BALANCEBOARD
ORBIT_STABLE
NEBULA_DRIFT
STELLAR_PHASE
GRAVITY_ZERO
COSMIC_BALANCE

PRIVACY_POLICY

EFFECTIVE: MARCH 30, 2026|LAST UPDATED: AUGUST 31, 2026|VERSION: 2026-08-31

Welcome to BalanceBoard ("we," "our," or "us"). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use our student academic management and wellness platform at balanceboard.app. We built BalanceBoard specifically for high school students, and we take your privacy—especially as a minor—with the utmost seriousness.

By using BalanceBoard, you agree to the collection and use of information in accordance with this policy. If you are under 18, we encourage you to review this policy with a parent or guardian. If you do not agree with any part of this policy, please do not use our service.

This policy should be read together with our Terms of Service, AI Disclaimer, Mental Health Disclaimer.

1. Information We Collect

1.1 Account & Identity Information

When you sign in with Google OAuth, we receive and store:

  • Full name and email address (from your Google account)
  • Profile photo URL (from your Google account)
  • Google Account ID (used to uniquely identify you)
  • Google OAuth tokens (access token and refresh token, encrypted)
  • School name, grade level, and graduation year (provided during onboarding)
  • Derived age band (13–15, 16–17, or 18+) and attestation time. Your date of birth is used transiently for the age check and is not retained after the band is derived.
  • Account role
  • Onboarding completion status
  • UI preferences (color theme)
  • Purpose-specific wellness and AI choices

1.2 Google Classroom Educational Data

With your explicit permission via Google OAuth, we access read-only data from Google Classroom:

  • Course IDs and names
  • Assignment titles, descriptions, due dates, and point values
  • Your submission status and Classroom link for each assignment

What we do NOT access: The content of your submitted assignments, teacher details, class rosters, enrollment codes, your grades, your private messages in Classroom, other students' data, or any data outside your own account. We operate with minimum necessary scopes and can never write to or modify your Google Classroom data.

1.3 Academic Task Data

  • Tasks you manually create: title, description, subject, due date, priority, status
  • Task category and estimated completion time
  • Links back to Google Classroom assignments (Google IDs stored as reference)
  • Sync history: when we last synced, how many courses and assignments were retrieved

1.4 Wellness & Mental Health Data

This is among the most sensitive data we handle. It is stored with encryption and is accessible only to you. See Section 9 for our specific commitments.

  • Daily check-in data: mood (scale), energy level, stress level (1–5)
  • Sleep data: hours slept, sleep quality (Good/Fair/Poor)
  • Physical metrics: water intake (glasses), exercise minutes, screen time hours, study minutes
  • Wellness "wins": boolean flags for daily healthy habits
  • Daily notes (free-text journaling)
  • BalanceIndex (calculated from above metrics)
  • Check-in counts, progress, and badges earned
  • AI Wellness Coach requests are processed when you ask for an insight; BalanceBoard does not maintain a conversation-history table for them

1.6 College Planning Data

  • College application tracking (school names, status, notes)
  • Target school lists (Dream/Target/Safety categorization)
  • Test prep goals and deadlines (SAT, ACT, AP exams)
  • This data is stored locally in your browser (localStorage) and optionally synced to our servers

1.7 Technical & Usage Data

  • IP address (collected by Supabase and Vercel hosting infrastructure)
  • Browser type, version, and operating system
  • Referring URL and pages visited within BalanceBoard
  • Device type (desktop, mobile, tablet)
  • Session duration and feature usage patterns
  • API request logs (timestamps and endpoints accessed)
  • Error logs (for debugging — contain no personal content)
  • Offline cache: BalanceBoard can be installed as an app (PWA). Your browser stores public app assets and an identity-free offline message on your device. Authenticated pages, API responses, wellness data, and task data are not saved by the service worker for offline display. On a shared device (e.g., a school Chromebook), sign out and clear browsing data to remove browser storage.
  • First-party product metrics: we record a small set of basic usage events in our own database (account created, active on a given day, first-time feature use such as slicing a task, that a check-in was submitted — never its contents — and that a check-in changed the app's task suggestion for the day). These help us understand whether BalanceBoard is actually helping students. No third-party analytics services are involved in these in-app metrics, and these events are never used for advertising or shared with anyone. (Separately, our public marketing pages — not the student app — use Google Analytics; see Section 3.1.)

