Skip to main content
Legal

Privacy Policy

We believe in transparency about how we protect your data. Learn how Principle handles your information.

Last updated: May 2, 2026

Sections

What Information We Collect

Account Information+

  • Email address (for account creation and communication)
  • Name (if you choose to provide it)
  • Profile preferences (theme, notification settings, accessibility options)
  • Educational status (for educational access verification)
  • Language preferences and accessibility settings

Educational Records (FERPA Protected)+

FERPA Compliance: We act as a School Official with a legitimate educational interest when handling student data. Educational records are isolated in our school schema with enhanced protections.

  • Student names, grades, and school identification numbers
  • Course enrollments and teacher assignments
  • Quiz scores and educational progress tracking
  • Parent/guardian contact information (when applicable)
  • LMS integration data: When you connect Google Classroom or other learning management systems, we receive only the information necessary to sync your class rosters and assignments. We do not access other information in your LMS account.

Educational Institution Accounts: Schools and districts that use Principle under institutional agreements are governed by separate Data Processing Agreements (DPAs) that include FERPA compliance commitments, enhanced data security requirements, institutional data access controls, and audit rights for district administrators.

Learning Data+

  • Quiz scores, performance metrics, and progress tracking
  • Questions answered, time spent, and learning patterns
  • Skill assessments and knowledge gap analysis
  • Content preferences and personalized recommendations
  • Gamification data (progress tracking, achievements, learning streaks)
  • Learning objectives and study goals

Technical Information+

  • Browser information: Browser type and version (web users only)
  • General platform: iOS or Android
  • IP address: For security and regional content delivery
  • Usage patterns: Feature usage and app interactions
  • Error logs: Crash reports and error data (anonymized)
  • Performance data: App load times and feature performance metrics

What we never collect for tracking: Device fingerprints, UDID, serial numbers, or battery levels. We do not use device hardware identifiers for tracking purposes. Our iOS app may access device storage information solely to ensure adequate space for app functionality — this information is not linked to your identity or shared with third parties. Biometric data (e.g., Face ID) never leaves your device.

Analytics & Metrics+

Transparency First: We measure our effectiveness to improve civic education quality. Here's what we track:

  • Content engagement patterns (which topics generate learning vs. clicks away)
  • Educational effectiveness metrics (knowledge retention and skill development)
  • Community feedback quality (user reports, content bookmarking, sharing patterns)
  • Accessibility usage data (text-to-speech, translation features, device compatibility)
  • Platform performance metrics (load times, error rates, feature adoption)
  • Source credibility tracking (how our content verification systems perform)

Payment & Subscription Data+

  • Subscription status and billing history (processed by Stripe)
  • Donation records for access verification
  • Educational access verification documents
  • Gift credit transactions and redemptions

Donor & Support Contributor Information+

When you make a donation or gift purchase — whether or not you have a Principle account — we collect:

  • Name and email address (provided at Stripe checkout)
  • IP address and device information (collected for fraud prevention)
  • Payment confirmation details (amount, date, transaction ID — not full card numbers)
  • Gift recipient email (if you purchase a gift for another person)

Processing and retention: Checkout data is transmitted to and processed by Stripe and stored in our Supabase database. Donation records are retained for 7 years for tax and legal compliance.

Public Content

Letters to Congress: What We Collect and What We Publish

What you submit+

  • Your chosen display name (Anonymous, your platform username, or a custom first name you enter)
  • Your state (selected by you or confirmed from your account profile)
  • Your letter subject and body
  • Any references you attach (linked bills, news articles, or Principle content)

What we collect automatically at submission+

When you submit a Letter, we also collect and store your IP address at the time of submission, your browser’s user-agent string, and a timestamped, cryptographically signed record of the submission event. We collect this data to detect abuse, prevent spam, and maintain platform integrity. This data is never displayed publicly and is retained for 90 days, then deleted.

What we display publicly+

Published Letters display:

  • Your chosen display name and state
  • Your letter subject and body
  • The congressional recipients you selected
  • Aggregated cosign (support) counts

Your email address, full legal name, IP address, and user-agent are never displayed publicly.

Search engine indexing+

Published Letters may be indexed by third-party search engines including Google. Once a Letter is indexed, search engines may retain cached copies. If you delete your Letter, we will remove it from Principle and submit removal requests to major search engines, but we cannot guarantee removal of cached copies within any particular timeframe or at all.

Deletion and retention+

  • You may delete your Letter at any time from your account. The Letter is removed from public display immediately.
  • Submission metadata (IP address, user-agent, timestamp) is retained for 90 days for fraud-prevention purposes, then deleted.
  • Letter text and display data are purged from our database within 30 days of deletion, except as retained in anonymized aggregate form.

Minors (ages 13–17)+

If you are between 13 and 17, your Letter may be published publicly with your chosen display name and state. We recommend using “Anonymous” as your display name. Parents or guardians may contact privacy@principlecivics.comto request deletion of any content associated with a minor’s account. You may also delete your own Letters from your account settings at any time.

