Privacy and data handling
Privacy Policy
What Shibutz collects, which services process it, and what happens when you generate or export a class placement.
Last updated: September 9, 2026
This policy covers the Shibutz website and class placement product. It explains the current data flow in plain language. Shibutz does not sell or rent personal or student information. Read it alongside our Terms of Service.
Information we collect
Account and profile information
Clerk handles sign-up, sign-in, account identity, and profile information. Depending on what you save, that can include your name, email address, school name, country, role, and birthday.
Student and placement information
A school user can enter or import student names, gender, feeder school or group, support notes, academic and behavioral scales, social and emotional context, attention needs, friend preferences, separation rules, required placements, classroom definitions, and placement settings. Shibutz also stores generated assignments and statistics so staff can review past runs.
Full names are not required. Schools can use partial names, initials, or internal IDs when that fits their policy. Other roster fields may still be personal or educational records, so changing names alone does not make the full dataset anonymous.
Billing information
Pro checkout uses your account ID, name, and email address. Polar handles the hosted checkout, payment method, invoices, and subscription. Shibutz stores the billing records needed to manage your subscription and plan limits; it does not store a full card number.
Analytics and cookies
Shibutz uses Google Analytics to understand which pages and features people use. Analytics storage is off until you accept cookies. Rejecting analytics cookies keeps that storage off, but usage information can still be sent to Google.
Your cookie choice is saved in this browser. Changes in another tab also apply to open tabs. Clearing this site's browser storage resets the choice and shows the banner again.
Google can receive pages visited, the page you came from, browser and device information, language, and IP address. Product usage information can include a coded account ID, plan type, workspace or placement identifiers, actions, and counts. Shibutz removes extra details from page addresses and filters names, email addresses, roster contents, and notes out of product events. These measures reduce the information shared; they do not make all analytics data anonymous.
Hosting and operational logs
Vercel hosts Shibutz and records information needed to operate and troubleshoot the service. This can include IP addresses, browser and device information, pages requested, error details, and account references. These logs are not removed when you delete your Shibutz account. Contact support for current log retention information.
Services and data flow
These services help Shibutz run your account and placement work. They may use additional providers of their own. Your roster is sent to the placement service only when you ask Shibutz to generate or export a placement.
- Vercel
Application hosting and operational logs
IP address, browser and device information, pages requested, and records of errors or other service activity.
When: When you visit Shibutz or use its features.
Keeping and deleting data: Hosting logs are not removed when you delete your Shibutz account. Contact support for current log retention information.
- Clerk
Authentication and account profile
Account identity, email address, and profile details you save, such as school name, country, role, or birthday.
When: At sign-up, sign-in, and profile updates.
Keeping and deleting data: Deleting your account starts cleanup of your Shibutz records. Clerk's own retention policies also apply.
- Supabase
Saved placement work
Class rosters, placement rules, settings, generated assignments, statistics, and subscription status.
When: While you use the Shibutz workspace.
Keeping and deleting data: Saved work remains until you delete it or account deletion completes. A limited record of your account ID and deletion date remains to prevent old billing updates from restoring deleted data. It has no set expiry.
- Shibutz placement service
Placement generation and XLSX export
Students, classes, keep-together and keep-apart rules, required placements, and placement settings. Export requests also include the generated assignment and statistics.
When: When you request placement generation or XLSX export.
Keeping and deleting data: Retention and deletion terms have not been confirmed. Deleting your Shibutz account does not automatically delete data held by the placement service.
- Polar
Pro checkout and subscription management
Account ID, name, email address, subscription details, invoices, and payment information entered on the hosted checkout page. Student rosters are not part of the billing request.
When: When you start checkout or manage a Pro subscription.
Keeping and deleting data: Your Shibutz subscription records are removed when account deletion completes, apart from the limited deletion record described above. Polar may retain invoices and other billing records under its own requirements.
- Google Analytics
Product and site usage measurement
Pages visited, browser and device information, IP address, plan type, actions and counts, and coded account and workspace identifiers. Names, roster contents, and notes are filtered out of product events.
When: When you use the live website. Analytics storage is off until you accept cookies, but usage information can still be sent to Google if you reject them.
Keeping and deleting data: Deleting your Shibutz account does not automatically remove Google Analytics records. Contact support about retention or a data deletion request.
Student rosters are not included in billing requests. Analytics events use the controls described above. Generation sends the full roster, classes, rules, and settings needed for a run to the placement service. XLSX export also sends the generated assignment and statistics.
AI and automated placement
Shibutz uses a placement service to generate class lists and Excel exports. Its use of AI, use of student data for model training, retention, further sharing, and deletion practices have not been confirmed. If your school requires assurances on these points, contact support before uploading student records.
Generated placements remain drafts for staff review. Shibutz shows the resulting classes and statistics so educators can inspect the tradeoffs before sharing a final list. Read how placement generation works or the student data handling guide.
How we use information
- Authenticate users and maintain account profiles.
- Store rosters, rules, settings, placements, and results.
- Generate placements and XLSX exports when a user requests them.
- Manage Free and Pro access, checkout, invoices, and subscriptions.
- Measure product and site usage with the analytics controls described above.
- Respond to account, billing, and product support.
Student data and school responsibility
Shibutz is intended for authorized adult school staff. It does not include a student-facing workflow or ask children to submit placement data. Schools are responsible for deciding what they are permitted to enter and whether their use meets FERPA, COPPA, local law, district policy, and contractual requirements.
Our security and compliance page gives schools a practical review checklist. It is product information, not legal advice or a compliance certification.
Retention and deletion
Shibutz keeps account and placement data while the account is active and the data is needed to provide the product. Canceling Pro changes billing access; it does not delete existing class lists or assignments.
You can delete your account from your profile settings. Shibutz cancels any active subscription before deleting your saved workspaces, placements, and most billing records. If cancellation cannot be confirmed, deletion is delayed while Shibutz retries. It may not finish immediately.
We keep a limited record of your account ID and deletion date to prevent old billing updates from restoring deleted data. This record has no set expiry. Your name, email address, and subscription details are removed from Shibutz's billing records when deletion completes.
Payment providers may retain billing, invoice, tax, audit, or dispute records under their own requirements. Account deletion also does not automatically remove hosting logs, analytics records, or data retained by the placement service. Contact support@shibutz.com if a deletion does not complete as expected or you need help with a data deletion request.
How we protect your information
- You must sign in to access your placement workspace.
- Access to saved rosters and results is restricted to the account that owns them.
- Data sent to the placement service is encrypted in transit.
- Shibutz checks roster data and generated results for missing, duplicate, or invalid entries.
- Product analytics filters out names, roster contents, notes, and other sensitive fields.
No service can remove every risk. Schools should minimize the data they enter, limit account access, and contact support if they suspect unauthorized use.
Policy updates and contact
We may update this policy when the product, providers, or legal requirements change. The date at the top shows the latest revision.
Questions about this policy or a data request can be sent to support@shibutz.com. For general questions, email contact@shibutz.com or visit our FAQ section.