Privacy Policy
Lamppost Solutions Inc.
Last updated: 27 August 2026
1. About this policy
This policy explains how Lamppost Solutions Inc. ("Lamppost", "we", "us") handles personal information in connection with the Lamppost platform at lamppost.io and app.lamppost.io (the "Service").
Lamppost Solutions Inc. is a Canadian company. You can reach us about this policy at info@lamppost.io.
2. Who the Service is for
Lamppost provides planning and productivity tools to educators, school administrators, and school authorities.
Accounts may only be created by individuals 18 years of age or older. We do not create accounts for students, market the Service to students, or knowingly collect personal information directly from students.
Educators may enter information relating to their students into the Service in the course of their planning work. Where that occurs, we process that information on behalf of and under the direction of the educator and their school authority.
3. Our role, and your school authority’s role
When you use Lamppost as an individual educator paying for your own account, we determine how your account information is handled, and this policy governs.
When Lamppost is provided through or on behalf of a school, school board, or school authority, that institution remains the custodian of any student information entered into the Service. We act as a service provider processing that information on the institution’s instructions. Requests for access to or correction of student information should be directed to the institution, which remains subject to the access and privacy legislation applicable in its jurisdiction.
4. Information we collect
Account information. When you create an account we collect your name, your email address, and the province or territory in which you teach. If you sign in using Google or Microsoft, we receive your sign-in profile from that provider — your email address, name, account identifier, and profile photo URL.
Teacher profile. Information you provide to personalize your planning, including the grades and subjects you teach, your teaching preferences, and any notes you add.
Content you create. Lesson plans, unit plans, assessments, meeting agendas, meeting notes, and other material you create or upload.
Lamppost is not designed to store student records, and we do not ask you for student-identifying information. We do not maintain student profiles, individual education plans, or assessment records as a feature of the Service. However, free-text fields such as meeting agendas and notes will contain whatever you type into them, and may therefore incidentally include information about students. We ask that you avoid entering student-identifying information into the Service, and use your school authority’s designated systems for that purpose.
Google Workspace information. If you connect your Google account, we access your Google Calendar, Google Contacts and Workspace directory, Gmail, and files you create or open through Lamppost in Google Drive. Section 13 sets out in detail what we access, how it is used, how it is protected, and how long it is kept. You can disconnect your Google account at any time in Lamppost, or revoke access at myaccount.google.com/permissions.
Payment information. We do not collect, process, or store payment card information. Payments are processed through Stripe’s hosted checkout, where card details are entered on Stripe’s own page and never reach our database, logs, or support tools. We store only Stripe reference identifiers. Stripe’s handling of your payment information is governed by Stripe’s own privacy policy.
Support communications. Messages you send us, and our replies.
We do not collect browsing history outside our Service, search history from other services, social media profile information, precise geolocation, biometric information, or advertising identifiers.
5. Artificial intelligence processing
Lamppost uses Google Vertex AI to generate planning materials. AI requests are processed in Google’s Montréal region, in Canada.
What is sent. When you generate a lesson, unit, or assessment, or use the in-app chat, we send the text you have entered, your chat history, the relevant curriculum outcomes, and your teacher profile — your name, the grades and subjects you teach, your teaching preferences, and your notes. When you generate a meeting recap, we send the agenda name, the meeting notes, the decisions recorded, and the names of attendees.
These are free-text fields, and they contain whatever you have entered. Lamppost does not send student records, and does not send individual education plan or English language learner designations. However, if you type a student’s name or details into a note or an agenda, that text is included in the request. We ask that you avoid entering student-identifying information into the Service.
How Google handles it. Content sent through Vertex AI is not used to train or improve Google’s models. Google may retain prompts and responses for a limited period for abuse detection and safety purposes only, stored in the same region selected for our project.
What we retain. We do not log the content of AI requests or responses. Our records contain only the model used, the processing region, the request status, and a user identifier. Content generated for you is stored in your own tenant database as part of your account.
Other providers. We do not send your information to any artificial intelligence provider other than Google.
We do not send Google user data — your Gmail messages, calendar events, contacts, or Drive files — to any artificial intelligence or machine-learning model.
6. How we use information
We use personal information to operate and provide the Service; to generate planning materials at your request; to process subscriptions and payments; to provide customer support; to maintain security and prevent misuse; to communicate with you about your account and material changes to the Service; and to comply with legal obligations.
We do not sell personal information. We do not use your content to advertise to you, and we do not disclose it to third parties for their own marketing purposes.
7. Service providers
We use the following service providers, which may process personal information on our behalf:
Provider Purpose
Amazon Web Services Hosting, database, file storage, cache, and logs
Google Cloud (Vertex AI) AI generation
Google Workspace APIs Calendar, Contacts, Gmail, and Drive, where you connect your account
Google and Microsoft Sign-in
Google (Gmail SMTP) Sending account and notification email
Stripe Payment processing
Cloudflare Automated bot protection on signup and checkout
Webflow Hosting our public website
We require service providers to protect personal information and to use it only for the purposes we specify. We do not use analytics, error-monitoring, or third-party support tooling.
8. Where information is stored
All customer data in the Lamppost application is hosted in Canada on Amazon Web Services, including the database, file storage, cache, logs, and backups. A redundant copy of file storage is held in a second Canadian region. AI processing takes place in Google’s Montréal region.
