Legal
Privacy Policy
Syllogic is a practice management platform for independent LSAT tutors. This policy describes what we collect, who else processes it, how long we keep it, and how to have it removed. We do not sell your data or your students’ data, and we do not share it with third parties for their own purposes.
Effective August 17, 2026
1. Who controls the data
Syllogic is operated by Ethan Kent, a sole proprietor based in North Carolina, trading as Syllogic. Where this policy says Syllogic is the controller of some data, he is the controller, and hello@syllogic.io reaches him. There is no separate company: the person and the business are the same in law, which is worth knowing when you decide what to entrust to it.
Syllogic is a white-label platform. Each tutor gets their own portal, and the distinction between the two roles matters for your rights.
For tutor account data—the tutor’s own email, name, login records, and subscription—Syllogic is the controller.
For student data—student rosters, practice attempts, scores, tutor feedback, appointments, and invoices—the tutor is the controller and Syllogic is a processor acting on that tutor’s instructions. A student who wants their data corrected or deleted should contact their tutor first. If you cannot reach your tutor, write to us and we will help.
2. What we collect
We collect only what the platform needs to work. There is no advertising instrumentation, no third-party analytics script, and no tracking across other websites.
- Account information. Email address, display name, and a hashed password. Passwords travel to us over an encrypted TLS connection and are stored only as Argon2id hashes, so we never hold one in a form that could be read back.
- Session records. When you log in we store a session identifier together with the IP address and browser user-agent string that created it, so that we can investigate account misuse. Signing out revokes the session immediately, and any session expires on its own after seven days.
- Practice data. Answers to practice questions, correctness, elapsed time, self-reported confidence, and any tags, notes, or feedback a tutor records. We store question metadata and answer keys, never the copyrighted text of LSAT questions.
- Scheduling and billing records. Appointments, availability, and invoices a tutor issues to a student, including amounts and status.
- Operational logs. Request metadata, internal record identifiers, and error diagnostics used to keep the service running.
Rate limiting inspects the requesting IP address in memory to block abusive traffic. That counter is transient and is never written to the database.
We do not ask for and have no use for payment card numbers, government identifiers, or dates of birth. Card details are entered directly with Stripe and never reach our servers.
3. Who else processes it
We use a small number of subprocessors. Each receives only what its function requires.
- Amazon Web Services hosts the application and database in the US East (N. Virginia) region. All platform data resides there.
- Stripe processes subscription payments and, for tutors who enable student invoicing, payments from students. Stripe receives the email address and billing details of the paying party and handles all card data under its own privacy policy.
- Amazon SES delivers transactional email such as password resets, email verification, and student invitations.
- Axiom receives application logs and traces for monitoring and debugging. These carry request metadata and internal identifiers rather than account credentials or practice content.
We do not sell personal data, and we do not disclose it to anyone else except where the law requires it or to protect the security of the service.
4. How long we keep it
- Sessions expire seven days after sign-in and are invalidated immediately on logout.
- Account and practice data are kept for as long as the account exists, because their value to a tutor is longitudinal. They are removed on deletion, subject to the exception below. Where a record belongs to someone else and merely notes that you acted on it — feedback you wrote for a student, a tag you applied to a question — the record stays with your name taken off it, because deleting it would delete another person’s history.
- Operational logs. The application writes technical logs — request timings, error traces, and internal identifiers — to help us keep the service fast and working. On our own infrastructure those are discarded automatically after fourteen days. Copies also reach Axiom, the monitoring provider named above, and we are keeping those in place for longer while we are still adding features, because a bug reported this month is often explained by something that happened last month. They are working data for operating the software, not a record of your account: the database is the system of record, and we do not use logs as a substitute for it. We expect to adopt a shorter, fixed retention period for the monitoring copies once the product settles, and we will say so here when we do.
- Database backups are kept on a rolling fourteen-day window. Deleted records can persist in a backup until it ages out, which is why the window is shorter than the thirty days we allow ourselves to complete a deletion request.
- Invoice records. Tax and accounting law oblige a business to keep a record of a transaction for some years after the person it relates to has been removed. Deleting an account therefore leaves its invoices in place with the identifying details removed: the amount, currency, date, description, and payment status remain, and the link to the person is erased. What stays is a transaction with no one’s name on it.
5. Your rights and how to exercise them
You may request a copy of your data, correction of anything inaccurate, or deletion of your account and its contents. Depending on where you live you may also have the right to object to or restrict certain processing, and to lodge a complaint with your data protection authority.
These requests are handled by a person, not by a self-service button. Write to hello@syllogic.io from the address on the account. We will verify the request and complete it within thirty days, and we will tell you if anything must be retained under the invoice exception above.
Deleting a tutor account deletes the entire portal, including every student record inside it. Tutors should export anything they need first and should tell their students before requesting it.
6. Security
Traffic is encrypted in transit with TLS, and the database and its automated backups are encrypted at rest. Passwords are hashed with Argon2id and are never recoverable, even by us. Session cookies are HTTP-only, which keeps them out of reach of page scripts, and signing out revokes the session immediately. Every record is scoped to its tenant, and those scopes are enforced in the database queries themselves rather than in the user interface. The database is not reachable from the public internet; only the application can connect to it.
No system is perfectly secure. If you believe you have found a vulnerability, please report it to hello@syllogic.io rather than disclosing it publicly, and we will work with you on it.
7. Children and international users
Syllogic is intended for adults preparing for law school admission and for the tutors who work with them. It is not directed to children under 13, and we do not knowingly collect their information. A tutor who enrolls a minor is responsible for obtaining whatever consent applies.
The service is operated from the United States and all data is stored there. If you use Syllogic from outside the United States, you are sending your information to the United States for processing.
8. Changes and contact
If we change this policy we will update the effective date above, and for changes that materially affect your rights we will email account holders before they take effect.
Questions about this policy, or about anything we hold, go to hello@syllogic.io.