Privacy Policy
What we collect, how we use it, and how schools can create student logins that need no real name or personal email address.
Last updated: September 15, 2026
Who we are
This site is a community-hosted, open source edition of Trinket operated by Strive Math ("Strive", "we", "us"), a Singapore-based education technology company. This policy explains what information we collect when you use this site, how we use it, and the choices you have. If anything here is unclear, email trinket@strivemath.com and we'll explain.
In short: we collect the minimum we need to run the service, we don't sell data, we don't show ads, and schools can create student logins that need no real name or personal email address. We do still hold the generated username, which classes the student is in, the work they submit, and technical logs — so those accounts are pseudonymous, not anonymous.
Strive Math is the main site for everything we operate, including this page's canonical, up-to-date version: strivemath.org/data-privacy. That page covers data privacy across all of Strive Math's products; this one goes into more detail on Trinket's coding-specific features.
What we collect
Account information
- Teachers and individual users sign up with a username, an email address, and a password. You can optionally add a display name to your profile.
- Students in a school organization can be given a randomly generated username and password instead — no real name, personal email address, or date of birth required (see Generated student logins below).
- Passwords are never stored in plain text; only a salted, hashed form is kept.
Content you create
We store the work you make on the site: your trinkets (code, text, and project names), courses, and, where the feature is enabled, uploaded files and images. If you publish or share something, it's visible to the people you share it with or to anyone with the link. Don't put personal information into code or projects you plan to share — and teachers should remind students of the same.
Organization and class data
For school organizations we store the organization's name, its member list and roles, its classes, and which student accounts belong to which classes. This is visible only to members of that organization.
Technical data
- Logs. Like nearly every website, our servers record basic request information (IP address, browser type, pages requested, timestamps) for security, debugging, and abuse prevention. Logs are kept for a limited time and then deleted.
- Cookies. We use a session cookie to keep you signed in. Session data itself is stored on our servers, not in the cookie. The site works without any marketing or advertising cookies, because we don't use any.
- Analytics. This site loads no third-party analytics or session recording — no Google Analytics, no PostHog, no advertising trackers. The server logs described above are the only usage data we keep. The separate Strive sign-in and organization dashboard do use analytics; see the Strive privacy policy linked above.
How we use information
- To provide the service: run your code, save your work, keep you signed in, and let organizations manage their classes and students.
- To communicate with you: password resets, sign-in links, invitations, and replies to your support requests. We send these to teacher and staff account emails only. Generated student logins are registered against a placeholder address derived from the username, and we never send mail to it.
- To keep the service safe: preventing abuse, debugging errors, and protecting accounts.
We do not sell personal information, show advertising, or share data with third parties for their own marketing. Every feature on this site is free, so there is no commercial pressure to do otherwise.
Generated student logins
Many schools can't sign students up for online tools with their real names or school email addresses. So we let teachers generate student logins instead: each student gets a randomly generated username and password that you hand out, with no real name, personal email address, or date of birth required. These accounts are pseudonymous rather than anonymous — we still hold the username, the classes it belongs to, and the work submitted under it — and we treat all of that as protected student data.
Usernames look like lin482k — three letters from your organization's name, three digits, and a
letter. Passwords are randomly generated too. Because you decide which student receives which login, the mapping
from a login to a real person stays with your school and is never sent to us. Bear in mind that class membership
and the content a student submits can still make them identifiable, so treat these accounts as student records
rather than as untraceable.
Creating them
- Open Organization from the menu at the top of the page. This takes you to your organization on the Strive dashboard, where you'll see your teachers, your classes, and all of your students on one page.
- Choose Generate Logins, enter how many students you need, and optionally pick a class to enrol them all in.
- Download the list of usernames and passwords as a spreadsheet, or copy it, and hand each student their login.
Passwords are shown to you once and are stored only in hashed form, so we can't show them to you again later. If a student forgets theirs, you can set a new one from your dashboard at any time — for one student or for a whole class at once.
What's stored for a generated login
- The generated username and a hashed form of the password.
- A placeholder email address derived from the username, used only so the account can sign in. It is on a domain we control, and we never send mail to it.
- Which organization and which classes the student belongs to.
- The work the student creates — their trinkets, projects, and progress.
No real name, personal email address, date of birth, or school details are required, and none are collected unless a teacher chooses to add them. We ask schools to keep personal information out of student profiles and submitted work. We don't knowingly collect personal information from children; student accounts are created and managed by their school, and we encourage schools to use generated logins for students under 13 (or the age your local law sets). If you believe a child has given us personal information directly, contact us and we'll delete it.
Managing your organization
Everything to do with your students lives on your organization page, and only members of your organization can see it. From there you can:
- Invite teachers and staff by email, and give each one a role that controls what they can change. Teachers see the classes they're assigned to.
- Create classes and move students between them.
- Add students — generate logins in bulk, or create individual accounts if your school prefers to use names or emails.
- Reset passwords for a single student or for an entire class.
- Remove students from a class or from the organization when they leave.
Teacher and staff accounts do use an email address, because that's how invitations and sign-in links are sent. That applies to the adults managing the organization, not to students.
Who we share data with
We share data only with the service providers we need to run the site, and only so they can provide their service to us:
- Cloud hosting and databases — the servers and managed databases (including Supabase) where the site and your data run.
- Email delivery — providers that send password resets, invitations, and notifications on our behalf.
Beyond that, we disclose information only if the law requires it, or to protect the safety and integrity of the service. Content you choose to publish or share is, of course, visible to whoever you shared it with.
International transfers
We're based in Singapore and use cloud providers that may process data in the United States and other countries. Wherever the data is processed, it's protected by the safeguards described in this policy.
Security
- All traffic to the site is encrypted in transit (HTTPS).
- Passwords are stored salted and hashed, never in plain text.
- Organization data is visible only to that organization's members, with role-based access controls.
- Access to production systems is restricted to the small team that operates the service.
Data retention and deletion
We keep your account and content for as long as your account exists, so your work is there when you come back. Teachers can remove student accounts from their organization at any time. If you'd like an account and the work attached to it deleted entirely — yours or a student's — or you need a record of the deletion for your school, email us and we'll take care of it. Server logs and backups are kept for a limited period and then deleted on a rolling basis.
Your rights
You can ask us at any time to access, correct, export, or delete the personal information we hold about you. For student accounts managed by a school, we'll work through the school, since the school — not us — knows who each account belongs to. To exercise any of these rights, email trinket@strivemath.com; we aim to respond within 24 hours.
Data protection agreements
If your school or district requires a signed data protection agreement before using a new tool, we're happy to review and sign yours. Send it to us and we'll get it back to you.
Changes to this policy
If we make meaningful changes to this policy, we'll update this page and the date at the top. We won't reduce your protections without telling you.
Questions about any of this? Email trinket@strivemath.com or get in touch — we aim to respond within 24 hours.