This page is written to be pasted into a procurement form. What we collect, where it lives, what is deleted and when, and the list of every third party that touches the data. If something you need is not answered here, email privacy@classbreak.app and a human replies.
Most classroom tools ask schools to upload student rosters and then promise to protect them. ClassBreak removes the risk instead of managing it: live games are joined with a self-chosen display name on the student’s own device, so there is no roster to breach, subpoena or misconfigure.
Premium game and course media is released only through an authenticated server endpoint that checks the teacher’s subscription on every request and answers with no-store caching. The full paid library is never compiled into the public site, so it cannot be scraped out of the page source.
Wellbeing check-ins are stored under the individual teacher’s account and shown only to that teacher. They are not aggregated into school dashboards and are not visible to leadership. A teacher’s reflections on a hard week belong to the teacher.
Database security rules block clients from deleting user documents; destructive operations run only through authenticated server routes. Public endpoints (contact, demo requests, newsletter) are rate-limited and spam-trapped.
This is the complete list. Each provider processes data only to run the service described, under its own data processing terms.
Student display names and live room state exist only for the session. An automated daily job deletes room records older than 24 hours. There is nothing to request deletion of, because nothing persists.
A teacher can delete their own account from Settings. The deletion runs server-side: it cancels any active Stripe subscription, then permanently removes the account record and every activity record under it (sessions, plans, preferences, course progress and wellbeing logs), then removes the login itself. This happens at the time of the request, well inside the 30-day window our Privacy Policy commits to.
A designated safeguarding lead or IT director at a partner school can request an export of all data held for their institution, teacher account suspension, or full deletion. Email privacy@classbreak.app.
Email privacy@classbreak.app for data processing agreements, vendor security questionnaires or data export requests. Safeguarding queries from designated leads are answered within 2 business hours.