Back to Saved By The Plan

Privacy Notice

Effective July 25, 2026 · Revision 3 (policy version 2026-07-25-v3)

Saved By The Plan is a product and service of OLYV LLC (“OLYV,” “we,” “us,” or “our”). For privacy questions or requests, contact support@savedbytheplan.com.

The short version: we use the curriculum you submit to make and email one lesson-plan PDF. We do not offer a curriculum repository, a customer plan library, or an owner content viewer. The working material is temporary, but it necessarily passes through the service and selected providers while we process and deliver it.

1. Scope and agreement

This Notice explains how we handle personal information when you visit, create an account for, or use Saved By The Plan. Before a first curriculum request or paid checkout, the service asks you to affirmatively accept this Notice and the Terms of Service. This Notice does not replace provider notices that apply to a payment, email, AI, hosting, or mailbox service.

2. Information we collect and receive

Account, consent, and support information

We collect your email address for passwordless sign-in and transactional lesson delivery. We keep account identifiers, session and authentication records, your role/entitlement, and the version and time of your Terms and Privacy Notice acceptance. If you contact support, we receive the information you include in that message.

Curriculum and lesson-plan information

When you submit a request, we process the files, images, and text you choose to provide; temporary extracted and source-validation data; and the resulting lesson-plan content. A final PDF can include source-backed excerpts, teacher language, and other curriculum-derived material because those details are part of the requested plan. Do not submit student personal information or any material you are not permitted to use.

Billing information

Stripe processes payments. We receive limited billing and account information such as Stripe customer and subscription identifiers, billing country, payment/subscription status, tax, refund, fee, and payout status. To prevent duplicate checkout attempts, we may query the current Stripe subscription state and record an expiry-bound checkout-request identifier and selected price tied to your account; that request record cannot be used to create another Checkout Session once its bounded retry window ends. We do not receive or store full payment-card numbers.

Technical and security information

Our infrastructure and service providers may process standard technical and security information needed to operate and protect the service, such as request time, browser/device and network information, cookie/session information, request identifiers, page count, status, duration, service cost, and error category. Our internal operational metrics are designed to be content-free: they do not intentionally contain curriculum text, image bytes, raw model responses, or final plan text.

3. How we use information

We do not sell curriculum or lesson-plan content. We do not use it for targeted advertising or make it available to the owner/admin portal. We do not use OpenAI API content to train OpenAI models unless OpenAI’s API data-sharing settings are separately changed to opt in.

4. How curriculum is processed and retained

In your browser. Before you submit, selected files and photo previews remain in the browser’s working memory. Clearing the staged upload or leaving the page removes those local working references; your browser may separately manage its own cache.

In our service. We keep original curriculum files, image evidence, raw extraction data, and curriculum-derived planning data only while the active request needs them. Private image evidence is designed to be deleted on normal terminal paths and is treated as expired after one hour. Verified child extraction records are deleted when their material moves to the short planning stage. Terminal worker records become eligible for purge after 15 minutes. Source-bearing active worker tasks have a 23-hour safety cap: scheduled cleanup replaces an unfinished task with a content-free finalization record rather than retaining its curriculum payload. That finalization normally releases the reserved credit only after the related job bookkeeping succeeds. Scheduled cleanup is best-effort, so an outage can delay the physical deletion of an expired record. These timeframes describe live application records. A provider backup, disaster-recovery copy, or security log may retain a copy for a longer provider-controlled recovery or security cycle; we do not use those systems as a customer-content library. Content-free account, credit, consent, billing, and operational records remain because they are needed to run, secure, support, and account for the service.

Final plan and email. The final lesson plan is held only in the active delivery task until the transactional email provider accepts the PDF or the request reaches a terminal failure. The PDF is rendered in memory for email delivery; we do not provide a customer plan library, saved curriculum repository, or finished-plan history. Once the provider accepts the email, we clear the task’s plan payload. The separate post-send recovery window does not extend retention of original curriculum or raw extraction material: after a send attempt, the recovery task contains only the final-plan delivery payload and a fixed email envelope, which we may retain for up to 23 hours from that send attempt to retry the provider’s idempotent request safely. It does not retain the original files, image evidence, or raw extraction packet. If an email request still has an ambiguous provider outcome at the end of that window, we remove the final-plan payload and retain only a content-free support status while the related credit is held for review. The email, its attachment, and copies in your sent/received mailbox are then handled by the email provider and mailbox providers under their own retention settings. Resend’s published Data Processing Addendum describes processing message metadata, addresses, content, and attachments to deliver application email, with provider-level retention governed by its contract and settings; we do not control that retention.

