Back

How AdminCue handles data

Written to be read by a superintendent of business, a privacy officer, and a federation representative — not just by the person using the tool.

Your data is stored in Canada

All AdminCue data at rest is stored on Canadian infrastructure — the managed Postgres database runs in the Montreal region (ca-central-1), including automated backups, which stay inside that Canadian region. Nothing about your school is stored in a United States region.

Uploaded board documents never sit on a server as files

When you upload a procedure, memo, or policy file to the board knowledge library, the text is extracted and only that text is written to the Canadian database. The original PDF, Word, Excel, PowerPoint, or image file is never stored — it is discarded once the text has been read. There is no file storage bucket to breach.

AI generation and what leaves the server

Drafting, document text extraction, and calendar reading are done by Google's Gemini models, reached through the Lovable AI Gateway. What leaves the server is only what you typed into the drafting form, the board documents you explicitly selected as ground truth, and the instruction set. The gateway and the model provider operate under enterprise terms that prohibit using submitted content to train models, and no content is retained for training. Model inference itself does not run in Canada, which is why AdminCue is designed so no real student names or identifying information is ever part of what is sent — coded identifiers only, with a warning in the writing studio if a real name appears in a field.

It does not connect to your student information system

AdminCue has no Trillium, Aspen, PowerSchool, or Maplewood connection. It cannot read enrolment, marks, attendance, or IEPs. Anything about a student is there because an administrator typed it, and the interface asks for coded references instead of names.

Nothing leaves without a human approval

Every generated document sits in a draft state until an administrator approves it. The approval is recorded with a name, a timestamp, and whether the human edited the AI output. That record is the point: it is what survives a grievance, an audit, or a freedom-of-information request.

Statutory documents are fact assembly only

For behaviour incidents, progressive discipline, and anything that could become a suspension or expulsion record, AdminCue organises the facts you provide under the board's headings and stops. It will not recommend, choose, or hint at a consequence. The decision, the rationale, and the duration are yours, written by you.

It cites its ground truth

Board procedures and ministry memos are only used if your school pastes them in. When a draft leans on one, it cites it inline so you can check the source. Where a policy reference is needed but absent, it writes a visible placeholder rather than inventing a procedure number.

Retention is yours to set

Each school sets a retention window for drafts. Drafts are working documents, not the record of the school — the record lives in your board systems, where it belongs.

What it will not do

It will not give legal advice, characterise conduct as a breach of the Education Act or a collective agreement, write a teacher's professional judgement for them, rewrite report card comments, or generate scripture or prayer text presented as authoritative. Faith content is drafted for a chaplaincy or clergy review, and the interface says so.

For board IT and procurement

Data residency
Canada — Montreal, ca-central-1. Database and backups in region. No file storage bucket; uploaded documents are reduced to text on ingest.
AI provider
Google Gemini via the Lovable AI Gateway, under terms that prohibit training on submitted content. Inference is not Canadian-region; no student names or identifiers are sent by design.
Approval trail
Each document stores the AI draft, the final text, the approving administrator, the timestamp, and whether a human edited the output.
Retention
Draft retention window is set by the school in settings. Drafts are working documents; the record of record stays in board systems.
This pilot build is for evaluation. Before a board-wide deployment it needs a completed privacy impact assessment, a data processing agreement, and a named board owner for the board knowledge library.