DigiLabs logo
DIGILABS
CoursesPricing
Hardware BreakdownVocab LabFree AI PromptsShopAbout & Manifesto
Log InSign Up

Last updated September 19, 2026

Privacy Policy

DigiLabs TechTank is a technology curriculum for students in grades 3–12, used by families at home and by schools in class. Because our users include children, we built the platform to collect as little as possible — and this page describes exactly what that is. It is written to be read by a parent, not a lawyer.

Who we areStudent accountsParent and teacher accountsHow we use informationWhat we never doSchools and FERPAChildren under 13Service providersSecurityRetention and deletionYour choices and rightsCookiesChanges and contact

Who we are

DigiLabs is a trade name of Roccus Technologies LLC, a Florida limited liability company based in Miramar, Florida. We operate the website digi-labs.org and the TechTank learning platform on it (together, the "Service"). Questions about this policy go to admin@digi-labs.org.

Student accounts: what a student profile holds

Students never create their own accounts and never give us an email address. A student profile is created by a parent (for family accounts) or by a teacher or school administrator (for school accounts), and it holds only:

  • A display name chosen by the parent or school. For schools we recommend first name and last initial.
  • Grade level and grade band (elementary 3–5, middle 6–8, high 9–12), so the student sees age-appropriate courses.
  • Graduating year (school accounts only), for class organization.
  • An avatar picked from a fixed set of icons. There is no photo upload.
  • A 4-digit PIN for logging in, stored only as a one-way hash. We cannot read or recover a PIN; a parent or teacher can reset it.
  • Learning records the student generates by using the Service: which activities they completed, quiz answers and scores, placement and exit-check results, written answers to activity prompts, daily learning-time totals, badges and certificates earned, and the daily learning goal a parent or teacher set.

There is no field for anything else. The Service cannot store a student's email, date of birth, home address, phone number, photograph, government ID, student ID number, health or disability information, disciplinary records, free-lunch status, race, ethnicity, religion, or precise location — because the database has no place to put them.

The student area of the Service has no messaging, no comments, no public profiles, no chat, no advertising, no in-app purchases, and no links out to other sites except the supplemental videos described below. Students cannot contact DigiLabs or anyone else from inside it.

Parent and teacher accounts

Adults create the accounts. For a parent or guardian we collect:

  • first and last name, email address, and a password (stored hashed);
  • zip code, used to surface local events and for sales-tax purposes;
  • purchase history if you buy a course band — payment card details go directly to Stripe and never touch our servers;
  • any promo code you redeem, any feedback you send us through the site, and your newsletter subscription status.

For a teacher or school administrator we collect first and last name, work email address, a password (stored hashed), the school's name, and the role and class assignments the school configures. We do not ask school staff for a home zip code.

Anyone who visits the site may also give us an email address to join the newsletter or to request a school quote (school name, contact name, email, phone, city, state, grade levels, and notes).

How we use information

We use the information above only to:

  • run the Service and deliver the curriculum;
  • show progress, results, and learning time to the student, their parent, and (for school accounts) their assigned teacher and school administrators;
  • place students at the right point in a course and unlock content as they progress;
  • generate completion certificates and let anyone verify one by its ID (the verification page shows the course, date, and display name as printed — never anything else);
  • send account emails: confirmation, password reset, receipts, and progress reports;
  • send the weekly DigiLabs newsletter to parents, school staff, and subscribers (every issue has a one-click unsubscribe link, and unsubscribing never affects your account);
  • answer your support requests and feedback;
  • keep the Service secure (for example, locking a PIN after repeated failed attempts) and diagnose faults;
  • produce de-identified, aggregate statistics such as average quiz scores across all users, which cannot reasonably be used to identify a student, a family, or a school, to improve the curriculum.

What we will never do

  • Sell, rent, or trade personal information — a student's, a parent's, or a teacher's.
  • Show advertising anywhere in the Service, or use any information for advertising or marketing to students.
  • Build a profile of a student for any purpose other than delivering their education.
  • Use student information to train or improve any artificial-intelligence or machine-learning model. The read-aloud narration and lesson videos in the Service were generated from our own lesson text; no student information is ever sent to an AI provider.
  • Contact a student directly.
  • Disclose personal information to anyone except the service providers listed below, or when the law requires it (see below).

Schools, teachers, and FERPA

When a school uses the Service, the school owns and controls its students' information and DigiLabs acts as a "school official" on the school's behalf under FERPA (34 C.F.R. § 99.31(a)(1)) and under Florida Statutes § 1002.22. In that setting we use student information only as the school directs and only for the purposes above. We offer every school a written Student Data Privacy Agreement that commits to these same terms; where it applies, that agreement controls over this policy for student data.

Role boundaries are enforced in the database itself: a teacher can see only students in the classes assigned to them; a school administrator can see every class at their school and manage staff; only a school administrator can move a student between teachers. DigiLabs staff do not look at student records except to provide support a school or parent asks for, or to investigate a security issue.

Children under 13

Students in grades 3–6 are typically under 13, so the Children's Online Privacy Protection Act (COPPA) applies. We meet it as follows:

  • Children never sign up themselves and never provide contact information. A student profile is created by a parent, who gives consent by creating it under their own verified account, or by a school, which consents on parents' behalf under the FTC's guidance for educational use.
  • We collect from a child only what is described under Student accounts, and use it only for the child's education.
  • A parent can review everything we hold about their child on their dashboard at any time, correct the display name, grade, and avatar directly, and delete the child's profile — which deletes all of the child's learning records with it.
  • We do not condition a child's participation on disclosing more information than is reasonably necessary.

