Privacy Policy
Last updated:
Powderhouse ("we," "us," or "the School") is a tuition-free lab school, and we take protecting your information seriously — especially because we work with students. This policy explains what we collect, how we use it, when we share it (and when we don't), and the rights you have.
It applies to everyone who interacts with us: students, parents and guardians, staff, volunteers, community partners, prospective families, and website visitors.
What we collect
About students:
- Name and date of birth
- Contact info (address, phone, email)
- Educational records, academic progress, and attendance
- Health or medical information we need to support you
- IEPs, if you have one
- Emergency contacts
- Photos or videos from school activities (with consent)
About parents and guardians:
- Name, contact info, and relationship to the student
- Emergency contact details
- Financial information, if it's relevant to a program
From our website:
- Basic technical data — IP address, browser, device, and pages visited — collected automatically through cookies and analytics tools. You can control cookies in your browser, though some features may stop working.
Powderhouse Software
This section applies to Powderhouse Home, the authenticated services at home.powderhouse.org, and related software that Powderhouse provides to its school community. Attendance is one of the software's core functions. Other functions may include schedules, school information, forms, and authorized staff tools.
The current Powderhouse Home iOS version does not access health or medical information, IEPs, financial information, photos or videos, website cookies, or website analytics. Those categories described elsewhere in this policy concern other school or website activities, not collection by the current iOS app. The App Store privacy information describes the submitted iOS version specifically.
Accounts and sign-in
Powderhouse Software is for people whom Powderhouse has already authorized. Students and staff ordinarily receive a Powderhouse-managed Google Workspace account before they can use the software. Signing in proves control of that existing account; it does not create school membership or let someone sign up for a Powderhouse account in the app.
To authenticate and authorize a person, we process their name, institutional email address, stable Google and Powderhouse account identifiers, sign-in and session records, and security information such as IP address, device or browser type, and user agent. We use stable account identifiers—not an email address alone—to connect a sign-in to the correct Powderhouse person and records.
Attendance and Presence
The software displays and processes school information such as schedules, expected attendance, recorded attendance status and times, authorized notes, and corrections. Access is limited according to the person's relationship to Powderhouse and assigned permissions.
Powderhouse Home also offers Presence, an optional feature that can help a person and authorized school staff understand whether the person is at a configured Powderhouse site and support the attendance process. Presence is off until an authenticated person chooses to enable it in the app. The app explains the feature before asking iOS for Location Services permission. Attendance and the rest of the person's available apps continue to work if Presence is not enabled or Location Services permission is denied.
When Presence is enabled, the device may use Location Services while the app is open. If the person separately permits background location, it may also keep the result current when the app is not open. The device compares its location with a configured school-site boundary. Powderhouse does not receive or retain the device's raw latitude or longitude. Those coordinates are processed on the device. The app may retain on the device and send to Powderhouse a derived observation that includes:
- whether the device was inside, outside, or near the configured site;
- the configured site or boundary identifier and version;
- observation and receipt times;
- source, confidence, reported location accuracy, and distance from the site boundary; and
- the Powderhouse person or account to which the observation belongs.
These derived observations are linked to the person. They are not anonymous and are not used to track a person across other companies' apps or websites. We use them for app functionality, attendance review and correction, resolving attendance questions, security, and maintaining reliable records. Presence is evidence that can inform attendance; it is not by itself an irrevocable or infallible official attendance decision.
The person can turn Presence off in the app and can change Location Services permission in iOS Settings. Turning it off stops future collection and upload; it does not by itself delete official attendance records or other records that Powderhouse must retain. Contact us using the details below to request access, correction, or deletion where applicable.
Updates, hosting, and service providers
The app checks Expo's EAS Update service for compatible software updates. Expo may receive the device operating system, Powderhouse's project identifier, a randomized update token, IP address, and update-request performance or error information. The randomized token helps determine whether an installation has received an update; Powderhouse does not use it for advertising or cross-app tracking.
