Privacy Policy

Another Angle Privacy Policy

Version: 1.0.0

Effective date: August 1, 2026

Status: Active

This policy describes the actual parent, student, analytics, reporting, billing, deletion, and processor data practices currently represented in the Another Angle codebase.

Launch blockers

  • Legal operator name, business address, telephone number, and privacy contact are not configured.
  • Production processor retention links for provider-controlled logs are not configured.
  • Attorney review has not been recorded for the Privacy Policy or Children's Privacy Notice.
  • Support email is not configured.
  • Checkout, Stripe identifiers, and subscription price are not configured.

Table of contents

  1. 1. Operator Identity and Contact Information
  2. 2. Scope
  3. 3. Parent Information Collected
  4. 4. Student Information Collected
  5. 5. Information Collected Automatically
  6. 6. Purposes of Collection
  7. 7. Service Providers and Disclosures
  8. 8. Cookies and Persistent Identifiers
  9. 9. Payment Information
  10. 10. Data Security
  11. 11. Retention Periods
  12. 12. Parent Access, Correction, and Deletion
  13. 13. Student-Profile Deletion
  14. 14. Entire-Account Deletion
  15. 15. Email Communications
  16. 16. International or State-Specific Disclosures
  17. 17. Changes to the Policy
  18. 18. Contact Information

01

Operator Identity and Contact Information

Another Angle operates this educational practice platform. Legal company name, business address, telephone number, and privacy contact are not configured in this environment.

Support email is not configured. Production activation is blocked until a support contact is configured.

02

Scope

This Privacy Policy covers the public site, parent signup and login, student profiles, generated practice, section quizzes, parent dashboard, problem reports, account privacy controls, and related administrative systems.

This policy is pending review and is not active production legal copy until attorney review is recorded in the legal-document registry.

03

Parent Information Collected

Another Angle collects parent account information such as first name, email address, normalized email address, account status, email verification timestamp, role assignments, and last login timestamp.

Passwords are stored as password hashes, not plaintext passwords.

04

Student Information Collected

Student profiles may include a display name or nickname, grade level, selected interests, preferences, household student list, topic progress, mastery, practice sessions, answer submissions, Hint usage, section quiz attempts, and section quiz scores.

Student problem reports may include topic and variant IDs, problem seed, generated problem values, expected-answer metadata for administrator review, viewport data, app version, a student description, and an optional screenshot reference.

05

Information Collected Automatically

The application uses persistent identifiers such as secure session cookies, internal user IDs, student profile IDs, household IDs, topic IDs, problem seeds, and deletion tombstone identifiers.

Security and operational systems may record route, session ID, IP address, request path, operational error metadata, viewport size, device pixel ratio, and provider-controlled request metadata.

06

Purposes of Collection

Another Angle uses collected information to create parent accounts, verify email, authenticate sessions, provide student profiles, run Grade 7 practice, validate answers, show progress, administer section quizzes, support parent dashboards, accept problem reports, maintain security, and improve curriculum quality.

Another Angle does not use under-13 student information for targeted advertising, behavioral advertising, sale of personal information, or unrelated profiling.

07

Service Providers and Disclosures

Current processor registry entries are: internal-product-analytics, internal-security-audit-log, resend-transactional-email, problem-report-object-store, manual-founder-pilot-ledger, hosting-operational-logs, application-database, routine-backups. These processors are used to operate the platform, send transactional email, store application records, handle problem-report screenshot references, maintain analytics and security logs, and manage routine backups.

Another Angle may disclose information when required by law, to protect security, or to operate the service through configured processors. Another Angle does not claim that it never shares information, because service providers receive data needed to operate the platform.

08

Cookies and Persistent Identifiers

Another Angle uses secure session cookies for authentication and may use internal persistent identifiers such as user IDs, student profile IDs, household IDs, topic IDs, problem seeds, report IDs, and deletion request IDs.

These identifiers support login, progress, quizzes, reports, analytics, security, and deletion replay. They are not configured for targeted advertising.

09

Payment Information

No Stripe checkout or payment processor is configured in this environment, and no subscription price is configured.

The administrative manual revenue ledger can contain household ID, billing period, payment status, refund amount, renewal indicator, referral source, and notes when admin-maintained records exist.

10

Data Security

Another Angle uses server-side session validation, secure cookie settings in production, password hashing, email verification and reset tokens, role checks, deletion audit records, and sanitized security logging.

No system can be guaranteed perfectly secure. Parents should keep passwords private and sign out on shared devices.

11

Retention Periods

Student profile identity, student learning records, parent dashboard profiles, parent auth account records, sessions, and local auth tokens are deleted from live systems when the applicable deletion request completes.

Problem reports and product analytics may be anonymized and retained for 18 days after deletion completion. Sanitized security audit logs may remain for 18 days from creation. Manual revenue ledger records may remain for 7 years from payment date. Routine backups expire after 30 days and restored backups must replay deletion tombstones before serving live traffic.

External provider logs are provider-controlled where no deletion API is configured.

