Human Aspire
Last Updated: August 12, 2026
1. Purpose
This document describes Human Aspire's written information security program for the protection of personal information, with particular attention to student data governed by COPPA, FERPA, and SOPIPA.
2. Scope
This program covers all Human Aspire platforms (Lumina, Mint, Anchor It, PakoBots), supporting infrastructure, and all personnel with access to user data.
3. Data We Collect
- Student accounts — a first name or alias, educational activity records, and sign-in security records (network address, device description, and whether the attempt succeeded). Audio from read-aloud activities is converted to text and immediately discarded; no recording is retained. We collect no home address, phone number, government identifier, photograph, or precise location from a child.
- Parent/teacher accounts — email address and hashed credentials.
- Operational data — usage logs and performance metrics that may contain pseudonymized identifiers linked to accounts. Treated as personally identifiable information.
4. Program Coordination and Risk Assessment
Coordinator. Mike Aumock, Founder, is designated to coordinate this information security program and is accountable for its operation and annual review. Security questions may be directed to support@human-aspire.org.
Annual risk assessment. At least annually we identify and assess reasonably foreseeable internal and external risks to the confidentiality, security, and integrity of personal information — including student data — and evaluate whether existing safeguards are sufficient to address them. Findings are documented and drive the following year's work.
Testing and monitoring. We monitor the effectiveness of our safeguards continuously rather than relying on point-in-time review. This includes automated scanning of our software and its dependencies for known vulnerabilities, runtime monitoring of our production systems, and continuous verification that our services are reachable and behaving correctly.
Annual evaluation. This program is evaluated at least annually and modified in light of the risk assessment, testing results, material changes to our data practices, and changes in applicable law.
5. Our Commitments
- We collect only the minimum data necessary to deliver the educational service.
- Personnel access to production data follows the principle of least privilege.
- Infrastructure providers are evaluated for SOC 2 compliance before adoption.
- Student account data is purged after 6 months of inactivity, with notice to the associated organization.
- Sign-in and security records are retained for 12 months, then deleted.
- Audio from read-aloud activities is never retained; it is converted to text and discarded immediately.
- Speech-to-text and all AI processing run on hardware we operate. Student voices, writing, and conversations are never sent to an external AI provider.
- Account data is deleted within 30 days of a deletion request.
- All personnel with access to student data complete annual privacy and security training.
- Student data is never shared with third parties for advertising, marketing, profiling, or any non-educational purpose.
6. Incident Response
- Data breaches affecting student accounts trigger notification to affected organizations and parents within 72 hours of discovery, as required by COPPA and our COPPA School & Tutor Agreement.
- All incidents are documented with timeline, scope, root cause, and corrective actions.
7. Vulnerability Management
8. Program Review
This program is reviewed and updated at least annually, or whenever a material change occurs in our data practices or applicable law.
9. Contact
Email: support@human-aspire.org
Human Aspire
Broomfield, CO
human-aspire.org