Powderhouse uses service providers only to operate and protect the software. The providers currently relevant to Powderhouse Home include:
- Google Workspace, for institutional accounts and sign-in;
- Vercel, for application and API hosting and associated request/runtime logs;
- PlanetScale, for managed database hosting;
- Expo, for building and delivering compatible app updates;
- Sentry, for error monitoring and release health in the current iOS release; and
- Apple, for App Store distribution, device Location Services, maps, and other iOS platform functions under the person's Apple settings.
These providers may process the limited information needed to perform their services. We require service providers that receive Powderhouse-controlled personal information to protect it consistently with this policy and applicable law. Their own platform relationship with a person—for example, the person's Apple Account and device settings—is also governed by their privacy terms.
When the app calls Powderhouse services, Powderhouse and Vercel may receive the institutional account or session identifier, IP address, user agent, requested API route, request time and status, app/native/build/update version, and limited function-duration or error metadata. We use these fields only to authenticate requests, deliver app functions and updates, prevent abuse, diagnose failures, and keep the service reliable—not for advertising or cross-app tracking.
The current iOS release initializes Sentry error monitoring. When a JavaScript or native crash occurs, Sentry may receive the error and stack trace, app and release identity, device and operating-system technical context, and recent diagnostic breadcrumbs needed to understand the failure. Powderhouse does not explicitly set a person's name, email address, or Powderhouse user identifier as the Sentry user, and does not enable default PII collection, performance tracing, profiling, session replay, screenshots, view hierarchy, the standalone Sentry Logs product, or failed-request event capture. Error details and automatic diagnostic breadcrumbs can nevertheless include data involved in the failing operation, so Powderhouse limits access and reviews this diagnostic path. We use Sentry only to diagnose errors, protect the service, and improve reliability—not for advertising or cross-app tracking. Sentry retains accepted events under the current project's plan-specific retention window; Powderhouse does not copy them into a longer-lived general archive for ordinary use.
The current mobile release does not use advertising SDKs, sell personal information, or use personal information for targeted advertising or tracking across other companies' apps or websites. If a future release changes those facts or begins sending app diagnostics to a new provider, we will update this policy and the App Store privacy information before that collection begins.
How long software data is kept
We use a separate schedule for each kind of record:
- Detailed Presence evidence: Derived Presence observations and their detailed diagnostic copies are kept for no more than 365 days from the time observed. Copying, syncing, correcting, or viewing an observation does not restart that period. Afterward, Powderhouse deletes or irreversibly de-identifies the observation from active systems, unless a specific legal or attendance dispute—including an outstanding record-access request—requires a narrow, documented, time-limited hold. When this evidence is part of a student's temporary record and is scheduled for destruction while the student is enrolled, Powderhouse's authorized records custodian determines that the expiring information is outdated or no longer relevant, provides the written notice and opportunity to receive the information required by Massachusetts student-record rules, and keeps a copy of that notice in the temporary record.
- Official attendance and student records: Official attendance status, authorized corrections, and the records needed to interpret that status are kept separately from detailed Presence evidence. Powderhouse's current Massachusetts student-record schedule may dispose of outdated or irrelevant temporary-record information during enrollment only through the required written-notice procedure and destroys the remaining temporary record no later than seven years after graduation, transfer, or withdrawal. The transcript schedule is 60 years after the student leaves Powderhouse. A different period applies if law requires it or a record is not part of those student-record classes.
- Accounts and sessions: Account and authorization records are kept while needed to provide and secure an active institutional account and to preserve required attribution. Sessions expire or are revoked after sign-out, offboarding, credential change, or their configured lifetime. Short-lived application request and security logs are kept only for operations, reliability, abuse prevention, and incident response, ordinarily no longer than 30 days unless a specific incident requires a time-limited hold.
- Error monitoring: Accepted Sentry error events age out under the current Sentry plan's retention window. The exact window is plan-specific and is not stated here; Powderhouse reviews it when the project or plan changes. Retained events are not copied into a longer-lived general archive.
- On-device data: The app applies the same 365-day observed-time limit to detailed Presence evidence it controls on the device. Removing the app removes its local data from the device, subject to Apple's device and backup behavior.