1.8 AI Interaction Data

  • Messages you send to the AI Buddy or AI Wellness Coach
  • AI responses generated for you
  • Your current task list and workload context (sent to AI to enable intelligent responses)
  • Natural language commands for task creation/deletion

See our AI Disclaimer for full details on how Anthropic processes this data.

2. How We Use Your Information

We use the information we collect to:

  • Provide core services: Syncing your Google Classroom assignments after you connect Classroom, displaying your task dashboard, and providing the optional wellness features you enable.
  • Power optional AI features: When you deliberately use AI task planning, sending the disclosed task/message fields needed for that request to Anthropic. Structured wellness fields are sent only after a separate AI-wellness choice and only when you request an insight.
  • Personalize your experience: Calculating your BalanceIndex, generating wellness insights, and tailoring AI responses to your specific workload and stress patterns.
  • Connect your workload and wellbeing: Combining your assignment/due-date data with your self-reported wellness check-ins — within our systems only — to show you how your workload and stress move together (e.g., the weekly workload-vs-stress view) and to adjust in-app suggestions (e.g., recommending a smaller first step on a day you reported high stress). This combination is not shared with any additional third party.
  • Send important notifications: Reminders for upcoming assignments, wellness check-in prompts, and security alerts about your account. Browser/desktop deadline notifications are strictly opt-in (your browser asks for permission first) and can be revoked at any time in your browser settings; their content is limited to your own task titles and deadlines and is generated on your device.
  • Improve the platform: Analyzing aggregated (non-personally-identifiable) usage patterns to understand which features are most helpful and fix bugs.
  • Comply with legal obligations: Responding to valid legal processes, protecting our rights, and maintaining records required by law.
  • Crisis resources: A limited automated phrase check may display resource links. It does not create a monitoring case or automatically contact another person. See our Safety Policy.

3. Data Sharing & Disclosure

Core Commitment

We do not sell, rent, or trade your personal data to anyone, for any purpose, ever. We do not use your data for targeted advertising or share it with data brokers.

3.1 Service Providers (Sub-processors)

We share data with the following trusted third-party services to operate BalanceBoard. Each is bound by data processing agreements and privacy obligations:

Supabase (Supabase, Inc.)

Our database and file storage provider. All your data (profile, tasks, wellness entries, social data) is stored on Supabase-hosted PostgreSQL servers. Data is encrypted at rest and in transit; see Supabase's published security and compliance documentation for its current certifications.

Data shared: All user data stored in our platform.

Anthropic, PBC

Our AI provider. Purpose-specific information is sent to Anthropic only when you deliberately invoke an AI task-planning action or, after a separate choice, request an AI wellness insight. BalanceBoard does not claim a vendor retention or training term beyond the terms/settings actually applicable to its API account. See AI Notice.

Data sent to Anthropic when using AI task planning: The current sanitized, length-limited message, plus up to 100 pending-task records containing ID, title, subject, due date, priority, and local-date context. Prior chat turns are not sent by the current route.

Data sent to Anthropic when using AI Wellness Coach: Up to 7 recent wellness check-ins containing structured fields such as mood, sleep hours, stress level, energy, water intake, exercise, screen time, outdoor time, social quality, and study time. Journal notes are deliberately excluded. This context is not linked to your name, email, school, or grade.

Data sent to Anthropic when using the AI Task Slicer: A length-limited copy of the title and description/notes of the single task you choose to slice. Because Google Classroom assignment descriptions and any teacher instructions you paste into a task's notes become part of that description, they are included when — and only when — you press the slice button on that task. Not linked to your name or email.

NOT sent to Anthropic: Your name, email address, school, grade, Google account ID, OAuth tokens, wellness journal notes, other users' data, or uploaded files.

Google LLC

We use Google OAuth for authentication and Google Classroom APIs for assignment syncing. Your authentication tokens are stored encrypted. We operate under Google's API Services User Data Policy, including the Limited Use restrictions detailed in Section 4.

