Privacy Policy

Last updated: September 25, 2026

1. Introduction

Substitute Management System ("we", "us", "our") provides a web-based platform that helps school districts manage teacher absences, substitute assignments, and related communications. This Privacy Policy explains what information we collect, how we use it, and the choices you have, including when you connect a Google account to the platform.

2. Information We Collect

  • Account information: name, email address, phone number, and role (teacher, substitute, school admin, district admin) for users invited to the platform.
  • Absence and assignment data: absence dates, times, type, grade levels, content areas, special instructions, and lesson plan notes entered by teachers and administrators.
  • School and district information: district and school names, settings, and configuration.
  • Google account information (only if a district administrator chooses to connect Google) — see Section 3 below.

3. Google User Data

A district administrator may optionally connect a Google account from their district settings page to enable calendar sync, email delivery, and AI-generated lesson plan documents. When you connect a Google account, we request the following Google API scopes:

  • Gmail send (gmail.send) — used only to send absence/assignment notification emails from the connected district Gmail address. We cannot read, delete, or otherwise access your mailbox.
  • Google Drive (drive) — used to create a dedicated "Lesson Plans" folder, upload AI-generated lesson plan documents, copy a district-provided lesson plan template, and set sharing permissions on documents created by the platform.
  • Google Calendar (calendar) — used to list the connected account's calendars and to create, update, and delete calendar events representing teacher absences and substitute assignments.
  • Google Docs (documents) — used to create and edit Google Docs containing AI-generated substitute lesson plans.
  • Email address (userinfo.email) — used to display which Google account is connected and as the sender/reply-to address for notifications.

How this data is used: Google user data obtained through these scopes is used solely to provide the district's requested features described above — sending notification emails, syncing absence events to a calendar, and generating/storing lesson plan documents. We do not use Google user data for advertising, do not sell it, and do not share it with third parties except as strictly necessary to provide these features (see Section 4).

Storage and security: Google OAuth access and refresh tokens are encrypted at rest in our database and are only decrypted at the moment of use to call the relevant Google API on the district's behalf.

Revoking access: A district administrator can disconnect their Google account at any time from the district settings page. Disconnecting immediately deletes the stored tokens from our database. You can also revoke access at any time from your Google Account permissions page.

Substitute Management System's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Third-Party Services

  • Google APIs (Gmail, Drive, Calendar, Docs) as described in Section 3.
  • Google Gemini API: if a district enables AI lesson plan generation and provides their own Gemini API key, lesson context (teacher name, school name, grade/subject, topic, and notes) is sent to Google's Generative Language API to generate lesson plan text, which is then saved as a Google Doc in the district's own Drive.
  • Push notification and email providers used to deliver in-app and email notifications about assignments.

5. Data Retention

We retain account and absence/assignment data for as long as a district's account is active, or as needed to provide the service. Google OAuth tokens are retained only until a district disconnects Google or revokes access, at which point they are deleted.

6. Data Security

We use industry-standard measures to protect information, including encrypted storage of sensitive credentials (such as Google OAuth tokens), encrypted connections (HTTPS), and role-based access controls limiting who within a district can view or manage data.

7. Your Choices

District administrators can disconnect Google integration at any time. Users may contact their district administrator to request access, correction, or deletion of their account information.

8. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date at the top of this page.

9. Contact Us

If you have questions about this Privacy Policy or how your data is handled, please contact us at support@substituteapp.com.