Legal
Privacy Policy
This policy explains how Archiva collects, uses, and shares information when you use the family homeschool product, the association (umbrella / cover school) product, the member portal, and related sites and emails.
Effective date: Last updated:
1.Introduction
Archiva is a parent-first homeschool learning system and, separately, an association operations product for umbrella and cover schools. We designed the service to hold school records — names, grades, attendance, transcripts, and membership files.
This Privacy Policy applies to https://myarchiva.com, the Archiva applications (including family, student, association staff, and member portals), transactional email, and related APIs. It does not apply to third-party websites we link to, or to an association’s own code of conduct, dues instructions, or other policies.
By creating an account, submitting a membership application, or otherwise using Archiva, you acknowledge this policy. If you do not agree, do not use the service. Our Terms of Service govern your contract with us.
2.Who we are
“Archiva,” “we,” “us,” and “our” mean Archiva LLC, a South Carolina limited liability company. The Service is offered at https://myarchiva.com. You can reach us at support@myarchiva.com.
Archiva currently offers these products on the same platform:
- Family product — a homeschool LMS for a single family: students, courses, assignments, grades, attendance, and PDF report cards, transcripts, and attendance logs.
- Association product — staff tools for umbrella / cover schools: roster, intake, dues, documents, and related operations, plus a member household portal.
- Student access — a limited view of a child’s own assignments, grades, and/or attendance, enabled only by a parent.
3.Controller and processor
Privacy law distinguishes who decides why personal information is processed (the controller) from who processes it on that party’s instructions (the processor).
- Family product. For accounts you create to run your own homeschool — including student records you enter, co-parent invites, billing identity, and product feedback — Archiva is the controller.
- Association roster and membership. For household and student information an association collects through public intake, staff entry, CSV import, dues, or document generation, the association is the controller and Archiva is the processor. We process that information only to operate the association features the association configures. Details are in Section 18 and in the association data-processing terms in our Terms of Service.
- Optional family ↔ household link. If a parent accepts an association’s invitation to link a family account to a household, that link is identity only. It does not merge the two products or give association staff login to the family gradebook.
4.Information we collect
We collect information you provide, information generated by use of the service, and limited information from service providers who help us run it.
| Category | Examples | Typical source |
|---|---|---|
| Account | Email, password (hashed by our auth provider), display name, role (parent, student, staff, or member), optional authenticator-app enrollment | You |
| Family profile | Homeschool / family name, timezone, US state, school years and terms, grading schemes | Parent |
| Student records (family) | Name, grade level, birth date, photo, courses, assignments, scores as percentages, attendance, narrative comments, generated PDFs | Parent; limited student self-completion if enabled |
| Association roster | Household contacts, addresses, phones, emails, student names, birth dates, curriculum notes, membership status, dues, optional SSN for transcripts, intake answers, generated letters and transcripts | Applicant or association staff |
| Billing | Plan, subscription status, trial or complimentary-access dates, and identifiers from our payment processor. We do not store full card numbers. | You and our payment processor |
| Communications | Support email, product feedback (message, page, account, browser details), invite emails, paperwork you send via a connected Gmail account | You |
| Usage | Pages viewed, feature clicks tagged in the product, approximate engaged time, viewport size. Student sessions are page-level only. | Automatic |
| Technical | Hashed or truncated network context for rate limiting, user agent, error diagnostics. We do not store raw visitor IP addresses in analytics. | Automatic |
We do not require government ID for a family account. An association may optionally store a student Social Security number for cover-school transcripts. Full SSNs are encrypted at rest, shown as last-four in the staff browser, and printed on a transcript PDF only when staff generate that document.
If you use school-district lookup, we send the address you enter to a third-party US government address service to estimate a district. That lookup exists to help with homeschool paperwork.
5.How we use information
We use personal information to:
- Provide, maintain, and improve the products — including gradebooks, attendance, PDF records, membership intake, dues, and staff workflows.
- Create and authenticate accounts, enforce role doors (parents, students, staff, and members cannot use one another’s apps), and offer optional MFA.
- Process subscriptions, trials, complimentary access codes, and invoices through our payment processor.
- Send transactional email (confirmations, password reset, invites, trial-ending notices). We do not send marketing newsletters unless we later offer that with a separate opt-in.
- Respond to support requests, investigate abuse, and keep an integrity trail of important changes (audit) and operator access to tenant records.
