Privacy
2600i Homeschool holds a family’s own education records, including a child’s. This page says what is stored, who can reach it, and how it is removed. It describes what the software actually does.
2600i Homeschool is operated by 2600i LLC, a Florida limited liability company. This page covers school.2600i.com only — 2600i.com and the other 2600i products each have their own policy.
Draft. This is written from the system’s design and has not been reviewed by a lawyer. It is not legal advice. Review it before the pilot grows beyond invited families.
What is stored
- Your account — email address and a display name. Passwords are handled by Supabase Auth and stored only as a hash; nobody at 2600i can read one, and the app never sees it after you type it.
- Your family record — student names, birth dates, grade levels, school years, courses, weekly logs, and progress.
- What a learner writes — weekly reflections and vocabulary entries, which belong to the student record rather than to the login that wrote them.
- Parent notes — observations and accommodations.
- Documents you upload — FLVS grade-report PDFs and any other evidence you add.
- An audit trail — who did what and when, within your family. This exists so a record can be trusted later, and it deliberately outlives the rows it describes.
What is not stored
The application loads no analytics, no tracking pixels, and no advertising, and it ships no client-side JavaScript of its own. There is no cookie banner because there is nothing to consent to beyond the cookie that keeps you signed in. Your records are never sold, rented, or used to train anything.
One caveat, stated because it is true rather than because it is required: Cloudflare sits in front of this site and can add things the application did not send. It currently rewrites email addresses on the page to hide them from scrapers, and runs a small script of its own to distinguish people from bots. Those are Cloudflare’s, not ours, and they see traffic rather than records.
Who can see it
- Your family, and no other. The boundary is enforced in the database itself, by row-level security, not by hiding things in the interface. A request for another family’s data returns nothing, whoever makes it.
- Parents and learners see different things. A learner reaches their reflections, their vocabulary, their own account, and the weekly log of the courses they are enrolled in — which they can read but not change, and only ever their own, never a sibling’s. Not the rest of the family record. That too is enforced in the database.
- The administrator has no standing access to your records. When you register, an administrator sees your email address, your display name, and whether you signed up as a parent or a learner — enough to decide whether to let you in, and nothing else. There is no policy anywhere granting an administrator a view of family content.
Uploaded files
Every storage bucket is private; none is ever public. Files are reached only through short-lived signed links issued per request, after your membership has been checked, and the storage path is chosen by the server rather than accepted from your browser.
Who else processes it
- Supabase — database, authentication, and file storage.
- Hetzner — the server the application runs on.
- Cloudflare — sits in front of the site, terminates HTTPS, and therefore sees every request: the address you came from, the page you asked for, and your browser’s description of itself.
- Resend — sends account email. It handles your address and the contents of those messages, which never contain your records.
How long it is kept, and how to remove it
Nothing is deleted on a timer. Your records are your long-term evidence for an annual evaluation, so they are kept until you remove them. A parent can delete an entire family — every student, log, reflection, and uploaded document — from the Account page. That cannot be undone, so export your data first if you want a copy; the same page will produce one.
Deleting a learner’s login does not delete what they wrote: reflections and vocabulary belong to the student record, which is the family’s evidence, not the possession of one account.
Children
A parent creates the student records in their family. A learner only gets their own login when a parent issues them a single-use join code, so a child cannot create an account here on their own initiative.
Asking about any of this
Write to [email protected]. Legal and entity questions go to [email protected].
