01 / Overview
Overview
Puppet Pals 1 School Edition is designed for use in educational settings. It can be deployed via Apple School Manager or Mobile Device Management (MDM) solutions on iOS, and via private managed Google Play distribution on Android & Chromebooks. We are committed to protecting the privacy of students and educators, and we comply with the Children's Online Privacy Protection Act (COPPA), the Family Educational Rights and Privacy Act (FERPA), and the General Data Protection Regulation (GDPR).
All content created in the app (puppet shows, recordings, images) is stored entirely on-device and is never uploaded to or stored on our servers.
That on-device boundary applies to student-created work. The app separately sends limited first-party usage analytics. Adults may also choose to provide an email address or feedback through parent-facing controls. The general Polished Play website contact form is a separate, voluntary communication channel and is not part of the School Edition app or its student workflow. Each path is described below.
- Normal student use
- No student PII collected
- Created content
- Remains on-device
- Usage analytics
- First-party session and event records
- AI image features
- Blocked for School Edition
02 / Collection
Information We Collect
School Edition Usage Analytics
The School Edition sends basic usage analytics directly to Polished Play's first-party analytics API. No third-party analytics or tracking SDK is embedded in the app. School Edition analytics do not include a name, email address, advertising ID, hardware device identifier, or School Edition user ID.
The records stored by our analytics system include:
- A random session ID used to connect events within the same session
- App identifier and app version
- Event type, event properties, and event timestamp
- Country, region, and general device type
- Session creation timestamp
The random session ID is not an account identifier, School Edition user ID, device ID, or advertising ID. We use these session and event records to produce aggregate reports, but the underlying records are retained as described in Data Retention and Deletion below.
Parent Email Addresses (Optional)
Behind a parent gate within the app, parents or guardians may optionally provide their email address to receive notifications about Puppet Pals updates. The email address and a source label identifying where it was submitted are stored in our database. This feature is:
- Completely voluntary and optional
- Only accessible through the parent-gated section
- Used solely for sending app update notifications
- Not shared with third parties for their own marketing purposes
If we send an update, our email delivery provider receives the address and message needed to deliver it. Every update includes an unsubscribe mechanism.
Adult Feedback and Website Contact (Optional)
Behind the same parent gate, parents or guardians may submit feedback about the app. Separately, someone may choose to contact Polished Play through the general website contact form. These are voluntary communications; they are not School Edition usage analytics or student-created app content.
Depending on the form, a submission can include a name, email address, subject or category, message, and a source label. We store the submission and use it to screen for spam, review and respond to the message, and improve our products and support. The processors involved in this path are listed under Data Sharing and Third-Party Services.
Adults should not include student names, student contact information, student-created recordings or images, or other student personal information in a feedback or website contact submission.
03 / Exclusions
What We Don't Collect
During normal student use, Puppet Pals 1 School Edition does not ask for or collect personally identifiable information from students or children. The app does not automatically collect:
- Names, usernames, or contact information from children
- Photos, recordings, or any content created in the app (all content remains on-device)
- Precise location data
- Hardware device identifiers or advertising IDs
- Any information that could identify individual student users
Voluntary adult feedback and website contact forms are a separate path: they store what the person submitting the form chooses to enter. They are not part of the School Edition student workflow and should not be used to send student personal information or student-created content.
School Edition boundary
About AI image features: The standard Puppet Pals 1 app offers AI image features to active Creative Club subscribers; those features send data off-device. The School Edition has no AI image generation features, and this restriction is enforced on our servers — not just hidden in the app — so even if the app were modified to attempt an AI image request, our API would reject it for the School Edition source identifier. There is no configuration that turns AI image generation on for the School Edition. The separate optional feedback path may use AI for spam screening or an administrator-assisted reply, as disclosed below; it does not enable AI features in the student app.
04 / Purpose
How We Use Information
- Usage Analytics
First-party usage analytics are used to:
- Improve app functionality and user experience
- Understand which features are most used
- Identify and fix technical issues
- Make informed decisions about future app updates
- Parent Email Addresses
Parent email addresses are used to:
- Send notifications about app updates and new features
- Allow parents to stay informed about the app their children use
- Manage delivery, unsubscribe, bounce, and complaint suppression records so unwanted messages are not resent
- Feedback and Contact
- Voluntary feedback and website contact submissions are used to screen spam, route a private support notification, review and respond to the message when appropriate, understand user needs, and improve our products and support.
