Back

Security & Compliance

Shibutz is designed with security and privacy at its core, implementing strong data protection measures and following COPPA and FERPA guidelines to keep student information safe and secure.

Privacy Protected
COPPA & FERPA Guidelines Followed

Strong Encryption

AES-256 encryption protects all data

Student Data Privacy

Student information is never shared with third parties

Account Control

Delete your account and data anytime

Security & Privacy Measures

COPPA Guidelines
Children's Online Privacy Protection Act - Following Best Practices
Following Guidelines
  • No direct collection from children under 13
  • Personal information minimization
  • Privacy Policy includes child data protection section
  • Transparent data usage policies
  • Account deletion available to schools
  • Clear data retention policies
  • Security measures protecting data
  • Schools authorize data entry on behalf of students
FERPA Guidelines
Family Educational Rights and Privacy Act - Following Best Practices
Following Guidelines
  • Data use limited to educational purposes
  • Schools maintain control of their data
  • No re-use of student data for marketing
  • Data export and deletion capabilities available
  • Designed for educational professional use
Security Measures
Strong security infrastructure
Strong Security
  • TLS encryption for data in transit
  • AES-256 encryption for data at rest
  • Row-level security ensuring data separation between schools
  • User authentication and session management
  • Student data not shared with third parties
  • Regular security updates via Supabase
Transparency & Policies
Clear policies and user controls
Transparent
  • Privacy Policy written in clear language
  • Terms of Service outline responsibilities
  • Consent mechanisms for educational staff
  • Support available for privacy questions
  • Data export functionality available
  • Account deletion available

Built for Schools

Privacy-Focused Design
Built with student privacy in mind
  • No advertising or tracking cookies
  • Student data not shared with third parties
  • Option to use partial names or initials
  • Data separation between schools using row-level security
  • Account deletion removes data
  • Educational purpose data usage
School-Friendly Controls
Designed for educational staff
  • Straightforward onboarding process
  • Excel file import with templates
  • Drag-and-drop data management
  • Data export capabilities
  • Account management options
  • Clear privacy policies
Technical Security Infrastructure
Enterprise-grade security powered by Supabase

Encryption

  • • TLS encryption in transit
  • • AES-256 encryption at rest
  • • Secure API communications

Access Control

  • • Row-level security (RLS)
  • • User authentication required
  • • Data separation between schools

Data Management

  • • Account deletion available
  • • Data not shared with third parties
  • • Educational purpose only
  • • Anonymous analytics for site improvement

Learn More About Our Policies

Questions about our security or compliance measures?