1. Who operates SPICE Spark
SPICE Spark is owned and operated by Jeremy Roberts. “We,” “us,” and “our” refer to Jeremy Roberts operating SPICE Spark. Use the dedicated service email in Contact for privacy questions.
2. Information collected
Student activities
Students enter a teacher code or lesson coupon. The player does not create student accounts, request a nickname or PIN, or save a student learning history. It holds the current activity, answers, feedback, tutoring conversation, and access token temporarily in the browser. This tab’s session storage supports refresh recovery; the student player does not use local storage or IndexedDB to build a learning record.
Relevant activity content, submitted answers, and recent tutor conversation are transmitted through the application server when needed for AI generation, grading, or tutoring. Processing this input is different from saving a learning history. The application does not save student-generated activity content, answers, tutor transcripts, or misconception history to its database.
Text filtering reduces common identifying details but cannot guarantee anonymity. Do not enter names, contact details, addresses, school identifiers, or student IDs into activities or tutoring. Student file uploads, handwriting recognition, and remote speech services are unavailable in this player.
Reports
A report is assembled in the browser and can be printed or downloaded. Its optional name is held only in the open page and included in the report you create; the application does not send that name to its server or AI provider or include it in refresh recovery. A report is formative feedback and does not verify identity. Downloaded, printed, or shared copies are controlled by whoever receives them.
Educator accounts and operational information
Educator sign-in uses Firebase Authentication. Account information can include a name, email address, account identifier, and sign-in provider. We store educator access requests and decisions, saved lessons and quizzes, reference materials, publication settings, teacher codes, coupon allocations, usage totals, and administrative actions. Educators should keep student personal information out of saved materials and administrative notes.
Short-lived access and processing records contain identifiers, timestamps, activity references, credit reservations, request status, and cost or token counts. These support access control, retry handling, and accounting; they do not contain student answers or tutor conversations. Hosting and cloud services also receive technical information such as IP addresses and request metadata. The application uses a hashed network identifier for rate limiting. Information you send in a support or privacy email is handled to answer that request.
3. How information is used
We use information to deliver requested activities and AI feedback, authenticate educators, enforce access and spending limits, maintain educator materials, prevent misuse, resolve support requests, and operate the service. Teachers receive student reports through the sharing method they arrange; the session-only player does not provide a server-stored student progress dashboard.
SPICE Spark does not sell student information or use student activity content for targeted advertising. Advertising is disabled in this deployment. Student activities, reports, private authoring, account screens, and administration contain no advertising SDK. The separate public teacher resources site does not receive private activity state or application credentials. Checkout and paid subscription enrollment are not active in this experience.
4. Service providers and AI
- GoDaddy
- Hosts the public, student, educator, administration, and resources websites. Website requests reach GoDaddy’s infrastructure. GoDaddy Real User Metrics is disabled for this hosting account; the published application pages do not load its metrics script. This does not mean the host keeps no access or security logs.
- Google Firebase and Google Cloud
- Provide educator authentication, server functions, database and file storage, and operational services. Students use a limited activity token through the application API, without signing into Firebase. The educator application can use browser storage to support account and authoring functions; administrative sign-in is held in memory. See Firebase privacy and security information.
- Google Cloud Vertex AI
- Processes instructional input with Gemini models for requested generation, feedback, and tutoring. AI output may be inaccurate. The application does not train its own model on student activity input. Google describes circumstances in which prompts or other data can be retained, including abuse monitoring and some optional features; see Google’s AI data retention documentation. We have not verified a zero-retention exception for this account and do not promise zero provider retention.
Provider processing, technical logs, backups, and recovery copies are separate from the application’s browser checkpoint and database cleanup. Clearing an activity does not issue a deletion request to every provider. Account-specific limits for every provider-held copy have not been verified. Contact us for the current provider arrangements before authorizing use that requires a particular retention or contractual commitment.
5. School use and student information
Educators must have the school or other responsible adult’s authority for the intended educational use and follow the school’s rules for AI tools and report sharing. Operator approval of a teacher account only permits application access; it does not establish school authorization or parental consent.
