PD That Works Build my cycle →
Privacy · For teachers and school leaders

What your school can and cannot see.

By Yechiel · Founder, PD That Works. Yechiel builds PD That Works — the workshops, the daily AI coach, and the monthly faculty reports — and wrote every page on this site.

A teacher who believes the principal is reading over her shoulder writes for the principal. That single fact decides whether any of this works, so the privacy boundary here is not a policy page — it is the product. This is the precise version: what a leader sees, what a leader never sees, who chooses, and how the limit is actually held.

The sentence that governs everything

School leaders cannot open teacher reflections or coach responses. Depending on the privacy mode chosen before launch, they may see either aggregate participation or named participation status. Teachers see that choice before joining.

Everything below is detail on that sentence. Nothing below contradicts it.

The two modes

A leader picks one before the cycle launches. The choice is visible to every teacher on the page where they join.

 Aggregate-onlyNamed participation
Invited / activated / active countsYesYes
Cohort engagement percentagesYesYes
Themes meeting the thresholdYesYes
Wins a teacher chose to shareYesYes
Which named teacher activatedNoYes
A named teacher's last check-in dateNoYes
The reflection, rating, goal text, or coach responseNeverNever

Named participation is a real reduction in privacy and is described that way when a leader chooses it. It answers "is anyone stuck?" — never "what did she say?" A leader in that mode can see that a teacher has been quiet for a week. They cannot see a single word she wrote.

The mode cannot change mid-cycle

Once a cycle launches, the privacy mode is frozen for its duration. This matters more than it sounds: a promise that can be revised on day 12 is not a promise, and a teacher who suspects it might be revised writes accordingly from day one. The deal a teacher sees before joining is the deal that holds for all 30 days.

Where the limit actually lives

The boundary is enforced in the database, not in the interface. Access rules sit on the tables themselves, so a leader's account is not served a teacher's reflection in the first place — there is no screen to hide, because there is no data to hide it from. A bug in a page cannot reveal what the database refuses to return.

This is a deliberate choice about what kind of guarantee to make. "We don't show it to you" is a design decision, and design decisions get revisited. "You cannot fetch it" is a property of the system.

Themes need a crowd

Patterns across a faculty are useful; a pattern of one is a name with extra steps. So nothing is synthesized at all until at least five teachers in the cohort have written, and within that, no pattern is reported unless at least three teachers' entries stand behind it.

Every draft of every theme is then checked, before a leader can see it, against a single question: could someone who knows this staff read this sentence and work out whose it is? Anything that fails comes out — not softened, not rephrased as "one teacher," not folded upward into "a few." Dropped. A cohort too small to be summarized safely produces participation data and no themes, which is the correct outcome rather than a missing feature.

Student information

Teachers are asked not to type student names or identifying details, because the coach does not need them to be useful — "a student pushed back on the question" carries the same coaching value as a name, without the risk.

As a backstop, free text is scanned locally before it is sent for processing, and email addresses, phone numbers, links, long ID numbers, and names that appear in student context are replaced with placeholders. That scan runs on our own servers using fixed rules; nothing is sent anywhere to decide whether it contains something sensitive.

The honest limit: this is defense in depth, not a guarantee. It reliably catches high-signal identifiers and it will not catch every one. The primary protection remains the instruction, and the reason to follow it is that the tool genuinely works better without the specifics.

What this product does not do

For the teacher reading this because your school just signed up

Five minutes a day, in your own words, about your own goal. Your principal sees that the faculty is participating and what the group as a whole is working on. Your writing is yours. The coach is a place to think honestly about a hard job — which only works if nobody is grading it, so nobody is.

Common questions

Can my principal read what I write?

No. Leaders cannot open reflections or coach responses in any mode. What varies by mode is participation status, not content.

Can my principal tell that I haven't checked in?

Only in named participation mode, and only that fact — when you last checked in, never what you wrote. In aggregate-only mode, inactivity appears as a cohort number with no name attached.

What happens to what I write if I leave the school?

Your account and your record travel with you, and the school's view of the cohort does not follow you. See the privacy notice for data handling, retention, and deletion.

Does the AI train on my reflections?

No. Your writing is used to produce your coaching and, above the thresholds described above, anonymized cohort themes. Our AI provider does not use our data to train its models unless we expressly permit it — we have not, and we will not. The privacy notice states the confirmed terms.

See the teacher side before you decide

A fictional sample of the private letter a teacher receives at Day 30 — the one the school never sees — shows what the record actually looks like from the inside.

Nothing goes to teachers until you approve the launch.