Privacy Policy
Collect less. Protect what matters.
StatSprout is a nonprofit that teaches statistics to children and adults. We collect the minimum needed to run a learning account, we never sell it, and nothing about a learner is ever made public.
Effective 30 August 2026
This policy explains what StatSprout collects, why, who can see it, how long we keep it, and what you can do about it. It applies to statsprout.org and everything served from it. Using StatSprout with an account means this policy applies to you; you can also use the site without an account, and we explain below what changes when you do.
We do not sell personal information, we do not share it with advertisers, and we run no advertising, tracking, or profiling of any kind. There are no third-party analytics scripts, no advertising pixels, and no social media trackers anywhere on this site.
Using StatSprout without an account
The whole of our first course is available at /guestwith no sign-up. In that mode we create no account and store nothing about you on our servers. Any progress is kept in your own browser’s local storage on that one device, and clearing your browser data erases it. Nothing is transmitted to us and nothing follows you to another device.
What we collect, and why
When you create an account, you give us:
- A display name — what we call you in the product. It need not be your legal name.
- An email address — to sign you in, confirm your account, and reset your password.
- A birth year and month — used only to work out whether an account is for an adult, a teenager, or a child under 13, and to apply the right rules. We do not ask for a full date of birth.
- A learning level, and optionally a high-school path and learning interests, so we can show the right courses.
As you learn, the platform records:
- Which courses you are enrolled in, and which lessons and units you have started or completed.
- Your answers to checkpoints and quizzes, your scores, and the skill mastery calculated from them.
- Growth points, achievements, Sprout Tokens, items bought in the Sprout Shop, and what your plant is wearing.
- Daily game results and weekly goals.
- A log of significant actions in your own account — finishing a lesson, earning a badge — used to build your own progress views.
- Workshop registrations, if you sign up for one.
All of it exists to run the product for you: to show your progress, to decide what to teach next, and to award the things the product awards. None of it is used to build a profile of you for any other purpose.
What we deliberately do not collect
- No home address, phone number, photograph, or government identifier.
- No precise location. We do not use geolocation.
- No contact list, no microphone or camera access — the browser is instructed to refuse those outright.
- No behavioural advertising profile, and no data brokers.
- No public profiles. Learners cannot see one another, and there are no leaderboards or rankings between learners.
Children under 13
StatSprout teaches children, so the US Children’s Online Privacy Protection Act (COPPA) matters here and we have built around it.
A child under 13 cannot create an account on their own. Sign-up asks for a birth year and month before anything else, and our server — not the browser, which could be tampered with — refuses to create a self-serve account for anyone under 13. A child who arrives at sign-up is sent to guest mode, which needs no account and collects nothing.
An account for a child under 13 can only be created by a parent or guardian, from their own adult account. That process works like this:
- The parent is shown, item by item, exactly what will be collected: their child’s display name, birth year and month, chosen learning level, and learning progress. They must agree to each item separately — there is no single blanket tick.
- Consent is then confirmed by email to the parent’s own verified address, using a single-use link that expires after 72 hours. The child’s account does not become usable until that link is followed. This is our method of obtaining verifiable parental consent.
- We record which version of the consent wording was agreed to, and when, so it is always clear what was actually consented to.
- A parent can revoke consent at any timefrom their account, which immediately ends their child’s access.
What a parent can see.A linked parent can view their child’s learning report: lessons completed, courses in progress, growth points, badges, skill scores, and quiz results. They cannot see their child’s individual answers, and they cannot complete work on their child’s behalf. This access ends the moment consent is revoked.
For a child’s account we collect nothing beyond what the service needs. We never condition a child’s participation on disclosing more than is reasonably necessary. Children’s data is never used for advertising, never sold, and never disclosed to third parties except the infrastructure providers listed below, who process it only to run the service.
Parents may at any timereview their child’s information, ask us to delete it, and refuse to permit any further collection. Email us and we will act on it — see Contact. Deleting a child’s account erases their records as described under Deleting your data.
If we ever learn that we have collected personal information from a child under 13 without the consent described above, we delete it.
Schools and teachers
Teachers are welcome to use StatSprout with a class, and no permission or agreement from us is needed to do so. We have no school agreements, no district contracts, and no institutional accounts. That means each learner’s account is their own and their records belong to them, not to a school. Where a school directs the collection of student data, obligations such as those under FERPA fall on the school, and a teacher should follow their own institution’s rules before asking students to create accounts.
Who can see your data
Access is enforced in the database itself, not only in the application. Every table carrying personal data has row-level security switched on and forced, so a request can only ever return rows belonging to the account that made it. We have verified that a signed-in learner cannot read or modify another learner’s records, and that a signed-out visitor can read nothing but the public course catalogue.
- You can see everything in your own account.
- A linked parent can see their child’s learning report, as described above.
- StatSprout administrators can see aggregate statistics about how the curriculum is performing — which questions are too hard, which units people abandon. These figures are aggregated inside the database and any figure covering fewer than five learners is withheld, so they cannot describe an individual.
- Nobody else. We do not disclose personal information to third parties except the processors below, or where we are legally required to.
Who processes data for us
- Supabase — our database and authentication provider. Stores your account and learning records.
- Vercel — hosts the site and serves it to your browser.
- IONOS — provides our email, used when you write to us or when the contact form sends us a message.
These providers process data on our instructions in order to run StatSprout. They are not permitted to use it for their own purposes. Our infrastructure is located in the United States, so if you are elsewhere your data is transferred there.
Cookies
We use cookies only to keep you signed in and to keep sign-in secure. There are no analytics, advertising, or tracking cookies, which is why you have never seen a cookie banner here — we have nothing to ask you to consent to. Your theme and sound preferences are stored in your browser’s local storage and never sent to us.
How your account is protected
Passwords are hashed by our authentication provider; we never store or see them in plain text. The site is served over HTTPS only. Quiz answer keys are never sent to the browser, so they cannot be read from a page. No security is absolute, but access to learner records is restricted at the database level rather than only in application code.
How long we keep things
We keep your account and learning records for as long as your account exists, because that is what a record of your learning is for. If you delete your account we erase them as described below. We do not have a fixed inactivity period after which accounts are removed; if that changes we will say so here before it takes effect.
Your rights
Wherever you live, you can do all of the following, and you do not have to give a reason:
- See what we hold. Settings has a data export that downloads everything in your account as a file.
- Correct it. Your name, learning level and preferences are editable in Settings.
- Delete it. Settings has account deletion. It asks for your password first, because deletion cannot be undone.
- Ask us anything about it. Write to us and a person will answer.
If you are in the UK or EU, the lawful bases we rely on are performance of a contract with you (running the account you asked for) and, for a child’s account, the consent of the holder of parental responsibility. If you are in California, note that we do not sell or share personal information as those terms are defined there, and we do not offer financial incentives for data.
Deleting your data
Deleting your account removes your profile, enrolments, lesson and unit progress, quiz attempts and answers, skill records, points, achievements, tokens, purchases, activity log, and workshop registrations. Deletion is immediate and permanent, and we cannot restore an account afterwards. Backups taken before deletion age out on their normal cycle. A parent deleting a child’s account removes the same records for that child.
Changes to this policy
If we change this policy we will update the effective date at the top. If a change materially affects what we collect or who can see it, we will tell account holders by email before it takes effect rather than changing it quietly.
Contact
Questions about this policy, requests about your data, or anything a parent needs to ask about their child’s account: write to us. StatSprout is small, so replies come from a person rather than a queue. See also our Terms of Use.