Privacy Policy
1. Who we are
VSA.IM ("VSA", "we", "us") is the Virtual Science Activities platform available at https://vsa.im. It is operated by the VSA.IM team on behalf of the schools and educators who use it. This policy explains what information the platform processes and why.
2. What we collect
Information you or your school give us
- Account details. When you sign in with a school Google account we receive your name, email address, and a Google account identifier. When a teacher or parent creates a username for you, we store the username, a display name, and a salted one-way hash of the password (never the password itself).
- Team and play information. Team names, player display names, join codes, and the answers, scores, streaks, achievements, in-game currency, and cosmetic items you earn while playing.
- Content you create. Quizzes and questions built with the student quiz builder, and any messages sent through the contact form.
Information collected automatically
- Session information. A browser identifier (user agent) and IP address are stored with each sign-in session so you can review and revoke your active sessions.
- Security logs. Sign-in attempts, administrative actions, and content changes are written to an audit log with a timestamp and, where relevant, the account involved.
- Technical logs. Standard web-server logs (request path, status, timing). We do not use third-party analytics, advertising pixels, or fingerprinting.
3. Google sign-in (Google Workspace for Education)
Schools may allow students and staff to sign in with their school Google account. When you choose
"Continue with Google" we request only the openid, email, and profile
scopes. From Google we receive your name, email address, profile picture URL, the stable account identifier
(sub), and the hosted-domain claim (hd) that tells us which school Workspace you
belong to. We use the hosted domain to decide whether you are a student, teacher, or parent under your
school's configuration.
VSA.IM's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we:
- use Google account data only to create and sign you into your VSA.IM account and to attribute your progress to you;
- do not transfer Google account data to third parties except as needed to provide the service, comply with law, or as part of a merger or acquisition;
- do not use Google account data for advertising, and do not allow humans to read it except with your consent, for security purposes, to comply with law, or for internal operations where the data has been aggregated or anonymised.
You can revoke VSA.IM's access at any time from your Google Account permissions page. Revoking access does not delete your VSA.IM progress; see Retention & deletion.
4. How we use information
- To sign you in and keep you signed in across devices and browser sessions.
- To save your progress, scores, achievements, and in-game rewards so they persist over time.
- To let teachers see class rosters, assignments, and per-student progress for their own students.
- To run live team activities (real-time scoring, join codes) with the other people in your team or class.
- To keep the platform secure: detecting abuse, rate limiting, reviewing audit logs.
- To respond when you contact us.
We do not use personal information to build advertising profiles, and we do not use it to train machine-learning models.
5. Sharing
We do not sell personal information. We share it only:
- With your school. Teachers and administrators at your school can see the progress and content of students in their classes.
- With other players, by design. Your display name and scores are visible to your team-mates and on leaderboards for the activities you take part in.
- With service providers who process data on our instructions: Google (sign-in), our hosting provider (application and PostgreSQL database), Backblaze (storage of uploaded media), Bunny (content delivery), and our email provider (sign-in links, password resets, contact-form delivery).
- When required by law or to protect the rights, safety, or security of users and the platform.
6. Students and schools
VSA.IM is designed for use in schools. Where a school directs students to use the platform, we process student information as a service provider to that school and under its instructions, consistent with the Family Educational Rights and Privacy Act (FERPA) and comparable laws. We collect from students only the information needed to provide the service and never for commercial purposes.
We do not knowingly collect personal information from children under 13 outside of a school-directed context. If a school uses VSA.IM with students under 13, the school provides the consent permitted under the Children's Online Privacy Protection Act (COPPA) on parents' behalf. Parents and guardians who have questions about a student's account should contact the student's school, which can review or delete the account, or contact us directly.
Parents can also create supervised profiles for their own children, set a username and password, and remove them at any time.
7. Cookies
We use only first-party cookies that are strictly necessary to sign you in and protect your account. We do not use advertising or tracking cookies.
| Cookie | Purpose | Lifetime |
|---|---|---|
vsa_session | School-portal sign-in (Google, passkey, magic link, parent-set password) | 30 days, renewed while you stay active |
kids_auth_token | Student identity used to save progress, scores, and rewards | 24 hours, re-issued automatically from an active school session |
team_session | Your place on a team during live activities | 30 days |
auth_token | Teacher / administrator console sign-in | Until expiry or sign-out |
oauth_state, vsa_pk_chal | One-time anti-forgery values during Google or passkey sign-in | Minutes |
Browser localStorage is used for preferences (language, accessibility settings) and to cache progress for anonymous play. It never leaves your device unless you sign in and choose to sync.
8. Retention and deletion
- Sign-in sessions expire after 30 days without activity and can be revoked at any time from the Sessions page.
- Account and progress information is kept while the account is active. A teacher or administrator can delete a student account from the admin console at any time; the school can also ask us to delete accounts in bulk. Progress may be retained for a limited period after deletion so end-of-season reports remain accurate, then purged.
- Audit, security, and server logs are kept for no more than 60 days and then deleted.
- Backups are rotated on a fixed schedule (currently about 30 days); deleted data leaves backups within that cycle.
9. Security
All traffic is encrypted in transit (HTTPS). Passwords are stored as salted bcrypt hashes. Session tokens are
stored only as SHA-256 hashes, so a database copy cannot be used to sign in. Authentication cookies are
HttpOnly and Secure. Sign-in endpoints are rate-limited and every sign-in and administrative
action is audit-logged. No security measure is perfect; if you believe an account has been compromised, contact us
or your school right away.
10. Your choices and rights
- Access and correction. Your display name and progress are visible in the app. Ask your teacher or contact us to correct anything else.
- Deletion. Ask your school, or contact us, to delete your account and progress.
- Revoke Google access from your Google Account permissions page.
- Sign out everywhere from the Sessions page of the school portal.
Depending on where you live you may have additional rights under local law (for example the GDPR or state student-privacy laws). We honour those requests regardless of location.
11. Changes to this policy
We will post any changes on this page and update the effective date above. For material changes affecting students we will also notify participating schools in advance.
12. Contact
Questions about privacy, or requests to access or delete information, can be sent through the contact form on the home page. Schools with data-processing questions may use the same channel and mention their school name so we can route the request.