Some services that support the Service — sign-in, outbound email, bot protection, and our public website — are operated by providers that may process limited information outside Canada. This does not include the content you create in Lamppost, which remains in Canada.
9. Security
Our database and file storage are encrypted at rest, and all web and application traffic is encrypted in transit using TLS.
Access to production systems is limited to a small technical team. The database is not publicly reachable and can be accessed only through a secured bastion host using key-based authentication, with connections logged. Administrative and support actions within the application are recorded in an audit trail, and infrastructure access is logged through AWS CloudTrail, retained in Canada.
No system is completely secure. We cannot guarantee absolute security, but we take reasonable steps to protect information in our custody and will notify affected users and, where applicable, their school authority of a breach that creates a real risk of significant harm.
10. Retention
We retain account information for as long as your account is active.
If a school or district agreement ends, the workspace becomes read-only, the data is retained for 60 days, and is then deleted.
If you cancel an individual or school subscription, your account is downgraded to the free plan and your content is retained, so that it remains available to you if you return.
If you ask us to delete your account, we delete your data from our systems, retaining only a limited audit record. Deletion requests are handled by our team — contact info@lamppost.io.
Automated database backups are retained for 7 days and held in Canada. Where data has been deleted from our active systems, residual copies may persist in backups until they expire on that cycle.
11. Your choices
You can access and update your account information in your account settings, export your content at any time, disconnect your Google account, and cancel your subscription.
Export. You can export your content yourself from within the Service, as a spreadsheet workbook or as a compressed archive containing the workbook and your uploaded files.
Deletion. Account deletion is handled by our team on request. Contact info@lamppost.io.
To request access to or correction of your personal information, contact info@lamppost.io. Where the request concerns student information entered by an educator, please direct it to the relevant school authority, which is the custodian of that information.
12. Cookies
We use only essential session and security cookies: an authentication cookie set as HttpOnly and Secure, and standard session and cross-site request forgery protection cookies. We do not set tracking or advertising cookies, and we do not use analytics or tracking within the Service.
13. Google user data
What Google data we access
Google Calendar
We read the events on the calendars you connect and, when you schedule or edit a meeting in Lamppost, create, update, or delete events on your behalf, including creating Google Meet links.
Google Contacts and Google Workspace directory
We read your saved contacts and, where your organization’s administrator has enabled contact sharing, your organization’s directory, solely to suggest people when you add attendees to a meeting.
Gmail
When you connect your Google account to use our in-app Inbox, we read your email messages and settings, create and update drafts, manage message state such as read/unread and labels, and send email on your behalf, so that you can read, organize, compose, and send email from within Lamppost.
Google Drive
Where you choose to save a plan or assessment to Google Drive, we create and access that file. Our access is limited to files you create or open through Lamppost. We cannot see the rest of your Drive.
How we use it
We use Google user data only to provide features that are visible to you within Lamppost: displaying your calendar events in the in-app planner; creating and managing calendar events when you book or edit a meeting; suggesting attendees in the meeting attendee picker; letting you read, organize, compose, and send your email in our in-app Inbox; and saving plans and assessments to your Drive at your request. We do not use Google user data for advertising, and we do not use it to train, or transfer it to, any generalized or non-personalized artificial intelligence or machine-learning models.
Who we share it with
We do not sell your Google user data, and we do not share, transfer, or disclose it to third parties, except: to service providers and sub-processors that host and operate Lamppost on our behalf, under confidentiality and data-protection obligations, and only to deliver the features described above; to Google, as necessary to carry out the API requests you initiate; where required by law, or to protect the rights, property, or safety of our users or the public; or with your explicit consent. Your Google user data stays within your own account and school workspace and is not shared with other schools or made public.
How we protect it
Google user data is protected in transit with TLS. Your Gmail messages, calendar events, contacts, and Drive files are retrieved directly from Google and shown to you in the app. We do not store your email content, calendar, contacts, or Drive content on our servers.
We do not store your Google password, and we do not store Google refresh tokens. Access to your Google account uses a short-lived access token, valid for approximately one hour and re-issued by Google. The only account information we retain is your sign-in profile — email address, name, Google account identifier, and profile photo URL — held in our tenant-isolated environment with access restricted to authorized systems and personnel.
How long we keep it, and how it is deleted
We retain Google user data only while your Google connection is active and your account is open. You can disconnect at any time in Lamppost, or revoke access at myaccount.google.com/permissions. On disconnect, we stop accessing your account and delete the associated Google user data from our active systems. When your account is closed, or your school’s data is deleted, associated Google user data is deleted as part of that process, and backup copies are purged on our normal retention cycle.
Limited Use disclosure
Lamppost’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We only use Google user data, including Gmail data, to provide user-facing features that are prominent in the Lamppost user interface. We do not sell this data, do not use it for advertising, and do not use it to develop, improve, or train generalized or non-personalized AI or machine-learning models. We do not allow humans to read your Gmail data unless we have your explicit consent for specific messages, it is necessary for security purposes such as investigating abuse, it is required to comply with applicable law, or the data has been aggregated and anonymized.
14. Changes
We may update this policy. If we make a material change to how we handle personal information, we will notify account holders by email before the change takes effect. The date at the top reflects the most recent revision.
15. Contact
Questions about this policy: info@lamppost.io