skip to main content

privacy for schools

what this product does with data, today, in plain words.

students

students never need an account, and cannot create one. a student enters a class code or opens a link, types, and sees their own result. we do not ask for a student’s name, email, birthday or student id, and nothing a student types is stored on our servers. their typing progress stays in their own browser, on their own device.

teachers

teachers may create an account with an email address and a display name. practices a teacher saves are stored on our servers under that account. the display name and the practices a teacher marks visible are shown to anyone who enters the teacher’s class code — a class code is a way to find a class, not a password, so please don’t put student names or private information in what you make visible.

we email teachers a sign-in link through Cloudflare Email, and for nothing else. the link works once and stops working after fifteen minutes; we keep only a one-way fingerprint of it, never the link itself. a signed-in teacher is remembered by one cookie for 30 days; signing out ends it on every device. there is no password to store or leak.

we also note, at most once an hour, when a teacher last used their classroom and when their class page was last opened — the date and hour only, never who opened it. this is how we know classrooms are in use.

deleting an account deletes the teacher, their class code and their saved practices, at once. teacher accounts and libraries are otherwise kept until deleted.

shared links

a shared practice link carries its own copy of the words, after the # in the address. that part of a link is never sent to any server — not ours, not anyone’s — so the words in a link never reach us, and the link keeps working even after the account that made it is gone.

what we count

to learn whether this product is used, we count anonymous events: a practice was created, shared, opened, started or finished, and a class page was opened. each count carries the practice’s content id — a fingerprint of the words, not the words — and nothing else. these counts are not shown to teachers and are kept for three months, then deleted automatically.

we do not record who: no names, no student identifiers, no ip-derived identity, no fingerprinting, no cookies beyond the one that keeps a teacher signed in, no cross-site identifiers, and no advertising of any kind. browsers that send do-not-track or global privacy control are not counted at all.

third parties

the only host a student’s browser talks to is lowkeytype.com. there are no analytics services, no advertising, no social widgets and no fonts or scripts from anywhere else. the product runs on Cloudflare, which also sends the teacher sign-in email.

what changes next

when live class sessions arrive, this page will say — before they do — what a session sends, for how long it is kept, and what a teacher can see. nothing here will be quietly narrowed.

questions

districts that need a written privacy review, or need lowkeytype.com allowed through a content filter, can write to schools@lowkeytype.com.