📋
Overview

Puffin Resilience Lab ("we," "our," or "us") operates an online classroom emotional wellness platform for K–8 educators in Canada. This Privacy Policy explains how we collect, use, disclose, and protect personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and other applicable Canadian privacy legislation, including Ontario's Education Act where it applies.

Our platform is used by teachers and school administrators. We take our obligations seriously, especially when it comes to protecting children's data. If you are a parent or guardian with questions about your child's information, please see Section 10 below.

📊
1. What Data We Collect

We collect the following categories of information:

Data Category What It Includes Required?
Teacher Account Data Name, email address, school name, grade level, province Required
Classroom Data Classroom name, 6-character class code (auto-generated), creation date Required
Student Check-in Data Emotional state selected (9 options: Happy, Excited, Ready, Confused, Anxious, Tired, Sad, Angry, Frustrated), timestamp, classroom ID, and — if entered — first name Optional
Student Roster Principal Dashboard Student numbers assigned by the teacher + gender marker (M/F) — stored per classroom Optional
Mindfulness Stories Stories read and reflection responses submitted by students during story interactions Optional
Kindness Quest Progress Kind acts logged, stars earned, and unlock achievements — tied to student number or first name Optional
Parent Account Data Parent name, email address, hashed password, linked child name + class code Required
Analytics Events Page views, feature usage, scroll depth, time on page, visitor ID (anonymized), device type, screen size Automatic
🔑

No student surnames, health records, or identifying documents are collected. Students access the platform using a 6-digit class code shared by their teacher. They can optionally enter a first name to personalize their experience, but this is never required.

🛡️
2. How We Store and Protect Your Data

🔒Encryption

All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security). Our database is hosted on Neon (a PostgreSQL service by Neon Technologies, Inc.) with encryption at rest enabled.

👤Privacy-First Student Design

Students do not create individual accounts. They join a classroom by entering a 6-digit code shared by their teacher. This means:

💼Access Controls

📡Real-time Data (SSE)

Our live teacher dashboard uses server-sent events (SSE) to stream check-in data in real time. This data is ephemeral — it is not stored beyond the current session — and is scoped to the teacher's classroom.

⚠️

For children using the platform: Because students access the platform without individual login credentials, it is the responsibility of the school and teacher to ensure that access is used appropriately within the school environment. We recommend that teachers supervise student access as they would any digital classroom resource.

👥
3. Who Has Access to Your Data
Who What they can access Basis
Classroom Teachers Check-ins, mood trends, and wellbeing flags for their own classrooms only Contractual (teacher account)
School Principals Aggregated school-wide wellbeing data, classroom-level summaries, student roster (via teacher entry) School authorization
Parents / Guardians Daily check-in summaries for their linked child via the parent dashboard Parent account + child consent
Puffin Resilience Lab Team System logs, error reports, and performance metrics for service maintenance only Operational necessity
Hosting Provider (Render) Infrastructure that stores and serves the application — not the data itself beyond what the app uses Data processor agreement
Database Provider (Neon) PostgreSQL database hosting — all database content is encrypted at rest Data processor agreement

We do not sell, rent, or share student data with third parties for advertising, marketing, or profiling purposes. We do not share individual student records with school boards or government agencies unless required by law (see Section 7).

🗂️
4. Data Retention and Deletion

📅How Long We Keep Data

Data Type Retention Period
Teacher account data Until account deletion requested, or 2 years of inactivity
Classroom data + check-ins Until teacher deletes classroom or account; checked annually for inactivity
Student check-in data 12 months after the school year ends, then anonymized or deleted
Student roster (numbers + gender) Until teacher removes the roster or deletes the classroom
Parent account data Until account deletion requested
Analytics events 90 days, after which data is aggregated and individual visitor IDs are deleted

🗑️Requesting Deletion

You can request deletion of your data at any time:

We will confirm deletion within 30 days of a verified request.

