1. Introduction
HAM Insight Solutions, LLC ("Company," "we," "us," or "our") operates InlightiReads™, an AI-powered literacy platform ("Platform") that generates personalized stories for children at public libraries and schools. This Privacy Policy explains how we collect, use, disclose, and protect information when you use InlightiReads™.
By using the Platform, you agree to the practices described in this Policy. If you do not agree, please do not use the Platform.
2. Who We Serve
InlightiReads™ serves two types of users:
- Library Users: Library patrons (including parents and children) who access the Platform using a library card barcode.
- School Users: Students who access the Platform using a teacher-issued class code, and educators and school administrators who manage class codes and review reading analytics.
The Platform is designed for children in grades 1–8. We take the privacy of minors seriously and have designed the Platform to collect the minimum information necessary to operate.
3. Information We Collect
3.1 Library Patron Sessions
When a library patron generates a story, we collect:
- A one-way cryptographic hash of the library card barcode (not the barcode itself — the original number cannot be recovered from the hash)
- Grade level and reading level selected by the patron
- Reading setting preference (e.g., bedtime, independent)
- Topic interests selected or typed by the patron
- Whether the patron's name was included in the story (yes or no), but not the name itself unless explicitly provided
- Quiz results (score only)
- Timestamp of the session
We do not store library card numbers, patron names, email addresses, or any other personally identifiable information for library sessions.
3.2 School Sessions
When a student accesses the Platform via a class code, we collect:
- First name and last initial ("nickname") provided by the student
- A hash of the class code and nickname used to link sessions across visits
- Grade level and reading level
- Topic interests
- Quiz scores and session timestamps
The student's nickname is visible to their teacher in the class roster and session history. No email addresses, full names, or contact information are collected from students.
3.3 Educator and Administrator Accounts
Teachers and school administrators create accounts with their full name, work email address, and an encrypted password (bcrypt hash — the plaintext password is never stored).
3.4 Automatically Collected Information
We automatically collect IP addresses (for rate limiting and abuse prevention), HTTP request metadata (for error logging), and session timestamps. We do not use cookies for tracking.
4. How We Use Information
We use collected information to:
- Generate personalized, age-appropriate stories using the Anthropic AI API
- Enforce rate limits to ensure fair access across all patrons
- Provide teachers and administrators with anonymous class-level reading analytics
- Detect and prevent abuse, fraud, and inappropriate content generation
- Improve the quality and safety of story generation
- Send system emails (welcome links, password resets) to educator accounts
We do not use patron or student data for advertising, marketing profiling, or any purpose other than operating the Platform.
5. How We Share Information
We do not sell patron or student data. We may share information with the following service providers:
- Anthropic, Inc. — AI story generation. Story prompts include grade level, topics, and optional first name. No contact information is sent. Governed by Anthropic's API usage policies.
- SendGrid (Twilio) — Email delivery for educator account management. Only educator email addresses are transmitted.
- GoDaddy — Web hosting and server infrastructure.
We may also disclose information if required by law, court order, or to protect the rights, property, or safety of HAM Insight Solutions, LLC, its users, or the public.
6. Children's Privacy
InlightiReads™ is designed for use by children. We take the following measures to protect children's privacy:
- Library sessions are fully anonymous — no name, contact information, or persistent identifier is stored
- School sessions store only a first name and last initial, visible only to the student's teacher
- We do not collect email addresses, phone numbers, or contact information from students
- We do not display advertising to students or patrons
- Content filtering prevents inappropriate topics from reaching the AI model
For school use, we operate under the institutional consent model. Library use requires no account creation and collects no personal information — the library card barcode is immediately hashed and the original is discarded.
7. Data Retention
- Session records (anonymous analytics): retained for 24 months, then automatically deleted
- Student nicknames and class records: retained for the duration of the class code's active period, plus 12 months
- Educator accounts: retained for the duration of the subscription, plus 90 days following termination
- IP address rate limit records: automatically purged after 24 hours
Libraries and schools may request deletion of their branch data at any time by contacting us.
8. Data Security
- All data is transmitted over HTTPS/TLS encryption
- Library card barcodes are immediately converted to one-way SHA-256 hashes — the original number is never stored
- Passwords are stored as bcrypt hashes with a cost factor of 12
- Session tokens use cryptographically secure random values
- Database access is restricted to application servers only
- Error logs do not contain patron PII
No security system is impenetrable. In the event of a data breach that affects personal information, we will notify affected parties in accordance with applicable law.
9. Your Rights
Depending on your location, you may have rights to access, delete, correct, or receive a portable copy of your information. Because library patron sessions are anonymous (identified only by a hash), we are unable to retrieve or delete specific patron session records without the original barcode.
Schools and educators may contact us to exercise these rights for their account data.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify library administrators and school administrators of material changes via email or a prominent notice on the Platform. Continued use of the Platform after the effective date of any changes constitutes acceptance of the updated Policy.