Skip to content
Legal

Privacy Policy

Effective as of April 10, 2026  ·  Last updated: September 21, 2026

Questions about this policy? Contact us at privacy@incluxa.com. See also our Terms of Service and Cookie Policy.

1. Who We Are·2. Scope·3. Data We Collect·4. Legal Bases·5. How We Use Data·6. Data Sharing·7. International Transfers·8. Retention·9. Your Rights·10. Cookies·11. Security·12. Children & Student Privacy·13. Changes·14. Contact

1. Who We Are

Angstroma, Inc. operates the INCLUXA accessibility service ("INCLUXA," "we," "us," or "our") from the United States.

Business nameAngstroma, Inc. (Delaware corporation; operator of the INCLUXA brand)
Operates fromMichigan, United States
Privacy contactprivacy@incluxa.com

2. Scope of This Policy

This Privacy Policy applies to portal users (incluxa.com accounts), website visitors, end users of our accessibility widget on customer websites, and users of the INCLUXA Chrome Extension.

If you are a visitor to a website using the INCLUXA widget: The website operator is the data controller for your personal data. INCLUXA acts as a data processor on their behalf. Please refer to that website's own privacy policy.

If you are a Chrome Extension user: All accessibility adjustments (contrast, fonts, reading aids, etc.) run locally on your device. We do not collect your browsing history, nor any data about the websites you visit. We do not track which pages you open or how long you spend on them. See Section 3 for the full list of what an extension install does send to our servers.

3. Data We Collect

Portal users

CategoryDataPurpose
AccountName, email, hashed password (Argon2id — never stored in plain text)Authentication
BillingPayment method tokenized via Stripe — we never store raw card numbersPayments and invoices
UsageAPI call logs, scan history, feature usageService, billing, analytics
TechnicalIP address, browser type, session data, error logs, device fingerprint (browser user-agent and language derived hash — used for trusted device recognition only, not for tracking)Security, debugging, and trusted device recognition

We do not sell your data. Widget end user data is never used for advertising or cross-site tracking.

Chrome Extension users

The extension is designed to minimize data collection. Most of what you configure stays on your device and is never transmitted to our servers.

CategoryDataPurposeWhere it lives
Accessibility preferencesWhich accessibility tools you enabled, UI language, Quick Actions text-size level, master on/off state, collapsed-section state, accessibility profile selectionRestore your setup each time you open the panelYour device only (chrome.storage.local) unless you sign in AND opt into cloud sync
Account data (optional)Email address (via Google OAuth or email/password), first + last name (registration only)Optional sign-in for cross-device settings sync and future Extension+ subscriptionOur servers (hosted on Microsoft Azure, United States)
Cloud-synced preferences (optional)Copy of your accessibility preferences + languageSync settings across every device where you sign in with the same account; restore settings after reinstallOur servers — sync is OFF by default on the free tier and requires opt-in
Feedback submissionsMessage text (user-written), optional email, feedback type (bug/idea/compliment/etc.), browser user agent, submission timestampRespond to bug reports; improve the productOur servers; we only send a notification to support@incluxa.com — we never publish or share feedback
Authentication tokensShort-lived access token (in-memory only, never written to chrome.storage); refresh token (stored locally, encrypted at rest by Chrome)Keep you signed in across service worker restarts; re-obtain an access token when it expiresYour device; refresh token bound to your device ID
Technical — receive-time onlyIP address at the moment a request reaches our API (used for rate-limit keying + anti-abuse); never correlated with browsing or stored beyond the rate-limit windowAnti-abuse, rate limiting, security monitoringTransient at our servers; IPs in audit logs are masked (/24 for IPv4, /64 for IPv6) within 90 days
AI features (coming soon)ONLY the text or image you explicitly select and hand to the AI tool (e.g. a paragraph you ask to summarize). Personal identifiers are stripped before transmission where technically feasible.Claude API processes the input and returns a result to your extension. We do not train any AI model on your content.Anthropic (Claude API) — United States

What we explicitly do NOT collect from Chrome Extension users: your browsing history, the URLs or content of pages you visit, which sites you spend time on, your tab list, passwords, form data, bookmarks, or any advertising identifiers. The extension applies visual adjustments locally on the page in front of you and nothing else.

5. How We Use Your Data

  • Provide, operate, and maintain the INCLUXA service
  • Process transactions and send billing-related notices
  • Send account notifications and security alerts
  • Respond to support requests
  • Detect and prevent fraud, abuse, and security incidents
  • Generate aggregated, anonymized analytics to improve the product
  • Comply with applicable laws and enforce our Terms of Service

6. Data Sharing and Disclosure

We do not sell your personal data. We share data only with service providers (sub-processors) required to deliver our service, and when required by law.

