Trust & Privacy
Schools trust us with students — we treat that as the most important feature we ship. Here's exactly how STEM Builder handles student data, in plain language.
Our commitments
No trackers. No third parties on student pages.
Student pages load no analytics, advertising pixels, session recording, error-reporting tools, third-party fonts, or outside scripts. Every request a student's browser makes goes to STEM Builder's own domain, and no AI service ever sees student work. The one exception is a student who chooses “Sign in with Google,” which takes them to Google for that single step.
FERPA & COPPA-aligned
STEM Builder is designed for schools from the ground up. Student accounts are minimal by design, teachers and schools stay in control of class data, and our onboarding is built around child-privacy requirements — not retrofitted for them.
No ads. No data sales. Ever.
There is no advertising anywhere on STEM Builder, and we never sell student data or use it for marketing. Student information exists for one purpose: running your class.
Class codes need no email
Students who join with a class code use a username and a password — no email address, no contact information. Students are never asked for more personal information than the class needs. When a school syncs a roster from Google Classroom, the school provides student names and school email addresses under its own agreement with us.
Data minimization by default
We collect the minimum needed to run a classroom: a display name, a username, class membership, and the work students create. If we don't need it to make the tools work, we don't collect it.
Deleted means deleted
When a teacher or school deletes a student, a class, or an account, it disappears from the app immediately and is permanently purged within 30 days by an automated, logged process. Deleted data never lingers.
School data stays isolated
Each school's and district's data is separated with database-enforced access rules — isolation is enforced at the data layer, not just in application code.
Stored in the United States
Student data is stored on infrastructure located in the United States.
For districts: NDPA-ready
We're prepared to sign a data privacy agreement with your district, including the National Data Privacy Agreement (NDPA). Request our DPA at privacy@stembuilder.io.
Questions?
Privacy questions from teachers, parents, or district staff are always welcome: privacy@stembuilder.io.
Subprocessors
These are the infrastructure providers that help us run STEM Builder. Each one processes data only to provide its service to us.
| Provider | Purpose |
|---|---|
| Vercel | Application hosting; as the web server it receives every request (including IP addresses) and keeps standard request logs for a short period |
| Supabase | Database (US) holding accounts, classes, and student work |
| Optional “Sign in with Google” and Google Classroom roster sync — only when a teacher or school chooses to use them | |
| Resend | Transactional email (account and verification messages) |
| Stripe | Payment processing for paid teacher plans, on Stripe's own checkout pages — no student data |
The documents
Ready to see your students build?
It takes about a minute to get started — free, no credit card required.
