STEM Builder

Trust & Privacy

Schools trust us with students — we treat that as the most important feature we ship. Here's exactly how STEM Builder handles student data, in plain language.

Our commitments

No trackers. No third parties on student pages.

Student pages load no analytics, advertising pixels, session recording, error-reporting tools, third-party fonts, or outside scripts. Every request a student's browser makes goes to STEM Builder's own domain, and no AI service ever sees student work. The one exception is a student who chooses “Sign in with Google,” which takes them to Google for that single step.

FERPA & COPPA-aligned

STEM Builder is designed for schools from the ground up. Student accounts are minimal by design, teachers and schools stay in control of class data, and our onboarding is built around child-privacy requirements — not retrofitted for them.

No ads. No data sales. Ever.

There is no advertising anywhere on STEM Builder, and we never sell student data or use it for marketing. Student information exists for one purpose: running your class.

Class codes need no email

Students who join with a class code use a username and a password — no email address, no contact information. Students are never asked for more personal information than the class needs. When a school syncs a roster from Google Classroom, the school provides student names and school email addresses under its own agreement with us.

Data minimization by default

We collect the minimum needed to run a classroom: a display name, a username, class membership, and the work students create. If we don't need it to make the tools work, we don't collect it.

Deleted means deleted

When a teacher or school deletes a student, a class, or an account, it disappears from the app immediately and is permanently purged within 30 days by an automated, logged process. Deleted data never lingers.

School data stays isolated

Each school's and district's data is separated with database-enforced access rules — isolation is enforced at the data layer, not just in application code.

Stored in the United States

Student data is stored on infrastructure located in the United States.

For districts: NDPA-ready

We're prepared to sign a data privacy agreement with your district, including the National Data Privacy Agreement (NDPA). Request our DPA at privacy@stembuilder.io.

Questions?

Privacy questions from teachers, parents, or district staff are always welcome: privacy@stembuilder.io.

Subprocessors

These are the infrastructure providers that help us run STEM Builder. Each one processes data only to provide its service to us.

ProviderPurpose
VercelApplication hosting; as the web server it receives every request (including IP addresses) and keeps standard request logs for a short period
SupabaseDatabase (US) holding accounts, classes, and student work
GoogleOptional “Sign in with Google” and Google Classroom roster sync — only when a teacher or school chooses to use them
ResendTransactional email (account and verification messages)
StripePayment processing for paid teacher plans, on Stripe's own checkout pages — no student data

Ready to see your students build?

It takes about a minute to get started — free, no credit card required.