Privacy Policy | Lemonade Stand Business Plan
Back to home
Student Data Privacy

Privacy Policy

Last updated: February 5, 2026

The Lemonade Stand Business Plan ("the Platform") is operated by The WE Mentality (Las Vegas, Nevada). We build entrepreneurship and career-readiness experiences for K-12 students, their teachers, and their families. This Privacy Policy explains — in plain language — what we collect, why, and the choices you have.

In one sentence:

We collect only what's needed to run lessons and show progress, we never sell student data, and parents/schools can request deletion at any time.

1. Who this policy is for

This policy applies to anyone who uses the Platform — students, educators, parents/guardians, school administrators, and visitors browsing our public pages.

2. What we collect

We try to collect as little as possible. Here's the full list:

  • Account information — name, email, and role (student, educator, parent, admin). Educators may also provide a school name.
  • Learning activity — lesson responses, quiz answers, reflections, and your Mini Business Plan as you build it. This is the actual product.
  • Optional pitch recordings — only if you choose to record one. Stored solely to score and replay.
  • Aggregate usage — anonymized counts (e.g., how many lessons were completed this week), used to improve the Platform.
  • Light technical data — IP address (for security and rate-limiting), browser type, and referring page. This auto-deletes after 30 days unless tied to a security incident.

3. What we do not collect

  • Social-security numbers, government IDs, or financial information.
  • Precise location (GPS).
  • Health, biometric, or sensitive demographic data.
  • Targeted-advertising profiles. We don't run ads on the Platform.

4. Students under 13 (COPPA)

Our Elementary pathway ("Lemonade Leaders Jr." — grades 2-5) is currently preview-only: nothing is sent to our servers, and all progress is stored in the child's own browser. We do not collect personal information from children under 13 through this experience.

For any future student accounts under 13, we will only create them with verifiable consent from a parent, legal guardian, or school acting under FERPA "school official" exception with parental notice. Schools may sign our standard Student Data Privacy Agreement on behalf of students under 13.

5. FERPA & schools

When a school or district uses the Platform, we act as a "school official" under FERPA (34 CFR § 99.31(a)(1)). That means:

  • Student education records remain under the school's direction.
  • We use student data only to deliver the service the school requested.
  • We do not disclose student data to anyone the school hasn't authorized.
  • Schools can request export or deletion at any time.

We will sign your district's Student Data Privacy Agreement on request. Email privacy@thewementality.com to start.

6. AI features & responsible use

"LemonBot" is our AI coach. It helps students think — it does not write their work for them. When a student chats with LemonBot:

  • The conversation is sent to OpenAI for processing under their Enterprise/API agreement (no training on customer data).
  • We do not store the conversation for AI-model training.
  • Educators can disable LemonBot for any class at any time.
  • We design prompts to be Socratic — LemonBot asks questions, it doesn't hand over answers.

7. How we share data

We share data only with the service providers we need to run the Platform. See our Subprocessors list for the full, current list. We never sell student data. We never share student data for advertising.

8. How long we keep data

  • Active accounts: while you're using the Platform.
  • Inactive accounts (no login for 18 months): we email you, then archive.
  • On request: we delete your account and learning data within 30 days.
  • Backups: rotated and overwritten within 90 days.
  • Aggregate usage metrics: retained indefinitely (no PII).

9. Your rights

You (or your parent/school on your behalf) can always:

  • See what's in your account (download your Mini Business Plan PDF + Workbook).
  • Correct anything that's wrong — use the in-app profile editor.
  • Delete your account and all associated data — visit /delete-account or email us.
  • Ask us a question — email privacy@thewementality.com and we'll respond within 5 business days.

10. Security

We use industry-standard practices: HTTPS everywhere, bcrypt password hashing, JWT tokens, rate-limiting against brute-force attempts, restricted access controls inside our team, and Sentry error tracking with personal-information redaction. We host on U.S.-based Emergent Cloud (Kubernetes) and MongoDB Atlas.

If we ever discover a breach affecting student data, we will notify affected schools and parents within 72 hours.

11. Cookies & analytics

We use a small set of cookies/local storage for: login sessions, language preference, and accessibility settings. We use anonymized, privacy-respecting analytics (PostHog & Google Analytics 4) to count page views — these are configured to not capture personal information.

12. Changes to this policy

If we make material changes, we'll email account holders at least 30 days before the change takes effect. The "last updated" date above always reflects the current version.

13. Contact us

The WE Mentality
Las Vegas, Nevada, USA
Privacy contact: privacy@thewementality.com

Districts & schools

We're happy to sign your district's Student Data Privacy Agreement and complete vendor-review questionnaires. Email us and we'll respond within 2 business days.