Data shared: basic Google account details for sign-in; encrypted Classroom authorization tokens only if you later choose to connect Classroom.

Vercel, Inc.

Our hosting and deployment infrastructure. Vercel may log IP addresses and request metadata for operational purposes per their privacy policy.

Data shared: Request logs, IP addresses (infrastructure-level only).

Google Analytics (Google LLC)

We use Google Analytics on our public marketing and informational pages only (homepage, blog, comparison and legal pages) to understand how visitors find BalanceBoard. It is never loaded inside the student app: your dashboard, tasks, wellness check-ins, and AI conversations send nothing to Google Analytics. IP addresses are anonymized and Google advertising features (Google Signals, remarketing) are disabled.

Data shared: Anonymized visit data on public pages only (pages viewed, referring site, device type). No account data, no wellness data, no in-app activity.

Upstash, Inc.

Our rate-limiting provider. To prevent abuse of AI and account features, request counters are kept in Upstash-hosted Redis. These counters are keyed by an account identifier (such as your user ID or account email) or, for logged-out visitors, an IP address, together with request timestamps. No message content, task content, or wellness data is sent to Upstash, and counters expire automatically after a short period.

Data shared: Account identifier or IP address, request counts/timestamps (short-lived).

3.2 Legal Disclosures

We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court order or government agency subpoena). We will notify you of such requests where legally permitted.

3.3 Safety Emergencies

The automated phrase check only displays resources and does not contact third parties. If a person deliberately sends information to support, we may disclose limited information when required by law or valid legal process, or when reasonably necessary to address an imminent threat, subject to applicable law. See our Safety Policy.

3.4 Counselor and School Access

BalanceBoard does not currently provide counselor dashboards, school rosters, or institutional student-data access. No counselor or school receives account, task, or wellness data through BalanceBoard.

3.5 Business Transfers

If the service or its assets are acquired, merged, or transferred, account data may be part of that transaction, subject to applicable law and the notices and choices required at that time.

4. Google API Services — Limited Use Policy

BalanceBoard's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, Google Classroom data is used only to:

  • Display your enrolled courses and upcoming assignment due dates in your BalanceBoard dashboard
  • Automatically populate your task list so you don't have to enter assignments manually
  • Help the AI Buddy understand your current workload to provide relevant academic support

Google Classroom data is NOT used to:

  • Serve advertisements or for any commercial purpose
  • Share with third parties for their own use (other than our service providers listed above)
  • Analyze for any purpose other than providing and improving BalanceBoard features
  • Build profiles for sale or transfer
  • Train AI models (we do not train on your Classroom data)

5. Student Privacy — FERPA & COPPA

5.1 FERPA (Family Educational Rights and Privacy Act)

FERPA protects the privacy of student education records. When BalanceBoard accesses your Google Classroom data (courses, assignments, submission status), that data may constitute education records under FERPA. Our commitments:

  • We access education records only with your explicit authorization via Google OAuth consent — we never access Classroom data without user-initiated permission
  • We operate in read-only mode — we cannot write to, modify, or submit anything in your Google Classroom account
  • We do not re-disclose education records to third parties (other than the service providers listed in Section 3) without consent
  • You retain the right to review, correct, and delete your education-related data at any time through Settings
  • We do not use education record data for any purpose beyond providing BalanceBoard's features to you directly
  • If a school district, administrator, or parent/guardian requests data about a specific student, we require a valid legal process (subpoena or court order) unless the student themselves authorizes the disclosure
  • BalanceBoard is a student-initiated tool, not a school-deployed institutional tool. Institutional use requires a separate agreement with appropriate FERPA provisions.

5.2 COPPA (Children's Online Privacy Protection Act)

Minimum Age: 13

BalanceBoard is not directed to children under 13 and does not knowingly collect personal information from children under 13. If you are under 13, please do not register or use BalanceBoard.

