Architecture of Grace · Privacy Policy
The short answer: by default, nowhere. Everything a student does here stays in the browser of the device they used. The rest of this page explains that answer for parents first, and then in the detail a district needs.
What does this site collect about my child?
By default, nothing. There are no accounts, no sign-ins, no trackers, no ads, and no company server. What your child writes and does stays in the browser of the device they used — it travels nowhere at all. That is the default, and it stays the default until the school connects a Sheet of its own; the next answer explains what changes then.
What if the school turns on syncing?
A school can choose to collect results in a Google Sheet the school itself owns. When it does, a finished activity sends one row there — and what is in that row depends on what the activity is.
The check-in and the screener send a short code the student types (a code the school assigns — not a name), grade, class label, the seasonal window, and the item responses and domain scores. Structured answers only — no free writing.
Assignments and practice pages send the work itself, on purpose. An exit slip, a daily note, a home observation, a worksheet or a Daily Drafts page sends what the student actually did: the answers they gave, and on a writing page the writing itself. That is what handing in an assignment means. It happens only after the student puts a name on the page and taps Send.
Whatever is typed in the name box is what travels. A school that would rather have codes than names hands out codes — these pages ask for “your name, or the code your teacher gave you.”
Who can see it?
The school — and only the school. The rows go straight from the device to the school's own Sheet. They never pass through me or any company server, because there is no company server in the data path at all.
How do we erase it?
On the device: use the on-page Erase button, which clears what that browser holds. Anything synced: ask the school to delete the rows in its Sheet — they are the school's records and the school can delete them at any time.
Who do I ask about my child's data?
Your child's school first — it holds any synced records and can show, export, or delete them. For questions about how the software itself works, ask me, the founder; my contact is at the bottom of this page.
Architecture of Grace is a static website: pages that run entirely inside your browser. There is no operator database, no login system, no analytics beacon, and no third-party ad or tracking script. I could not read your child's responses even if I wanted to, because they are never sent to me.
When a school opts into syncing, the school sets up its own Google Sheet with its own script inside its own Google account. Rows travel from the student's device directly to that Sheet. The honest claim is not that data never travels — it is that there is no company server; data travels only to a Sheet the school owns.
When a school enables syncing, each completed instrument — the check-in and the screener — sends one row containing only the following. Nothing else is transmitted by those two.
| Element | What it is | Notes |
|---|---|---|
| Student code | A short code the student types | Assigned by the school; the app challenges entries that look like full names. Pseudonymous, not anonymous — the school's roster mapping can re-identify it, which is why the Sheet must belong to the school. |
| Grade | Grade level | As entered on the device. |
| Class label | A class or group label | Chosen by the teacher. |
| Seasonal window | Which administration window (e.g., fall, winter, spring) | |
| Item responses | The student's selected answers on the instrument | Structured responses only. |
| Domain scores | Computed domain scores | Calculated on the device before sending. |
| Timestamp | When the row arrived | Added by the school's own script. |
Assignments and practice pages carry more, by design. A worksheet, exit slip, daily note, home observation or Daily Drafts page sends the student’s own responses — and on a writing page the text the student wrote, with the planning notes beside it — under the name or code they typed. It is sent only when the student taps Send, only to the school’s own Sheet, and only if the school has connected one. A school that does not want student writing in its Sheet should not hand out those pages with a destination attached.
Never transmitted, in any mode, by anything on this site: email addresses, photos, location, device identifiers, or behavioral advertising identifiers of any kind. Student information is never sold, rented or traded. The check-in and the screener additionally never send free-text writing or a student’s name — they carry a code and structured answers only.
Records a school collects through syncing are part of the student's education record, created by and held within the school's own systems (its Google Workspace). The school remains the custodian; parents exercise their FERPA rights — inspection, amendment, and control of disclosure — through the school, exactly as with any other education record. The operator holds no copy and is not in the chain of custody.
The site offers no accounts and collects no personal information from children — no names, email addresses, screen names, photos, voice, location, or persistent identifiers used for tracking. There is nothing for the operator to collect consent for, because the operator collects nothing. In sync mode, the data flows to the school, not to the operator.
In the default local-only mode, no covered information reaches the operator at all. In sync mode, covered information flows only from the student's device to a Sheet the school owns — the operator never receives, stores, or processes it.
Even so, Illinois districts should still execute a data privacy agreement so the arrangement is documented in the form their board and records officers expect. A SOPPA-shaped agreement, ready to sign as written, is here: Data Privacy Agreement. Details of retention, deletion, and key custody are in the Data Governance document.
None. The operator engages no subprocessors, because the operator processes no student data. The only third-party service in the picture is Google Workspace — and that relationship is the school's existing relationship with Google, under the school's own agreement, in the school's own account. The website loads its fonts from Google Fonts, which serves font files and does not receive student data.
Because the operator holds no student data, a breach of student data at the operator is not structurally possible; a compromise of a school's Sheet is handled under the school's own incident procedures and its agreement with Google. If the operator ever becomes aware of a security issue in the published site or sync script that could expose synced data — for example, a flaw in the Apps Script code schools deploy — the operator commits to notifying affected schools' designated contacts within 72 hours of determination, with a description of the issue and the corrective steps. This commitment is made binding in the Data Privacy Agreement.
The site is served as static files by a hosting provider. Like any web host, the host's infrastructure logs ordinary web requests (IP address, page requested, timestamp) for operation and abuse prevention; the operator does not add analytics, cookies, fingerprinting, or tracking of any kind on top of that, and does not use server logs to identify or profile visitors.
If this policy changes, the new version will be posted at this address with a new effective date, and material changes will be summarized at the top. The core commitments — no operator server in the data path, no sale, no ads, no profiling — are the design of the system, not just its policy, and a change to them would mean a change to what the product is; do not expect one.