privacy for schools
what this product does with data, today, in plain words.
this page covers lowkey type for schools — the classroom app at schools.lowkeytype.com: shared links, class codes, class sessions and teacher accounts. the free lessons on lowkeytype.com are a separate product with their own, stricter privacy page: there, a student’s progress stays on their device.
students
students never need an account, and cannot create one. a student enters a class code or opens a link, types, and sees their own result. we do not ask for a student’s name, email, birthday or student id, and nothing a student types is stored on our servers. outside a class session, their typing progress stays in their own browser, on their own device.
class sessions
when a teacher runs a class session, each student who joins is given a generated alias — like “blue fox” — for that session and no other. while they type, we receive how far through the practice they are; when they finish, their accuracy, speed and time, and which of the practice’s words and keys gave them trouble. never what they typed, never a name. the teacher sees this by alias, and nothing links an alias to a student or to any other session.
the joining browser keeps a random key for that session, so a reload rejoins as the same alias. a session ends when the teacher ends it or after three hours, and everything it received is deleted 30 days after it ends, or sooner if the teacher deletes it or their account. because this is how the feature works rather than something we measure, it is not affected by do-not-track or global privacy control — joining a session is the choice.
teachers
teachers may create an account with an email address and a display name. practices a teacher saves are stored on our servers under that account. the display name and the practices a teacher marks visible are shown to anyone who enters the teacher’s class code — a class code is a way to find a class, not a password, so please don’t put student names or private information in what you make visible.
we email teachers a sign-in link through Cloudflare Email, and for nothing else. the link works once and stops working after fifteen minutes; we keep a one-way fingerprint of it, never the link itself. a signed-in teacher is remembered by one cookie for 30 days; signing out ends it on every device. there is no password to store or leak.
we also note, at most once an hour, when a teacher last used their classroom and when their class page was last opened — the date and hour, never who opened it. this is how we know classrooms are in use.
deleting an account deletes the teacher, their class code, their saved practices and their class sessions, at once. teacher accounts and libraries are otherwise kept until deleted.
shared links
a shared practice link carries its own copy of the words, after the # in the address. that part of a link is never sent to any server — not ours, not anyone’s — so the words in a link never reach us, and the link keeps working even after the account that made it is gone.
what we count
to learn whether this product is used, we count anonymous events: a practice was created, shared, opened, started or finished, and a class page was opened. each count carries the practice’s content id — a fingerprint of the words, not the words — and nothing else. these counts are not shown to teachers and are kept for three months, then deleted automatically.
we do not record who: no names, no student identifiers, no ip-derived identity, no fingerprinting, no cookies beyond the one that keeps a teacher signed in, no cross-site identifiers, and no advertising of any kind. browsers that send do-not-track or global privacy control are not counted at all.
third parties
a student’s browser talks to one host: schools.lowkeytype.com. every page, font and practice comes from it. there are no analytics services, no advertising, no social widgets and no fonts or scripts from anywhere else. the twenty free lessons are a separate site on a separate host, lowkeytype.com: a browser goes there when someone follows a link to them, never on its own. the product runs on Cloudflare, which also sends the teacher sign-in email.
what changes next
if this product ever needs to know more than it does today, this page will say so before it happens. nothing here will be quietly narrowed.
questions
districts that need a written privacy review, or need schools.lowkeytype.com allowed through a content filter, can write to schools@lowkeytype.com.