Data Privacy at Acumen

What we do to protect the data of the students and professionals who use Acumen, and how the platform fits within FERPA — in plain language, for anyone evaluating Acumen.

Acumen is an AI-native platform for developing professional judgment in accounting and finance, built by a CPA and former FASB staff member on faculty at BYU. Because Acumen works directly with the coursework, submissions, and grades of the students and professionals who use it, protecting that data is a first-order design constraint, not an afterthought.

The short version

  • Submitted work is used only to grade, coach, and support your course or cohort — never sold, never used for advertising, never used to train a third party’s general-purpose AI model.
  • AI grading runs through Anthropic’s Claude API, which does not train its models on submitted work by default.
  • Data is encrypted in transit and at rest, and access is scoped so students and professors only see what they’re authorized to see.
  • Acumen is built to operate within FERPA’s “school official” framework — data isn’t sold, shared, or repurposed, and a full written designation is available via Acumen’s Data Privacy Addendum whenever your institution is ready to formalize it.

What data does Acumen touch?

Four kinds. Roster and account information — name, institutional email, class enrollment. Submitted coursework — memos, case analyses, and Discovery Case interview transcripts. Grading and feedback data — AI-generated and professor-reviewed scores and comments. And basic usage data — login and submission timestamps. That's the full list; Acumen doesn't collect anything beyond what it needs to run the class.

Does Acumen require personally identifiable information?

No — and it's designed not to. Case work is written to be answered on its own facts, without a student needing to include a real name, ID number, or other identifying detail beyond what's already in their roster record. Acumen instructs students not to add that kind of information to a memo, upload, or Judgment Coach conversation. Practically, this means most of what reaches the AI grading engine doesn't rise to the level of a FERPA "education record" in the first place — the safeguards described in the rest of this page apply regardless, but data minimization is the first and simplest one.

How does the AI grading actually work?

When a student submits work, Acumen sends the relevant text to Anthropic's Claude API, which generates a grade and feedback for that submission and returns it. Nothing more happens with that data on Anthropic's side: by default, Anthropic does not use API inputs or outputs to train its models.

One nuance worth knowing, current as of August 2026: Anthropic now retains prompts and responses sent to its most capable models for up to 30 days, purely for safety and abuse monitoring, with access restricted to a small, logged set of reviewers. That's an industry-wide shift, not something specific to Acumen, and it doesn't change the no-training policy — but we'd rather you hear it from us than discover it later.

What do Anthropic's own terms say?

Acumen's agreement with Anthropic — the Commercial Terms of Service and the Data Processing Addendum incorporated into it — makes several commitments that flow through to every institution using Acumen: Anthropic may not train models on Acumen's customer content; Acumen retains all rights to what it submits and owns the outputs it receives back; submitted content is treated as Acumen's confidential information, protected from unauthorized use, access, or disclosure; and Anthropic will not sell or share personal data, using it only to provide the service. These are contractual terms from our AI infrastructure provider, not just Acumen's own assurances — you're welcome to review them directly.

Is student data ever sold or used for advertising?

No. Acumen uses student data for one purpose: to provide, support, and improve the Service for your institution. It is never sold, never rented, never used for behavioral advertising, and never used to train a general-purpose AI model beyond the per-request use described above. The only other use is de-identified, aggregated analysis for product improvement — the kind of data that can't be traced back to an individual student.

How is the data secured?

Encryption in transit and at rest. Access controls that scope every student's data to their own enrollment, and every professor's access to their own class. A centralized authorization layer that governs every grading, rubric, and roster change. Rate limiting on the endpoints that call the AI models. These aren't aspirational — they're what's running in production today, most recently verified in an internal security review in August 2026.

Who else touches the data?

A small set of infrastructure providers, each under contract and each restricted to using the data solely to provide their service to Acumen — none of them can use it for their own purposes.

ServiceWhat it doesWhat it sees
Anthropic (Claude) — Terms · DPAPowers AI grading, feedback, and the Judgment CoachSubmitted work, one request at a time, to generate that student's output
SupabaseDatabase, authentication, file storageEverything Acumen stores — accounts, submissions, grades
VercelHosts the applicationRequests passing through; nothing persisted independently
ResendSends notification emailsName, email address, notification content
SentryAlerts us to bugs and errorsTechnical error metadata only — not student content

What happens when a course ends, or an institution stops using Acumen?

Data is retained only as long as it's needed to run the course and preserve grade history. On request, or when an agreement ends, Acumen will export an institution's data and then delete it from production systems within 30 days, aside from routine backup rotation and any short-term retention required by law or described above.

Want something more formal?

This overview is meant to answer the questions that come up before a contract is on the table. When you’re ready to move forward, Acumen has a full Data Privacy Addendum — the FERPA “school official” designation, permitted-use limits, breach notification terms, subprocessor list, and retention/deletion commitments, in contract language — for your legal or IT team to review and execute alongside your agreement.