Deletion from active systems does not always remove a byte immediately from an encrypted disaster-recovery or device backup. Recovery copies are not available for ordinary use, age out under the applicable recovery schedule, and must have the current disposal rules reapplied before restored data is returned to use. A hold ends when its specific obligation ends; it does not create a new 365-day period.
How we use it
We use your information to:
- Run the school and provide education
- Track progress and attendance
- Communicate with you and your family
- Keep students safe
- Process enrollment and answer questions
- Send important updates
- Follow education laws and regulations
When we share it — and when we don't
We do not sell your personal information, and we do not share it with third parties or affiliates for marketing or promotional purposes.
We share information only when there's a real need:
- With service providers who help us run the school, under strict confidentiality agreements
- With government agencies when the law requires it
- With emergency services when someone's safety is at stake
- With another school if you transfer (with your consent)
- In anonymized form — with identifying details removed — to research and improve education
Your text-message information gets extra protection, described in Text Messaging below.
How we keep it safe
- Encryption of sensitive information
- Secure servers, firewalls, and strict access controls
- Regular security checks and staff privacy training
- Secure disposal when information is no longer needed
- A plan for responding if something goes wrong
Your rights
We protect education records under FERPA where it applies and under applicable Massachusetts student-record and privacy rules. Depending on the record and the person's status, rights include the ability to:
- See your education records and ask us to correct them
- Decide, in writing, when your information can be shared
- Opt out of "directory information" sharing (basic details a school can otherwise share, like name or grade level)
- Ask us to delete personal information, where the law allows
- File a complaint if you think we've gotten something wrong
Parents can review, correct, or request deletion of their child's records, and we ask for parental consent before releasing student information.
Students under 13: We follow COPPA where it applies. Information is collected only with the authorization required for the particular use. That may be direct parent or guardian consent, or school authorization for a school-controlled, noncommercial educational use when the law permits the school to act for the parent. We give families the required notice and a way to review, request deletion where applicable, or stop further optional collection.
Text Messaging (SMS)
Powderhouse texts students and families to stay in touch about school. Some texts come straight from our staff; some (like reminders or announcements) are sent automatically — but they're always from Powderhouse and always about school. We never send ads, and we never sell or share your phone number. For the complete program terms, see our Text Messaging Terms.
What we text about: scheduling meetings, visits, and interviews; attendance, pickup, and reminders; school announcements and updates; answers to your questions; and emergencies. We only text people who gave us their number and said yes — never numbers bought from anyone else, and never marketing.
Signing up: You opt in by entering your mobile number and checking the consent box on our interest form or family intake form. Checking that box means you agree to get texts from Powderhouse. If you're under 18, a parent or guardian opts in with you.
How often, and when: How often we text varies, depending on what's happening. We usually text during the day (about 9:00 AM–6:00 PM); urgent messages may come outside those hours.
Cost: Message and data rates may apply, depending on your phone plan. Powderhouse isn't responsible for charges from your carrier.
Stopping or getting help:
- To stop: reply STOP to any text and we'll stop texting that number. (You can also email us@powderhouse.org.)
- For help: reply HELP, or reach us at us@powderhouse.org or 617.800.6992.
If you opt out, we may not be able to reach you quickly about time-sensitive things.
We protect your number:
- We will not share, sell, rent, or trade your mobile number or your text opt-in information with any third parties or affiliates for marketing or promotional purposes — ever.
- The only place your number goes is the service that delivers our texts (our messaging provider), and only so your messages reach you.
- Your texts are treated as confidential school records, stored securely, and read only by authorized Powderhouse staff.
If you're under 18: we need a parent or guardian to give permission before we collect a minor's number and text them, and to help set it up.
Changes to this policy
We may update this policy from time to time. If we make a significant change, we'll let families know through our usual channels.
Questions?
Powderhouse Privacy Officer 339R Summer Street, Somerville, MA 02144 us@powderhouse.org · 617.800.6992