Student data collection & retention
Contact legal@yflp.org about privacy, student records, or suspected exposure. For school records, include the school name and request type; do not email passwords, financial account numbers, or sensitive student documents.
Who can create an account?
Adults and teens can register directly and confirm their email. The age screen appears before name and email fields. School/class codes are optional for account creation; school membership requires actual approved access.
Under-13 accounts use the public parent or school authorization process. An adult initiates consent without providing child account details. After independent verification and review of the signed parent form or appropriate school educational authority and direct notice, the platform owner issues an email-bound, one-use authorization. Signup checks it before showing child account fields. It must be used within seven days. School authority authorizes only the reviewed school. Public curriculum and fictional financial tools remain available without an account.
Collection is closed by default
The platform owner must publish the actual operator identity, phone and mailing address and record a review of the school agreement, family notices and lawful authority, security and service providers, retention schedule, and deletion procedure. Review references point to securely held evidence; a checkbox or a reference alone does not establish compliance. Collection outside Illinois is currently disabled pending a jurisdiction-specific review.
Approved reviews have a collection end date within one year and a deletion date no later than 30 days afterward. Collection can be paused. Database checks enforce these restrictions on student codes, memberships, rosters, submissions, reviews, guided participation/answers/journal notes, and family links. A stop-collection request blocks further student collection and remains in effect after the request is fulfilled.
Information used for the service
| Information | Purpose & access |
|---|---|
| Email, short display name or school alias, age range, policy acknowledgement | Sign-in and school access. We ask for age range, not a birth date. Authentication services process account credentials; passwords are not shown to teachers. |
| School membership, role, class enrollment, assignment responses, progress and teacher feedback | Provide school learning and authorized review. Authorized staff see records within their assigned permissions; responses are not publicly published. |
| Guided lesson participation, comprehension responses, and journal notes | Teachers manage authorized class sessions and see submitted answers. Journal notes are visible to the student in the learning workspace; verified privacy exports include them. School membership deletion cascades to remove guided answers, participation, and journal notes under the existing retention workflow. |
| School-issued parent links | Share permitted progress and feedback with a linked guardian. Parent authority must be verified through the school. |
| Organization applications, staff contacts, privacy requests and administrative audit records | Verify organizations, administer permissions, respond to requests and investigate access issues. Platform owner access is restricted. |
| Service-provider security and infrastructure logs | Operate and secure hosting and authentication. Provider settings, contracts, backup retention and subprocessors must be reviewed before student collection is opened. |
Keep learning data limited
Use fictional financial amounts and a first name or school alias. Do not submit bank details, Social Security numbers, home addresses, medical information, or actual family income. Lesson answers are limited to 2,000 characters each and a bounded total size. These limits reduce collection; they cannot detect every sensitive detail.
The current app has no advertising or optional analytics cookies. Student information is for the educational service, not sale, targeted advertising, or unrelated commercial profiling. Do not use assignments to collect protected survey information about families. Any new use, integration, or data category requires an additional notice and legal review before collection.
Retention and deletion
| Records | Current rule |
|---|---|
| School student responses, feedback, rosters, memberships, family links and student signup codes | Daily cleanup deletes covered live database records when the school review’s deletion date is reached, no later than 30 days after collection ends. It also removes student-specific audit entries in that school. |
| Youth account identity without active memberships | Cleanup removes eligible youth accounts with no active memberships or recent sign-in after 30 days, subject to dependency checks. Linked learning records are removed through the school schedule first. Owner and staff accounts are protected from this cleanup. |
| Cleanup monitoring records | Counts and timestamps, without student names or responses, kept for 90 days. |
| Adult accounts, organization records and verified request evidence | Managed according to their ongoing purpose and the documented operating schedule. A deletion request requires verified fulfillment, not just a status change. |
| Provider backups/logs, school exports and copies outside this database | Not erased by the database job. Contracts and operating procedures must establish their deletion or expiry, verify fulfillment, and preserve only legally necessary records. |
The scheduled job runs daily at 08:15 UTC; deletion is therefore subject to the next successful run. The platform owner can inspect the latest run and invoke due cleanup. Failed jobs must be investigated. Do not treat the schedule as proof that all provider copies have been erased.
Child consent and request retention
Child authorizations expire within one year with deletion scheduled within 30 days afterward. Expired authorization blocks collection and daily cleanup deactivates memberships/revokes sessions; the deletion job removes eligible child identities and their live learning data by the scheduled date. Unused signup authorizations lose their child email after seven days. Unverified parental-consent contact expires after seven days. Other requests retain their original receipt date while verification and legal deadline handling continue. Closed/denied/withdrawn request contact is removed after 90 days; minimal consent evidence references are retained while the authorization supports an account and removed after its purpose ends under the scheduled process. Signed documents outside this database require the documented evidence schedule.
Family rights and requests
Ask the school or legal@yflp.org to review, correct or delete a child’s records or stop further collection. We must verify identity and authority without asking for unnecessary information. Signed-in users can export their own learning records and submit a request below. Administrators must record identity verification and a completed action before closing a request; closing it does not itself perform deletion.
Your privacy requests
Sign in to submit a requestLegal basis and operating responsibilities
School use requires an appropriate agreement, authority, notices, and controls. YFLP’s technical safeguards do not replace those obligations or establish compliance with every law. Student collection stays restricted until the operator completes the applicable review. New states, countries, ages, or uses require another review.
- COPPA Rule, 16 CFR Part 312: covered under-13 services require applicable notice, consent, security and limited retention. Under-13 collection requires verified authorization before account creation.
- U.S. Department of Education FERPA guidance: school-official arrangements require school control and restrictions on use and redisclosure.
- Illinois SOPPA operator duties: review written agreements, permitted educational uses, security and deletion requirements.
- PPRA guidance: review restrictions on protected student surveys and family information.
The operator must also maintain a written security and incident-response program, review vendors and backup retention, assess applicable breach-notification duties, monitor the legal mailbox, and obtain qualified review of actual agreements and practices. These are ongoing operating tasks.