ProviderPurposeLocation
Microsoft AzureCloud infrastructure, database hosting, blob storage, secrets (Key Vault), application monitoring (Application Insights)United States
VercelMarketing site and customer portal hosting; edge request routingGlobal (edge; primary US)
StripePayment processing and subscription managementUnited States
ResendTransactional email delivery (verification, invites, password reset, 2FA codes, billing notices)United States
CloudflareDNS, CDN, WAF, DDoS protection, bot mitigation (Turnstile CAPTCHA)Global
Bunny CDNWidget SDK and asset deliveryGlobal
SentryError monitoring and crash reportingUnited States
Have I Been PwnedPassword breach screening. Our server hashes the password and sends only the first 5 characters of its SHA-1 hash (k-anonymity); the password itself is never sent to HIBPAustralia
Anthropic, PBCAI processing — IEP accommodation extraction + extension AI features (redacted / user-selected text only)United States
Google"Sign in with Google" for the portal and the Chrome Extension (Google sees the sign-in event, not your product usage)United States
Google FontsGoogle Fonts: web fonts loaded by the widget on customer websites (the visitor's browser requests the font files, so Google receives the visitor's IP address and browser details)United States
jsDelivrOpen-source files loaded by the widget from the jsDelivr CDN (the visitor's browser requests them, so jsDelivr receives the visitor's IP address and browser details)Global (CDN)
Google Workspace (Gmail)Email inbox for mail sent to our privacy, security and support addressesUnited States

All sub-processors are bound by Data Processing Agreements. Contact privacy@incluxa.com to request a copy.

7. International Data Transfers

Our infrastructure is primarily hosted in the United States. Transfers from the EEA, UK, or Switzerland are made under Standard Contractual Clauses (SCCs) or UK IDTAs. Contact us to request a copy of the relevant safeguards.

8. Data Retention

DataRetention period
Account dataDuration of account + 90 days after deletion
Billing records7 years (legal requirement)
API usage logs13 months rolling
Security and audit logs2 years (internal audit-log retention policy)
Support correspondence3 years
Widget end-user preference tokens12 months of inactivity
Trusted device tokens (hashed)30 days, or until revoked in Security Settings
Student accessibility profiles (Schools tier)Retention period selected by the district (1–120 months), or earlier on school request
IEP accommodation records (Schools tier)Retention period selected by the district (1–120 months), or earlier on school request
IEP source filesDeleted after parsing — never retained
Student feature usage logsRetention period selected by the district (1–120 months), or earlier on school request

9. Your Rights

All users may access, correct, delete, and export their data, and opt out of marketing at any time.

EEA / UK users (GDPR) may additionally restrict processing, object to legitimate-interest processing, and withdraw consent at any time. You may lodge a complaint with your national data protection authority.

California residents (CCPA / CPRA) have the right to know, delete, correct, and opt out of the sale or sharing of personal information. We do not sell data.

To exercise your rights: privacy@incluxa.com. Response within 30 days (GDPR) or 45 days (CCPA).

10. Cookies

We use strictly necessary, functional, and analytics cookies. For a complete list see our Cookie Policy. Manage preferences via the Privacy Choices link in our footer.

11. Security

We use Argon2id password hashing, RS256 JWT, AES-256 encrypted session cookies, TLS 1.2+ in transit, and immutable audit logs. For full details see our Security page.

No system is completely secure. In the event of a breach, we will notify affected customers within 24 hours of confirming it, and supervisory authorities within 72 hours where the law requires.

12. Children's Privacy & Student Data (COPPA · FERPA)

Schools tier customers: This section governs all student data processing. The district agreement (SDPC National Data Privacy Agreement v2.0 plus the applicable state exhibit) must be signed in the portal under Settings → Schools before IEP automation, the teacher dashboard or LMS connections can be used. The district selects the student-data retention period (1–120 months).

12.1 Platform Not Directed to Children

The INCLUXA portal, API, and scanner are B2B services directed to businesses and educational institutions — not to individual children. Portal accounts are for adults acting for a business or school (our Terms of Service require account holders to be at least 18). We do not knowingly solicit or collect personal information directly from children under 13, except as a school's service provider under a signed district agreement. If you believe a child under 13 has provided us personal data without appropriate consent, contact privacy@incluxa.com and we will delete it within 5 business days.

