PRIVACY

Effective August 12th, 2026

Student was created by a privacy-minded teenager who wants a better alternative to StudentVUE®. We promise to never sell, share, or unnecessarily access your student information.

Who we are

Student (“we,” “us,” “our”) is a third-party alternative client for StudentVUE®. We are not affiliated with Edupoint Educational Systems, LLC, StudentVUE® (a product of Edupoint), or any school district.

We operate in the state of Washington, in the United States. StudentVUE® is a trademark of Edupoint Educational Systems, LLC.

What information we collect about you

To connect you to your district, your StudentVUE® credentials are passed through our servers in transit. They are held in memory only for the moment it takes to relay the request between your browser and your district's Synergy server.

Your data is never logged, written to a disk, or stored in a database, and is not retained after the request completes. We will never store the user's StudentVUE® data or log in information on our servers. We do not operate any user accounts. Because this data does briefly pass through our systems, we describe ourselves as transiently processing it on your behalf and at your direction, not collecting or maintaining it.

User data may be saved in browser storage (local storage or cookies) to help keep the user signed in across pages and ensure a seamless experience. This data is not stored on our servers and is kept on the user's own computer.

Our hosting provider (Vercel, their privacy policy can be read here) may process standard technical data (anonymized IP address, user agent, timestamps, request metadata) in connection with delivering the Service, performance monitoring, and security. They also host the relay described above, where the user's data is ensured not to be written to a disk, stored to a database, or logged.

Our primary analytics provider (Umami, their privacy policy can be read here) collects anonymized and aggregated usage of the service. You may opt out of analytics collection on the settings page. Our hosting provider, Vercel, also collects analytics on user performance and speed to help understand user experience. These tools may collect device and user information such as pages viewed, country (derived from IP), and device/browser characteristics. We do not use analytics to access your StudentVUE® credentials or student records.

How we interact with StudentVUE®

When the user enters district information and signs in, the Service sends the user's credentials to a relay server. Synergy servers block direct browser-to-district connections, so a relay is technically required to make the app work. We keep the relay stateless. More info on the relay can be found in the section “What information we collect about you.”

Entering district information or sign-in information results in the user's credentials and their request being sent through the relay in stateless memory to the school district's Synergy (a product of Edupoint, and the server powering StudentVUE®) server. Data flows from the User to the Service to the Synergy server and back to the user to display the user's information. User information is used only for that purpose, and is not used for any other purpose. The entirety of our codebase is publicly available as “open source” code under the GNU AGPLv3 license, on GitHub.

What we do not do

  • We do not sell or share the user's information.
  • We do not collect student credentials or records in our own database, write them to a disk, or log them. Your data stays in host memory and is discarded shortly after.

What Subprocessors touch your data

Student may share limited information with select subprocessors to deliver the Service and improve the service.

  • With the user's district's Edupoint server (operating as StudentVUE®) when the user uses the service, to provide student records to display to the user.
  • With infrastructure providers (Vercel) to host and deliver the service.
  • With analytics providers (Umami Analytics; Vercel Speed Insights) for usage and performance improvement to help improve user experience.
  • For legal reasons if required to comply with law or valid legal process.

How we store your data

Our server and database do not store the user's data. Data may pass through the relay server temporarily in stateless memory but is removed shortly after the request is made. The service may use browser storage and cookies to improve the user's experience; this is only visible to the user, not us. The user can clear stored data at any time by clearing site data for the service in the browser settings.

How long we retain your data

StudentVUE® data is not stored on our servers and is not retained after each request completes. Operational logs (which never contain credentials or student records) are handled by our hosting provider, Vercel, under their retention practices (typically around 30 days). Analytics data is kept in aggregated and anonymized form. Email you send us is kept only as long as needed to respond to your inquiry.

Security incidents

If we become aware of a security incident affecting data we process, we will post notice on this page and, where required by law, notify affected users.

Exercising your rights

As we do not collect or store StudentVUE® data, we cannot delete data we do not hold. Local laws may impose different requirements (for example GDPR or CCPA), so requests (like deletion of email inquiries) can be sent to inquiries@aram.sh, and we will do our best to honor them.

How we protect your data

We use Hypertext Transfer Protocol Secure (HTTPS), HTTP Strict Transport Security (HSTS), and Transport Layer Security (TLS), and take reasonable measures to protect the service. No method of transmission or storage is completely secure. Vercel's Data Processing Addendum can be found here.

Children's privacy

Student is intended for use by students, including those under 18, who have access to StudentVUE® through their school or district. We do not knowingly collect or store StudentVUE® credentials or student records on our server. If a parent/guardian believes we have received personal information directly (for example, through an email inquiry), please contact us at inquiries@aram.sh and we will delete it.

Grades, attendance, schedules, and similar records are “education records” held and controlled by your school district, and governed by laws such as FERPA. We are not a “school official,” we are not endorsed by Edupoint or your district, and we do not create, own, or maintain any education record. You access your own records using credentials your district gave you. If your school or district explicitly prohibits third-party clients or automated access to StudentVUE®, do not use Student. You are responsible for ensuring your use is permitted. We act as a third-party tool authorized at student/family discretion.

Student is not directed to children under 13. We do not knowingly collect personal information from children under 13. Analytics are disabled by default for users who indicate they are under 13, and parental consent is required before use. If you believe a child under 13 has provided us personal information that we have stored (for example, via an email inquiry), please contact us at inquiries@aram.sh and the data will be deleted.

Changes to this policy

This policy may be changed at any time. We will post a new updated version with a new effective date.

How to contact us

Thanks for reading! If you would like to contact us with inquiries (especially regarding your data), you can reach out to us at inquiries@aram.sh. If you have a general concern or comment about the service, you can reach out to us at student@aram.sh.

This policy is governed by the laws of the State of Washington, USA.