Notes for whoever writes this are in the app repo at
docs/plan/04-legal-compliance.md.
One thing that must be worded exactly right: synced work is encrypted with a key derived from the account password on the student's own device, so a database dump is unreadable. But the server does see the password at sign-in. So the honest phrasing is “we can't read a database dump” — never “zero-knowledge”, which would be a false privacy claim.