The safest student data is the data we never collect.
This page is written to be pasted into a procurement form. What we collect, where it lives, what is deleted and when, and the list of every third party that touches the data. If something you need is not answered here, email privacy@classbreak.app and a human replies.
Privacy as architecture, not as a promise.
Most classroom tools ask schools to upload student rosters and then promise to protect them. ClassBreak removes the risk instead of managing it: live games are joined with a self-chosen display name on the student’s own device, so there is no roster to breach, subpoena or misconfigure.
Premium game and course media is released only through an authenticated server endpoint that checks the teacher’s subscription on every request and answers with no-store caching. The full paid library is never compiled into the public site, so it cannot be scraped out of the page source.
Wellbeing check-ins are stored under the individual teacher’s account and shown only to that teacher. They are not aggregated into school dashboards and are not visible to leadership. A teacher’s reflections on a hard week belong to the teacher.
Database security rules block clients from deleting user documents; destructive operations run only through authenticated server routes. Public endpoints (contact, demo requests, newsletter) are rate-limited and spam-trapped.
Exactly what we hold, by who it belongs to.
- Name, email address and school name, provided at signup.
- Password, if used, stored only as a hash by Firebase Authentication. Google sign-in shares only name and email.
- Activity records the teacher creates: which games were run, how many student devices joined, session plans, course progress, and optional class labels the teacher types themselves.
- Wellbeing check-ins a teacher chooses to log. These are stored under that teacher’s own account and are visible only to that teacher, never to school admins or other staff.
- No student accounts exist anywhere in ClassBreak. There is nothing for a student to sign up to.
- To join a live game, a student enters a self-chosen display name on their own device. No login, no email, no age, no lasting identifier.
- Live game data (the room, display names and any anonymous wellbeing taps) is deleted by an automated daily job within 24 hours of the session.
What ClassBreak cannot hold.
Every third party that touches the data.
This is the complete list. Each provider processes data only to run the service described, under its own data processing terms.
How data leaves the system.
Student display names and live room state exist only for the session. An automated daily job deletes room records older than 24 hours. There is nothing to request deletion of, because nothing persists.
A teacher can delete their own account from Settings. The deletion runs server-side: it cancels any active Stripe subscription, then permanently removes the account record and every activity record under it (sessions, plans, preferences, course progress and wellbeing logs), then removes the login itself. This happens at the time of the request, well inside the 30-day window our Privacy Policy commits to.
A designated safeguarding lead or IT director at a partner school can request an export of all data held for their institution, teacher account suspension, or full deletion. Email privacy@classbreak.app.
DPAs, security questionnaires and procurement forms.
Email privacy@classbreak.app for data processing agreements, vendor security questionnaires or data export requests. Safeguarding queries from designated leads are answered within 2 business hours.