VED
Trust & Verification OS · Procurement
VettED — Round 1 Privacy Triage
Flint
Round 1 · Privacy Triage · VettED Privacy Triage (Avenues-derived) — Round 1 · assessed
🟠 Insufficient Evidence — Round 2 required
Privacy score 60.0% · band Average
3 mandatory gates are unaddressed in the privacy policy (Q1 (Data Collection); Q5 (Data Sharing); Q11 (Data Safety)) — more than we tolerate at triage. No violation found, but silence can't earn a pass; escalate these specific items to Round 2.
Unaddressed gate(s): Q1, Q5, Q11 — not covered by the public policy. Confirm before relying on this.

Dimension scorecard

DimensionScore
Data Collection GATE
15.0%
Data Sharing GATE
50.0%
Data Sold GATE
100.0%
Data Rights GATE
73.3%
Data Safety GATE
0.0%
Ads & Tracking GATE
100.0%
Parental Consent
100.0%
School Purpose
100.0%
AI & Model-Training GATE
50.0%
Jurisdiction & Residency
100.0%

Findings — 18 questions, every answer cited

Data Collection
Q1Does the vendor limit collection/use of information to only data required for the product? GATE
? Not addressed T0
Answer: Unclear
Policy does not explicitly state whether collection is limited to data required for the product.
Q2Does the vendor collect PII beyond what's necessary for the stated educational purpose?
✗ Concern T3
Answer: Yes
“The personal information we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use. The personal information we collect may include the following: names, email addresses, google profile picture, location, Professional Contact Details (such as workplace name, workplace title, and work address), phone number, usernames, passwords, chat history with our AI chatbots”
Collects multiple categories of PII including location, profile pictures, and chat history beyond minimal educational necessity.
Q3Is any image of the user collected?
✗ Concern T3
Answer: Yes
“The personal information we collect may include the following: names, email addresses, google profile picture”
Explicitly collects google profile picture.
Q4Does the vendor collect precise geolocation data?
✗ Concern T3
Answer: Yes
“We collect location data such as information about your device's location, which can be either precise or imprecise. How much information we collect depends on the type and settings of the device you use to access the Services. For example, we may use GPS and other technologies to collect geolocation data that tells us your current location (based on your IP address).”
Explicitly collects precise geolocation via GPS.
Data Sharing
Q5Does the vendor limit data sharing with third parties to the purpose for which it was collected? GATE
? Not addressed T0
Answer: Unclear
Policy does not explicitly state whether data sharing with third parties is limited to the original purpose of collection.
Q6Does the vendor impose contractual limits on how third parties use shared personal information? GATE
✓ Good T3
Answer: Yes
“We have contracts in place with our third parties, which are designed to help safeguard your personal information. This means that they cannot do anything with your personal information unless we have instructed them to do it. They will also not share your personal information with any organization apart from us. They also commit to protect the data they hold on our behalf and to retain it for the period we instruct.”
Policy states contractual limits on third-party use.
Data Sold
Q7Does the vendor sell or rent users' personal information to third parties? GATE
✓ Good T3
Answer: No
“Student Personal Data and Student-Created Content will not be used for marketing purposes without prior consent, and will not be disclosed or sold to third parties or business partners.”
Explicitly states student data will not be sold to third parties.
Data Rights
Q8Do the student / educator / parent / school retain ownership of data and IP of uploaded content? GATE
✓ Good T3
Answer: Yes
“Schools own all personally identifiable student information, including name, ID number, and photo, as well as all Student Personal Data and Student-Created Content.”
Explicitly states schools own student data and content.
Q9Can the user delete all of their PII and personal information from the vendor?
✓ Good T3
Answer: Yes
“You have the right to request that Flint erase your personal data, under certain conditions. If you make a request, we have one month to respond to you. Upon your request to terminate your account, we will deactivate or delete your account and information from our active databases.”
Users can request deletion of PII.
Q10Does the vendor auto-delete data after a defined period of inactivity (data sunset)?
✗ Concern T3
Answer: No
“Flint will keep your personal identification information and chat history for the duration necessary to fulfill the purposes outlined in this notice. Once this time period has expired, we will delete your data by securely erasing digital records and sanitizing any related storage devices.”
Policy states data is kept 'as long as necessary' but does not specify automatic deletion after defined inactivity period.
Data Safety
Q11Can students contact or interact with UNKNOWN users (strangers / the general public) in environments NOT supervised by a teacher or school? (Teacher-managed or within-class interaction, and content-only sharing, do NOT count.) GATE
? Not addressed T0
Answer: Unclear
Policy mentions 'enable user-to-user communications' and that students can 'communicate with you within our Services' but does not explicitly describe whether students can contact unknown/public users without teacher supervision.
Ads & Tracking
Q12Does the vendor display behavioral or targeted advertising to students inside the product? (Sending product/marketing emails to account holders does NOT count.) GATE
✓ Good T3
Answer: No
“Student Personal Data and Student-Created Content will not be used for marketing purposes without prior consent, and will not be disclosed or sold to third parties or business partners.”
Policy explicitly states student data will not be used for marketing/advertising purposes.
Q13Does the vendor share students' personal information with third parties for third-party advertising or ad-targeting? GATE
✓ Good T3
Answer: No
“Student Personal Data and Student-Created Content will not be used for marketing purposes without prior consent, and will not be disclosed or sold to third parties or business partners.”
Policy explicitly states student data will not be shared with third parties for advertising.
Parental Consent
Q14Does the vendor limit collection for children aged 13 or under, or require parental/school consent?
✓ Good T3
Answer: Yes
“With their Parents' consent, Students under the age of 13 can sign up for and use our services. We work with Schools to protect Student Personal Data consistent with COPPA and FERPA.”
Requires parental consent for children under 13 and complies with COPPA.
School Purpose
Q15Does the vendor state the product is intended for students in preschool or preK-12?
✓ Good T3
Answer: Yes
“Users under 13 years old can sign up and use our Services with parental consent. We use student data solely for educational purposes and comply with student data privacy regulations including COPPA and FERPA.”
Explicitly states product is intended for preschool/preK-12 students.
AI & Model-Training
Q16Does the vendor use student/user data — including uploaded content — to train, fine-tune, or improve AI/ML models? GATE
✓ Good T3
Answer: No
“Data collected automatically may include information about a Student's use of our Services through our servers and in log files... This information is de-identified and aggregated to protect individual Student privacy. We do not link this automatically-collected data to a Student's personal information.”
Policy states data is de-identified and aggregated; no mention of using student data to train AI/ML models.
Q17Does the vendor disclose which AI sub-processors/models power its features and any automated decisions affecting students?
? Not addressed T0
Answer: Unclear
Policy mentions 'AI chatbots' and 'chat history with our AI chatbots' but does not disclose which AI models power features or automated decisions affecting students.
Jurisdiction & Residency
Q18Does the vendor disclose where data is stored and which privacy regimes it complies with?
✓ Good T3
Answer: Yes
“Flint securely stores your data in the United States. When Flint engages with a third-party data processor (Processor), it will require any Processor to protect Customer Data to the standard required by Applicable Data Protection Laws, such as including the same data protection obligations referred to in Article 28(3) of the GDPR, in particular providing sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the processing will meet the requirements of the GDPR; and require any appointed Processor to agree in writing to only process data in a country that the European Union has declared to have an "adequate" level of protection; or to only process data on terms equivalent to the Standard Contractual Clauses.”
Discloses storage location (United States) and compliance with GDPR, COPPA, FERPA.

