01 Scope and roles
CodeJumbo LLC ("CodeJumbo," "we," "us") builds education and online-learning software. This policy explains what personal information we collect, why we collect it, who we share it with, and what control you have over it. It covers codejumbo.com and the apps, tools, and services that link to it (the "Services").
We collect the least we can get away with, we use it to run the product you asked for, we do not sell it, and we do not use children's information for advertising. When a school hires us, the school's data stays the school's data.
Two different roles
As a controller. For our own website, marketing, and directly purchased accounts, we decide how personal information is handled, and this policy governs.
As a processor or service provider. When a school, district, publisher, or business client uses our Services with their own learners or users, that client decides what data is collected and why. We process it under their instructions and under our contract with them. In that case, the client's own privacy notice governs the relationship with the individual, and privacy requests should go to the client first — though you can always contact us and we will route your request.
02 Information we collect
Information you give us
- Account details — name or display name, email address, password (stored only as a salted hash), role (learner, educator, parent, admin), and school or organisation where relevant.
- Learning activity — answers, submissions, attempts, scores, time on task, streaks, mastery estimates, and content you create or upload.
- Communications — messages you send to support or sales, including attachments, and your responses to surveys.
- Payment information — billing name, address, and the last four digits and brand of your card. Full card numbers are handled by our payment processor and never stored on our systems.
Information we collect automatically
- Device and connection data — IP address, browser and operating system, device type, language, and time zone.
- Usage data — pages and screens viewed, features used, referring page, and timestamps.
- Diagnostics — crash reports, error logs, and performance traces.
We do not collect precise geolocation, we do not use device-fingerprinting for advertising, and we do not build cross-site behavioural profiles.
Information from others
- Rostering and single sign-on — if your school connects Google Workspace, Clever, ClassLink, an LMS, or a similar system, we receive the roster fields that system shares (typically name, school email, class and section, and role).
- Service providers — payment status from our processor, deliverability signals from our email provider, and abuse signals from our security vendors.
03 How we use information
- Provide the Services — create accounts, deliver lessons and practice, save progress, sync across devices, and generate reports.
- Personalise learning — choose the next question, schedule review, and estimate mastery. This personalisation applies only to educational content.
- Support — answer questions, investigate problems, and restore lost work.
- Improve and secure — understand which features are used, fix bugs, measure performance, detect abuse and fraud, and protect accounts.
- Billing — process payments, prevent chargebacks, and keep financial records.
- Communicate — send service notices, security alerts, and (for adult account holders who opt in) product news you can unsubscribe from at any time.
- Comply with law — meet legal obligations and enforce our Terms of Service.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not serve targeted advertising inside our learning products, and we never use student data for advertising of any kind.
04 Legal bases (EEA and UK users)
If you are in the European Economic Area or the United Kingdom, we rely on:
- Contract — to provide the Services you or your organisation signed up for.
- Legitimate interests — to secure our systems, prevent abuse, improve our products, and communicate with business contacts, balanced against your rights.
- Consent — for optional cookies, marketing email, and any processing where we ask for it. You may withdraw consent at any time.
- Legal obligation — to keep tax, accounting, and compliance records.
05 Children's and student data
Learning products are used by children, so we hold this data to a stricter standard than everything else we handle.
Our commitments
- We collect from a child only what the educational service actually needs.
- We do not require a child to disclose more than is reasonably necessary to participate.
- We do not serve behavioural or targeted advertising to children, and we do not build advertising profiles from student data.
- We do not sell student data, and we do not use it to train third-party commercial models.
- Student data is used only to provide and support the educational service, and for authorised research or aggregate, de-identified reporting.
COPPA (United States, under 13)
Where we collect personal information from children under 13, we do so either with verifiable parental consent or under the school-consent model, in which a school or district provides consent as the parent's agent for educational use. A school that uses our Services on this basis is responsible for notifying parents about the categories of information collected and for obtaining any consent required by law; we make that information available to schools on request.
Parents may review their child's personal information, ask us to delete it, and refuse further collection by contacting privacy@codejumbo.com. If the account was created through a school, we will direct the request to the school and support them in fulfilling it. If we learn we have collected information from a child under 13 without the required authorisation, we delete it promptly.
