YFLP help · How-to guides

Privacy, records & safe use

Keep school data safe and request access, correction, or deletion.

Updated October 4, 2026

Use fictional financial examples

Never enter passwords, real bank details, card numbers, Social Security numbers, or unnecessary identifying information in lesson responses or practice tools. Student work is private and limited by account permissions. Read Student & family privacy, Privacy Policy, Terms, and the Cookie Notice for current notices.

Before real student onboarding

Under-13 accounts require verified parent or school authorization. Student collection stays closed until the platform owner records an Illinois school privacy review with actual operator contact details, school agreement, family notices, security/vendor review, and retention/deletion evidence. Collection approval expires within one year; daily cleanup removes covered records by the agreed deletion date. Use /legal/parent-consent for consent, /legal/requests for records and withdrawal, /legal/school-packet for printable family forms, and /legal/workflows for instructions. Public forms do not require sign-in; records and account actions require independent verification. Contact legal@yflp.org. The school and operator must establish appropriate authorization or verified parental consent, notices, agreements, permitted educational uses, retention/deletion procedures, and incident response before collecting real student data. A signup checkbox or access code does not replace these preparations or certify legal compliance.

Request your information

Open Settings → Your privacy requests. Download my account data provides your account information, memberships, your own attempts, and reviews visible to you. Choose an access, correction, deletion, or stop-collection request and submit. For a child’s records, contact the school or published privacy contact so authority can be verified.

What a request does

The request queue tracks pending, acknowledged, and closed requests. A request or status change does not automatically delete or correct data. The operator verifies identity, coordinates with the school, carries out the actual action, and records verified fulfillment before closing the request. A stop-collection request continues blocking student collection after closure. Deactivating a membership also preserves records; it is an access change, not deletion.

Keep accounts and exports safe

Use a unique password and sign out on shared devices. Share codes privately and revoke exposed codes. Restrict staff permissions and deactivate access when staff leave. Store exported CSVs securely. Necessary sign-in cookies must be allowed for account access; current notices describe no optional advertising or analytics cookies.

Your verified membership determines access. Instructions describe the current platform; school policies may add requirements.