Privacy Policy

Effective date: September 17, 2026

1. Introduction

Locus is a mathematics practice platform operated by Stel Studio Inc. It runs as two products on two separate sites.

  • locusmath.org is the personal product. People sign up for themselves, practice, play ranked rounds, and appear on public leaderboards.
  • class.locusmath.org is the school product. Classes, assignments, rosters, and the teacher workspace live there, and students sign in only there. It is a separate site with its own privacy overview: Privacy for schools.

This policy covers both. It explains what each product collects, why, who else receives it, how long we keep it, and how you (or a school, on a student's behalf) can see it, correct it, export it, or have it deleted. Section 11 is the part written for schools and districts.

2. The accounts this policy describes

There are three kinds of account, and they are separate in the software, not just on paper.

  • Personal accounts on locusmath.org: someone practicing on their own.
  • Teacher accounts: an adult who runs classes on class.locusmath.org. A teacher account is the same kind of account as a personal one.
  • Student accounts: created only through a school sign-in on class.locusmath.org. A student has no password and no username, is never shown on a public leaderboard or profile, cannot follow anyone or be followed, cannot buy anything, and cannot submit free text to us. A student session is refused by every part of the personal product, and a personal session is refused by every student endpoint.

3. What we collect on locusmath.org

3.1 Account information (you give it to us)

  • Email address and username.
  • Password, stored only as an Argon2 hash. We never see or store the plain text. Accounts created through a sign-in provider have no password at all.
  • Account creation date and which versions of these policies you accepted.
  • Display preferences you set, such as language and theme.
  • We do not ask for your age, your date of birth, your address, or your phone number, and there is nowhere in the product to enter them.

Purpose: to create and secure your account, sign you in, and show you your own work.

3.2 Sign-in providers (they give it to us)

If you sign in with Google or GitHub we receive your email address, your name, and that provider's account identifier for you. If you sign in with Clever we also receive your school role and district identifier, which decide what kind of account you get. Purpose: to identify you at sign-in without a password.

3.3 Learning activity (the product generates it as you work)

  • Problems served to you, the answers you submitted, whether they were correct, how long you took, and hints used.
  • Ratings, streaks, bookmarks, review queue, goals, and progress per topic.
  • Daily puzzle attempts, and live-play and arcade results.

Purpose: to grade your work, show you your progress, place you on the leaderboards you choose to play for, and choose what to serve you next.

3.4 Fairness signals during ranked play

In ranked mode only, and disclosed in the product before you start, we record the kind and millisecond timing of a small set of events: the tab or window losing and regaining focus, and a blocked copy, paste, or drag. We never record what you typed, what was on your clipboard, or your keystrokes. Purpose: to keep the public leaderboard honest. Nothing is automated: a person reviews the signals, and the only sanction is removal from the public leaderboard, which can be undone.

3.5 Device and technical data

  • Crash reports, if the app fails: the error text, the page path, the app version, your browser version, and the last few things you clicked.
  • Ordinary web request data, handled by our hosting provider in transit. We do not store IP addresses in our database, and email addresses in our own log lines are masked.

Purpose: to find and fix crashes, and to keep the service running.

3.6 Billing and developer API

  • If you buy a subscription, Stripe processes the payment. We store the subscription state and Stripe's identifiers; we never see or store card numbers. Subscriptions are not offered on student accounts.
  • If you create a developer API key we store only a SHA-256 hash of it, plus daily counts of problems fetched, for quotas and your usage dashboard. The key itself is shown once and cannot be recovered by us.

3.7 Cookies and analytics

Section 12 lists every cookie. In short: one authentication cookie, plus Google Analytics cookies that are set on locusmath.org only, and only after you sign in with a personal learner account. Signed-out visitors, teacher accounts, and students are never measured, and class.locusmath.org carries no analytics tag at all.

4. What we collect on class.locusmath.org

The classroom site is where schools work. Teachers are adults with ordinary accounts, so section 3 describes them too. For students we collect less, and only what running a class needs.