If we discover or are notified that a user is under 13, we will immediately:

  • Suspend the account and block further access
  • Permanently delete all personal information associated with that account from our systems
  • Revoke any Google OAuth tokens associated with the account
  • Return a deletion-request status in the product and route failures for operational follow-up

For users aged 13–17 (minors): BalanceBoard can hold personal data including tasks, wellness check-ins, mood logs, and stress indicators. We strongly encourage parents and guardians to:

  • Review this Privacy Policy and our Terms of Service together with their teen
  • Discuss what data is collected and how it is used
  • Review the AI Disclaimer to understand what data is sent to Anthropic
  • Help their teen make informed decisions about optional wellness and AI features

If you are a parent or guardian and believe we have inadvertently collected information from a child under 13, please contact us immediately at privacy@balanceboard.app — we will respond within 24 hours and take immediate action.

6. Data Retention

Data TypeRetention PeriodNotes
Account profileUntil deletion requestedAccess is disabled and deletion begins promptly
Google OAuth tokensUntil disconnected or expiredEncrypted; refreshed automatically
Tasks & assignmentsUntil deleted or account closedYou can delete individual tasks
Wellness check-insUntil deleted or account closedExportable from Settings
AI requests/responsesNo BalanceBoard conversation-history tableThe AI provider may process request data under its applicable API terms/settings
Sync and technical logsLimited to operational and legal needsHosting and backup providers may retain limited records under their applicable schedules

When you request deletion, account access is disabled and BalanceBoard begins deleting registered account data and revoking connected Google access. Incomplete steps are retried and their status is shown in Settings. Provider backups may follow the providers' separate schedules.

7. Security Measures

We implement industry-standard security measures to protect your data:

  • Encryption in transit: All data transmitted between your browser and our servers uses TLS (HTTPS). Plain HTTP is not accepted.
  • Encryption at rest: Database and storage encryption at rest is provided by our infrastructure provider; Google OAuth tokens also use application-level authenticated encryption before storage.
  • OAuth tokens: Google access and refresh tokens are stored encrypted and never exposed in client-side code or API responses.
  • Access control: Account data is restricted to the signed-in student and authorized service operations.
  • Secure headers: We enforce X-Frame-Options, X-Content-Type-Options, and strict Referrer-Policy on all responses.
  • Session management: JWT-based sessions have a 30-day maximum lifetime. Normal sign-out removes the browser cookie; protected APIs also re-check account status on every request.
  • Service protection: We use technical and organizational safeguards intended to prevent unauthorized access, misuse, and disruption.
  • No plain-text storage: We do not store passwords — authentication is handled exclusively via Google OAuth.

No system is 100% secure. If you discover a security vulnerability, please responsibly disclose it to support@balanceboard.app. Do not publicly disclose security issues before we have had 30 days to respond.

If a data breach affects your personal information, we will provide notices within the time and through the channels required by applicable law.

8. Your Privacy Rights

Regardless of where you live, you have the following rights regarding your data:

Right to Access

Request a copy of all personal data we hold about you. Contact us at support@balanceboard.app.

Right to Correction

Update inaccurate data via your Profile settings or by contacting us.

Right to Deletion

Request deletion of your account and associated data via Settings → Delete Account.

Right to Portability

Export supported account, task, and wellness data as a structured JSON file via Settings → Export Data. The export includes a manifest showing any section that could not be read.

Right to Restrict Processing

Request that we stop processing your data for specific purposes while retaining the data. Contact us to invoke this right.

Right to Object

Object to our processing of your data for certain purposes (e.g., AI analysis). You can disable AI features in Settings.

Right to Withdraw Consent

Revoke Google Classroom access at any time by disconnecting the integration in Settings. Your existing synced assignments will remain but no new syncs will occur.

Right to Non-Discrimination

We will not discriminate against you for exercising any of these rights.

To exercise any right, email support@balanceboard.app with the subject line "Privacy Rights Request." We will respond within the timeframe required by applicable law.

