Privacy Policy
Effective 3 August 2026
This Privacy Policy describes how Basecamp Learning Center (“we”, “us” or “our”) collects, uses, discloses and retains personal information in connection with na8ve, the teaching studio made available at na8ve.ai (the “Service”).
It forms part of, and is incorporated into, our Terms of Service. Capitalised terms not defined here have the meanings given in those Terms.
1. Scope and definitions
1.1This Policy applies to the Service and to our public web pages. It does not apply to any other service operated by us, each of which publishes its own terms.
1.2“Account Holder” means the adult who subscribes to the Service and teaches through it. “Student” means the learner whom an Account Holder invites into a studio. “School” means a school, school district, charter school, county office of education, or an educational facilitator acting for one. “Student Information” means personal information relating to a Student.
1.3The Service is software licensed to educators. It does not enrol Students, does not confer academic credit, and does not supervise Students. Nothing in this Policy constitutes an offer of a place at any school.
2. Roles of the parties
2.1Where an Account Holder subscribes in an individual capacity, that Account Holder determines the purposes for which Student Information is processed within the studio, and we process it on their behalf and on their instructions.
2.2Where a School procures the Service for a family, or funds a subscription, and the studio is established under that arrangement, the School remains responsible for its education records. In that case we act as the School’s service provider and process Student Information solely under the School’s direction.
2.3Where a School designates us a school official with a legitimate educational interest for the purposes of the Family Educational Rights and Privacy Act, 20 U.S.C. 1232g, we shall: use education records only to perform the services for which we were engaged; remain under the School’s direct control with respect to those records; not redisclose them except as the School directs or as law requires; and return or destroy them upon the School’s written instruction.
2.4Payment or funding by a School does not constitute endorsement, approval or adoption of the Service by that School, and no statement in this Policy may be construed as a representation that any School has approved us as a vendor.
3. Categories of information collected
3.1Account information: name, email address, and a password retained only in salted and hashed form. Where an Account Holder authenticates through Google, we receive that person’s name, email address and profile image from Google, and no Google credential.
3.2Instructional content: courses, modules, lesson pages, syllabi, lesson plans, student guides, assessment rubrics, and documents uploaded or imported by the Account Holder.
3.3Student work: submitted files, responses entered into lesson pages, written reflections, instructor feedback, marks, attendance confirmations, and completion credentials.
3.4Interactions with the artificial-intelligence features, comprising messages submitted to the tutor and assistants and the responses returned.
3.5Operational and billing records: authentication events, the number of model tokens consumed by a request, subscription status, and invoices. Payment card data is collected and processed by our payment processor and is not transmitted to or retained by us.
3.6We do not collect a Student’s date of birth, residential address, telephone number, government-issued identifier or biometric information, and the Service provides no field in which to enter them. We do not employ advertising cookies and do not track users across third-party websites.
4. Students and minors
4.1A Student account is created only upon invitation by an Account Holder. The Service provides no means by which a Student may self-register.
4.2Where the Children’s Online Privacy Protection Act, 15 U.S.C. 6501 et seq., applies to a Student under the age of thirteen, the verifiable parental consent on which we rely is that of the parent or guardian who establishes the studio and issues the invitation, or that of a School acting on the parent’s behalf to the extent permitted by law. A parent may inspect the information held about their child, require its deletion, and refuse its further collection by closing the studio.
4.3Consistent with the Student Online Personal Information Protection Act, California Business and Professions Code section 22584, and comparable legislation in other states, we do not sell Student Information; we do not use it to serve targeted advertising; we do not amass a profile of a Student except in furtherance of the instruction the Account Holder is conducting; and we do not disclose it save as provided in Section 7.
4.4A completion credential may be verified at a public address. That page discloses the course, the achievement recorded, and an opaque identifier. It does not disclose the Student’s name, email address or work, and the identifier is not derived from any attribute of the Student.
4.5Instructions transmitted to image-generation providers describe subject matter only. Student names and personal details are excluded by design.
5. Artificial-intelligence processing
5.1The Service transmits instructional material and interaction text to third-party model providers in order to draft lessons, tutor Students, propose feedback and marks, and generate illustrations.