Do not put student information in shared lessons, reference materials, publication titles, or support messages unless needed for an authorized request. Share student reports only through an approved method. An applicable signed school agreement controls where it imposes additional restrictions. Account signup, activity access, and this notice do not waive privacy rights or replace required agreements.
We may disclose information when required by law or when legally permitted and necessary to address a security or safety incident. Requests involving school information are coordinated with the responsible school where appropriate. This notice is a description of the service, not FERPA or COPPA certification.
6. Children’s privacy
School use by children under 13 requires valid authorization before collecting their personal information. Where permitted, a school may authorize collection for its educational use and benefit; that authorization does not permit unrelated commercial uses. A teacher code, coupon, or acceptance of this notice is not itself verified school authorization or parental consent.
We do not offer independent child account signup. Parents and guardians can contact the responsible school or the operator to request review, deletion, or a stop to further collection. An educator can arrange another way to complete work when the required authorization is unavailable.
7. Retention and clearing data
- Current activity in the browser
- Refresh recovery expires after two hours of inactivity, and activity access lasts no longer than eight hours or the next midnight in America/New_York, whichever comes first. Starting a new activity or selecting Finish and clear clears the checkpoint. Expired storage is cleared when the player next runs. Closing a tab is not secure erasure: browsers may restore tabs, and a disconnected device cannot be cleared remotely.
- Access and processing receipts
- Access lists and preview codes expire after their short access periods. Completed or reconciled activity, AI-call, and generation receipts are scheduled for removal after 48 hours. Unresolved operations are reconciled before cleanup. Rate-limit records are scheduled for removal after one hour. Expiration denies access immediately; database removal occurs separately through scheduled maintenance.
- Usage and administrative records
- Monthly allowances, cost and revenue totals, and coupon accounting use a two-year cleanup period (730 days from the relevant update or coupon expiry). Administrative audit entries and advertising reports use a one-year period (365 days). These records support accounting and review without storing student responses. Cleanup runs in batches, so an expired record can remain until its batch succeeds.
- Educator accounts and saved materials
- Accounts, access decisions, teacher codes, and saved educator materials remain until removed through the appropriate controls or a verified operator request; they do not expire when a student activity ends. Automatic age-based deletion is not configured for these items. Contact us to request removal or account closure.
- Privacy correspondence
- Our operating policy is to remove correspondence within 90 days after a request closes and keep only limited authorization evidence and outcome receipts for up to 12 months after closure or the relevant authorization ends, whichever applies later. The operator must carry out this policy; it is not an automatic email deletion feature.
- Provider records and report copies
- The periods above govern the described application data. They do not establish a deadline for every hosting log, provider-held copy, backup, downloaded report, or printed copy. Copies shared outside the service are managed by their recipients.
Contact us when information is no longer needed or an earlier deletion is required. A request or access expiration alone does not confirm completed deletion. We will explain any remaining provider copies, processing failures, or retention obligations relevant to a verified request.
8. Access, correction, and requests
Parents, guardians, eligible students, and educators may request access, a copy, correction, or deletion of personal information, or ask that further collection stop. Contact the responsible school or use the service email below. We may need to verify authority and coordinate with the school while protecting other people’s information.
Describe the request and provide a way to reply. Do not include passwords, access codes, identity documents, or complete student work in an initial email. A student’s optional report name is not sent to the server, and we cannot retrieve an unsaved activity or report by that name. Privacy requests do not require payment. Nothing in this notice limits applicable privacy rights.
9. Security and incidents
The service uses HTTPS, separate student and administrative websites, restricted activity tokens, authenticated educator access, server-side role checks, and content security policies. These measures reduce risk but cannot guarantee complete security. Keep teacher codes and account credentials private, sign out on shared devices, and clear a student activity before leaving.
If we learn of unauthorized access or disclosure, we will investigate, contain the incident, preserve necessary evidence, and coordinate notices and corrective action with affected parties as required by applicable law and agreements.
10. Changes to this notice
We will update the date when this notice changes. Material changes to processing will be communicated to affected educator or school contacts as appropriate. A new use requiring authorization will not begin merely because a notice has been posted or someone continues using the service.
11. Contact
SPICE Spark privacy contact