upvote
> First, those are all verbatim quotes from the educators. They were taken directly from letters of reference (which I recently had to compile for a quite intense Technical Due Diligence for a district). They're real school leaders. They're listed plainly on the website. You can look them up online. Whether they used AI in the creation or editing of their letters, I do not know.

This feels off to me as they don't feel like real quotes given they're all very similar.

> The platform has been designed to minimize PII required. We have a very standard third-party vendor stack. Basically just OpenAI and Anthropic as frontier labs for the models, but neither is permitted to train on our data (we have Zero Data Retention agreements with those organizations). The other vendors are standard for operating the app (e.g., Supabase, Vercel). Nothing crazy here.

There are many sections in your "Privacy Snaphot" section where you don't explicitly say there is data retention. This to me feels like a convenient workaround to the other training callouts. You listed 4 vendors above yet none of that stack is called out transparently in any of your publicly facing documentation. Why? Do kids educations not deserve for parents and staff to understand where the data actually resides and how it's processed? That's the thing with technology in schools - there's always a loophole way for any company to collect and store data on kids. Their behavior, their persona, their intentions, their thoughts... We all know how egregiously Flock is being used against taxpayers. I suspect these types of learning platforms will also be used against kids in the near future and startups like Bloomy don't actually have the improvement of kids as their goal - the goal is $$$. And when you sell off Bloomy to Google or Meta, then what? You state no long term goals and you make no commitments to student, staff or parents. Those districts who trust you have no clue in how they're handing data over to you.

> Not only can users request deletion of their data -- it's standard for any user who cancels their relationship, within 30 days. You can read it right in our privacy policy.

I've read a lot of ToS and Privacy policy for companies like this. They all fall apart when you ask for proof. So... How do you prove the data is gone? I'm a parent who requests my kids account do be deleted along with the data. How do you showcase all of this? I know that, from experience, nobody puts time or effort into this because it's not a money maker. But, yes, I can read your policy. Your policy actually says nothing to the extent of giving me any sort of confidence in how you handle student data. By all means please explain.

Finally, you don't address (at all) the impact study I referenced. So where is your data coming from? Any long term studies? Or are these metrics one offs? You don't share # of students, nothing. I don't understand how you build trust with kids data that is very proximal to AI systems that have not been proven safe with respect to young children. What is Bloomy's response?

Edit: I think it would be rather interesting for Bloomy to provide free accounts to some red-teamers to really understand if what you claim is true with respect to your pipeline of protections. I have zero confidence an educator building something like this has actually thought through data protection, model protection or any of the base level considerations you need when building a tool that handles user data, let alone data of minors.

reply