- Understand how the product is used so we can fix bugs and decide what to build next — using first-party analytics, not advertising networks.
- Comply with law and enforce our Terms.
We do not use student or household information to profile children for advertising, to train public generative-AI models, or to sell lists.
6.Legal bases
If a data-protection law that uses “legal bases” (such as the GDPR) applies to your use, we rely on:
- Contract — to provide the service you request (account, gradebook, billing, association operations).
- Legitimate interests — security, fraud prevention, product improvement with minimized analytics, and supporting our business, where those interests are not overridden by your rights.
- Consent — where we ask for it, including a parent enabling student login, staff connecting Gmail (send-only), and optional collection of an SSN by an association.
- Legal obligation — when we must retain or disclose information (for example tax, accounting, or a valid legal process).
For association roster data, the association determines its own legal bases. Archiva processes that data on the association’s documented instructions, which include this policy, our Terms, and the association’s configuration of the product.
7.Children and student accounts
Archiva is directed at adults: parents, guardians, and association staff. You must be 18 or older (or the age of majority where you live) to create a parent, staff, or member account.
Children — including children under 13 — appear in Archiva only because an adult created a student record or submitted a membership application. That adult is responsible for having authority to provide the child’s information.
Family student login. A parent may enable a limited student session (PIN or access link). Students never reach the parent app, billing, or co-parent invites. Student behavioral analytics are restricted to page view and heartbeat only: we do not record student clickstreams, page text, or form values.
COPPA. We do not condition participation in a child’s educational activity on collecting more personal information than needed to provide that activity. We do not display third-party advertising to students. We treat a parent’s creation of the student record and enablement of student login as the parent’s authorization for that child’s use. Association roster rows for children under 13 have no student login and no separate analytics channel.
A parent may request that we delete a child’s family-product information by writing to support@myarchiva.com from the account email, subject line “Child Privacy Request.” Association roster deletions are decided by the association (see Section 18).
8.Educational purpose
We process student information solely to provide educational and school-administration features you or your association request: instruction records, grading, attendance, transcripts, membership, and related support. We do not use student information for targeted advertising, and we do not sell student information.
Archiva is a software tool. We are not a school, school district, college, or accrediting body. Whether a PDF we generate satisfies a state’s homeschool statute, an umbrella school’s policy, NCAA, admissions, or any third party is the parent’s or association’s responsibility.
10.Service providers
We use other companies to help us run the Service. They may process personal information only to provide their service to us, not for their own marketing. Typical categories include:
- Cloud hosting, database, authentication, and file storage in the United States.
- Payment processing. Card numbers are handled by the processor, not stored in full on Archiva.
- Transactional email (confirmations, invites, password reset).
- DNS, TLS, and content delivery for the site.
- Error and security monitoring. Diagnostic captures of failed pages, when used, mask on-screen text, inputs, and media.
- Optional school-district lookup via a US government address service, only if you use that feature.
- Optional email sending through Google, only if association staff connect their own Google account. We request send and email identity access, not inbox read. Google’s terms apply to that connection.
We do not publish a named vendor list. If you need more detail for a legitimate compliance review, email support@myarchiva.com.
12.Analytics and error monitoring
Archiva’s product analytics are first-party. The tracker does not read input values, form contents, or on-screen names and grades. It only sends an explicit tracking key when a control is marked for it, plus page path, viewport size, and engaged time.
Parent and staff sessions may include those feature events. Student sessions may include only page view and heartbeat. Association member and public intake pages follow the same first-party rules; we do not load third-party analytics SDKs.
Raw behavioral events are kept for a limited window (about 90 days) and then dropped or rolled up without extra personal detail. Mutation audit logs keep a redacted trail of what changed (not secrets such as passwords, PINs, invite tokens, or SSNs) so we can investigate integrity and support issues.
If the application crashes, our error-monitoring provider may receive a diagnostic report and, on some errors, a masked capture of the failed page. Support emails may include a short reference code so we can find the matching log without asking you to paste personal records.
13.Security
No method of transmission or storage is perfectly secure. We take measures appropriate to a school-records product, including:
- Encryption in transit (HTTPS) and encryption of selected secrets at rest (including Gmail refresh tokens and association SSNs).
- Postgres row-level security with default-deny policies keyed to the signed-in tenant, so families and associations cannot read one another’s rows through the application database role.
