Privacy policy

Privacy built for the classroom.

This policy explains how Mrs Morenos Class collects, uses, shares, protects, and retains information. It applies to the website, teacher and student accounts, classroom tools, and learning supports. Last updated September 29, 2026.

Who operates the service

Mrs Morenos Class operates the service. Questions, school requests, and privacy requests can be sent to support@morenoenterprises.org.

Information we collect

Depending on the features used, we collect:

  • Teacher account information: name, email address, account role, account status, sign-in provider, provider account identifier, and account timestamps.
  • Student account information: a system-generated username selected by the student, an internal non-deliverable authentication alias, account role and status, authentication provider identifier, and account timestamps. Students are not asked for a name, email address, birthday, student ID, or other direct identifier when registering.
  • Classroom information: classroom name, teacher-selected dashboard music links, teacher and pseudonymous student memberships, a random reusable class-link token, link status, and related timestamps. Class links do not contain a student name or email address.
  • Teacher-verification information: professional name, job title, school, district, school location, verified work email, an optional directory URL, verification status, public professional evidence, and review decisions.
  • Teacher subscription information: selected plan and billing interval, trial and paid-period dates, payment and cancellation status, recurring-billing consent and notice records, and Stripe customer, subscription, checkout-session, and event identifiers. Notice records include the message, recipient address, and delivery status. Stripe collects and processes payment details; we do not store full card or bank account numbers in the application database.
  • Technical and usage information: session and security information needed to operate the service. Where analytics is enabled, it may include page visits, approximate location, browser and device information, and interactions.
  • Support information: information included in a message when someone contacts us for help or makes a privacy request.

We do not ask students to submit names, email addresses, birth dates, student IDs, grades, disability information, health information, government identifiers, or other sensitive education records through the service.

How we collect information

We receive information directly from users, from a teacher or school that creates a classroom and class link, from Firebase Authentication, and from official public school or district sources used to verify a teacher. Privacy-configured product analytics and necessary security technology may also collect limited information automatically.

How we use information

  • Authenticate accounts and keep them secure.
  • Provide teacher, student, classroom, and learning features.
  • Verify eligibility for teacher-only tools.
  • Maintain class join links and classroom memberships.
  • Restrict student learning access when no teacher is providing an active classroom seat.
  • Manage teacher subscriptions, document recurring-billing consent, and send billing and retention notices.
  • Respond to support, safety, and privacy requests.
  • Detect misuse, investigate security problems, and comply with law.
  • Understand aggregate use, troubleshoot user flows, and improve the service.

Student information is used to provide teacher-directed educational features and support the internal operation of the service. It is not used for targeted advertising, behavioral profiling, or unrelated commercial purposes.

Authentication, local storage, and cookies

Firebase Authentication provides teacher Google or email-and-password sign-in and student username-and-password authentication. A student username is converted in the browser to a non-deliverable internal account alias so Firebase can authenticate the account without collecting the student's email address.

Passwords are transmitted directly to Firebase Authentication over an encrypted connection and are not stored in the Mrs Morenos Class application database. Passwords are not included in analytics, application logs, teacher or administrator screens, or requests to AI models. Teachers, administrators, and Mrs Morenos Class cannot view a student's password. The student interface requires at least eight characters and does not require a particular mix of character types. After sign-in, the service uses a secure session cookie to keep the user authenticated.

A teacher may create a single-use, 15-minute password reset link or QR code only for an active student in that teacher's classroom. The student chooses the replacement password. The application stores only a one-way hash of the reset token, along with its classroom authorization and status timestamps; it does not store the usable reset link or replacement password.

After an account is permanently deleted, the service temporarily retains a one-way hash of the former Firebase identifier for seven days. This short-lived security record prevents an already-issued session token from recreating the deleted account and cannot be used to recover the Firebase identifier.

Teacher Dashboard settings—including agenda items, roster text, theme choices, alarm choices, and a selected presentation link—are stored locally in the teacher's browser. Teacher-selected YouTube music links, display names, order, and default choice are stored with the teacher's classroom workspace so they can be restored on another device. Optional Google Drive access tokens stay in the browser and are not stored in the application database.

Analytics

Google Analytics may be used on public and teacher-facing product pages to understand aggregate use, troubleshoot user flows, and improve educational features. It is configured for internal product measurement, not targeted advertising or cross-site profiling. Advertising storage, advertising user data, advertising personalization, and Google Signals are disabled in the site implementation. URLs sent by the application are path-only and omit query parameters, invitation tokens, searches, presentation sessions, and form state. User-provided identifiers are not intentionally supplied as analytics event parameters.

Google Analytics is not loaded on student-facing experiences, including class-join pages, student sign-in and signup, student account and password-reset pages, the student library, or student learning pages. Those experiences do not send Google Analytics page views, learning answers, search activity, clicks, or other product events.

We do not respond to legacy browser “Do Not Track” signals because there is no common technical standard for them. Where a legally recognized opt-out signal applies, we will honor it as required.