9. Wellness & Mental Health Data — Special Protections

Wellness data — including mood scores, stress levels, sleep quality, and daily notes — is among the most sensitive data we hold. We apply additional protections:

  • Private by default: Your wellness data is never shown to other users, peers, or anyone else. It is visible only to you.
  • Not shared for advertising: We will never use your mental health or mood data to target you with advertisements.
  • Separate AI choice: You can track wellness without AI sharing. Only after you separately enable AI wellness insights will up to seven structured check-ins be sent to Anthropic when you request an insight. Journal notes are excluded.
  • Crisis-resource phrase check: A limited deterministic check may match some expressions and display resources such as 988. It is not monitoring, risk assessment, or a substitute for emergency help, and it never automatically contacts third parties.
  • No counselor or school access: BalanceBoard does not currently provide counselors or schools access to wellness data.
  • Not a medical record: BalanceBoard wellness data is not a medical record and is not governed by HIPAA. See our Mental Health Disclaimer.

10. California Residents — CCPA & CalOPPA

11.1 CCPA (California Consumer Privacy Act)

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you specific rights:

  • Right to Know: You can request that we disclose what categories of personal information we collected, the sources, our business purpose, and which third parties we share it with.
  • Right to Delete: You can request deletion of personal information we have collected from you (with exceptions).
  • Right to Opt-Out of Sale: We do not sell personal information. Therefore, no opt-out is needed.
  • Right to Non-Discrimination: We will not deny service or charge different prices based on your exercise of CCPA rights.

Additionally, the California Student Privacy Alliance (CSPA) and California Education Code Section 49073 provide additional protections for student data. We commit to complying with these provisions where applicable.

To submit a CCPA request, email support@balanceboard.app with subject "CCPA Request."

11.2 CalOPPA (California Online Privacy Protection Act)

Under CalOPPA (California Business and Professions Code §§ 22575–22579), which requires commercial websites collecting personally identifiable information (PII) from California residents to post a conspicuous privacy policy, BalanceBoard discloses the following:

  • What PII we collect: See Section 1 for a full enumeration of all personal information categories we collect, including account data, educational data, wellness data, and technical logs.
  • Third-party data collection: Third-party service providers (Supabase, Vercel, and — on public marketing pages only — Google Analytics) may collect infrastructure-level or anonymized visit data (IP addresses, request metadata, pages viewed) through our platform as described in Section 3. We do not permit third-party advertising networks or data brokers to collect PII through BalanceBoard.
  • How to review or change your PII: You may access, correct, or delete your personal information via your Profile settings or by emailing support@balanceboard.app. Full data export is available via Settings → Export Data.
  • Current version: The version and "Last Updated" date at the top identify the notice currently presented for acceptance.

Do Not Track (DNT) Signals

CalOPPA requires us to disclose how we respond to browser "Do Not Track" signals. BalanceBoard does not currently respond to DNT signals because we do not engage in cross-site behavioral tracking or advertising in the first place. Your activity on BalanceBoard is never used to track you across third-party websites.

11. EU & UK Users — GDPR Rights

If you are located in the European Union or United Kingdom, the General Data Protection Regulation (GDPR) or UK GDPR applies to our processing of your personal data.

Legal Bases for Processing:

  • Contract performance: Providing the services you requested (account management, task tracking)
  • Consent or your requested action: optional Google Classroom access, wellness tracking, AI task actions you initiate, and separately enabled AI wellness insights
  • Legitimate interests: Security, fraud prevention, service improvement (balanced against your rights)
  • Legal obligation: Compliance with applicable laws

Your GDPR rights include: access, rectification, erasure ("right to be forgotten"), restriction of processing, data portability, and the right to object. You also have the right to lodge a complaint with your local supervisory authority.

Note: BalanceBoard accounts are currently offered only in the United States. Public pages may still be visited from elsewhere. Our infrastructure (Supabase, Vercel) may process data outside the EU/UK. Where applicable, international transfers rely on Standard Contractual Clauses or equivalent safeguards.

To exercise GDPR rights: support@balanceboard.app with subject "GDPR Request."

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Notify affected users through an appropriate available channel when required
  • Provide additional in-app notice when required for a material change

Continued use of BalanceBoard after the effective date of updated terms constitutes acceptance. If you do not agree to material changes, you may delete your account before the effective date.

13. Contact Us

BalanceBoard

Email: support@balanceboard.app

Website: balanceboard.app

For privacy-specific concerns, include "Privacy Request" in your email subject line. We aim to respond within 30 days for all privacy-related requests, and within 72 hours for urgent security issues.