  • Student account: the name and email address supplied by the school sign-in (Google or Clever), the provider's identifier, and, if the school imported a roster, the student identifier the school used. No password, no username, no age, no date of birth.
  • Class membership: which classes and groups the student belongs to, and when they joined.
  • Assignment work: the problems served, the answers submitted, correctness, score, hints used, time taken, corrections, and any grade a teacher overrides. This is visible to the student's own teachers.
  • Self-study on the classroom site: practice attempts, per-topic rating, review queue, bookmarks, and goals. These belong to the student and are not shown to other students.
  • Crash reports, which for a student carry only the error text and the page path. The click trail and free-text context a personal account sends are dropped for students before anything is stored.
  • No behavioral monitoring. The ranked fairness signals in section 3.4 are never recorded for a student, and no anticheat flag is ever raised against one: a student is not on any leaderboard, so there is nothing to police.

Purpose: to run the class. Student data is used to serve and grade work, show teachers their own students' results, and keep the student's own progress. Nothing else.

5. How we use information

  • Creating accounts, signing you in, and keeping sessions secure.
  • Serving and grading problems, and tracking your progress.
  • Showing teachers the work of students in their own classes.
  • Ratings and public leaderboards, for personal accounts only.
  • Service email: address verification, password reset, class invitations, assignment reminders, and billing notices.
  • Our newsletter, only if you opted in; every issue carries an unsubscribe link.
  • Diagnosing crashes, enforcing rate limits, and preventing abuse.
  • Meeting legal obligations and enforcing our Terms of Service.

6. What we do not do

  • We do not sell personal data, and we do not rent, trade, or share it for anyone else's marketing.
  • We run no advertising on either site, and we do not use anyone's data for advertising or behavioral targeting.
  • We do not build advertising or behavioral profiles, and we do not buy data about you from anyone.
  • We do not use student data to train AI models, and we never send a roster, a name, an email address, or an account identifier to an AI provider. Our AI features run only when a teacher starts one; section 7 lists what they send, which is statistics about a class and, for a single assignment question, up to ten wrong answers with nothing attached to say whose they are.
  • We do not market to students. A student sees no upsell, no subscription offer, and no third-party embed unless the district turns embeds on.
  • We do not disclose personal data to anyone except the processors in section 7, the school for its own students, and where the law requires it.

7. Subprocessors

We keep this list short and serve nearly every page asset from our own domains. These are the only third parties that receive data, and they receive only what is listed.

ServiceWhat it receivesWhere
CloudflareHosting, TLS termination, and delivery for every Locus site, so all traffic passes through it. It also delivers our service email (recipient address, subject, and message body, which can contain a username, a class or assignment name, or a school name) and provides the Turnstile bot check on the sign-up page when that is switched on.Both sites
Google (sign-in)Only if you sign in with Google: the sign-in exchange, from which we receive your email address, name, and Google account identifier.Both sites
GitHub (sign-in)Only if you sign in with GitHub: the sign-in exchange, from which we receive your email address, name, and GitHub account identifier.locusmath.org
CleverSchool sign-in and rostering: the sign-in exchange, from which we receive the student's or teacher's name, email address, school role, and district identifier.class.locusmath.org
Google ClassroomOnly if a verified teacher connects a Google Classroom course: we read that course's roster (student names and email addresses) to fill the Locus class.class.locusmath.org
StripeAdult billing only, never students: your email address and the payment details you enter on Stripe's form. Card numbers never reach us. Deleting your Locus account also deletes the customer record Stripe held.locusmath.org
Google AnalyticsPage-view measurement, loaded only after you sign in with a personal learner account. It receives the page address (a public profile page address contains that profile's public username), your browser and device type, and an approximate location Google derives from your IP address. It receives no name, no email address, no learning data, and no Locus account identifier. Google signals and ad personalization are off, and the consent defaults deny every advertising purpose.locusmath.org only
YouTube (Google)Optional help videos. When a video tile is on the page your browser requests its thumbnail image from YouTube; the player itself loads only when you click, through the privacy-enhanced youtube-nocookie domain. Students see no tile and make no request unless their district has authorized embeds.Both sites
AnthropicThe paid teacher AI features: the assists in the teacher workspace, the physics studio, and the problem authoring assistant. A teacher starts each one, and it runs only on an account that holds the paid Author plan, bought or granted by us, on a server configured with a provider key. The assists send de-identified class statistics - accuracy per skill, how many mistakes fell into each category, weekly attempt counts, mastery percentages against standards - and the text of the questions behind those numbers. Diagnosing a single assignment question also sends up to ten wrong answers to it, each a math expression cut to 80 characters. The authoring assistant sends a topic, a difficulty, and up to 2000 characters the teacher typed; the studio sends the teacher's own draft. No names, email addresses, rosters, account identifiers, class names, or teacher names: a draft written about one student carries the placeholder [Student], and the teacher's browser puts the name back on their own screen. Everything that comes back is a draft the teacher reads and edits before anyone else sees it.class.locusmath.org

