Architecture of Grace · Privacy Policy

Where your child's information goes

The short answer: by default, nowhere. Everything a student does here stays in the browser of the device they used. The rest of this page explains that answer for parents first, and then in the detail a district needs.

Effective date: September 7, 2026 · Written by the founder, a classroom teacher · Applies to architectureofgrace.org and its activities

The short version, for families

What does this site collect about my child?

By default, nothing. There are no accounts, no sign-ins, no trackers, no ads, and no company server. What your child writes and does stays in the browser of the device they used — it travels nowhere at all. That is the default, and it stays the default until the school connects a Sheet of its own; the next answer explains what changes then.

What if the school turns on syncing?

A school can choose to collect results in a Google Sheet the school itself owns. When it does, a finished activity sends one row there — and what is in that row depends on what the activity is.

The check-in and the screener send a short code the student types (a code the school assigns — not a name), grade, class label, the seasonal window, and the item responses and domain scores. Structured answers only — no free writing.

Assignments and practice pages send the work itself, on purpose. An exit slip, a daily note, a home observation, a worksheet or a Daily Drafts page sends what the student actually did: the answers they gave, and on a writing page the writing itself. That is what handing in an assignment means. It happens only after the student puts a name on the page and taps Send.

Whatever is typed in the name box is what travels. A school that would rather have codes than names hands out codes — these pages ask for “your name, or the code your teacher gave you.”

Who can see it?

The school — and only the school. The rows go straight from the device to the school's own Sheet. They never pass through me or any company server, because there is no company server in the data path at all.

How do we erase it?

On the device: use the on-page Erase button, which clears what that browser holds. Anything synced: ask the school to delete the rows in its Sheet — they are the school's records and the school can delete them at any time.

Who do I ask about my child's data?

Your child's school first — it holds any synced records and can show, export, or delete them. For questions about how the software itself works, ask me, the founder; my contact is at the bottom of this page.

How this can be true

Architecture of Grace is a static website: pages that run entirely inside your browser. There is no operator database, no login system, no analytics beacon, and no third-party ad or tracking script. I could not read your child's responses even if I wanted to, because they are never sent to me.

When a school opts into syncing, the school sets up its own Google Sheet with its own script inside its own Google account. Rows travel from the student's device directly to that Sheet. The honest claim is not that data never travels — it is that there is no company server; data travels only to a Sheet the school owns.

For districts: the detail

Data elements in sync mode

When a school enables syncing, each completed instrument — the check-in and the screener — sends one row containing only the following. Nothing else is transmitted by those two.

ElementWhat it isNotes
Student codeA short code the student typesAssigned by the school; the app challenges entries that look like full names. Pseudonymous, not anonymous — the school's roster mapping can re-identify it, which is why the Sheet must belong to the school.
GradeGrade levelAs entered on the device.
Class labelA class or group labelChosen by the teacher.
Seasonal windowWhich administration window (e.g., fall, winter, spring) 
Item responsesThe student's selected answers on the instrumentStructured responses only.
Domain scoresComputed domain scoresCalculated on the device before sending.
TimestampWhen the row arrivedAdded by the school's own script.

Assignments and practice pages carry more, by design. A worksheet, exit slip, daily note, home observation or Daily Drafts page sends the student’s own responses — and on a writing page the text the student wrote, with the planning notes beside it — under the name or code they typed. It is sent only when the student taps Send, only to the school’s own Sheet, and only if the school has connected one. A school that does not want student writing in its Sheet should not hand out those pages with a destination attached.

Never transmitted, in any mode, by anything on this site: email addresses, photos, location, device identifiers, or behavioral advertising identifiers of any kind. Student information is never sold, rented or traded. The check-in and the screener additionally never send free-text writing or a student’s name — they carry a code and structured answers only.

FERPA

Records a school collects through syncing are part of the student's education record, created by and held within the school's own systems (its Google Workspace). The school remains the custodian; parents exercise their FERPA rights — inspection, amendment, and control of disclosure — through the school, exactly as with any other education record. The operator holds no copy and is not in the chain of custody.

COPPA

The site offers no accounts and collects no personal information from children — no names, email addresses, screen names, photos, voice, location, or persistent identifiers used for tracking. There is nothing for the operator to collect consent for, because the operator collects nothing. In sync mode, the data flows to the school, not to the operator.

Illinois SOPPA (105 ILCS 85)

In the default local-only mode, no covered information reaches the operator at all. In sync mode, covered information flows only from the student's device to a Sheet the school owns — the operator never receives, stores, or processes it.

Even so, Illinois districts should still execute a data privacy agreement so the arrangement is documented in the form their board and records officers expect. A SOPPA-shaped agreement, ready to sign as written, is here: Data Privacy Agreement. Details of retention, deletion, and key custody are in the Data Governance document.

Subprocessors

None. The operator engages no subprocessors, because the operator processes no student data. The only third-party service in the picture is Google Workspace — and that relationship is the school's existing relationship with Google, under the school's own agreement, in the school's own account. The website loads its fonts from Google Fonts, which serves font files and does not receive student data.

No sale, no ads, no profiling

Breach notification

Because the operator holds no student data, a breach of student data at the operator is not structurally possible; a compromise of a school's Sheet is handled under the school's own incident procedures and its agreement with Google. If the operator ever becomes aware of a security issue in the published site or sync script that could expose synced data — for example, a flaw in the Apps Script code schools deploy — the operator commits to notifying affected schools' designated contacts within 72 hours of determination, with a description of the issue and the corrective steps. This commitment is made binding in the Data Privacy Agreement.

What the operator's website itself sees

The site is served as static files by a hosting provider. Like any web host, the host's infrastructure logs ordinary web requests (IP address, page requested, timestamp) for operation and abuse prevention; the operator does not add analytics, cookies, fingerprinting, or tracking of any kind on top of that, and does not use server logs to identify or profile visitors.

Changes to this policy

If this policy changes, the new version will be posted at this address with a new effective date, and material changes will be summarized at the top. The core commitments — no operator server in the data path, no sale, no ads, no profiling — are the design of the system, not just its policy, and a change to them would mean a change to what the product is; do not expect one.

A plain disclosure: this policy was written by the founder — a classroom teacher, not an attorney. It describes the system truthfully, but districts should have their own counsel review it, and the agreement, before adoption.