Privacy Policy
[TODO: legal entity name] - Effective date: [TODO: effective date]
Who we are and who is in charge of the data
Flux Student Directory ("Flux", "we") is a school directory service operated by [TODO: legal entity name]. Each school that uses Flux decides which parents, guardians, staff and students are in its directory. We process that information on behalf of the school; the school is responsible for the roster it enters and for deciding who may see it. This applies equally to information about children: we handle student information only to provide the directory to the school, never for our own purposes.
What information we collect
- Parents and guardians: name, email address, phone number(s), home address, optional profile photo, and which student(s) you are linked to.
- Students: name, grade or graduation year, home address (we also compute map coordinates from it), and an optional photo.
- School staff and administrators: name, email, role, and optional biography, photo and contact details they or their school choose to add.
- Things you create: your private stars, notes and custom lists, which are visible only to you.
- Responses to your school: poll answers, sign-up choices, permission slip responses and notice read-receipts.
- Account and device data: your sign-in credentials (passwords are stored only as secure hashes by our authentication provider), optional authenticator-app second factor, your time zone, and, if you turn on push notifications in the iPhone, iPad or Mac app, a device push token.
- Operational records: audit logs of administrative actions (who changed what, and when) kept for the school's accountability and security.
We do not use advertising or analytics trackers, and the web app does not set tracking cookies. Cookies we do set are strictly functional (for example, your sign-in session and which school you last selected).
How we use it
Only to run the directory for your school: showing the roster and staff directory to the people your school has authorized, sending school notices and notifications, collecting responses to polls, sign-ups and permission slips, showing maps and lunch menus, keeping your account secure, and supporting your school when it asks for help. We do not sell personal information, do not share it for advertising, and do not use it to build advertising profiles.
Who can see it
- School administrators (Senior and Junior Admins) can see their own school's full directory and manage it.
- Parents and guardians can see the school directory subject to the privacy settings each family chooses: a parent can limit their own profile so other families see only their name, and can hide their address. Your private stars, notes and lists are visible only to you, not to other parents and not to administrators.
- Flux operators cannot browse your school's data by default. They can enter a school only after a Senior Admin of that school approves a support request, the access expires automatically after one hour, requires multi-factor authentication, and every use is recorded in an audit log.
- Schools are separated from one another at the database level; one school can never see another school's information.
Where it is stored and who processes it
We use the following service providers (sub-processors) to run Flux. Each receives only what it needs for its function:
- Supabase - database and sign-in (account identity, directory data).
- Vercel - hosting of the web application.
- Backblaze B2 - file storage. Student and parent photos and attachments live in a private bucket and are shown only through short-lived links issued after an access check. School logos live in a public bucket.
- Cloudflare - content delivery for school logos only.
- Resend - sending email (registration invitations, notices, password resets, support notifications).
- Google - Maps and Geocoding (a home address is sent to turn it into map coordinates and to display the directory map) and, for lunch menu illustrations, the Gemini API (only menu text is sent, no personal information).
- Apple - push notification delivery (APNs); and, only if you choose "Continue with Apple" or "Continue with Google", Apple or Google as your sign-in provider.
Registration is by school invitation
You can only create an account if your school has added your email address to its approved list. We use that list to link your account to the right school and students.
Retention, account deletion and data export
- Deleting your account: from your Account page you can delete your account. Your access is switched off immediately; you have 30 days to change your mind and restore it, after which your account and your private notes, stars and lists are permanently purged.
- Removed students and parents: when a school removes a student or a family, the related directory data is deleted from the school's roster.
- School export: a school's administrators can export the school's directory data (roster, guardians, staff, notices, menus and more) at any time. Private parent notes, stars and lists are never included in an export.
- When a school leaves Flux: the school's data is archived and can be exported or deleted at the school's request.
- Operational audit logs are kept for as long as needed for security and accountability.
Your choices and rights
You can view and correct your own contact information, change who sees your profile and address, turn off push notifications, enable a second sign-in factor, leave a school, or delete your account at any time from your Account page. For anything else - including requests to access, correct or delete information about you or your child - contact your school administrator first, since the school controls the roster; you may also contact us using the details below and we will route or act on your request.
Security
Data is encrypted in transit, access is controlled by per-school database rules, sensitive administrative access requires multi-factor authentication, and administrative actions are logged. No system is perfectly secure; if we learn of a breach affecting your information we will notify the affected school(s) as required by law.
Children
Flux is used by parents, guardians and school staff. Students do not create accounts or sign in. Information about children is entered by their school or their parents and is used only to provide the school directory.
Changes to this policy
We may update this policy; the effective date above shows the current version. Material changes will be communicated to schools and, where appropriate, in the app.
Contact
[TODO: legal entity name]
Email: [TODO: contact email address]
Address: [TODO: mailing address]