Uptime monitoring requests public pages only and receives no personal data. Adding a subprocessor, or widening what one already receives, means updating this list, and for schools it also means notice under the data privacy agreement.

8. How long we keep data

DataKept for
Personal account, profile, and learning historyUntil you delete the account, which removes it immediately.
Student account, class membership, and assignment workUntil the school or district asks us to delete it, or the contract ends. There is no automatic expiry: while the school's account is active we keep the student's record so grades and progress stay intact.
Crash reports90 days, then deleted by a nightly job.
Ranked fairness signalsRaw events 90 days, after which they are reduced to per-month counts. Problem-serve records 7 days.
Email verification and password-reset tokensDeleted when they expire. The send records behind our rate limits are deleted after 30 days.
Class invitationsAn invitation expires 7 days after it is sent, and unused invitations are deleted then. The moment one is accepted, the name, email address, and student identifier it carried are erased and only the record that this class invited someone, when, and from which roster remains. Deleting a student also deletes any invitation still open to their address.
Public API grading records31 days after the problem was last served.
Administrative audit logKept as the record of who read, exported, or deleted student data. It keeps the identifier of the account an action was taken against even after that account is deleted, because a disclosure record has to stay meaningful.
District inquiries sent through our contact formKept as a business record. If the person who sent one deletes their account we sever the link to that account, and we delete the inquiry itself on request.

9. Access, correction, export, and deletion

9.1 Personal and teacher accounts

  • Correction: change your email address, username, password, and preferences yourself in Settings.
  • Deletion: Settings, then Danger Zone, then Delete Account. Deletion is immediate and permanent. Your account, attempts, ratings, presets, crash reports, and problem reports are removed, any live subscription is canceled, and the customer record Stripe held is deleted. We cannot undo it.
  • Export: a complete JSON copy of your account, attempts, physics attempts, per-topic ratings, presets, reports, daily-puzzle attempts, and fairness records is available from GET /api/user/export while you are signed in, or by writing to privacy@locusmath.org. There is no download button in Settings yet.

9.2 Student accounts

Students do not delete or export their own records; the school controls them. A school or district can ask us for a copy of a student's data, or for its deletion, by writing to privacy@locusmath.org from the contact on the contract. Both actions are recorded in our audit log.

The export covers everything we hold: the student's profile, their classes, their assignment work, corrections and physics quiz scores, and their own practice attempts, topic ratings, physics attempts, bookmarks, review schedule, and goals. Deletion removes all of it, along with class memberships and grade overrides, and clears the roster invitation trail that named them.

9.3 Timing

Anything you do yourself takes effect at once. For a request you send us, we confirm who is asking and then act within 30 days, usually sooner.

10. Children under 13

Personal accounts on locusmath.org are for people aged 13 and over. That is a condition of the Terms of Service, section 3.1. We do not knowingly collect personal information from a child under 13 on the personal site. We also do not ask anyone for an age or a date of birth, because collecting one would mean holding more data about every user, not less.

Students under 13 use Locus only through their school, on class.locusmath.org, and only where the school or district has a signed agreement with us. Under COPPA's school-authorization provision the school consents on the parent's behalf for the educational use that agreement describes: we use the data only to provide the service to the school, we make no commercial use of it, and the school may review or delete it at any time.

If we learn that we hold data from a child under 13 who is not covered by a school agreement, we delete the account rather than keep it. To tell us about one, write to privacy@locusmath.org.