12.2 Schools Tier — COPPA (16 C.F.R. Part 312)

The Schools tier enables K–12 institutions to deploy accessibility features for students, including those under 13. Schools may consent on parents' behalf for educational use, consistent with long-standing FTC COPPA guidance, where the operator processes student data solely for the use and benefit of the school and for no other commercial purpose. The amended COPPA Rule's compliance date was April 22, 2026.

By activating the Schools tier and uploading student data, the subscribing institution:

  • Represents it is providing parental consent on behalf of enrolled students for the limited purpose of delivering accessibility services
  • Warrants it has complied with all applicable COPPA requirements, including providing direct notice to parents where required
  • Agrees that INCLUXA processes student data solely as a data processor on the school's instructions

We never use student data for advertising, marketing, profiling, or any commercial purpose beyond the accessibility services contracted by the school. Student data is never sold.

12.3 FERPA (20 U.S.C. § 1232g; 34 C.F.R. Part 99)

For educational institutions subject to FERPA:

  • School Official Designation. Schools that sign the district agreement designate INCLUXA as a "school official" with a "legitimate educational interest" as defined under 34 C.F.R. § 99.31(a)(1). INCLUXA uses education records only to provide contracted accessibility services.
  • No Re-Disclosure. INCLUXA will not re-disclose education records to any third party except as explicitly authorized by the district agreement or required by law.
  • Breach Notification. We will notify the school within 24 hours of discovering any unauthorized access to or disclosure of education records.

12.4 IEP Document Processing & AI Safeguards

Critical disclosure: IEP documents are processed using Claude AI (Anthropic, PBC, United States) to extract accessibility accommodation types. Automated redaction is applied before any content leaves our systems.

When a school uploads an IEP document, the following sequence is enforced:

  1. PII Redaction. Before any content is transmitted externally, an automated redaction engine replaces student names, dates of birth, parent/guardian names, contact information, Social Security Numbers, and other direct identifiers with anonymized placeholders (e.g., [STUDENT], [DATE], [GUARDIAN]).
  2. AI Extraction. Only the redacted text is transmitted to Anthropic's Claude API. Redaction is automated and may not catch every identifier, so schools should upload only the IEP content needed for accommodation mapping.
  3. File Deletion. The IEP file itself is deleted after parsing.
  4. Accommodation Storage. We store an opaque student ID, accommodation types, a short description and a supporting quote from the redacted IEP (encrypted at rest), plus the uploaded file name.

INCLUXA maintains a Data Processing Agreement with Anthropic, PBC governing AI processing. Anthropic processes only the redacted content described above and does not retain it for model training without explicit consent.

12.5 What Student Data We Collect

DataPurposeCollected From
ExternalStudentId — opaque, school-assigned identifier (not the student's name or SSN)Link accessibility profile to student within the school systemSchool's LMS / SIS
Accessibility feature preferences (toggles and values)Deliver personalized accessibility accommodationsStudent's widget interactions
Accommodation types extracted from IEP (e.g., "requires large font")Apply recommended accessibility settings to student profileIEP document (after redaction + AI extraction)
Short description and supporting quote from the redacted IEP (encrypted at rest); uploaded file nameLet staff review and confirm each suggested accommodationIEP document (after redaction + AI extraction)
Feature usage eventsVerify accommodation effectiveness; improve serviceWidget usage telemetry

We do not ask for: student names, dates of birth, Social Security Numbers, medical diagnoses, grades, disciplinary records, or any data beyond what is strictly necessary for accessibility service delivery. Uploaded file names are stored as provided, so schools should not put student names in IEP file names.

12.6 Parent, Guardian & Student Rights

Parents of students under 18, and eligible students (18+), may exercise the following rights through their school administrator:

  • Review accessibility profiles and accommodation records on file
  • Request correction of inaccurate data
  • Request deletion of all data associated with a specific student
  • Receive a copy of student data in a machine-readable format (data portability)

Schools submit requests on behalf of parents or students by emailing privacy@incluxa.com with the subject line "Student Data Request — [School Name]". We respond and act within 30 days. Deletion requests are confirmed in writing.

13. Changes to This Policy

We will provide at least 30 days' notice of material changes via email and a notice on our website. Continued use after the effective date constitutes acceptance.

14. Contact Us

For privacy questions, data subject requests, or to execute a DPA:

Email: privacy@incluxa.com
Postal address: Angstroma, Inc., 131 Continental Drive, Suite 305, Newark, DE 19713, United States (Delaware registered agent address — accepts executed DPAs and legal service of process).