05 / Third parties
Data Sharing and Third-Party Services
We do not sell user data or share it with third parties for their own marketing or advertising purposes. No third-party analytics or tracking SDK is embedded in Puppet Pals 1 School Edition.
Student-created shows, recordings, and images are not processed by the services below because that content remains on-device. These services support the separate data paths described in this policy: first-party School Edition usage analytics and voluntary email, feedback, or website contact submissions.
- Vercel
- Hosts our website and API routes. It handles network requests for School Edition usage analytics and voluntary email, feedback, and website contact submissions. Vercel also supplies the country and region request headers used by our analytics endpoint. Our analytics database records do not store the raw request IP address.
- PostgreSQL hosting
- Stores School Edition analytics session and event records, parent email addresses and source labels, voluntary feedback and contact submissions, and email delivery and suppression records.
- Google Gemini
- When spam screening is configured, Gemini receives limited portions of a voluntary feedback or website contact submission—including the message and any submitted name, email, and subject—to classify it for spam. An authorized administrator may also choose to send a stored message, submitted name, category, and source to Gemini to prepare an editable reply draft.
- Slack
- A submission classified as non-spam may be posted to our private feedback channel. That notification can contain the source and the submitted name, email, subject, and message.
- Google Gmail
- If we reply to a feedback or contact submission, Gmail may process the recipient's submitted name and email address, the reply, and the resulting message thread.
- Resend
- Delivers optional Puppet Pals update emails. It receives the parent's email address and the update message, and returns message identifiers plus complaint or permanent bounce events used to suppress future sends.
School Edition usage analytics use the Vercel and PostgreSQL paths above. Google Gemini, Slack, Gmail, and Resend are used only when someone voluntarily submits feedback or a website contact message, signs up for updates, receives an update, or receives a support reply.
06 / Lifecycle
Data Retention and Deletion
- Usage analytics
- Session and event records are retained until Polished Play manually prunes them. No automatic fixed retention window is currently configured. Reports may aggregate these records, but the underlying session and event rows remain stored until they are pruned.
- Parent email addresses
- Email addresses are retained until a deletion request is received. Unsubscribing, reporting a message as spam, or a permanent delivery failure suppresses future update emails; the address and suppression record remain stored so the suppression can be honored unless deletion is requested.
- Feedback and contact
- Feedback and website contact submissions are retained for as long as they are useful for support and product improvement. Related support notifications, drafts, and replies may also exist in the service-provider systems named above.
Parents or guardians may request deletion of parent email-list, feedback, or website contact records held by Polished Play by contacting us at privacy@polishedplay.com.
07 / Students
Children's Privacy
Puppet Pals 1 School Edition is designed for use by children in educational settings. Its normal student workflow does not ask children to provide personal information. The optional email collection and feedback features inside the app are located behind a parent gate and are intended for adult parents or guardians.
The general Polished Play website contact form is separate from School Edition and is not part of the classroom or student workflow. Anyone contacting us about School Edition should avoid including student personal information or student-created content in that form.
We comply with the Children's Online Privacy Protection Act (COPPA), the Family Educational Rights and Privacy Act (FERPA), and the General Data Protection Regulation (GDPR).
08 / Safeguards
Data Security
We implement appropriate technical and organizational security measures to protect the limited data we collect. All data transmission between the app and our servers is encrypted using industry-standard TLS encryption. Server access is restricted to authorized personnel and requires multi-factor authentication. For the full plan, see the School Edition Data Security & Privacy Plan.
09 / Distribution
School Deployment
On iOS, Puppet Pals 1 School Edition supports deployment through Apple School Manager and Mobile Device Management (MDM) solutions including Jamf, Mosyle, and Kandji.
On Android & Chromebooks, the School Edition is distributed privately through managed Google Play: the school's Google organization ID is added to the app's private distribution list, the app appears in the school's managed Google Play, and administrators assign it to devices via the Google Admin console or their device-management tool.
No additional data is collected during the deployment process on either channel — adding an organization ID to the private distribution list involves no student data. Schools retain full control over app distribution and device management.
10 / Revisions
Changes to This Policy
We may update this privacy policy from time to time. Any changes will be posted on this page with an updated effective date.
11 / Questions
Contact Us
If you have any questions about this privacy policy or our data practices, please contact us at privacy@polishedplay.com.