie identifier, message count, IP address) is automatically purged after 12 months.
  • Canceled accounts are retained for 90 days to allow reactivation, after which all associated data (users, students, schools, sections, enrollments, saved materials, usage logs, and the live audit log) is permanently and automatically deleted, except the deletion record described next.
  • Audit logs are retained for 7 years in compliance with FERPA record-keeping requirements while the organization's account exists. When an organization is deleted (by the 90-day canceled-account rule or at the organization's request), we keep a deletion record (which organization was deleted, when, and why, together with a copy of its audit trail) for 7 years from the date of deletion, so that access to student records remains accountable after the account is gone. The deletion record contains no student scores, plans, notes, or other education-record content beyond what the audit trail itself records.
  • Site visit data (anonymous visitor analytics) is retained for 12 months.
  • Event raffle entries (name, role, district, and email collected when you enter a giveaway at a conference booth) are used to administer the drawing and, unless you opt out, for occasional Melaa updates; the raffle entry record itself is automatically deleted within 90 days of the drawing, while your business contact details (name, role, district, and work email) may be retained in our customer-relationship records so we can follow up with your school or district.
  • Price quote requests (organization, name, title, state, and work email entered when you download a quote from our pricing page) are kept so we can honor and reference the quote, and the quote record is automatically deleted after 24 months; your business contact details (name, title, organization, and work email) may be retained in our customer-relationship records so we can follow up with your school or district.
  • Demo invitations (the name and work email of the person we invite to the demo district, and when the link was used) are automatically deleted 12 months after the invitation expires; your business contact details may be retained in our customer-relationship records so we can follow up with your school or district.
  • Roster sync logs are retained for the duration of the organization's active account and deleted upon account termination.
  • Support indicators (IEP and 504 status and any note) are retained while the subscribing organization maintains an active account. Unlike score data they carry forward between school years rather than expiring annually, so that supports remain visible to the following year's teachers. They are deleted when the student record is deleted, on request from the district, and under the 90-day canceled-account rule above.
  • Family letters and their delivery records (the letter text, who reviewed it and any translation reviewer, and the date and method it was sent and returned or acknowledged, whether written one at a time or in a batch) are part of the student's compliance record: retained while the subscribing organization maintains an active account and deleted with the student record or under the 90-day canceled-account rule above. Melaa does not send letters or store family contact details; staff send them from their own accounts or print them. Batch records hold no student data, and a batch that never produced a letter is automatically deleted after 30 days.
  • Monitoring check-ins (for students who have exited English language services: the check-in date, what teachers report, a grades summary, whether there is a concern, the action taken, and the reviewer's name) are retained while the subscribing organization maintains an active account and are automatically deleted six years after the check-in date, which covers the state monitoring period and the four-year federal post-exit reporting period. They are also deleted with the student record and under the 90-day canceled-account rule above.
  • Service delivery records (weekly totals and individual service sessions with attendance) are part of the student's program record: retained while the subscribing organization maintains an active account and deleted with the student record, on request from the district, or under the 90-day canceled-account rule above.
  • Differentiation records (which saved material an educator used with which students, and when) are part of the student's program record: retained while the subscribing organization maintains an active account and deleted with the student record, on request from the district, or under the 90-day canceled-account rule above. A record the educator marked as planned but never confirmed leaves their list after 7 days and is automatically deleted 30 days after that. If the material itself is later deleted, the record keeps the material's title and date only.
  • Student work samples (only where your district has turned them on) are kept for the retention period your district chooses in Settings, from 1 to 5 years (2 years unless changed), counted from the day each was uploaded, and are then automatically deleted, file and details. They are also deleted when staff with permission delete them, when the student record is deleted (the file within 24 hours), when the account owner uses "Delete all work samples now", and under the 90-day canceled-account rule above. Turning the feature off hides every sample immediately; stored files are then kept only until their retention date unless the owner deletes them sooner.

Upon contract termination, educational institutions have 60 days to request transfer of their data in a machine-readable format (CSV or JSON). After 90 days, all data is permanently destroyed, apart from the deletion record and audit-trail copy described above, and we will provide written confirmation of destruction upon request.

9. Your Rights

You have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate information in your account
  • Delete your account and all associated data (organization owners can do this from account settings)
  • Export your data in a portable format (CSV or JSON) via the admin dashboard
  • Withdraw consent for optional data processing
  • Disconnect roster sync integrations at any time
  • Opt out of marketing emails by clicking the "unsubscribe" link included in any marketing or trial reminder email, or by contacting us directly

To exercise any of these rights, contact us at info@melaa.app.

Colorado residents may have additional rights under the Colorado Privacy Act (C.R.S. § 6-1-1301 et seq.), including the right to opt out of the processing of personal data for targeted advertising and the right to appeal a denial of a privacy request.

10. Children's Privacy

Melaa is designed for use by educators and administrators, not by students. Students do not create accounts, log into the Service, or interact with it directly. We do not knowingly collect personal information directly from children under the age of 13.

Student data is entered into the Service by authorized educators solely for the purpose of instructional planning. We comply with COPPA by ensuring that the educational institution has obtained any necessary parental consent for the disclosure of student education records to us as a school official under FERPA.

If you believe we have inadvertently collected information directly from a child, please contact us immediately at info@melaa.app.

11. Accessibility

We are committed to making Melaa accessible to all users, including those with disabilities. We target conformance with the Web Content Accessibility Guidelines (WCAG) 2.2 at Level AA, consistent with Colorado HB 21-1110 and ADA requirements. Our Accessibility Statement and Voluntary Product Accessibility Template (VPAT v2.5) are available upon request.

12. Business Transfers

In the event that IncluSend LLC is involved in a merger, acquisition, reorganization, bankruptcy, or sale of assets, your personal information and Student Data may be transferred as part of that transaction. In such an event:

  • We will notify affected users and subscribing organizations within 30 days via email and/or a prominent notice on the Service
  • This Privacy Policy will continue to apply to your data unless and until you are notified of a new policy and given the opportunity to opt out
  • The acquiring entity will be bound by the same data protection obligations described in this policy and any active Data Processing Agreements
  • We will not sell Student Data to any third party as part of a business transaction

In the unlikely event that IncluSend LLC ceases operations, we will protect your personal information and Student Data, provide reasonable notice and opportunity to export data, and securely delete all data in accordance with our retention policies and any active DPA obligations.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will provide at least fifteen (15) days' advance notice to subscribing organizations before making material changes to this policy. Notification will be sent via email to organization administrators. Continued use of the Service after changes take effect constitutes acceptance of the revised policy. The "Effective Date" at the top of this page indicates when the policy was last updated.

14. Contact Us

If you have questions or concerns about this Privacy Policy, our data practices, or to request a Data Processing Agreement, please contact us:

IncluSend LLC

453 E Wonderview Ave, Unit 3, PMB #263

Estes Park, CO 80517-8926

Email: info@melaa.app

Website: melaa.app