1. Who we are
CampusLayer is a service operated by Caleb Media Studio LLC. In this policy, “CampusLayer,” “we,” “us,” and “our” refer to Caleb Media Studio LLC and the CampusLayer services it operates.
This Privacy Policy applies to CampusLayer websites, CampusLayer Connect, CampusLayer Assistant, and other CampusLayer services that link to this policy. A school, district, organization, or other customer may have a separate agreement with us that adds privacy, security, retention, or data processing requirements. Where such an agreement applies, it may supplement this policy.
2. Information we process
The information CampusLayer processes depends on which services, integrations, and features are enabled.
Account and organization information
- Name, email address, account identifiers, and profile information.
- Authentication, session, organization, tenant, role, and access information.
- Configuration selected by you or your organization.
Connected service information
- Provider name, provider instance, connection status, and granted capabilities or scopes.
- Provider account identifiers and profile information returned by the provider.
- Authentication material such as OAuth tokens, refresh tokens, personal access tokens, developer credentials, or equivalent secrets when required to maintain an authorized connection.
Sensitive provider credentials are handled as server side secrets and are not intended to be placed into AI model context.
Content you choose to use with CampusLayer
- Assistant messages and responses.
- Files, documents, and generated artifacts.
- Data returned by connected services in response to an authorized request, such as learning platform records, calendar information, messages, or other provider data.
- Tool activity and information needed to carry out requested actions.
Usage, device, and security information
- Device, browser, IP address, session, and request information.
- Feature usage, model usage, token counts, tool counts, and operational metadata.
- Security events, audit records, error information, and sanitized diagnostics.
Support and inquiry information
If you contact us, request a demo, or work with us on an evaluation, we process the information you provide so we can respond and support the relationship.
3. How we use information
We use information to:
- Provide, operate, maintain, and improve CampusLayer.
- Authenticate users and enforce organization and role based access.
- Connect authorized third party services and perform requested operations.
- Provide Assistant, file processing, automation, and other enabled product features.
- Protect accounts, investigate abuse, prevent fraud, and maintain service security.
- Provide support, communicate service information, and respond to inquiries.
- Measure service usage and administer plans, entitlements, and billing where applicable.
- Comply with law and enforce our agreements.
4. Connected services and permissions
CampusLayer can connect to services operated by third parties, such as learning management systems, student information systems, Google Workspace, Microsoft 365, and other providers. CampusLayer accesses a connected service only through the permissions, credentials, or authorization available to the applicable user or organization.
The scopes shown by a provider determine what CampusLayer is technically allowed to request from that provider. CampusLayer also applies its own authorization and product controls. Disconnecting a provider stops future CampusLayer access through that connection, but it does not delete data that remains in the provider itself.
Third party services have their own terms and privacy practices. CampusLayer does not control data retained independently by those providers.
5. AI and automated processing
Some CampusLayer features use external AI model or execution providers. When an AI feature is enabled, information needed to fulfill the request may be sent to an approved provider according to the configuration and contractual terms that apply to that deployment.
CampusLayer is designed to reduce unnecessary disclosure before model inference. Depending on the feature, this can include access checks, data minimization, classification, tokenization, or other controls before information crosses an AI boundary.
Provider retention and data control settings can vary by provider, model, tool, and customer configuration. We do not describe a deployment as having Zero Data Retention unless the applicable provider configuration and tool path actually support it.
CampusLayer does not sell customer content or student data for AI training. We do not use institutional student data to train a general purpose CampusLayer model.
6. Student and school data
Institutional use of CampusLayer may involve education records or student personal information. When CampusLayer processes such data for a school or district, the school or district determines the authorized educational purpose and the users who are permitted to access that information, subject to the applicable agreement and law.
CampusLayer does not claim that architecture alone creates blanket compliance with FERPA, COPPA, state student privacy laws, or a district policy. Institutional deployments may require a data processing agreement, security review, parental or guardian consent, or other customer specific controls.
We do not sell student personal information, use student personal information for targeted advertising, or build advertising profiles from student education data.
More information about our product approach is available on the Student Privacy page.
7. When we share information
We may disclose information in the following circumstances:
- Service providers and subprocessors. We use vendors that help provide hosting, databases, authentication, email, observability, AI, file processing, and related service functions.
- Connected providers. We send requests to a connected service when a user or authorized workflow asks CampusLayer to read or change information there.
- Your organization. Organization administrators may have access to account, configuration, security, audit, or workspace information as allowed by the product and applicable agreement.
- Legal and safety reasons. We may disclose information when required by law or when reasonably necessary to protect rights, security, users, or the service.
- Business transactions. Information may be transferred as part of a merger, financing, acquisition, reorganization, or sale of all or part of the business, subject to applicable law and contractual obligations.
CampusLayer does not sell personal information for money.
8. Retention and deletion
We retain information for as long as reasonably necessary to provide the service, maintain security and auditability, satisfy contractual obligations, resolve disputes, and comply with law. Different data classes can have different retention periods.
For example, provider credentials may be retained until a connection is disconnected or revoked, while account, workspace, conversation, artifact, usage, and security records can follow different lifecycles. Institutional agreements may set specific retention, export, and deletion requirements.
Deleting information from CampusLayer does not automatically delete information that remains in a connected third party provider.
9. Security
CampusLayer uses technical and organizational safeguards intended to protect information, including access controls, encrypted network transport, protected server side secrets, authorization boundaries, and security monitoring appropriate to the service.
No service can guarantee absolute security. Customers and users are responsible for protecting their own credentials, devices, and authorized access.
10. Your choices and rights
Depending on your relationship with CampusLayer and applicable law, you may be able to access, correct, delete, export, or restrict certain personal information. You can also disconnect connected providers or revoke their authorization through CampusLayer or the provider.
If your account is provided or managed by a school, district, or other organization, requests concerning institutional records should generally be directed to that organization first. CampusLayer may refer an institutional data request to the applicable customer when the customer controls the record.
11. Cookies and local storage
CampusLayer may use cookies, browser storage, or similar technologies for authentication, session continuity, security, preferences, and service operation. We do not use student education data to serve targeted advertising.
12. Children
CampusLayer is not intended to let children create unrestricted consumer accounts without appropriate authorization. If a service is offered to a student through a school, district, parent, or guardian, that use may be governed by an institutional agreement and the permissions required by applicable law.
If you believe a child has provided personal information to CampusLayer without appropriate authorization, please contact us.
13. Changes to this policy
We may update this Privacy Policy as CampusLayer changes. We will post the current version at this URL and update the date shown above. If a change materially affects an institutional customer, we will provide any additional notice required by the applicable agreement or law.
14. Contact us
Questions, privacy requests, and institutional privacy inquiries can be submitted through the CampusLayer contact page.