Privacy Policy

What we collect, how we use it, and how your students can code here without sharing any personal information.

Last updated: July 30, 2026

Who we are

This site is a community-hosted, open source edition of Trinket operated by Strive Math ("Strive", "we", "us"), a Singapore-based education technology company. This policy explains what information we collect when you use this site, how we use it, and the choices you have. If anything here is unclear, email trinket@strivemath.com and we'll explain.

In short: we collect the minimum we need to run the service, we don't sell data, we don't show ads, and students can use the site without providing any personal information at all.

What we collect

Account information

  • Teachers and individual users sign up with a username, an email address, and a password. You can optionally add a display name to your profile.
  • Students in a school organization can be given anonymous accounts consisting only of a randomly generated username and password — no name, email address, date of birth, or any other personal details (see Students and anonymous accounts below).
  • Passwords are never stored in plain text; only a salted, hashed form is kept.

Content you create

We store the work you make on the site: your trinkets (code, text, and project names), courses, and, where the feature is enabled, uploaded files and images. If you publish or share something, it's visible to the people you share it with or to anyone with the link. Don't put personal information into code or projects you plan to share — and teachers should remind students of the same.

Organization and class data

For school organizations we store the organization's name, its member list and roles, its classes, and which student accounts belong to which classes. This is visible only to members of that organization.

Technical data

  • Logs. Like nearly every website, our servers record basic request information (IP address, browser type, pages requested, timestamps) for security, debugging, and abuse prevention. Logs are kept for a limited time and then deleted.
  • Cookies. We use a session cookie to keep you signed in. Session data itself is stored on our servers, not in the cookie. The site works without any marketing or advertising cookies, because we don't use any.
  • Analytics. We use Google Analytics and PostHog to understand how the site is used in aggregate — which pages are visited, which features are used, and where things break. These tools receive technical data such as pages viewed, browser type, and approximate location derived from IP address. We use them to improve the product, not to build advertising profiles.

How we use information

  • To provide the service: run your code, save your work, keep you signed in, and let organizations manage their classes and students.
  • To communicate with you: password resets, sign-in links, invitations, and replies to your support requests. We send these to teacher/adult account emails only — anonymous student accounts have no email.
  • To keep the service safe: preventing abuse, debugging errors, and protecting accounts.
  • To improve the product, using aggregate usage analytics.

We do not sell personal information, show advertising, or share data with third parties for their own marketing. Every feature on this site is free, so there is no commercial pressure to do otherwise.

Students and anonymous accounts

Many schools can't sign students up for online tools with their real names or school email addresses. So we let teachers create anonymous student accounts instead: each student gets a randomly generated username and password that you hand out, and nothing about that account identifies the student to us.

Usernames look like lin482k — three letters from your organization's name, three digits, and a letter. Passwords are randomly generated too. Because you decide which student receives which login, you're the only one who can connect an account to a real person; that mapping stays with you and is never sent to us.

Creating them

  1. Open Organization from the menu at the top of the page. This takes you to your organization on the Strive dashboard, where you'll see your teachers, your classes, and all of your students on one page.
  2. Choose Generate Logins, enter how many students you need, and optionally pick a class to enrol them all in.
  3. Download the list of usernames and passwords as a spreadsheet, or copy it, and hand each student their login.

Passwords are shown to you once and are stored only in hashed form, so we can't show them to you again later. If a student forgets theirs, you can set a new one from your dashboard at any time — for one student or for a whole class at once.

What's stored for an anonymous account

  • The generated username and a hashed form of the password.
  • Which classes in your organization the student belongs to.
  • The work the student creates — their trinkets, projects, and progress.

No name, no email address, no date of birth, and no school details are required, and none are collected unless a teacher chooses to add them. We don't knowingly collect personal information from children; student accounts are created and managed by their school, and we encourage schools to use anonymous logins for students under 13 (or the age your local law sets). If you believe a child has given us personal information directly, contact us and we'll delete it.

Managing your organization

Everything to do with your students lives on your organization page, and only members of your organization can see it. From there you can:

  • Invite teachers and staff by email, and give each one a role that controls what they can change. Teachers see the classes they're assigned to.
  • Create classes and move students between them.
  • Add students — generate anonymous logins in bulk, or create individual accounts if your school prefers to use names or emails.
  • Reset passwords for a single student or for an entire class.
  • Remove students from a class or from the organization when they leave.

Teacher and staff accounts do use an email address, because that's how invitations and sign-in links are sent. That applies to the adults managing the organization, not to students.

Who we share data with

We share data only with the service providers we need to run the site, and only so they can provide their service to us:

  • Cloud hosting and databases — the servers and managed databases (including Supabase) where the site and your data run.
  • Email delivery — providers that send password resets, invitations, and notifications on our behalf.
  • Analytics — Google Analytics and PostHog, as described above.

Beyond that, we disclose information only if the law requires it, or to protect the safety and integrity of the service. Content you choose to publish or share is, of course, visible to whoever you shared it with.

International transfers

We're based in Singapore and use cloud providers that may process data in the United States and other countries. Wherever the data is processed, it's protected by the safeguards described in this policy.

Security

  • All traffic to the site is encrypted in transit (HTTPS).
  • Passwords are stored salted and hashed, never in plain text.
  • Organization data is visible only to that organization's members, with role-based access controls.
  • Access to production systems is restricted to the small team that operates the service.

Data retention and deletion

We keep your account and content for as long as your account exists, so your work is there when you come back. Teachers can remove student accounts from their organization at any time. If you'd like an account and the work attached to it deleted entirely — yours or a student's — or you need a record of the deletion for your school, email us and we'll take care of it. Server logs and backups are kept for a limited period and then deleted on a rolling basis.

Your rights

You can ask us at any time to access, correct, export, or delete the personal information we hold about you. For student accounts managed by a school, we'll work through the school, since the school — not us — knows who each account belongs to. To exercise any of these rights, email trinket@strivemath.com; we aim to respond within 24 hours.

Data protection agreements

If your school or district requires a signed data protection agreement before using a new tool, we're happy to review and sign yours. Send it to us and we'll get it back to you.

Changes to this policy

If we make meaningful changes to this policy, we'll update this page and the date at the top. We won't reduce your protections without telling you.


Questions about any of this? Email trinket@strivemath.com or get in touch — we aim to respond within 24 hours.