🌱 teachChat guide Open teachChat β†—

πŸ”’ Privacy and your students' data

teachChat is built on a simple idea: the less student data the service holds, the less there is to worry about. This page is the plain-language summary for teachers; the canonical documents live at https://teachchat.app/privacy and https://teachchat.app/trust.

What students give (and what they never do)

Students join with a class code, a first name and last initial (for example "Alex R."), a screenname they pick, and a 4-digit PIN. The PIN is stored only as a salted cryptographic hash, never as the digits themselves. That is the whole sign-up: no student emails, no student accounts, no phone numbers, no birthdays, no photos, and nothing to install on a laptop or Chromebook.

Once class is running, teachChat stores ordinary classroom activity so the class works: chat messages, shared notes, reactions, poll answers, participation points, and moderation events such as timeouts.

Where real names actually live

Real names are never stored in the teachChat database. A student's name is checked once at sign-in, so nobody can impersonate a classmate, written to a roster file in your own Google Drive, and discarded on teachChat's end. The servers only ever keep the screenname.

That roster file sits in a "teachChat" folder in your Drive, created through Google's narrowest Drive permission (drive.file): teachChat can only see files it created itself, and cannot read, browse, or modify anything else in your Drive.

There is a stricter setting still. With a roster import, you build the class from a sheet in your own Drive and your browser does the reading, so a student's name never travels to teachChat's servers at all. Leave the name column empty and teachChat never has the names to begin with, which turns πŸ‘ reveal off for those students by construction rather than by promise.

Classmates, and anything shown on a projector, only ever see screennames. Real names are visible only to you, and the screenname validator refuses handles too similar to real names on the roster. More on what students see is in For students.

Every reveal leaves a record

Any time a screenname gets paired with a real name, it is written to a reveal log:

You can review the log from your console and download it as a CSV at any time. The log entries are permanent: hiding a name again on screen does not erase the record of having seen it.

The downloaded reveal log contains screennames only, never real names, so the record itself is safe to hand to an administrator.

Not in the building

No ads, no trackers, no analytics scripts, and no cookies beyond your own sign-in session (students use a device-local session instead of cookies). No selling or sharing of data, ever.

On AI: AI moderation is not a current feature, and we will never train AI on student data. The moderation you do get is rule-based, runs on the server, and stays under your control. Blocked messages are never shown to the class.

Deletion is real deletion

Deleting a class from your dashboard immediately and permanently erases its messages, notes, roster, points, and logs from teachChat's servers. Encrypted database backups rotate out on their own within 180 days, taking any last copies with them. Backups exist to recover from disaster and are never used to bring a deleted class back. Files already exported to your Drive stay put: those belong to the school.

Forgotten classes clean themselves up. You do not have to remember to tidy after June: a class with no activity for 12 months is deleted automatically by a job that runs every day. teachChat does not keep student data indefinitely, and that is enforced by a scheduled job rather than a good intention.

You can also delete your entire account, self-serve, from the home page; every class you own is erased the same way, and teachChat revokes its own access to your Google account. What remains afterward is a single administrative record: the account's email address, its name, when the account was created, when it was deleted, and how many classes were erased with it. It exists to answer later questions about whether an account existed, and it contains no classroom data.

Where teachChat is offered

The United States and its territories, and nowhere else. That is not only a line in the terms: requests from outside that area are turned away before they reach the application.

A one-person service cannot credibly satisfy every country's privacy law at once, so teachChat commits to one and builds for it: U.S. classrooms, under U.S. student privacy law.

You have to accept the documents

The first thing you meet after signing in with Google is a box asking you to read and accept the Terms of Service and Privacy Policy. It does not go away until you do, and teachChat records which version you accepted and when.

That is deliberate. A link in a footer is not an agreement anybody can point to later. If a district ever asks what their teacher agreed to, there is a real answer with a date on it.

The documents of record

This guide is a summary, like a plant tag next to the full field notes. When you need exact wording, or your district asks for it, point to:

Fielding questions from a principal or IT director? Send them the Trust page. It was written to be forwarded to exactly that reader.

If anything here seems to disagree with those pages, the pages win, and we would like to hear about it.