Skip to main content

For sponsors, principals and school IT

How StrikeLab handles student data

A plain description of how the product works today: what it stores, who can see it, where it goes and how it's deleted. It isn't a legal document; the privacy policy and terms are. Last checked against the code on October 1, 2026.

The short version

  • 13 and up. StrikeLab is built for ages 13 to 18.
  • Minimal. An email address, a display name and learning activity. No birth date, address, phone number, school ID, photos, grades or location.
  • Private by default. Nothing about a student is public unless they create a share link for their own capstone, and even that shows no name.
  • No ads, no selling data, no cross-site tracking.
  • Students can delete everything themselves, immediately, from Settings.

What's stored, and who can see it

Each rule below is enforced in the database with row-level security, and automated tests check every rule on every change.

  • Email and password (or Google sign-in)

    The student
    Yes
    Their club leader
    No
    Anyone else
    No
  • Display name (a first name and last initial is suggested)

    The student
    Yes
    Their club leader
    Yes: roster, scorecard, kickoff view
    Anyone else
    No
  • Lessons completed, XP, streak and timezone

    The student
    Yes
    Their club leader
    Lesson and track counts and last-active date only
    Anyone else
    No
  • When each assigned lesson was completed

    The student
    Yes
    Their club leader
    Yes, for students in their class
    Anyone else
    No
  • Short-lesson results (accuracy, time)

    The student
    Yes
    Their club leader
    Only whether the first short lesson was finished; never accuracy or time
    Anyone else
    No
  • Exercise code

    The student
    Yes
    Their club leader
    Yes, for students in their class
    Anyone else
    No
  • Capstone project

    The student
    Yes, including a log of every time their leader opened it
    Their club leader
    Opens it deliberately; each view is logged and shown to the student
    Anyone else
    Only through a share link the student creates: no name shown, and it stops working when sharing is turned off
  • Class membership and join date

    The student
    Yes
    Their club leader
    Yes
    Anyone else
    No
  • Weekly challenge times

    The student
    Yes
    Their club leader
    No
    Anyone else
    The leaderboard shows times only, never names
  • Paper-trading sandbox balance and trades

    The student
    Yes
    Their club leader
    No
    Anyone else
    No
  • AI tutor usage counts (not the messages)

    The student
    Yes
    Their club leader
    No
    Anyone else
    No
  • Certificates (name, track, date)

    The student
    Yes
    Their club leader
    No
    Anyone else
    Only someone the student gives the certificate link to
  • Subscription status, if a paid plan (no card data)

    The student
    Yes
    Their club leader
    No
    Anyone else
    No

StrikeLab staff (the founder) can read the database to run and support the service, and does so only for support, debugging and aggregate pilot numbers. Pilot reports use aggregate numbers only.

Where data goes

The services StrikeLab uses to run, and exactly what each one receives.

  • Supabase

    What for
    Database and sign-in
    What it receives
    Everything in the table above
  • Vercel

    What for
    Hosting and cookie-free, aggregate page analytics
    What it receives
    Web requests (IP address, pages visited); no account data in analytics
  • Sentry

    What for
    Error reports
    What it receives
    The error, the page, and a signed-in user's account id (no email or name)
  • Groq

    What for
    AI tutor and hints, only when a student uses them
    What it receives
    The question or code the student sends, without their name or email
  • Google

    What for
    "Continue with Google", only if used
    What it receives
    The sign-in itself
  • Stripe

    What for
    Payments; never used by students in a pilot
    What it receives
    The payer's checkout details, handled entirely by Stripe
  • Web3Forms

    What for
    Newsletter sign-up, only if used
    What it receives
    The email address entered
  • jsDelivr

    What for
    Backup source for the in-browser Python runtime, only if strikelab.dev's own copy fails
    What it receives
    A normal file download (IP address); no account data
  • Discord

    What for
    Only if a student connects their own server's webhook
    What it receives
    Lesson and achievement names posted to that server

Cookies and browser storage

  • Sign-in session cookies, plus two one-hour cookies that carry how someone found StrikeLab and whether they're a student or a leader through Google sign-in.
  • Progress and code are also kept in the browser so lessons work offline and without an account.
  • No advertising or cross-site tracking cookies.

Deletion and requests

  • Students delete their own account in Settings → Delete account. It takes effect immediately and removes every item listed above, including capstones, share links and class memberships.
  • Parents and schools can ask to see or delete a student's data by emailing hello@strikelab.app.
  • How long pilot data is kept is agreed with each school or club in its pilot agreement.

Security basics

  • Every table has row-level security turned on, and the rules are tested automatically on every change.
  • Joining a class needs the class's invite code and an account. Joining, creating classes, saving and sharing capstones, and deleting accounts are rate-limited.
  • Leaders see only students who joined their class, and only what's listed above. Opening a student's capstone is logged, and the student can see the log.
  • All traffic uses HTTPS. Keys and passwords live in the hosting provider's settings, never in the code.

If something goes wrong

If a problem could involve student data, the affected feature is taken offline first. The club leader hears within 24 hours what happened, which data was involved and what has been done. If the school has its own process, StrikeLab follows it.

Reviewing StrikeLab for your school?

If your school or district has its own student-data agreement or approval form, email it to hello@strikelab.appand we'll go through it with you. This page is also in the pilot approval packet.