AI assistant connector — data protection
Effective 8 June 2026
The LessonLoop AI assistant connector lets a studio connect its own AI assistant to read its LessonLoop studio data. It launches read-only: the assistant can read what the signed-in staff member can already see in LessonLoop, and cannot change anything or send messages.
Who is responsible
Your studio is the controller of your pupils' and guardians' personal data and decides to enable the connector. LessonLoop is your processor and provides the connector. When you connect an AI assistant, you engage that AI provider as your own processor — you choose it, and its terms apply to the data it receives.
What data can flow, and how we minimise it
- By default: pupil first name + last initial, instrument/grade, lesson and billing facts, and a guardian's relationship/payer status only.
- Pupil notes are never shared — in any mode.
- Full detail (surname, email, phone, guardian contact) is a separate, explicit, per-studio opt-in, confirmed in-app. Notes still never leave.
- Unknown fields are dropped, so a new data field cannot start leaking silently.
How it is protected
- The connector holds no privileged database key. It acts only as the signed-in staff member, so the database's row-level security returns exactly what that person could see — and nothing more.
- The studio is fixed at sign-in; the assistant can never name another studio.
- Sign-in uses OAuth 2.1 with PKCE; the assistant never sees your password. The connector stores only an encrypted sign-in token — no pupil data is stored in the connector.
- Every request that reads personal data is audited before it is answered; operational requests are logged on a best-effort basis. The record never stores the data itself, and every request is rate-limited. A request that reads personal data is answered only once that record has been written — if it cannot be written, the request is refused rather than answered off the record.
- A studio can disable the connector or disconnect every assistant at any time in Settings. Disabling takes effect within seconds, on every assistant already connected.
Where your data lives
All pupil and guardian personal data is stored in the EU (our database is hosted in Frankfurt). The connector stores no pupil data — only an encrypted sign-in token. The data your assistant receives goes to your chosen AI provider's account, under their terms and region.
Sub-processors
| Database & sign-in | All studio data — EU (Frankfurt) |
| Connector hosting & edge | Hosts the connector; stores only the encrypted sign-in token (no pupil data at rest) |
| Error monitoring | No personal data (diagnostics only) |
| Your chosen AI provider | Your own processor — chosen by you, not by LessonLoop |
Accuracy
The connector returns accurate studio data. We do not control the AI assistant you connect, so what the assistant says about that data is the assistant's, not LessonLoop's.
Questions about your data? Contact your studio's LessonLoop administrator or hello@lessonloop.net.
← Back