FERPA and state student-privacy laws
When we handle education records on behalf of a school or district, we act as a "school official" with a legitimate educational interest under FERPA, use the records only for the purposes authorised by the institution, and do not re-disclose them except as the institution directs or the law requires. We also honour our obligations under applicable state student-privacy laws (such as SOPIPA-style statutes), including restrictions on advertising, profiling, and sale of student data.
Deletion at the end of a relationship
When an institution's contract ends, we delete or return student data at the institution's direction, subject to the retention limits described in section 9.
08 Automated decisions and AI features
Some of our products use algorithms to choose the next item to practise, schedule review, or estimate how well a skill has been learned. These are educational recommendations, not decisions with legal or similarly significant effects. Learners and educators can always override them, and a human educator remains responsible for grading, placement, and reporting decisions.
Where a product includes AI-assisted features such as generated hints or explanations, we tell you in the product. We do not use student content to train third-party general-purpose models, and any use of your content to improve our own educational models is described in your agreement with us and is subject to opt-out where the law requires it.
09 How long we keep data
We keep personal information only as long as we need it for the purposes described here, then delete or de-identify it. In general:
- Account and learning data — for the life of the account, and for up to 90 days after deletion so accidental deletions can be reversed.
- Institutional student data — for the term of the contract, then deleted or returned at the institution's direction, normally within 45 days.
- Backups — encrypted backups roll off on a fixed schedule, typically within 35 days.
- Support messages — up to 3 years.
- Billing and tax records — as long as the law requires, typically 7 years.
- Security logs — typically 12 months.
10 Security
We protect personal information with encryption in transit (TLS) and at rest, role-based access controls and least-privilege access, multi-factor authentication for staff, environment separation, dependency and vulnerability monitoring, audit logging, and regular backups with restore testing.
No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant authorities or institutions within the timeframes the law requires. Report a suspected vulnerability or incident to security@codejumbo.com.
11 Your rights and choices
Depending on where you live, you may have the right to:
- know what personal information we hold and get a copy of it;
- correct information that is inaccurate or incomplete;
- delete your information, subject to legal exceptions;
- receive your data in a portable, machine-readable format;
- object to or restrict certain processing;
- withdraw consent you previously gave; and
- be free from discrimination for exercising any of these rights.
To make a request, email privacy@codejumbo.com. We will verify your identity — usually through the email address on the account — and respond within the time the applicable law allows, generally 30 to 45 days. Requests may be made by an authorised agent with proof of authorisation. If your account came from a school or employer, we will forward your request to them and assist them in answering it.
You can unsubscribe from marketing email using the link in any such message; we will still send essential service notices.
If you are in the EEA or UK and believe we have handled your data improperly, you may complain to your local supervisory authority. We would appreciate the chance to address it first.
12 US state privacy rights
Residents of California, Colorado, Connecticut, Virginia, and other states with comprehensive privacy laws have the rights described in section 11, plus the right to opt out of sale, targeted advertising, and certain profiling, and — in California — the right to limit the use of sensitive personal information.
We do not sell personal information and we do not share it for cross-context behavioural advertising, including the personal information of consumers we know to be under 16. We have not done so in the preceding 12 months. Because there is nothing to opt out of, we do not maintain a "Do Not Sell or Share" mechanism; if that ever changes, we will publish one and update this policy first.
The categories of personal information we collect, the purposes for collecting them, and the categories of recipients are listed in sections 2, 3, and 6. California residents may also request the specific pieces of personal information we hold. We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit.
13 International transfers
We are based in the United States, and our service providers may process data in the United States and other countries whose data-protection laws differ from those where you live. Where we transfer personal information out of the EEA, the UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses and the UK Addendum, along with supplementary technical measures. You can request a copy of the relevant safeguards by writing to us.
14 Third-party links and integrations
Our Services may link to or integrate with sites and tools we do not operate. Their privacy practices are their own, and we are not responsible for them. Please read their policies before providing personal information.
15 Changes to this policy
We update this policy when our practices or the law change. We will revise the "Last updated" date above, and for material changes we will give notice by email or in-product message before they take effect. If a change materially affects children's or student data, we will obtain any consent the law requires before applying it.
16 Contact us
Privacy questions, requests, or complaints:
CodeJumbo LLC — Privacy
502 W 7th St, Ste 100
Erie, PA 16502, United States
privacy@codejumbo.com
For security reports: security@codejumbo.com. For everything else: hello@codejumbo.com.