Security

Schools keep children's records here, so this page gathers in one place what we do to protect them. The Privacy Policy is the full version.

Access Control

We use technical and organizational measures to keep data safe. These include row level security in our database so each person only sees the data they are allowed to, encryption of data in transit, and access controls based on your role.

No system is perfectly secure, so we cannot promise absolute security. We work to reduce risk and to respond quickly if something goes wrong.

Children's Records

FutureNerds is built for schools, not for children to use directly. The platform processes children's data on behalf of schools. Schools and parents are the source of that data, and the school decides how it is used.

Because the data belongs to schools and families, we do not sell it and we do not use it to build advertising profiles. We handle it only to provide the service and as the school directs.

We support schools in meeting their duties under laws that protect children's information, such as COPPA and FERPA in the United States and the children's data rules in the GDPR. If you are a parent and want to review, correct, or delete a child's information, please contact the child's school, which controls that record.

Who Else Handles Your Data

We do not sell your personal data. We share it only with the service providers we need to run the platform, and only so they can do work for us. These providers, sometimes called sub-processors, are listed below with what each one does.

Supabase hosts our database, manages sign-in and authentication, and stores files you upload such as photos and documents.

Vercel hosts the application. It also provides Vercel Analytics, which measures traffic in an aggregate, cookieless way and does not track individuals.

Stripe processes payments for invoices and subscriptions. Stripe handles card details directly under its own security standards.

PostHog provides product analytics and masked session replay so we can see how features are used and find problems. Session replay masks input, and we only use PostHog when you allow analytics cookies.

Google Analytics, loaded through Google Tag Manager, gives us website and product usage reports. We only load it when you allow analytics cookies, and we use Google Consent Mode v2 to respect your choice.

Sentry monitors errors and performance so we can fix bugs. It does not collect personal data for marketing and does not record session replay.

We may also share data when the law requires it, to protect our rights or the safety of others, or as part of a business transfer such as a merger, in which case we will let you know.

Where Your Data Is Held

Our hosting and main service providers are based in the United States, so your data may be processed there. If you are outside the United States, this means your data may be transferred across borders.

When we transfer personal data internationally, we rely on appropriate safeguards, such as standard contractual clauses with our providers, to protect it.

How Long We Keep It

We keep account data for as long as your account is active. We keep school and children's data for as long as the school's account is active or as the school instructs, since the school controls that data.

When an account is closed, we delete or anonymize the related personal data within a reasonable period, usually within 30 days, unless we must keep some records longer to meet legal, tax, or accounting duties. Backups are removed on a regular cycle.

If Something Goes Wrong

If a breach affects your personal data, we will investigate, contain it, and take steps to limit harm. Where the law requires, we will notify the relevant authorities and the people affected without undue delay. When a school is the controller, we will inform the school so it can meet its own duties.

Reporting a Security Problem

If you think you have found a security problem, email support@futurenerds.dev. Tell us what you did and what you saw, and we will come back to you.