Some lessons include an optional "Go deeper" video from an educational YouTube creator, played inside our site through YouTube's privacy-enhanced embedded player. Nothing plays until a student chooses to press play; if they do, YouTube (Google) may set cookies or collect viewing data under Google's privacy policy. We do not send any student information to YouTube, and every such video is labeled as third-party content not made by DigiLabs.

Service providers who handle information for us

We use a small number of companies to run the Service. Each is bound by terms that restrict them to using information only to provide their service to us. All information is stored in the United States.

  • Supabase, Inc. — database, login, file storage, and server functions. Holds all account and student data.
  • Netlify, Inc. — web hosting and content delivery for the site itself.
  • Stripe, Inc. — payment processing for family purchases. Stripe receives your card details and email; it receives no student information. School invoices are handled outside the Service.
  • Resend, Inc. (via Amazon SES) — sends our emails to parents, school staff, and subscribers. Students have no email in the Service, so none is ever sent to a student.
  • OpenAI, L.L.C. — generated the audio narration for our own lesson text, in advance. No user or student information is sent to OpenAI.
  • Railway Corp. — renders certificate PDFs. At generation time it receives the student's display name, course title, date, and verification ID, and retains nothing.
  • Google (YouTube) — only if a student chooses to play a supplemental video, as described above.

We will update this list before adding a provider that handles student information, and give schools 30 days' notice.

Security

  • All traffic is encrypted in transit (TLS 1.2 or higher); databases and file storage are encrypted at rest.
  • Access rules are enforced in the database layer, not just in the app, so one family's or one teacher's session cannot read another's data even if the app had a bug.
  • Passwords and student PINs are stored only as one-way hashes.
  • DigiLabs staff access to production systems is limited to named accounts and logged.
  • If we learn of a breach affecting personal information, we will notify affected account holders and schools without unreasonable delay, and within the timeframe the law and our school agreements require, with a description of what happened and what was involved.

How long we keep information, and deletion

  • Family accounts: we keep your account and your children's profiles for as long as the account exists. You can delete a child's profile from your dashboard at any time; it and all of the child's learning records are removed. To delete your whole account, email us from the account's address and we will complete it within 30 days, including from backups within a further 30 days.
  • School accounts: a school can archive a student instantly (removing their login and hiding them from rosters). On a school's written request we permanently delete a student's data within 30 days. When a school's plan ends, the school has 60 days to export its data (we provide CSV/JSON on request at no charge), after which we delete it within 30 days and confirm in writing.
  • Certificates: a certificate you have downloaded is yours. So that a certificate can still be verified after the student's data is deleted, we keep the verification record (ID, course, issue date) and reduce the printed name to first name and last initial.
  • Server logs (IP address, browser type, timestamps, pages requested) are kept by our hosting providers for security for up to 30 days and are not linked to student profiles except for security investigation.
  • Newsletter and quote requests: kept until you unsubscribe or ask us to remove them.
  • De-identified aggregate statistics may be retained indefinitely.

Your choices and rights

  • Parents can see, correct, and delete their children's information from their dashboard, and can request a full export of it by email.
  • Schools can do the same for their students through the school portal, and parents of school students may exercise FERPA rights to inspect and correct records through their school — we will supply the school a complete export within 10 business days.
  • Everyone can unsubscribe from the newsletter with the link in any issue, and can email us to access, correct, or delete any personal information we hold about them. We respond within 30 days and never charge for these requests.
  • If you are in a state with a consumer-privacy law that grants additional rights (for example California, Colorado, Connecticut, Virginia, Texas, or Florida's Digital Bill of Rights), you may exercise them by emailing us; we do not sell or share personal information for targeted advertising, so there is nothing to opt out of on that front.

Legal requests. If we receive a subpoena or court order for personal information we will, unless legally prohibited, notify the affected account holder or school before responding so they can object, and we will disclose only what is legally required.

Cookies

We use only the cookies needed to keep you signed in and to remember which student profile is active. We do not use advertising cookies, tracking pixels, or third-party analytics on the Service. If a student plays a supplemental YouTube video, Google may set its own cookies as described above.

Changes to this policy, and how to reach us

We will not change what we collect from students, or how we use it, in a way that reduces protection without giving schools written notice and parents 30 days' notice by email. Other changes are posted here with a new "last updated" date.

Roccus Technologies LLC d/b/a DigiLabs
Miramar, Florida
admin@digi-labs.org

Schools: our Student Data Privacy Agreement is available on request at the address above and is reviewed with every school before its first roster is loaded. See also our school plans.

DigiLabs logo
DIGILABS

The Next Generation of Tech Starts Here.

Technology education for elementary, middle and high school students.

Learn

Online Courses
Hardware Breakdown
Vocab Lab
Free AI Prompts
Shop

Sister Company

DigiLabs ITAD
E-waste recycling & certified data destruction

Company

About & Manifesto
Privacy Policy
admin@digi-labs.org

© 2026 DigiLabs Education. The Next Generation of Tech Starts Here.