Privacy Policy
Version 2026-07-27.1 · Effective July 27, 2026
What we collect, by surface
We collect what each part of the service needs to work, and nothing beyond it. Here is every surface that collects something, and exactly what:
- Account. The parent's email address and name, used to sign in and to identify who accepted these terms.
- Compliance dates. The dates you choose to enter for your own family — notice-of-intent filed, annual evaluation, home-education end date — and your county. We store exactly what you type; we don't infer or add to it.
- Learner profile and intake. A short description you write of how your child learns and what's worked for them recently, in your own words.
- Records and work samples. The assignments, projects, reading logs, and files you or your child log or upload as evidence of the work you're doing.
- Photos. Photos you choose to upload of your child's work. See below for what we ask you to avoid photographing.
What we deliberately don't collect
Some things a platform like this could ask for, and we've chosen not to, on purpose:
- No health or medical information, of any kind.
- No learning-styles or psychometric instruments — we ask what's worked lately, in plain words, not which “type” of learner your child is.
- No requirement that a child's full legal name appear anywhere in the app — a first name or nickname is enough everywhere a child is named.
- No photos of children's faces by policy — every photo-upload screen asks you to photograph the work, not the child.
- No location or geolocation data.
- No income or financial information about your family.
- No advertising, no ad identifiers, and nothing built to target a child with marketing.
How long we keep it
This table is the actual, current retention schedule — the same one referenced from your account's consent screen and enforced by our nightly retention process, not a separate description of it.
| Category | Retention | Basis |
|---|---|---|
| Account and profile data | Retained for the life of the account plus 30 days after closure | Operational necessity and account recovery period |
| Portfolio and work-sample records | Upon account closure, you may choose: deleted after 30 days, or kept on file for two years then removed | Florida law § 1002.41(1)(d)-(e) provides for a portfolio of records; the closure choice lines your family up with that window, or removes it sooner if you prefer |
| Compliance vault documents (notice of intent, evaluations, and similar filings) | Removed 30 days after account closure, under either portfolio choice above | The vault is parent-only by design (never shared with your co-op) and follows its own privacy posture — it does not follow the two-year portfolio option; download anything you want to keep before closing your account |
| AI-generated drafts | Never stored by the Platform | Not used to train Anthropic's models; Anthropic retains API data only briefly under its own data policy; the Platform itself does not store the drafts |
| Usage counts and audience snapshots | Aggregate numbers only, no personal information, retained indefinitely | Aggregate analytics enable platform improvement without personal-data retention |
Who else touches your data
We use a small number of services to run LN Collective. This is the complete, current list — the same one shown on the sub-processor consent screen.
| Service | What it's for | What it sees |
|---|---|---|
| Supabase | Database, authentication, file storage | Account and family records |
| Vercel | Application hosting | Requests in transit |
| Resend | Transactional email | Email addresses |
| Anthropic | AI drafting features | Prompts structurally built to exclude child names (families are asked not to type them into free-text fields either); not used to train Anthropic models; Anthropic retains briefly under its own data policy; the Platform does not store drafts |
| GitHub | Source code hosting | No user data |
| Google Drive | Encrypted off-site backups | Full-database snapshots |
AI features
A few parts of the service use Anthropic's AI models to help draft things — a project outline, for instance. Drafting requests are processed by Anthropic. They are not used to train Anthropic's models, and Anthropic retains them only briefly under its own data policy. The service does not store the drafts — only what you choose to save after reviewing them. The platform never includes your child's name in what it sends — that's a structural property of how the prompt is built, not a setting someone could leave off — and we ask you not to type it into the free-text answers either, since anything typed there is sent as you wrote it.
Your rights and choices
You can review everything your family has entered at any time by looking at your own dashboard and records — there's no separate request process, because it's already all in front of you. You can correct anything directly in the app, the same way you entered it. When you want your data gone, you close your account and choose one of the two retention options above; that election is honored exactly, on the schedule shown, whether you initiate the closure yourself or ask your co-op administrator to. Your own login ends 30 days after you request closure either way, and your child's Compliance section documents (notice of intent, evaluations, and similar filings) are removed at that same 30-day point regardless of which portfolio option you chose — that vault follows its own parent-only privacy design rather than the portfolio's schedule, so download anything you want to keep from it before you close. If you chose to keep your portfolio and work-sample records for the two-year window and need something from them after that, your co-op administrator can retrieve them for you.
If something goes wrong
Florida's data-breach law (Fla. Stat. § 501.171) sets out what a business must do after a breach of personal information, and we've committed to it as our own floor, not a ceiling: if your family's information is involved in a breach, we notify you individually within 30 days of discovering it, consistent with the statute's timeline. Our internal incident-response plan (not published, since it describes our own security process) sets out how we contain, assess, and report an incident.
Children's privacy
Children under 13 don't have their own accounts or logins on LN Collective — a parent enters and manages everything about a younger child directly, so no data is ever collected directly from a child under 13. For a teen 13 or older, we may provision a separate login at the parent's request and with the parent's consent; the teen's own entries (their reading log, their reflections) are theirs to write, but the account itself remains under the parent's authority, as described in our Terms of Service. We set the line at 13 deliberately, rather than granting every child their own login from the start: it matches how federal children's-privacy law treats data collected directly from a child, and it means a family's youngest children never have anything collected from them directly at all. We go into this reasoning in more depth in our onboarding FAQ (item A.8), for families who want the full explanation.
A note on FERPA: FERPA is a federal law that applies to schools and school districts that receive federal education funding — it doesn't apply to a private, family-facing platform like this one, and we don't claim it does. What we offer instead is described above and throughout this policy: strict per-family data isolation, no data collected directly from young children, and deletion on your own schedule when you close your account.
Contact and version history
Questions about this policy? Email us at support@FLHome.School. This is version 2026-07-27.1 — see our Terms of Service for how we handle changes to our policies.