Privacy Policy
YFLP provides financial education and school learning workspaces. This notice describes the current platform. School use also depends on the school’s agreements, notices, and applicable student privacy requirements.
Information we use
Accounts include email, display name, account purpose, an age range for new independent signups, and policy acknowledgments. An access code supplied during signup is kept with the account while email confirmation is pending and cleared from the account profile after an activation attempt. Approved code use is logged for school administration. School records include organization memberships, classes, assignments, responses, progress, teacher reviews, guided lesson participation and answers, personal journal notes, and linked parent access. Organization applications include the details supplied by applicants. Authentication, security, and hosting providers also process technical information such as connection and service logs.
Why we use it
We use information to sign you in, control authorized access, deliver lessons and feedback, administer organizations, respond to privacy requests, and protect the service. Financial activities use fictional scenarios. Do not enter bank credentials, payment card details, Social Security numbers, or actual financial account numbers.
Who can see school records
Authorized school and district staff see records within their permissions. Teachers review their assigned classes. Linked parents see the progress shared for their linked child. Platform administrators administer the service and review applications. Student submissions are not public. Assigned teachers can review guided lesson answers and participation; students’ personal journal notes are not shown in teacher workspaces. Verified privacy requests can include both.
Service providers and advertising
Supabase provides account and database services; Sites and its hosting infrastructure deliver the website. These services necessarily process data to operate the platform. YFLP’s application does not include advertising, data sales, behavioral advertising, or optional analytics trackers. We do not use student work for marketing. Any new data use or provider requires a policy and agreement review before introduction.
Children and school authorization
Adults and teens aged 13–17 can register and confirm their email. Under-13 accounts require reviewed parental or school authorization before account details are collected. An adult starts the public consent process; a signed parent return or documented school educational authority, independent identity/authority verification, direct notice and platform review precede a one-use email-bound signup authorization. School authority is limited to the reviewed school educational purpose. A checkbox, receipt or class code is not verified consent. School student collection also requires a separate school agreement, security/vendor, notice and retention/deletion review.
Parent & school consent · Direct notice & printable forms · How verification works
Access, correction, deletion, and stopping collection
For school records, contact your school administrator or parent/guardian first. Signed-in users can submit a request below; a platform administrator must verify identity and authority, coordinate with the school, and carry out the appropriate action. Request status is administrative tracking and does not automatically delete records. Parents may contact the operator to request review, deletion, or an end to further collection of their child’s information.
Submit records or privacy request without signing in
Your privacy requests
Sign in to submit a requestRetention and security
Access uses secure session cookies and database permissions. Organization access can be suspended and memberships deactivated. School student collection stays closed until a platform review records the signed agreement, family notices, security and vendor review, retention schedule, and deletion procedure. Collection ends at the agreed review expiry. Daily cleanup removes covered school student records by the agreed deletion date, no later than 30 days after collection ends. Eligible youth accounts without active memberships and no sign-in for 30 days are removed after dependency checks. Child authorizations expire within one year and have a deletion date within 30 days after expiry. Unverified consent contact expires after seven days; fulfilled/denied request contact is removed after 90 days. School exports and provider backup/log deletion require the documented operational process. See the data practices notice for the scope and limitations. We cannot promise absolute security. Suspected exposure should be reported to the school and operator promptly.
Data inventory, retention & collection controls
Changes
We will update the date of this policy when practices change. Material changes affecting children’s data require an appropriate notice and authorization review before the changed use begins.
Operator & privacy contact
legal@yflp.orgPublic operator contact details have not been completed. Contact your school administrator for school records. Student collection stays closed until the platform owner publishes the actual operator name, phone and mailing address as well as the legal contact.
