ZoodleBug Privacy Policy
Effective and last updated: September 3, 2026
1. Who operates ZoodleBug
ZoodleBug is operated by Tim Bedley. This policy applies to zoodlebug.com and the ZoodleBug games, learning tools, account system, educator tools, and related support services.
2. Children, schools, and student accounts
A student may also join an educator-created classroom tournament with a short code as a guest. That flow uses an anonymous technical account and a made-up tournament name; it does not ask for a personal email. Inactive anonymous authentication accounts are scheduled for removal after 30 days, and tournament activity follows the retention schedule below.
When a school or district uses ZoodleBug, the school controls its pupil records. ZoodleBug processes those records only to provide the contracted educational service and as directed by the school. The school may act on behalf of a parent when the law permits school authorization for a solely educational use. ZoodleBug will cooperate with the school and family on access, correction, export, and deletion requests.
3. Information we process
| Category | Examples | Purpose |
|---|---|---|
| Account information | Pseudonymous username, Firebase user ID, account role, sponsor educator, account dates, and authentication records. Educator accounts also use an email address and verification information. Tournament guests use an anonymous technical account. | Authentication, account security, access control, and educator verification. |
| Educational activity | Game progress, scores, wins/losses, stars, levels, responses, practice results, adaptive progress, and educator-created rosters. | Provide activities, save progress, and help educators support learning. |
| Multiplayer and tournament records | Pseudonymous player names, opponents, game state, prewritten chat choices, team membership, results, and timestamps. | Operate shared games and classroom tournaments safely. |
| Educator-created content | Cuatro titles, topics, prompts, answers, descriptions, keywords, and educator-uploaded images. | Create, store, moderate, and optionally share educator learning activities. |
| Support and privacy requests | Name, reply email, account identifier, school/district, relationship to the learner, and request details. | Respond, verify authority, and complete support or privacy requests. |
| Technical and security information | IP address, device/browser information, authentication cookies or local storage, timestamps, service logs, and anti-abuse tokens. | Operate, secure, troubleshoot, and prevent abuse of the service. |
4. How information is used
- Provide accounts, games, educational tools, progress, and classroom features.
- Authenticate users and apply student, educator, and administrator permissions.
- Protect users, prevent abuse, investigate errors, and maintain security.
- Respond to support, access, correction, export, and deletion requests.
- Comply with school contracts and applicable legal obligations.
Student information is not used for targeted advertising, marketing to students, sale, rent, or unrelated commercial profiling.
5. Service providers
ZoodleBug uses service providers only to operate and protect the service:
- Google Firebase / Google Cloud: hosting, authentication, databases, file storage, Cloud Functions, logs, and related infrastructure.
- Cloudflare: domain/security services and Turnstile anti-abuse verification.
- Resend: delivery of contact and privacy-request email.
Cuatro may prepare an educator-authored prompt and open ChatGPT as a separate service. ZoodleBug does not automatically transmit student data or Cuatro content to ChatGPT. The user chooses whether to leave ZoodleBug and use that separate service under its own terms.
ZoodleBug may also disclose information when required by law, to protect safety or security, or in a business transfer subject to continuing student-privacy protections. We do not permit service providers to use student information for their own advertising or unrelated purposes.
6. Visibility and sharing
- District-mode student accounts are excluded from public leaderboards and public content sharing by default.
- Multiplayer names, game state, and prewritten chat may be visible to the participants in that game.
- Tournament records are limited to assigned participants and participating educators.
- Cuatro creation and community publishing are limited to verified educators and administrators.
7. Retention and deletion
| Record | Default retention |
|---|---|
| Student account and saved educational progress | While the authorized account is active; deleted within 30 days after a verified deletion request or the applicable district-contract deadline, unless law requires a shorter period. |
| Inactive anonymous tournament authentication account | 30 days after last authentication activity. |
| Waiting-room and multiplayer session records | Waiting records are removed after they are no longer operationally needed; completed or abandoned session records are removed within 30 days. |
| Tournament records | Up to 12 months after the tournament ends, or earlier on verified school request or contract end. |
| Educator-created content | Until the educator deletes it, the account ends, or the school requests deletion. |
| Support and privacy-request correspondence | Up to 12 months after the request is closed, unless needed longer for a documented dispute or legal obligation. |
| Security and operational logs | Normally up to 12 months, subject to shorter provider settings and documented security needs. |
| Deletion receipt | A non-readable hash and completion record may be retained for up to 24 months as evidence that deletion occurred. |
Backups and service-provider copies are deleted or overwritten on their normal secure cycles. Information subject to a valid legal hold may be isolated and retained only for that purpose.
8. Security
ZoodleBug uses role-based access, verified-educator controls, HTTPS, managed authentication, restricted database and storage rules, server-side functions for sensitive operations, secret management, logging, backups, and incident-response procedures. No online service can guarantee perfect security, but ZoodleBug maintains safeguards appropriate to the service and the information processed.
9. Parent, student, educator, and school rights
A parent, guardian, eligible student, educator, or school may request access, correction, export, or deletion. We verify identity and authority before disclosing or deleting records. A verified educator can delete student accounts that the educator provisioned and receives a deletion receipt. Schools may submit requests for all students under their control.
Submit a request through the ZoodleBug privacy request form. Never send a password through the form.
10. Changes to this policy
Material changes will be posted here with a new effective date. When a school contract or applicable law requires advance notice or consent, ZoodleBug will provide it before the change takes effect for that use.
11. Contact
Privacy email: privacy@zoodlebug.com
Mailing address: 31165 Temecula Pkwy, Suite G3, Unit #2120, Temecula, CA 92592
Telephone: 951-878-9140
Online request: Privacy request form
This public notice explains ZoodleBug’s general practices. A school or district data-privacy agreement may impose additional or shorter requirements; the stricter applicable requirement controls.