🌱 teachChat guide Open teachChat β†—

πŸ”’ Privacy and your students' data

teachChat is built on a simple idea: the less student data the service holds, the less there is to worry about. This page is the plain-language summary for teachers; the canonical documents live at https://teachchat.app/privacy and https://teachchat.app/trust.

What students give (and what they never do)

Students join with a class code, a first name and last initial (for example "Alex R."), a screenname they pick, and a 4-digit PIN. The PIN is stored only as a salted cryptographic hash, never as the digits themselves. That is the whole sign-up: no student emails, no student accounts, no phone numbers, no birthdays, no photos, and nothing to install on a laptop or Chromebook.

Once class is running, teachChat stores ordinary classroom activity so the class works: chat messages, shared notes, reactions, poll answers, participation points, and moderation events such as timeouts.

Where real names actually live

Real names are never stored in the teachChat database. A student's name is checked once at sign-in, so nobody can impersonate a classmate, written to a roster file in your own Google Drive, and discarded on teachChat's end. The servers only ever keep the screenname.

That roster file sits in a "teachChat" folder in your Drive, created through Google's narrowest Drive permission (drive.file): teachChat can only see files it created itself, and cannot read, browse, or modify anything else in your Drive.

Classmates, and anything shown on a projector, only ever see screennames. Real names are visible only to you, and the screenname validator refuses handles too similar to real names on the roster. More on what students see is in For students.

Every reveal leaves a record

Any time a screenname gets paired with a real name, it is written to a reveal log:

You can review the log from your console and download it as a CSV at any time. The log entries are permanent: hiding a name again on screen does not erase the record of having seen it.

The downloaded reveal log contains screennames only, never real names, so the record itself is safe to hand to an administrator.

Not in the building

No ads, no trackers, no analytics scripts, and no cookies beyond your own sign-in session (students use a device-local session instead of cookies). No selling or sharing of data, ever.

On AI: AI moderation is not a current feature, and we will never train AI on student data. The moderation you do get is rule-based, runs on the server, and stays under your control. Blocked messages are never shown to the class.

Deletion is real deletion

Deleting a class from your dashboard immediately and permanently erases its messages, notes, roster, points, and logs from teachChat's servers. Encrypted database backups rotate out on their own within a few months, taking any last copies with them. Files already exported to your Drive stay put: those belong to the school.

You can also delete your entire account, self-serve, from the home page; every class you own is erased the same way, and teachChat revokes its own access to your Google account. What remains afterward is a single administrative record: the account's email address, its name, when the account was created, when it was deleted, and how many classes were erased with it. It exists to answer later questions about whether an account existed, and it contains no classroom data.

The documents of record

This guide is a summary, like a plant tag next to the full field notes. When you need exact wording, or your district asks for it, point to:

Fielding questions from a principal or IT director? Send them the Trust page. It was written to be forwarded to exactly that reader.

If anything here seems to disagree with those pages, the pages win, and we would like to hear about it.