How information is disclosed

We do not sell or rent personal information, and we do not share student information for cross-context behavioral advertising. Limited information is disclosed only when needed to operate the service, protect users, or comply with law, including to:

  • Google, YouTube, and Firebase for authentication, optional Google Drive features, teacher-requested YouTube title lookups and playback, and privacy-configured product analytics.
  • Cloudflare for application hosting, database, network, and security services.
  • Stripe for teacher subscription checkout, payment processing, billing management, receipts, and billing notices.
  • OpenAI to help compare a teacher's submitted professional details with public school or district sources.
  • A teacher or school for the classroom they control. Teachers can view only the generated usernames of students who joined their classroom, not student names, email addresses, or passwords.
  • Authorities or professional advisers when reasonably necessary to comply with law, protect rights and safety, or address a security incident.

We require service providers to use information only to provide the requested service and to protect it appropriately.

Teacher verification and OpenAI

A teacher verification request may send the applicant's professional name, job title, school, district, school location, work email, and optional directory URL to OpenAI. The verification process searches for relevant public professional evidence from official school or district sources. It does not evaluate students or make educational decisions about them.

The service stores the verification result, cited public evidence, status, and any manual review decision to protect teacher-only tools. OpenAI processes API information under its applicable business and data-control terms.

Children and student privacy

A student account is created through a teacher-controlled class link that can be paused, replaced, or allowed to expire. The student selects from closed-choice, randomly generated usernames so the registration form does not invite the child to disclose personal information. The generated username and Firebase account identifier are persistent identifiers used only to authenticate the student and maintain the teacher-controlled classroom membership.

A student must have at least one active teacher-controlled classroom membership to use authenticated student learning resources. A student without an active classroom may sign in only to receive assignment instructions and join a new teacher through that teacher's class link.

A parent, guardian, school, or account holder may ask to review, correct, or delete a child's personal information and may ask us to stop further collection. Send requests to support@morenoenterprises.org. We may verify the requester's identity and relationship to the account before acting.

Requests concerning a student account must identify it using the generated username. Do not send the student's real name, email address, birthday, student ID, or password. We may verify the request through the signed-in account or the teacher-controlled classroom membership.

Retention and deletion

We retain personal information only as long as reasonably necessary for the specific purpose for which it was collected. We do not use “reporting and compliance” as a basis to keep student information indefinitely.

  • If a public teacher trial ends without payment, or paid classroom access is suspended for nonpayment after the last paid period, we keep that teacher's classroom data for 90 days from the suspension date. We notify the teacher when access pauses and at least seven days before classroom deletion. If that reminder is delayed, deletion is delayed too. Paying during this period restores access, subject to plan limits. After the 90 days and notice period, the teacher-owned classrooms and associated classroom data may be permanently deleted. Voluntary cancellation alone does not start this unpaid-data deletion process. A student account or membership in another active classroom is not deleted solely because one teacher's unpaid classroom reaches this deadline.
  • Student Firebase Authentication accounts and associated application account records are automatically deleted after six continuous months without an active teacher-controlled classroom membership. Joining or being recovered into a classroom before that deadline clears the inactivity period.
  • A teacher may recover a removed classroom membership for 30 days. After 30 days, the membership is no longer visible or manageable by the teacher. The underlying record is deleted when the associated student account or teacher-owned classroom is permanently deleted.
  • Student password-reset records are automatically deleted 30 days after the reset link expires. A reset link itself expires after 15 minutes, works once, and is replaced when the teacher creates another link for that student.
  • When a teacher requests account deletion, the teacher account and owned classrooms are deactivated immediately. The teacher may cancel for 30 days; after that period, the teacher's Firebase Authentication account, application account, dashboard music choices, owned classrooms, class links, and associated teacher-verification records are permanently deleted.
  • We retain verification of a teacher's affirmative consent to automatic renewal for at least three years, or one year after the subscription ends, whichever is longer. Billing acknowledgments and renewal-notice records may remain after teacher account deletion to document that consent and the notices sent, and for applicable legal, tax, or dispute obligations.
  • Deleted information may remain temporarily in service-provider backup or recovery systems until it expires under the provider's applicable retention schedule.

Security

We use authentication, recent-sign-in checks for teacher account deletion and student password-reset authorization, access controls, encrypted connections, high-entropy class and reset links with expiration, one-use reset tokens, teacher-controlled rotation, role-based classroom boundaries, path-only analytics on approved public and teacher-facing pages, analytics disabled throughout student-facing experiences, and limited administrative access to protect information. Student passwords remain with Firebase Authentication and are never available in teacher or administrator tools. No system can guarantee absolute security. If a security incident affects personal information, we will investigate and provide notices as required by law.

Your choices and California disclosures

Users, schools, parents, and guardians may request access, correction, deletion, or account closure by emailing support@morenoenterprises.org. We will not discriminate against someone for making a privacy request.

California residents can also request information about the categories of personal information collected and the categories of service providers to which it is disclosed. Mrs Morenos Class does not sell personal information or share it for cross-context behavioral advertising.

Outside links and embedded services

Learning resources, teacher-selected presentations, Google Drive, YouTube privacy-enhanced embeds, and external digital libraries may be governed by their own privacy policies. Teachers should review an outside resource before using it with students.

Changes to this policy

We may update this policy as the service changes. Material changes will be identified by a new date at the top of the page and, when appropriate, communicated through the service or to the responsible school or account holder before the change takes effect.

Contact

Privacy questions and requests can be sent to Mrs Morenos Class at support@morenoenterprises.org.