Privacy Policy
What we keep about students and the grown-ups who teach them, why, for how long, and how to see or delete it.
- Version
- October 4, 2026
- Students give
- No name, email or birthday
- Ads and trackers
- None
- Questions
- privacy@coolbeanstech.com
The short version
- Students never give us a name, an email, a birthday or a photo. Their teacher makes each one a login: a made-up username (like BraveOtter42) and a secret word. Or the teacher shares a class code, and students make the same kind of login and wait for the teacher to let them in.
- We keep what students build on the site, their progress and what their teacher writes to them, so their work is there next class.
- Grown-ups who run classes give their name, email, state and organization, so we know who's responsible for each class.
- No advertising, no analytics, no tracking. We never sell data or share it, and no AI service ever receives it.
- A class is deleted 12 months after its teacher archives it, students and work included. Anyone can ask us for a copy or deletion.
Students
Cool Beans Tech is built so students don't have to tell us who they are. A teacher makes their login, or shares a class code that students make their own login with. They never give a name, email, birthday, school, location or photo, and the site never asks.
A login can only be made with a class code a teacher has turned on, and it's a request to join that one class, so the class's school or program, and its permission from parents, covers it like any other. While it waits for the teacher, we keep only the login, the request and the secret word: nothing the student does is saved to it (projects work in that browser only), and it isn't in the teacher's lists or reports. Once the teacher lets them in, they're a student of the class. If the teacher turns it away, it's deleted at once; if nobody answers, it's deleted after 14 days.
| What | Exactly | Why |
|---|---|---|
| Their login | A made-up username built from word lists, when it was made, when they last signed in and the last day they were here | So they can sign in, and the teacher can see who's been here |
| A secret word | Kept scrambled (a hash) plus a locked copy only their teachers can open, and a count of wrong tries | Signing in, and keeping guessers out |
| A roster label | Initials or a seat number the teacher may add, never a real name | So a teacher can tell students apart |
| A request to join | For a login made with a class code: the class it asked to join and when, until the teacher answers | So the teacher can let them in or turn them away |
| Their work | Steps done, choices and answers on activities, the pages and projects they build, their last few tries and anything they share for show-and-tell | So work is saved and the teacher can help |
| Coaching | Their teacher's feedback and notes, a reaction to their newest work, how many hints they opened and how they feel about a session they finished | So teacher and student can talk about the work |
| A live line in class | The step they're on, a raised hand and why, and their answer to the current exit ticket. Only the current moment, overwritten as they go | The teacher's live view of the room |
| Comfort settings | Light or dark, text size, reading font, calm motion, reading aloud. Never why | So the site reads the way they like on any tablet |
A student sees their own work and what their teachers wrote to them. Students never see each other's work: show-and-tell is a student choosing to put one page on their teacher's projector. Teachers see only their own classes, never a student's comfort settings.
Never kept: real names, student emails, birthdays, photos, voices, location, device identifiers, browsing history, scores or rankings, chat between students, or any history of where a student was.
Grown-ups
Teachers, program leaders and school admins make an account to run classes. That's the only time we ask for personal details, and we ask for as few as we can.
| What | Why |
|---|---|
| First and last name | So the other teachers on your classes, and we, know who you are. Never shown to students: they see your username |
| Signing in, resetting your password, a link to check it's yours, and notices about your account. Never shown to students, never used for marketing | |
| Username and password | Signing in. Your password is held by Firebase Authentication, never by us |
| State | Which state's student-privacy law applies to you and your students |
| What you do | Teacher, program leader or school admin, so we can help the right way |
| Your organization | Its name, type and state. The type decides who gives permission for students' parents (below) |
| What you agreed to | Which version of these terms and this policy you agreed to, when, how, and the exact words you confirmed about your organization. Never your network address or your browser |
| What you did to a class | An audit line when you make, change or remove a class, a student or a co-teacher, so the program can see who did what |
We never ask grown-ups for a birthday, a phone number, a photo or a home address.
Who gives permission for students
Students are 10 to 15, so the Children's Online Privacy Protection Act (COPPA) applies. A parent or guardian's permission is needed before a student under 13 uses the site, and we ask for it the same way for every student. Who gives it depends on the organization:
- Schools and districts
- A school or district may give permission for parents when a service is used only for school (the FTC's COPPA guidance). Teachers at schools confirm their school or district has authorized them.
- Programs, camps, libraries and nonprofits
- These can't give permission for parents, so the program asks each parent or guardian first, on its enrollment form. We give programs a paragraph to paste in, and their leaders confirm they collect it.
- Homeschools
- The parent or guardian makes the account and the students' logins themselves, and confirms they're the parent.
- Education records
- In a school, students' work is an education record the school controls (FERPA). We use it only to run the class, never sell it or use it for advertising, and delete it when the school asks.
We follow Tennessee's Student Online Personal Protection Act and similar laws in other states: no targeted advertising, no profiles of students beyond their own class's learning, no selling, and deletion when a school asks.
How long we keep it
| What | How long |
|---|---|
| A student's login and work | While their class runs. Deleted 12 months after the teacher archives the class, or at once when the teacher removes the student |
| A login made with a class code, not let in yet | Deleted at once if the teacher turns it away, 14 days after it was made if nobody answers, or with its class |
| The live line in class | Only the current moment, overwritten as students go; cleared when a student is removed or the class is archived |
| Daily attendance counts (how many, never who) | Deleted with the class |
| A grown-up's account, organization and agreements | Until the account is deleted (ask us, or the program's admin deletes it). They go together, with the classes that grown-up made |
| Audit lines | One year |
| Backups the program downloads | Kept offline and deleted within 12 months of being made. They never hold secret words, comfort settings, the live line, earlier tries or logins still waiting to join a class |
| Guest progress (no account) | Only in that browser. Never sent to us |
| Counts of sign-in attempts and class codes tried per network address | Up to an hour, in the server's memory only, to slow down floods and guessing. Never saved |
Who helps us run it
These companies host the site for us. They use the data only to provide their service to us, never for anything of their own.
| Company and service | What it does | Where |
|---|---|---|
| Google Firebase Authentication | Signing in for everyone. Holds grown-ups' email addresses and passwords, and sends the email that checks an address. Students' sign-ins have no email | United States |
| Google Cloud Firestore | Stores everything else on this page | United States |
| Netlify | Hosts the site and runs its server | United States |
No advertising, analytics or AI company ever receives anyone's data. The site's fonts and icons are served from the site itself.
Seeing, fixing or deleting data
A parent, guardian, school or program can ask for a copy of a student's data, a correction (a new username or roster label) or deletion. Ask the student's teacher, or write to privacy@coolbeanstech.com. Teachers can download a student's portfolio and progress report themselves, and remove a student at any time.
Grown-ups can change their name, state and organization on their account page, and ask us to delete their account at the same address.
We answer within 30 days, usually much sooner.
Keeping it safe
Only our server reads or writes the database, and it checks who's asking on every request. Secret words are stored scrambled; after 10 wrong tries in a row, that login pauses for 15 minutes. Students' pages run in sealed-off frames that can't reach the rest of the site. If something ever goes wrong, we tell affected schools, programs and families quickly, in plain words.
Changes
This is the version of October 4, 2026. When it changes, the date here changes, and every grown-up is asked to read and agree to the new version the next time they sign in.
Contact
Cool Beans Tech · privacy@coolbeanstech.com. See also our Terms of Service.