12

Parent Access, Correction, and Deletion

A signed-in, verified parent can access account settings and account privacy controls. Parents may request correction through account settings where available or through support when support is configured.

Parents control student-profile deletion and entire-account deletion from the authenticated Account Privacy page.

13

Student-Profile Deletion

Only the selected student profile is affected.

The parent login remains active.

Other student profiles remain available.

The subscription remains unchanged.

14

Entire-Account Deletion

Parent access ends when the account deletion completes.

All active sessions for the account are revoked.

Every student profile belonging to the account is deleted from live application data.

The parent authentication identity is deleted only after dependent cleanup steps run.

15

Email Communications

Another Angle sends transactional emails for email verification, password reset, and deletion confirmations. Resend is configured as the transactional email provider when its server-side API key is present.

No newsletter or marketing campaign system is part of the initial authentication email foundation.

16

International or State-Specific Disclosures

No international transfer, state-specific privacy addendum, operator address, telephone number, or governing-law configuration has been finalized in this repository.

These disclosures require legal and business review before this policy can become active.

17

Changes to the Policy

Published legal-document versions are immutable. If privacy wording or practices materially change, Another Angle must create a new version and can require reacceptance where configured.

18

Contact Information

Support email is not configured in this environment.

Production activation remains blocked while these items are unresolved: Legal operator name, business address, telephone number, and privacy contact are not configured.; Production processor retention links for provider-controlled logs are not configured.; Attorney review has not been recorded for the Privacy Policy or Children's Privacy Notice.; Support email is not configured.; Checkout, Stripe identifiers, and subscription price are not configured..

Data categories disclosed

Parent account information

Examples: first name, email address, normalized email address, account status, email verification timestamp, last login timestamp, role assignments.

Purpose: Create and manage parent-owned accounts, verify email, authenticate sessions, and route parents to the correct product area.

Authentication and security information

Examples: password hash, session cookie, verification token records, password reset token records, IP address in security events, route and session ID in security events.

Purpose: Sign users in and out, protect accounts, verify email addresses, reset passwords, rate-limit abuse, and maintain sanitized security logs.

Student profile information

Examples: student display name or nickname, grade level, selected interests, student preferences, household student list.

Purpose: Create student profiles under the parent account and present Grade 7 practice in selected interest contexts.

Student learning activity

Examples: topic progress, mastery progress, practice sessions, answer submissions, first-attempt accuracy, Hint usage, section quiz attempts and scores, continued practice after mastery.

Purpose: Run practice, preserve progress, score section quizzes, show parent dashboard summaries, and improve curriculum quality.

Generated problem and report data

Examples: topic ID, variant ID, problem seed, generated problem values, expected-answer metadata stored for administrators, problem-report description, optional problem-report screenshot reference, viewport width and height, device pixel ratio, app version.

Purpose: Reproduce reported issues, correct curriculum defects, and verify that generated problems match their validators.

Payment and revenue records

Examples: manual household revenue ledger records, payment date, billing period, payment status, refund amount, referral source.

Purpose: Maintain admin-reviewed accounting, refund, renewal, and referral records when records exist.

Operational logs and backups

Examples: request path, operational error metadata, provider-controlled request metadata, encrypted backup copies of application and file data.

Purpose: Operate, secure, troubleshoot, and restore the service within the configured backup window.

Processors disclosed

internal-product-analytics

Stores Another Angle product analytics events and derived engagement/learning metrics.

Categories: user ID, student profile ID, household ID, topic IDs, problem seeds. Retention: No external analytics provider is configured.

internal-security-audit-log

Stores sanitized sign-in, reset, authorization, and role-change security events.

Categories: user ID, route, session ID, IP address. Retention: No external security-log processor is configured.

resend-transactional-email

Sends verification, password-reset, and deletion-confirmation transactional email.

Categories: recipient email address, message type, delivery status. Retention: Resend delivery/security logs follow configured Resend account retention; Another Angle deletes local tokens and delivery records.

problem-report-object-store

Stores object references for optional problem-report screenshots and derived files.

Categories: screenshot object key, screenshot URL when supplied. Retention: No object-storage provider is configured; exact-key deletion is verified in the local object registry.

manual-founder-pilot-ledger

Stores manually maintained revenue, refund, renewal, and referral records.

Categories: household ID, billing period, payment status, referral source. Retention: No Stripe or payment processor is configured; ledger rows are retained for the configured accounting period.

hosting-operational-logs

Hosting/runtime operational logs for the deployed application.

Categories: request path, operational errors, provider-controlled request metadata. Retention: Hosting provider operational logs are provider-controlled until production hosting retention is documented.

application-database

Authoritative application data stores represented by repository data modules.

Categories: parent account, student profile, learning records, reports. Retention: Live application stores are deleted/anonymized by policy handlers; backup retention is handled separately.

routine-backups

Database and file-storage disaster recovery backups.

Categories: encrypted backup copies of application and file data. Retention: Routine backup copies expire after 30 days under Another Angle deletion policy; selective surgical deletion is not performed.

For information specific to children under 13, see the Children's Privacy Notice.