Jurisdiction & residency — Nord Anglia footprint

Vendor named 1 of 11 Nord Anglia countries. Shown alongside the verdict, not folded into the score — a vendor can be strong on privacy yet leave residency gaps for specific countries.
“Flint securely stores your data in the United States. When Flint engages with a third-party data processor (Processor), it will require any Processor to protect Customer Data to the standard required by Applicable Data Protection Laws, such as including the same data protection obligations referred to in Article 28(3) of the GDPR... We work with Schools to protect Student Personal Data consistent with COPPA and FERPA.”
CountryPrivacy lawCoverage
MexicoLatAmLFPDPPP⚠ Gap
Costa RicaLatAmLaw 8968⚠ Gap
PanamaLatAmLaw 81/2019⚠ Gap
Dominican RepublicLatAmLaw 172-13⚠ Gap
BrazilLatAmLGPD⚠ Gap
ColombiaLatAmLey 1581/2012⚠ Gap
EcuadorLatAmLOPDP (2021)⚠ Gap
PeruLatAmLaw 29733⚠ Gap
ChileLatAmLaw 21.719⚠ Gap
UruguayLatAmLaw 18.331⚠ Gap
United StatesFERPA / COPPA✓ Named
GDPR (overlay)Nord Anglia is UK-headquartered, global✓ Named
Advisory only. Round 1 reads the vendor's public privacy policy — a T3 (self-asserted, unverified) source. This is a triage signal, not a final verdict or legal advice. An explicit gate violation is a hard no; silence routes to Round 2, it never fakes a pass. A human reviews and signs off.
Reviewed by: __________________________ Date: ____________