11. Schools, FERPA, and district agreements

For student records created through a school, Locus acts as a school official with a legitimate educational interest under FERPA, under the direct control of the school with respect to those records. In practice:

  • We use student data only to provide the service to the school, and for no other purpose.
  • We act under the school's direction and do not decide on our own what the data is used for.
  • We do not redisclose student data to anyone other than the processors in section 7, and each of those receives only what section 7 lists.
  • The school may review, correct, export, or delete any student's data at any time, and we log every such action.
  • At the end of a contract we return or delete the district's student data on request. The purge covers every student the contract accounts for: those linked to it directly, those the district's Clever identifier matches, and those on one of its email domains.
  • Only a verified teacher can import or sync a roster, and a student who belongs to a district can only be added to a class by a teacher on that same district's contract. An emailed invitation still does nothing until the student accepts it.
  • Parents and eligible students exercise their access and correction rights through the school, which can obtain either from us.
  • Students are kept off public leaderboards, public profiles, the follow graph, and the activity feed, and they have no way to send us free text.

We sign NDPA-style data privacy agreements. There is no download link: ask for the agreement at privacy@locusmath.org and we will send it. The signed agreement, not this page, is the binding document between us and a district.

The school-facing overview, with the same subprocessor and retention detail written for procurement review, is at class.locusmath.org/privacy.

12. Cookies and local storage

  • Authentication cookie: locus_token for adults, locus_token_student for students. It is httpOnly, SameSite=Lax, marked Secure in production, limited to our API path, and expires after 24 hours. Without it you cannot stay signed in.
  • Google Analytics cookies (_ga and _ga_*): set on locusmath.org only, and only after a personal learner signs in. They are pinned to the exact host you are on, so class.locusmath.org cannot read them. A tracker blocker stops them, and Locus works normally without them.
  • Local storage in your browser: display preferences such as theme, language, and a remembered username. This never leaves your device.
  • There are no advertising cookies on either site.

13. Security

The measures below are in place today.

  • Every connection is encrypted in transit with TLS.
  • Passwords are hashed with Argon2 and never stored in a readable form. Sign-in takes the same time and returns the same message whether or not an account exists, so accounts cannot be probed.
  • Session cookies are httpOnly, SameSite=Lax, Secure in production, scoped to the API path, and expire after 24 hours. Adults and students carry different cookies and different token types, and each is rejected by the other's endpoints.
  • Our API sends HSTS, a strict content security policy, X-Frame-Options DENY, nosniff, and a strict referrer policy.
  • Sign-in, registration, password reset, class joining, and report submission are rate limited.
  • Administrative access is behind a role check, and reads, exports, and deletions of student data are written to an audit log with the actor, the action, and the target. A teacher exporting a gradebook is logged the same way.
  • Developer API keys are stored only as SHA-256 hashes.
  • We do not store IP addresses, and email addresses in our own log lines are masked.
  • Nearly every page asset is served from our own domains rather than a public CDN, so ordinary browsing leaks nothing to third parties.

No internet service can promise absolute security, and we do not.

14. If there is a breach

If personal data is exposed, we contain the incident, work out exactly which accounts and records are affected, and notify within 72 hours of confirming it: affected schools through the contact on their contract, and affected individuals by email. The notice says what happened, what data was involved, what we have done, and what you should do. We notify regulators where the law requires it.

15. Where data is stored

Locus data is stored and processed in the United States. Our hosting provider delivers pages and static files from its global network, so a page asset may be served from a location near you, but accounts, learning records, and student data live in the United States. The subprocessors in section 7 are United States companies running their own global infrastructure.

16. Contact

Privacy questions, data requests, and requests for our data privacy agreement: privacy@locusmath.org. Anything else: support@locusmath.org. The operator and data controller is Stel Studio Inc.

Schools should write from the address on the contract so we can confirm the request before acting on it.

17. Changes to this policy

When this policy changes we post the new version here with a new effective date, and signed-in users see a notice asking them to read it. Every version carries a date, and acceptance is recorded against it. If a change materially affects school-linked accounts we tell the district directly, as the data privacy agreement requires.