5.2We do not train models on Account Holder or Student content, and we contract with providers whose terms prohibit the use of material submitted through their interfaces for model training.
5.3Our metering records the quantity of tokens consumed by a request. It does not record the text of any prompt or response.
5.4Marks proposed by a model are stored where only the Account Holder may see them and take effect only when that person saves them. Model output may be inaccurate or unsuitable, and the Account Holder is responsible for reviewing it before it reaches a Student.
5.5We identify the categories of provider on which we rely rather than particular vendors, which change. A current list of subprocessors is available on written request to the address in Section 12.
6. Information obtained through Google APIs
6.1Where an Account Holder authenticates through Google, we obtain basic profile information for the sole purpose of identifying the account.
6.2Where an Account Holder connects Google Drive in order to import a document, we request the drive.file scope, which confers access only to files that person selects through Google’s own picker. We are unable to enumerate, inspect or retrieve any other file. The authorisation is separate from authentication and may be withdrawn at any time, from a Google account or from within the Service, without affecting the ability to sign in.
6.3na8ve’s use and transfer of information received from Google APIs to any other application adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we use such information only to provide or improve the user-facing features for which it was obtained; we do not transfer it except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition following notice; we do not use it for advertising; and we do not permit human review of it except with the affected person’s express consent, to resolve a support request initiated by that person, for security purposes, or where required by law.
7. Disclosure to third parties
7.1We engage service providers, each bound by contract to process information only to supply their service to us, in the following categories: cloud hosting, database and file storage; model providers as described in Section 5; payment processing; and transactional email.
7.2We do not sell personal information and do not share it for cross-context behavioural advertising, as those terms are defined in the California Consumer Privacy Act.
7.3We may disclose information where compelled by law or where necessary to protect the rights or safety of any person, and shall notify the Account Holder unless prohibited from doing so.
7.4Should the business be transferred, information may transfer with it, subject to this Policy until amended on notice.
8. Storage, segregation and retention
8.1Information is stored on servers located in the United States.
8.2Each studio’s records carry an account identifier by which every query is filtered, such that one studio cannot retrieve the records of another.
8.3A trial subscription runs for fourteen days. Upon expiry the studio ceases to function; its records are retained for a further thirty days so that a subsequent subscription does not forfeit them, and are thereafter permanently deleted.
8.4Items deleted within the Service are held in a recycling facility for seven days before permanent destruction. Deletion of a course is reversible during that period, a course carrying with it a Student’s submissions and marks.
8.5Invoices and payment records are retained for the period required by applicable tax and accounting law, notwithstanding deletion of the balance of the account.
9. Rights of the individual
9.1An Account Holder may inspect and amend account details, export or delete instructional content, and close a studio from within the Service. Closure deletes the courses, Student work and files it contains.
9.2Subject to jurisdiction, an individual may have the right to know what personal information is held, to obtain a copy, to require its correction or deletion, and not to suffer discrimination for exercising those rights. Residents of California hold such rights under the California Consumer Privacy Act; residents elsewhere may hold equivalent rights.
9.3A request concerning Student Information should be directed in the first instance to the Account Holder responsible for the studio, who is able to act immediately, and whom we would in any event consult before acting. Where a School established the studio, we act on that School’s instruction.
9.4A request may be made to privacy@na8ve.ai. We shall verify that a request originates from the Account Holder before giving effect to it, and shall respond within the period prescribed by applicable law.
10. Security
10.1Passwords are stored in salted and hashed form and are not recoverable in plain text. Traffic is encrypted in transit. Access to production systems is restricted to personnel who operate the Service. Model-generated pages are rendered within a restricted frame that cannot reach an account or browser storage.
10.2No system is immune from compromise and we make no representation to the contrary. In the event of a breach affecting personal information, we shall notify the affected Account Holder and, where required, the competent authority, without undue delay.
11. Amendment
11.1We may amend this Policy. Where an amendment materially affects the handling of personal information, we shall notify Account Holders by email before it takes effect and shall revise the date appearing at the head of this document.
12. Contact
12.1Enquiries, requests and complaints concerning this Policy should be addressed to privacy@na8ve.ai.