AI-provider processing. We use the OpenAI API to process curriculum. We set the Responses API store option to false to avoid opting into the API’s longer stored-response state. Background processing still requires temporary response data for roughly ten minutes so the job can be polled. Under OpenAI’s default API data controls, abuse-monitoring logs may be retained for up to 30 days unless OpenAI approves and applies different controls to the relevant organization or project. Unless OpenAI has enabled Zero Data Retention for the relevant organization or project, its current documentation also says Responses API queries use extended prompt caching; this may keep encrypted key/value tensors in GPU-local application state for up to 24 hours. The application cannot verify an OpenAI account’s approved data-control setting, so we do not assume that stricter setting is enabled. See OpenAI’s current data controls documentation; provider policies and configurations can change.

5. Who receives information

We disclose information only as needed to provide and protect the service, including to:

Our public pages also load web-delivery assets from their providers. Those providers may receive ordinary browser connection information when your browser loads the page. We do not send curriculum or lesson-plan content to those asset providers.

6. Cookies and similar technology

We use necessary session/authentication cookies or equivalent browser storage to keep you signed in and protect the service. We do not operate advertising cookies or a cross-site behavioral advertising program in the service, and we do not knowingly authorize third parties to use the service to collect information about your activities across unrelated websites for behavioral advertising. The service does not respond to browser Do Not Track signals because it does not operate cross-site behavioral tracking.

7. Children and student information

Saved By The Plan is for adult teachers and other authorized education professionals, not students. Do not upload names, email addresses, student IDs, grades, attendance, IEP/504 information, health information, work samples tied to an identifiable student, or any other student personal information. If you believe student personal information was submitted, contact us promptly at support@savedbytheplan.com from the account email so we can investigate and take appropriate steps.

8. Your choices and privacy requests

You may ask about access to, correction of, deletion of, or a portable copy of account information, or exercise another privacy right available under applicable law, by emailing support@savedbytheplan.com from your account email with “Privacy Request” in the subject line. Tell us what you need and we may ask to verify your identity, account, and authority. We will respond within the time required by applicable law; where the law permits an extension, we will tell you why. Deletion may be limited where we need to retain information for a transaction, tax, security, fraud-prevention, dispute, or legal purpose. We cannot delete copies already delivered to your mailbox or information a separate provider must retain under its own policy. If we deny a request in whole or in part and an appeal is available under applicable law, reply to our decision with “Privacy Appeal” and we will review it.

U.S. state privacy disclosures

Where a U.S. state privacy law applies, the categories of personal information we collect or receive are: identifiers and account records (such as email, authentication/session information, and policy acceptance); commercial and billing records (such as subscription, customer, tax, and payment-status information); internet, device, and security activity; professional information you choose to provide; and user-provided curriculum and resulting lesson-plan content. We receive these categories directly from you, automatically through your use of the service, from Stripe and other providers while they provide their services, and from records generated while we operate the service. We use them for the purposes in Section 3 and disclose them for service-provider and other business purposes described in Section 5. We do not sell personal information or share it for cross-context behavioral advertising, and we do not use sensitive personal information to infer characteristics about you. We will not discriminate against you for exercising a privacy right, subject to lawful limits. An authorized agent may submit a request for you; we may require proof of authority and verify your identity.

9. Security and international processing

We use reasonable administrative, technical, and organizational measures appropriate to the service, including passwordless authentication, server-side access checks, signed payment webhooks, and restricted owner access. No internet transmission or storage system is completely secure. The service is operated primarily for U.S. customers, and our providers may process information in the United States or other locations where they operate. By using the service, you understand that those locations may have different privacy protections than your location.

10. Changes and contact

We may update this Notice when the service or legal requirements change. The effective date above shows the current version. If a material change requires renewed acceptance before a new curriculum request, we will ask for it in the service. Questions or requests: support@savedbytheplan.com.

This Notice describes the service as configured on its effective date. It is not a substitute for legal advice about a school, district, employer, publisher license, or your own privacy obligations.