For sponsors, principals and school IT
How StrikeLab handles student data
A plain description of how the product works today: what it stores, who can see it, where it goes and how it's deleted. It isn't a legal document; the privacy policy and terms are. Last checked against the code on October 1, 2026.
The short version
- 13 and up. StrikeLab is built for ages 13 to 18.
- Minimal. An email address, a display name and learning activity. No birth date, address, phone number, school ID, photos, grades or location.
- Private by default. Nothing about a student is public unless they create a share link for their own capstone, and even that shows no name.
- No ads, no selling data, no cross-site tracking.
- Students can delete everything themselves, immediately, from Settings.
What's stored, and who can see it
Each rule below is enforced in the database with row-level security, and automated tests check every rule on every change.
Email and password (or Google sign-in)
- The student
- Yes
- Their club leader
- No
- Anyone else
- No
Display name (a first name and last initial is suggested)
- The student
- Yes
- Their club leader
- Yes: roster, scorecard, kickoff view
- Anyone else
- No
Lessons completed, XP, streak and timezone
- The student
- Yes
- Their club leader
- Lesson and track counts and last-active date only
- Anyone else
- No
When each assigned lesson was completed
- The student
- Yes
- Their club leader
- Yes, for students in their class
- Anyone else
- No
Short-lesson results (accuracy, time)
- The student
- Yes
- Their club leader
- Only whether the first short lesson was finished; never accuracy or time
- Anyone else
- No
Exercise code
- The student
- Yes
- Their club leader
- Yes, for students in their class
- Anyone else
- No
Capstone project
- The student
- Yes, including a log of every time their leader opened it
- Their club leader
- Opens it deliberately; each view is logged and shown to the student
- Anyone else
- Only through a share link the student creates: no name shown, and it stops working when sharing is turned off
Class membership and join date
- The student
- Yes
- Their club leader
- Yes
- Anyone else
- No
Weekly challenge times
- The student
- Yes
- Their club leader
- No
- Anyone else
- The leaderboard shows times only, never names
Paper-trading sandbox balance and trades
- The student
- Yes
- Their club leader
- No
- Anyone else
- No
AI tutor usage counts (not the messages)
- The student
- Yes
- Their club leader
- No
- Anyone else
- No
Certificates (name, track, date)
- The student
- Yes
- Their club leader
- No
- Anyone else
- Only someone the student gives the certificate link to
Subscription status, if a paid plan (no card data)
- The student
- Yes
- Their club leader
- No
- Anyone else
- No
StrikeLab staff (the founder) can read the database to run and support the service, and does so only for support, debugging and aggregate pilot numbers. Pilot reports use aggregate numbers only.
Where data goes
The services StrikeLab uses to run, and exactly what each one receives.
Supabase
- What for
- Database and sign-in
- What it receives
- Everything in the table above
Vercel
- What for
- Hosting and cookie-free, aggregate page analytics
- What it receives
- Web requests (IP address, pages visited); no account data in analytics
Sentry
- What for
- Error reports
- What it receives
- The error, the page, and a signed-in user's account id (no email or name)
Groq
- What for
- AI tutor and hints, only when a student uses them
- What it receives
- The question or code the student sends, without their name or email
Google
- What for
- "Continue with Google", only if used
- What it receives
- The sign-in itself
Stripe
- What for
- Payments; never used by students in a pilot
- What it receives
- The payer's checkout details, handled entirely by Stripe
Web3Forms
- What for
- Newsletter sign-up, only if used
- What it receives
- The email address entered
jsDelivr
- What for
- Backup source for the in-browser Python runtime, only if strikelab.dev's own copy fails
- What it receives
- A normal file download (IP address); no account data
Discord
- What for
- Only if a student connects their own server's webhook
- What it receives
- Lesson and achievement names posted to that server
Cookies and browser storage
- Sign-in session cookies, plus two one-hour cookies that carry how someone found StrikeLab and whether they're a student or a leader through Google sign-in.
- Progress and code are also kept in the browser so lessons work offline and without an account.
- No advertising or cross-site tracking cookies.
Deletion and requests
- Students delete their own account in Settings → Delete account. It takes effect immediately and removes every item listed above, including capstones, share links and class memberships.
- Parents and schools can ask to see or delete a student's data by emailing hello@strikelab.app.
- How long pilot data is kept is agreed with each school or club in its pilot agreement.
Security basics
- Every table has row-level security turned on, and the rules are tested automatically on every change.
- Joining a class needs the class's invite code and an account. Joining, creating classes, saving and sharing capstones, and deleting accounts are rate-limited.
- Leaders see only students who joined their class, and only what's listed above. Opening a student's capstone is logged, and the student can see the log.
- All traffic uses HTTPS. Keys and passwords live in the hosting provider's settings, never in the code.
If something goes wrong
If a problem could involve student data, the affected feature is taken offline first. The club leader hears within 24 hours what happened, which data was involved and what has been done. If the school has its own process, StrikeLab follows it.
Reviewing StrikeLab for your school?
If your school or district has its own student-data agreement or approval form, email it to hello@strikelab.appand we'll go through it with you. This page is also in the pilot approval packet.