Puffin Resilience Lab ("we," "our," or "us") operates an online classroom emotional wellness platform for K–8 educators in Canada. This Privacy Policy explains how we collect, use, disclose, and protect personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and other applicable Canadian privacy legislation, including Ontario's Education Act where it applies.
Our platform is used by teachers and school administrators. We take our obligations seriously, especially when it comes to protecting children's data. If you are a parent or guardian with questions about your child's information, please see Section 10 below.
We collect the following categories of information:
| Data Category | What It Includes | Required? |
|---|---|---|
| Teacher Account Data | Name, email address, school name, grade level, province | Required |
| Classroom Data | Classroom name, 6-character class code (auto-generated), creation date | Required |
| Student Check-in Data | Emotional state selected (9 options: Happy, Excited, Ready, Confused, Anxious, Tired, Sad, Angry, Frustrated), timestamp, classroom ID, and — if entered — first name | Optional |
| Student Roster Principal Dashboard | Student numbers assigned by the teacher + gender marker (M/F) — stored per classroom | Optional |
| Mindfulness Stories | Stories read and reflection responses submitted by students during story interactions | Optional |
| Kindness Quest Progress | Kind acts logged, stars earned, and unlock achievements — tied to student number or first name | Optional |
| Parent Account Data | Parent name, email address, hashed password, linked child name + class code | Required |
| Analytics Events | Page views, feature usage, scroll depth, time on page, visitor ID (anonymized), device type, screen size | Automatic |
No student surnames, health records, or identifying documents are collected. Students access the platform using a 6-digit class code shared by their teacher. They can optionally enter a first name to personalize their experience, but this is never required.
All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security). Our database is hosted on Neon (a PostgreSQL service by Neon Technologies, Inc.) with encryption at rest enabled.
Students do not create individual accounts. They join a classroom by entering a 6-digit code shared by their teacher. This means:
Our live teacher dashboard uses server-sent events (SSE) to stream check-in data in real time. This data is ephemeral — it is not stored beyond the current session — and is scoped to the teacher's classroom.
For children using the platform: Because students access the platform without individual login credentials, it is the responsibility of the school and teacher to ensure that access is used appropriately within the school environment. We recommend that teachers supervise student access as they would any digital classroom resource.
| Who | What they can access | Basis |
|---|---|---|
| Classroom Teachers | Check-ins, mood trends, and wellbeing flags for their own classrooms only | Contractual (teacher account) |
| School Principals | Aggregated school-wide wellbeing data, classroom-level summaries, student roster (via teacher entry) | School authorization |
| Parents / Guardians | Daily check-in summaries for their linked child via the parent dashboard | Parent account + child consent |
| Puffin Resilience Lab Team | System logs, error reports, and performance metrics for service maintenance only | Operational necessity |
| Hosting Provider (Render) | Infrastructure that stores and serves the application — not the data itself beyond what the app uses | Data processor agreement |
| Database Provider (Neon) | PostgreSQL database hosting — all database content is encrypted at rest | Data processor agreement |
We do not sell, rent, or share student data with third parties for advertising, marketing, or profiling purposes. We do not share individual student records with school boards or government agencies unless required by law (see Section 7).
| Data Type | Retention Period |
|---|---|
| Teacher account data | Until account deletion requested, or 2 years of inactivity |
| Classroom data + check-ins | Until teacher deletes classroom or account; checked annually for inactivity |
| Student check-in data | 12 months after the school year ends, then anonymized or deleted |
| Student roster (numbers + gender) | Until teacher removes the roster or deletes the classroom |
| Parent account data | Until account deletion requested |
| Analytics events | 90 days, after which data is aggregated and individual visitor IDs are deleted |
You can request deletion of your data at any time:
We will confirm deletion within 30 days of a verified request.
PIPEDA (Personal Information Protection and Electronic Documents Act) is Canada's federal private-sector privacy law. We comply with PIPEDA's ten fair information principles:
Puffin Resilience Lab is designed for use in Ontario schools and takes into account the following:
Schools in other Canadian provinces and territories should satisfy themselves that our platform meets local requirements before teacher onboarding. Contact us at puffinresiliencelab@gmail.com for documentation or questions.
We use the following third-party services to operate our platform:
| Service | Purpose | Data Shared |
|---|---|---|
| Render (render.com) | Web hosting and deployment | Application code and runtime data (database queries, session data) |
| Neon (neon.tech) | PostgreSQL database hosting | All data stored in our database (teacher accounts, check-ins, classrooms) |
| Polsia (polsia.com) | Platform infrastructure, analytics, email delivery | Anonymous analytics events (visitor ID, page views, device type) |
| OpenAI | Text-to-speech for breathing exercises and body scan narration | Text prompts only (no student data is sent to OpenAI) |
| Polsia R2 (S3-compatible) | Image and asset storage (mascot illustrations, story thumbnails) | Static assets and UI images only — no student data |
| Google Fonts | Quicksand font delivery | No personal data — only font rendering requests |
| Stripe (future) | Payment processing when subscription features are enabled | Payment data handled entirely by Stripe; we store only subscription status tokens |
All third-party processors are bound by data processing agreements or equivalent terms requiring them to protect personal information at a level comparable to PIPEDA requirements.
We use a minimal number of cookies and tracking technologies:
Students using the platform through their teacher's classroom code experience the same anonymous analytics — no personally identifiable information is collected from student sessions.
In the event of a data breach that poses a real risk of significant harm to individuals, we will:
Breach notifications will include: a description of what happened, the data involved, steps we are taking, and contact information for questions.
If your child uses Puffin Resilience Lab through their teacher's classroom, here is what you need to know:
Your child's teacher may record their student number and gender for classroom management purposes. When your child uses the check-in feature, their selected emotional state is logged with a timestamp. Their first name may be entered (optionally) for a more personalized experience. No surnames, photos, or identifying documents are collected.
Yes. If you have a parent dashboard account, you can view daily check-in summaries for your linked child. If you do not have an account but believe your child's data exists in our system, contact us and we will help you access it.
Yes. Contact us at puffinresiliencelab@gmail.com with your child's first name, their teacher's name (if known), and your relationship to the child. We will work with the teacher to remove the relevant data within 30 days.
Puffin Resilience Lab is a classroom wellness tool, not a clinical or crisis service. If your child is experiencing a mental health emergency:
If a student's check-in data indicates acute distress (multiple consecutive negative emotional states), we recommend teachers follow their school board's established wellbeing and safety protocols.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make significant changes, we will:
If you continue using Puffin Resilience Lab after a policy update, you are deemed to have accepted the revised terms.
If you have questions, concerns, or requests related to this Privacy Policy or your personal information, we want to hear from you.
For privacy inquiries, data access requests, or deletion requests — our team will respond within 5 business days.
✉️ puffinresiliencelab@gmail.com