Draft. This describes how the product actually behaves today, but it has not been reviewed by a lawyer. Anything marked like this still needs to be filled in. Don't rely on it as a final policy until that review has happened.
Privacy Policy
Last updated September 22, 2026
The short version
Teachers and school staff have accounts. Students do not. A student joins a class with a link and a nickname, and that nickname is essentially the whole record — no name, no email address, no date of birth, no password. We sell nothing, we run no advertising, and no analytics or ad-tech vendor sits behind us. We count page views ourselves, on our own server, without cookies and without knowing who you are.
Who we are
Dabbled for Schools is operated by Equilibrium Software Solutions LLC ("we", "us"). For anything in this policy you can reach us at [privacy contact address].
What we collect
Teachers, administrators and other staff
Your email address, the name you give us (both parts are optional), a hash of your password — never the password itself — whether your email has been verified, your school and your role in it, and the date your account was created. If you are the person who set up the school, your school also carries its billing balance.
Students
A nickname, an address-bar version of that nickname, the school they belong to, a token that lets their browser be recognised as the same person next time, and a recovery code so a teacher can restore that identity on a new device. That is the entire student record. We do not ask for, and have nowhere to put, a student's real name, email address, date of birth, year group, photograph, or any roster imported from a school information system.
What people make
The description you write of the app you want, the answers you give to any follow-up questions, the app that gets built, its tags and its screenshot, any lesson notes a teacher writes, and any feedback a teacher sends us. Apps a student makes are attributed to their nickname.
Billing
Payments are handled by Stripe. Card numbers never reach our servers: what we store is the customer and payment-method identifiers Stripe gives us, the amount of each payment, and a record of each app generation and what it cost, so a school can see where its balance went.
Operational records
Ordinary server logs — requests, errors, timings. We deliberately keep personal information out of them: when the personal-information check blocks a request, for instance, the reason is shown to the person and is not written to the log.
What we don't collect
No advertising identifiers, no tracking pixels, no third-party analytics, no data brokers, no location tracking, no behavioural profiles. The site loads its typeface from Google Fonts, which means Google receives the IP address of anyone loading a page; that is the only third-party request the front end makes.
We do count page views, and we do it ourselves. The counter (Umami) runs on our own server, not a vendor's. It records which pages were opened and how often, and the browser and country they came from. It sets no cookie, stores nothing on your device, keeps no IP address, and has no way to tell that two visits were the same person. It honours your browser's Do Not Track setting, and it drops anything after the question mark in a web address, so an invite code or a prefilled form never reaches it.
How we use it
To run the product: authenticate you, build the apps you ask for, show your school its own work, bill for what was used, and email you when something needs your attention — chiefly the verification link when you sign up. We do not use anything from your school to advertise to you or to anyone else.
Who else sees it
- Anthropic — the app descriptions and existing app content are sent to Anthropic's API to build and revise apps, tag them and answer questions. Content sent through the API is not used to train models.
- Stripe — payments and stored cards.
- Our email provider — the address a verification email is sent to.
- Our hosting provider — everything, in the ordinary sense that the application runs on their machines.
- Google Fonts — the IP address of anyone loading a page, as above.
That is the complete list. We do not sell, rent, license or trade personal information, and we do not share it for anyone else's marketing.
Personal information in what people write
Before an app request made through the guided builder reaches the model, it is screened for personal information — full names, addresses, phone numbers, anything that identifies a specific real person. If any is found, the build stops and asks for a reword rather than silently rewriting it, and the explanation shown never repeats the personal information back. The check fails closed: an unclear result blocks rather than passes.
[This check does not currently run on the join-link flow a student uses from a class code. Either close that gap or say so plainly here before publishing.]
Who can see an app
In a school, apps are private by default. One becomes visible outside it only when someone at the school publishes it to the public library.
In an individual workspace — a tutor, a parent, a teacher on their own — it is the other way round: everything made there is published to the public library by default, which is what that free plan gives back. That includes apps made by students who join one of its classes, and the join page says so before they type anything. Any app can be made private afterwards.
A published app is attributed to the school or workspace, never to the teacher or student who made it. Unpublishing removes it from the library, though we cannot recall a copy someone already took.
Keeping and deleting
Apps and lesson notes can be deleted in the product at any time, and deleting means deleting. Accounts, schools and student records are kept until someone asks us to remove them — write to [privacy contact address] and we will. Backups roll off on their own schedule, so a deleted item may persist in a backup for [retention window] after it disappears from the product.
Children
The product is designed so that there is nothing to collect from a child. A student is never asked for a name, an email address or a birthday, and never creates an account. We rely on the school to decide which students use it and to supervise that use, and we do not knowingly collect personal information from a child. If you believe a student has typed personal information into the product, tell us and we will remove it.
Schools and education records
Where the work a student does here forms part of an education record, that record belongs to the school. We hold it on the school's behalf and act on the school's instructions, which includes deleting it when the school says so. A school administrator can see their school's apps, classes and students; a teacher sees their own classes. [If you intend to operate as a "school official" under FERPA, that arrangement needs to be stated here and in the district agreement.]
Security
Passwords are stored as bcrypt hashes. Email verification links are single-use, expire, and are stored only as hashes, so the link in your inbox cannot be reconstructed from our database. App screenshots are served through signed, expiring links rather than public URLs. Traffic is served over HTTPS. No system is perfectly secure, and we won't pretend otherwise.
Your choices
You can see and change your own account details in the product, delete apps and notes you own, and ask us for a copy of what we hold about you or for its deletion at [privacy contact address]. If your school holds the account, we may need to route a request through your school administrator. [Add the specific rights that apply in your jurisdictions - GDPR, CCPA, state student privacy laws - once counsel has confirmed which apply.]
Changes
If we change this policy we will update the date at the top, and we will tell schools directly about any change that materially affects student data.
Questions: [privacy contact address] · Terms of Service