Usage

How We Use Your Information

Core Educational Features

  • Personalize your experience: Track your progress, recommend relevant content, and adapt difficulty levels
  • Gamification: Track progress, achievements, and maintain learning streaks
  • Skill assessment: Identify knowledge gaps and suggest targeted learning paths
  • Progress analytics: Provide detailed insights into your learning journey

Platform Improvement & Communication

  • Improve our service: Analyze usage patterns to enhance features and fix issues
  • Build quality metrics: As a new platform, establish baseline measurements for educational effectiveness
  • Community feedback integration: Use user reports and educator feedback to refine our content standards
  • Communicate with you: Send important updates, respond to support requests
  • Security: Detect and prevent fraud, abuse, and security threats
  • Legal compliance: Meet legal obligations and enforce our terms of service
Partners

Third-Party Service Providers

We work with trusted service providers to deliver our educational platform. These providers are contractually obligated to protect your data and use it only for the services they provide to us. We do not sell your personal information to any third party.

  • Supabase — Database, authentication, and file storage. Processes account data, learning data, and educational records on our behalf. Infrastructure hosted on AWS (US regions).
  • Stripe — Payment processing for web subscriptions and donations. Processes payment card data and billing information. We do not store full card numbers.
  • RevenueCat — In-app purchase and subscription management for iOS. Processes purchase receipts, subscription status, and subscriber attributes.
  • Google Sign-In — Optional OAuth sign-in. If you use Google Sign-In, Google receives your authentication request and provides us your name and email address.
  • Google Classroom — Optional integration for teachers and students. If you connect Google Classroom, we access class names, student roster information, and assignment data solely to populate your Principle classroom.
Privacy

Data Sharing & Protection

What We Share

We never sell your personal data. Period. Your trust is more valuable than any payment.

  • Public achievements: Only achievements you explicitly choose to share publicly
  • Aggregated analytics: Anonymized, non-identifying usage statistics for research and improvement
  • Legal requirements: Information when required by law or to protect rights and safety

What We Don't Share

  • Personal information: Your email, name, or any identifying information
  • Private learning data: Your individual quiz scores, learning patterns, or progress details
  • Payment information: Any financial or billing details
  • Private communications: Messages or content not explicitly shared by you
Rights

Your Rights & Controls

Privacy Rights

You have the right to:

  • Data access: Request a copy of your personal data
  • Data correction: Correct any inaccurate information in your account settings
  • Data deletion: Request deletion of your account and all associated data
  • Data export: Request a copy of your account information and learning history
  • Processing limits: Limit how we use your information
  • Processing objections: Object to certain types of processing
Safety

Children's Privacy (COPPA Compliance)

Age Requirement: Principle is designed for users 13 and older. Users under 13 need parental consent.

Protections for Minors

  • Parental consent: Required for all users under 13 through our verifiable parental consent flow
  • Limited data collection: We collect minimal data from minors and never use it for advertising
  • Enhanced protections: Additional privacy safeguards for users under 18
  • Educational focus: All features for minors are strictly educational
  • Parental access: Parents can request access to their child's data and account deletion
Lifecycle

Data Retention

We retain personal information only as long as necessary for the purposes described in this policy.

Data CategoryRetention Period
Account informationDuration of account + 30 days
Learning historyDuration of account + 30 days
Published letters (text & display data)Until deleted by user; purged within 30 days of deletion
Letter submission metadata (IP, user-agent)90 days
Education recordsPer institutional agreement
Payment records7 years (tax and legal requirements)
Anonymized analyticsUp to 3 years
Global

International Data Transfers

Principle operates globally. Primary servers are located in the United States. We ensure appropriate safeguards are in place to protect your information regardless of where it's processed.

Tracking

Cookies & Tracking Technologies

We use cookies and similar technologies (including browser localStorage) to operate the site, keep you signed in, and — with your permission — understand how people use Principle. We do not use analytics data to build individual profiles or to serve advertising.

Protection

Security Measures

  • Encryption: All data is encrypted in transit and at rest using industry-standard protocols
  • Access controls: Strict employee access controls and regular security audits
  • Data minimization: We collect only what's necessary for our service
  • Regular backups: Secure, encrypted backups to prevent data loss
  • Incident response: Established procedures for handling any security incidents
  • Two-factor authentication: Available for enhanced account security
Transparency

Data Breach Notification

In the unlikely event of a data breach that affects your personal information, we will notify affected users within 24 hours of discovery. For educational institutions, we provide immediate notification to district administrators as required by law.

Contact

Contact Us About Privacy

Questions about this privacy policy or your data? We're here to help:

  • Privacy inquiries: privacy@principlecivics.com
  • Legal matters: legal@principlecivics.com
  • Educational compliance: support@principlecivics.com
Updates

Changes to This Policy

When we update this privacy policy, we'll notify you via email and in-app notification. Changes take effect 30 days after notification unless otherwise noted.

Our Privacy Promise: We collect only what's necessary to provide you with a great learning experience. We never sell your data, we use strong privacy protections for all features, and you have complete control over your information. Your trust is our most valuable asset.