🇨🇦
5. PIPEDA Compliance (Canada)

PIPEDA (Personal Information Protection and Electronic Documents Act) is Canada's federal private-sector privacy law. We comply with PIPEDA's ten fair information principles:

🏫
6. Ontario Education Act Considerations

Puffin Resilience Lab is designed for use in Ontario schools and takes into account the following:

ℹ️

Schools in other Canadian provinces and territories should satisfy themselves that our platform meets local requirements before teacher onboarding. Contact us at puffinresiliencelab@gmail.com for documentation or questions.

🔌
7. Third-Party Services and Integrations

We use the following third-party services to operate our platform:

Service Purpose Data Shared
Render (render.com) Web hosting and deployment Application code and runtime data (database queries, session data)
Neon (neon.tech) PostgreSQL database hosting All data stored in our database (teacher accounts, check-ins, classrooms)
Polsia (polsia.com) Platform infrastructure, analytics, email delivery Anonymous analytics events (visitor ID, page views, device type)
OpenAI Text-to-speech for breathing exercises and body scan narration Text prompts only (no student data is sent to OpenAI)
Polsia R2 (S3-compatible) Image and asset storage (mascot illustrations, story thumbnails) Static assets and UI images only — no student data
Google Fonts Quicksand font delivery No personal data — only font rendering requests
Stripe (future) Payment processing when subscription features are enabled Payment data handled entirely by Stripe; we store only subscription status tokens

All third-party processors are bound by data processing agreements or equivalent terms requiring them to protect personal information at a level comparable to PIPEDA requirements.

🍪
8. Cookies and Analytics

We use a minimal number of cookies and tracking technologies:

Students using the platform through their teacher's classroom code experience the same anonymous analytics — no personally identifiable information is collected from student sessions.

🚨
9. Data Breach Notification

In the event of a data breach that poses a real risk of significant harm to individuals, we will:

  1. Notify the Office of the Privacy Commissioner of Canada as required under PIPEDA
  2. Notify affected individuals directly (teachers, parents) as quickly as practicable
  3. Document the breach, its causes, and remediation steps taken
  4. Review and strengthen our safeguards to prevent recurrence

Breach notifications will include: a description of what happened, the data involved, steps we are taking, and contact information for questions.

👨‍👩‍👧
10. For Parents and Guardians

If your child uses Puffin Resilience Lab through their teacher's classroom, here is what you need to know:

🔍What data is collected about my child?

Your child's teacher may record their student number and gender for classroom management purposes. When your child uses the check-in feature, their selected emotional state is logged with a timestamp. Their first name may be entered (optionally) for a more personalized experience. No surnames, photos, or identifying documents are collected.

👁️Can I see my child's data?

Yes. If you have a parent dashboard account, you can view daily check-in summaries for your linked child. If you do not have an account but believe your child's data exists in our system, contact us and we will help you access it.

🗑️Can I request deletion of my child's data?

Yes. Contact us at puffinresiliencelab@gmail.com with your child's first name, their teacher's name (if known), and your relationship to the child. We will work with the teacher to remove the relevant data within 30 days.

🆘My child is in distress — who do I contact?

Puffin Resilience Lab is a classroom wellness tool, not a clinical or crisis service. If your child is experiencing a mental health emergency:

⚠️

If a student's check-in data indicates acute distress (multiple consecutive negative emotional states), we recommend teachers follow their school board's established wellbeing and safety protocols.

🔄
11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make significant changes, we will:

If you continue using Puffin Resilience Lab after a policy update, you are deemed to have accepted the revised terms.

📬
12. Contact Us

If you have questions, concerns, or requests related to this Privacy Policy or your personal information, we want to hear from you.

Get in Touch

For privacy inquiries, data access requests, or deletion requests — our team will respond within 5 business days.

✉️ puffinresiliencelab@gmail.com
Privacy Officer
Puffin Resilience Lab Team
Response Time
Within 5 business days
Privacy Commissioner
Language
English · Français
Last updated: May 21, 2026  ·  Puffin Resilience Lab  ·  Return to home