Privacy Policy
Draft — not yet in force
This is a working draft prepared alongside the platform. It has not been reviewed by legal counsel and is not yet in force. Do not rely on it.
Who we are
Code on Wheels is a Michigan-based non-profit that teaches computer science in schools and community programs. Code Meadows is the platform we use to deliver lessons and track learning. We are the controller of the information described here.
Who uses this platform
Three groups: our own staff and volunteers, parents and guardians, and learners. Learners include children under 13, so this policy is written to be read by a parent.
What we collect about a child
- ▸A name — whatever you want instructors to call them. We do not require a legal name.
- ▸Year of birth. We ask for the year only, never a full date of birth, because we need to know whether a child is under 13.
- ▸A username you choose for them. We do not ask a child for an email address and do not require one.
- ▸Which lessons they open and finish, and how long they spend.
- ▸Work they submit, along with any grade and written feedback from an instructor.
- ▸Anything they post in a lesson discussion.
We do not collect a child’s phone number, home address, photograph, or precise location. We do not use tracking cookies, advertising identifiers, or third-party analytics.
What we collect about a parent or guardian
Your name and email address, held through our sign-in provider, and a record of which children you are responsible for and what you have given permission for.
Children under 13
Before a child under 13 can use an account, we obtain verifiable parental consent. Registering online is not by itself enough: a member of Code on Wheels contacts you directly to confirm that you are the child’s parent or guardian. Until that confirmation happens the account is created but locked, and we collect nothing through it.
We ask only for information reasonably necessary to run the program. We never make a child’s participation conditional on giving us more than that.
School programs
When we deliver a program with a school under a written agreement, the school may provide the roster and consent on parents’ behalf for educational use, as permitted for education technology. We use that information only to deliver the program and report back to the school. If you would prefer we did not hold your child’s information, contact the school or us directly.
How we use it
- ▸To run lessons and show a learner what they have completed.
- ▸To let instructors see how a class is progressing and give feedback.
- ▸To show you your own child’s progress.
- ▸To report outcomes to a partner school, where a program runs with one.
We do not sell personal information, we do not share it for advertising, and we do not use it for targeted advertising or to build profiles unrelated to teaching.
Who else processes it
We use a small number of service providers to run the platform. They act on our instructions and may not use the information for their own purposes.
- ▸Convex — our database.
- ▸Clerk — sign-in for staff and parents. Children do not have accounts here.
- ▸Google Cloud — hosting and file storage, in the United States.
- ▸Resend — email to staff and parents.
- ▸Google Gemini — assists staff in preparing lesson material. Learner names and work are not sent to it.
- ▸CodeSandbox — runs code exercises inside the learner’s own browser.
Where it is held
Our hosting and file storage are located in the United States. We do not offer the platform to users outside the United States.
How long we keep it
A learner’s record, their progress, and their work are kept while they are taking part in a program, and removed when you ask us to remove them or when a school instructs us to. They are not deleted on a timer, so coursework does not disappear mid-program.
Operational logs are kept on a fixed schedule: raw webhook records for 30 days, error and page logs for 90 days, and usage accounting for 180 days. Records of who accessed or changed a learner’s information are kept for seven years, because that is the evidence we would need to answer a question about how information was handled.
Your rights as a parent
- ▸Review everything we hold about your child. The family portal will produce a complete copy on request.
- ▸Delete it. The portal removes your child’s record, progress, and work permanently.
- ▸Withdraw your permission at any time. Your child is signed out immediately and cannot sign in again until you re-authorise.
- ▸Refuse further collection while keeping what exists, by withdrawing permission without deleting.
You can exercise all of these yourself from the family portal, without contacting us.
Browsing without an account
Some programs are open to everyone. If you read those lessons without signing in, we do not create a record for you and do not track what you read.
Security
Passwords are stored using industry-standard one-way hashing. Session tokens are stored hashed, and learner sessions are short-lived because our programs run on shared classroom devices. Access to learner information is restricted by role, and changes to learner records are logged.
No system is perfectly secure. If we discover a breach affecting a child’s information we will notify the school where the program runs through one, and affected individuals as required by Michigan law.
Changes
If we change what we collect or how we use it, we will update this page and, where the change is material and affects a child, seek fresh consent rather than rely on the old one.
Contact
Questions about this policy, or about your child’s information, can be sent to Code on Wheels at [privacy contact address].