Privacy
How Sparkfield handles information across our website, parent and teacher app, and school learning tools.
Updated September 23, 2026
Who this covers
Sparkfield is operated by The Laithaus, LLC. We provide classroom learning and school–family communication. This notice covers parents and caregivers, educators, and students using Sparkfield. Parents and teachers sign in to the mobile app; students use school-managed learning tools.
School-managed education records are also subject to the school’s instructions and any applicable agreement with Sparkfield. Contact your school about its educational use of student information, and contact Sparkfield about how our service handles it.
Information we collect
Account information: name, email address, account role, sign-in credentials, and account settings. If you choose Google or Apple sign-in, we receive your provider account identifier, the name you share, and your verified email address. Apple lets you share a private relay email address instead. We do not request access to your inbox, contacts, Google Drive, or iCloud files. Apple connection credentials are encrypted on the server and used to disconnect Apple when your Sparkfield account is deleted.
Family and classroom information: class membership, student names and grade levels, parent–student connections, invitations, and connection requests. Class connection requests include the child’s name and require a teacher’s approval before granting access.
Content and learning activity: teacher–parent messages, message read status, class stream posts, student responses and work, grades, feedback, progress, rewards, and customization choices. Free-text content may contain personal information that its author includes.
Operational information: account and class identifiers associated with product events, error and performance diagnostics, request information such as IP addresses used for security and rate limits, and session records. If notifications are enabled and you opt in, we also store a device notification token and installation identifier. Paid website plans use billing and subscription identifiers.
Why we use it
We use information to sign you in, connect authorized family members and teachers, deliver messages and class updates, provide learning activities and feedback, manage subscriptions, answer support requests, and protect and improve the service.
Sparkfield does not sell personal information or use student information for targeted advertising. Educational personalization, such as adapting learning activities to a student’s progress, is part of the school learning service.
Who can see family information
A signed-in parent can access information for students connected to that parent’s account. Authorized teachers and co-teachers can access information needed for their classes. A class invitation alone does not grant access to every student in that class.
A student-specific invitation can authorize a connection to that student. Treat invitation links, QR codes, and family codes as private. Share them only with the intended caregiver and ask the teacher to revoke an invitation if it is shared by mistake.
Messages are available to their participants and are stored by Sparkfield to provide the service; they are not end-to-end encrypted. Class stream posts are shared with the authorized families for the class. Limited service access may also be needed for support, security, legal obligations, or school-directed administration.
Reporting and blocking
Use the options on a received message or class update to report a concern. Authorized Sparkfield staff review safety reports within 24 hours and can review the reported content and take action. Report details are not shared with the reported person. Blocking stops direct messages in both directions and hides that person’s updates without disconnecting your child from school. Reports and basic automated checks help address misuse; they do not guarantee every harmful message will be caught. For an urgent matter, contact your school directly.
Services that help us operate
Vercel hosts the website and server, and Turso/LibSQL supports the hosted database. Resend delivers service emails. Stripe processes payments for paid website plans; Sparkfield does not store full payment card numbers.
Google and Apple provide optional sign-in where configured. Expo supports mobile app builds and, when enabled, notification delivery together with Apple’s push notification service. Sentry may process error and performance diagnostics when configured. These providers receive information needed for their functions.
Anthropic processes inputs for AI-assisted school features, including activity generation, grading and feedback, translation, academic summaries, and a roster-import fallback. Inputs can include student work, prompts, classroom context, or roster content. Such content can contain names or other personal information; it is not accurate to describe every AI request as anonymous. Educators should avoid including sensitive information that is unnecessary for the task and review generated results.
Device permissions and local storage
The app asks for camera permission when you choose to scan a family QR code. You can enter a code instead. It asks for notification permission only when you choose to enable available notifications. You can change permissions in your device’s settings.
The mobile app keeps its parent sign-in token in the device’s secure credential storage. Website sign-in uses session cookies. These are used to keep you signed in, not to track you across other companies’ services.
Notifications, where available, use a general new-message or class-update alert rather than showing message text or a child’s name on the lock screen. Open the signed-in app to read the content.
Children and school authorization
Student accounts are used in a school or teacher-managed context. We collect students’ responses and learning activity as they use the service, even when an adult created the account. A teacher-created account does not mean no information is collected directly from a child.
Schools and Sparkfield must establish the appropriate authorization and notices for their use of student information. Where parental consent is required, it must be obtained before the covered collection. A family connection or acceptance of these terms is not a substitute for any required parental consent or school agreement.
Parents may ask to review or correct their child’s information, request deletion, or ask that further collection stop. Contact the school or Sparkfield so we can verify the request and coordinate any school-record obligations. These rights are not limited to having a connected mobile account.
Retention, access, and deletion
Account records, messages, class posts, and learning records are stored to provide the service. Archiving a class, removing a student from a class, disconnecting a family, deleting the app, or signing out does not by itself erase all associated records.
Parents can choose Delete account in the app’s Account screen and confirm with a code sent to their account email. This removes the parent account, sign-in sessions, family links, device notification registrations, and messages sent or received by that account. It does not delete the child’s school account, grades, or class records. Educators can initiate a verified deletion request from their app account screen. We complete verified teacher account-deletion requests within 30 days. Class ownership and school-managed records receive separate review; we explain any records that must be retained and why.
For access, correction, an export, account assistance, or a family-connection change, contact michael@thelaithaus.com. We may need to verify your identity and, for school-managed records, coordinate with the school. Tell us the type of request; do not email passwords, invitation codes, or sensitive student documents.
Retention and deletion also depend on school agreements, applicable obligations, security needs, and service-provider backups. We will explain applicable limitations when handling a request. Removing an active record does not necessarily remove every backup copy immediately.
Security
Hosted connections use HTTPS, adult passwords are stored as hashes, and the parent app checks authorization for connected students and conversations. Parent app session secrets and newly issued password-reset secrets are stored as hashes on the server.
New student passwords are shown to the authorized teacher once when they are created or reset, for printing private login cards. The service stores password hashes, not recoverable student passwords. A forgotten password must be reset. Keep printed cards private and use student credentials only for school access.
No system can guarantee complete security. We will assess security incidents and provide notices required by applicable law and school agreements.
Contact and changes
Contact The Laithaus, LLC, operator of Sparkfield, at michael@thelaithaus.com for privacy questions or requests. This notice will be updated as the service changes. Material changes require appropriate notice, and consent where required. Existing school agreements and applicable rights continue to apply.