← Palstart

Palstart Privacy Notice

Last updated: 18 September 2026 Operator: Palstart USA, 10251 Nations Circle, Stockton, CA 95209 Privacy contact: byars.jp5@gmail.com · (415) 624-6941

Palstart is an instruction-led coding program. Students learn in live classes, taught in person or virtually, and build projects on the Palstart platform. This notice explains what we collect, why, how long we keep it, and how a parent or guardian can review or delete it.

This notice covers students under 13 (subject to the Children's Online Privacy Protection Act), students 13 through 17, and adult learners.


1. What we collect

From students (all ages)

  • A display name chosen by the student. We instruct students not to use their full real name.
  • Account login credentials (username, hashed password).
  • Projects: code, files, assets, and project titles the student creates.
  • Showcase activity: posts, likes, and comments, visible only to others in the student's own environment.
  • Class session records: attendance and enrollment dates.
  • Basic technical logs needed to run and secure the service (IP address, browser type, timestamps).

From the parent or guardian

  • Name, email address, and phone number.
  • Payment records: what was paid and when. Payment itself happens outside the platform. Schools pay by cheque or bank transfer; individual families pay through a consumer payment app such as Venmo or Apple Pay, where the payment is made to us directly and those services handle the payment details under their own privacy policies. We never receive or store card or bank numbers.
  • Signed enrollment agreement, consent records, and media release elections.

We do not collect from students: real full names, home addresses, phone numbers, email addresses, photographs of students, voiceprints, biometric identifiers, government-issued identifiers, or precise geolocation.

Profile pictures are drawn, not uploaded. A student either keeps their initials or describes an avatar and the platform draws one. There is no way to upload a photograph as a profile picture, and the description they type is put through the same filter as everything else before it reaches the image model.

Project artwork. Students can upload artwork for their own projects: a sprite they drew, a background, a texture, a logo, a screenshot of their own work. Every upload is checked automatically before it is stored, and any photograph of a real person is refused, whoever is in it. A drawing, a pixel-art character, a screenshot or a computer-generated picture is not a photograph and is accepted.

Artwork uploaded before that check was introduced on 18 September 2026 was reviewed one file at a time. Nothing that was a photograph of a student was kept. What remains is stock imagery, screenshots of web pages, and reference art that students are using in their projects.

Voice. Some projects a student builds can record audio and send it to the AI for transcription. That recording is sent for the answer and is not stored by us or by the AI provider, and no voiceprint or voice model is made from it.

Prompts sent to the AI builder. Before any student prompt is sent to our AI provider, names, email addresses, phone numbers, and addresses are replaced with a pseudonym of the same kind, so the provider never receives the student's name or contact details. The real values are put back in the answer, which is why a student's own project still says what they typed. The substitution is not stored anywhere: it is worked out for each request and discarded with it. The key that decides which pseudonym a name becomes is unique to each school's environment, is never sent with the prompt, and is never kept alongside it, so the same student does not become the same pseudonym in two different environments. Students are also instructed in their first session not to enter personal information into the AI builder.


2. Why we collect it

  • To create and operate student accounts.
  • To let students build, save, run, and deploy projects.
  • To let students share work with classmates in their own cohort.
  • To track attendance and deliver instruction.
  • To communicate with parents about enrollment, billing, and class logistics.
  • To keep the service secure and prevent abuse.

We do not use student information for targeted advertising. We do not build advertising or behavioral profiles of students. We do not sell or rent student information. We do not share student information with third parties for their own marketing.


3. Who we share it with

We use a small number of service providers to run Palstart. Each is bound by contract to keep information confidential, use it only to provide services to us, and not use it for its own purposes.

ProviderPurposeData involvedLocation
Vercel (application) and Supabase (database)Application and database hostingAll platform dataUnited States
OpenRouter, restricted to United States hosted inference providersAI code assistance in the builderFiltered student prompts and codeUnited States only
Proton MailParent communicationsParent name and emailSwitzerland

Payment. No payment processor holds information on our behalf. Schools pay by cheque or bank transfer, and individual families through a consumer payment app such as Venmo or Apple Pay, paying us directly. Those services are the parent's own relationship, not ours, and we never receive card or bank numbers.

Parent email. Parent communications go through Proton Mail, which is based in Switzerland and stores mail there. This covers the parent's name and email address only. No student information is sent through it.

AI processing location. All AI requests are routed exclusively to United States hosted inference providers. Provider fallback outside the United States is disabled. Our AI providers are configured for zero data retention and do not train on our inputs.

We may also disclose information if required by law, to protect the safety of a student or another person, or in connection with a sale or transfer of the business (in which case this notice continues to apply or parents are notified).


4. Data retention policy

We do not retain personal information from children indefinitely. We retain each category only as long as reasonably necessary for the purpose it was collected, and then delete or de-identify it.

CategoryRetention periodReason
Student projects and filesDuration of enrollment, plus 60 days after withdrawalLets a returning student resume, and gives parents a window to export work
Showcase posts, likes, commentsDuration of enrollment, plus 60 days after withdrawalTied to the student's project history
Student account and loginDuration of enrollment, plus 60 days after withdrawalAccount restoration
Class attendance and session records1 year after the end of enrollmentProgram records and charter school reporting
AI prompts and responsesNot retained by our AI providers. We keep a copy of a finished answer for up to one hour so a dropped connection can recover it, then delete itNo business need for storage
Technical and security logs90 daysSecurity investigation and abuse prevention
Parent contact and billing records7 years after the end of enrollmentTax and accounting requirements
Signed enrollment agreements and consent records7 years after the end of enrollmentProof of consent

Where a cohort or school is operated in its own isolated environment, that environment and all student data in it are deleted within 30 days of the end of the contract, unless the school directs otherwise in writing.


5. Parent and guardian rights

At any time, a parent or guardian may:

  • Review the personal information we hold about their child.
  • Export their child's projects and work.
  • Delete their child's personal information.
  • Withdraw consent and stop any further collection. This will end the child's use of the platform.
  • Refuse to allow disclosure to a third party while still permitting the child to use the service, where that disclosure is not integral to the service.

To make a request, email byars.jp5@gmail.com. We verify that the requester is the parent or guardian on the enrollment record, and we respond within 30 days.

Students 13 and older, and adult learners, may make the same requests on their own behalf.


6. California students

For students in kindergarten through grade 12, we comply with the California Student Online Personal Information Protection Act. We do not use student information for targeted advertising, do not create advertising profiles of students, and do not sell student information. We delete student information at the request of a school or district where we hold it under a school contract.

For students under 16, we do not sell or share personal information as those terms are defined under California privacy law.


7. Security

We maintain a written information security policy. Information is encrypted in transit and at rest. Access to student data is limited to staff who need it to teach or operate the program, and is protected by multi-factor authentication. Each school or cohort is operated in its own isolated environment, with its own database, so that data is not accessible across cohorts.


8. Changes to this notice

If we make a material change to what we collect, how we use it, or who we share it with, we will notify parents by email and obtain new consent where the law requires it.


9. Contact

Palstart USA 10251 Nations Circle, Stockton, CA 95209 byars.jp5@gmail.com · (415) 624-6941

Privacy program responsibility: Phillip Byars, Director