- Separate product doors for parents, students, association staff, and members.
- Optional authenticator-app MFA; associations may require it for staff.
- Hashed student PINs; invite links treated as credentials; admin operator access logged.
- Service-role keys kept on the server, never shipped to the browser.
You are responsible for choosing a strong password, keeping student PINs and access links private, and telling us if you believe an account was compromised.
14.Retention
We keep information only as long as needed for the purposes in this policy, including to provide the service and to meet legal, accounting, and dispute needs.
- Family and association records remain for the life of the account. Canceling a subscription does not automatically wipe your records; canceled family accounts become read-only until you resubscribe or ask us to delete.
- Association historical membership is not auto-deleted when a household withdraws, because associations often need old transcripts. Staff may delete roster rows when the association no longer needs them.
- Behavioral analytics (raw): about 90 days.
- Audit diffs (raw): about 90 days, then summaries or anonymized integrity records.
- Operator access logs: about two years.
- Billing records held by our payment processor follow that processor’s retention. We keep subscription status and identifiers as needed to run the account.
When we delete a tenant at your (or an association admin’s) verified request, we delete or anonymize personal information in operating tables. We may retain anonymized audit facts, records we must keep by law, and information needed to prevent fraud or abuse.
15.Your rights
Depending on where you live, you may have the right to access, correct, delete, or export personal information, to object to or restrict certain processing, and to appeal a denial. You may also have the right not to be discriminated against for exercising those rights.
To make a request, email support@myarchiva.com from the address on your account with the subject “Privacy Request.” Tell us whether you want access, correction, export, or deletion, and which product (family, association, or member). We will verify that we are talking to the account holder. We may not fulfill a request that would violate the rights of another person, interfere with an association’s role as controller, or require us to keep operating an account we are required to close.
Parents can already edit and delete much of their family data in-product (students, courses, years, and so on). Association staff control roster edits. Full tenant deletion and a machine-readable export of a person are handled by Archiva support / operations after verification — they are not yet self-serve buttons in Settings.
Authorized agents (including California agents) must include proof of authorization. We will not fulfill a request we cannot verify.
16.California and other US state laws
If you are a resident of California or another US state with a comprehensive privacy law (including the CPRA and similar statutes), this section is for you.
Categories collected in the past 12 months are those in Section 4: identifiers, customer records, commercial information (subscription status), internet / electronic activity (first-party analytics), education information, and, where an association collects them, sensitive personal information such as a student’s SSN or precise address used for district lookup.
Sources, purposes, and recipients are described in Sections 4–10. We do not sell personal information or share it for cross-context behavioral advertising. We do not use sensitive personal information to infer characteristics about a consumer for advertising. Because we do not sell or share in the CPRA sense, we do not offer a “Do Not Sell or Share” opt-out link.
You may request access (including a portable copy), deletion, correction, and information about our practices by emailing support@myarchiva.com. We will respond within the time those laws require. You may appeal by replying to our decision. California residents may contact the California Attorney General if they have a complaint we cannot resolve.
17.International transfers
Archiva is built and hosted in the United States. If you access the service from another country, you understand that your information will be processed in the United States, which may have different data-protection rules than your home country. Where required, we use appropriate transfer mechanisms with our providers.
18.Association roster processing
This section applies when Archiva processes personal information for an association tenant.
- The association decides what to collect on intake, whom to admit, how long to keep withdrawn members, and whether to store an SSN.
- Archiva stores and processes that information to run membership operations, document generation, dues, tasks, and related support — not for Archiva’s own marketing.
- Staff may connect Gmail with send-only access to email paperwork they generate. Refresh tokens are encrypted. We do not read the staff inbox.
- If you are a member or applicant and want a roster correction or deletion, start with your association. If they have instructed us to assist, or if they are unresponsive and the law requires us to act, contact support@myarchiva.com.
19.Changes
We may update this policy. The “Last updated” date at the top will change. If a change materially reduces your rights, we will provide additional notice (for example email to the account address or an in-product notice) before it takes effect, except where we must change the policy to comply with law. Continued use after the effective date constitutes acceptance of the updated policy.
20.Contact
Privacy and data-protection requests: support@myarchiva.com (subject: “Privacy Request”).
General support: support@myarchiva.com.
Archiva LLC, South Carolina. A postal address for legal notices is available on request from the same email.