Privacy Policy
What we collect, and what we don't
GoodCents runs a classroom economy. It needs to know who a student is and what they've earned. It does not need to know anything else, so it doesn't collect anything else.
Last updated 31 August 2026
The short version. GoodCents holds a student's name, their school Google account, and the record of their classroom economy — what they earned, bought, saved, borrowed and invested with play money. There are no ads, no analytics, no tracking, and nothing is ever sold or shared for marketing. A student can delete their own account from inside the app.
1. What we collect
From signing in with Google
GoodCents uses Sign in with Google and receives only the basic profile scopes: email address, name, and profile picture. We do not request access to Gmail, Drive, Calendar, Classroom or any other Google service, and we cannot read them.
Entered by school staff
A teacher or administrator sets up the roster. That record holds a student's first and last name, and optionally an expected email address, grade level, and a seat or class label.
Created by using the app
| Data | What it is |
|---|---|
| Transactions | Every award, fine, purchase, payroll run and transfer, with the note attached to it |
| Balances & paystubs | Current balance, and a record of each payday's pay, tax and deductions |
| Savings | Deposits, withdrawals and interest |
| Loans & credit | Loans taken, repayments, missed payments, and the in-app credit score derived from them |
| Investments | Simulated holdings and trades in the classroom exchange |
| Store | Items bought and redeemed |
| Attendance counts | The number of classes attended in a week, entered or imported by staff to calculate pay |
All amounts are classroom points. No real money moves through GoodCents, and we never ask for or store payment details.
From the device
If push notifications are enabled, we store a push token — an anonymous identifier the operating system issues so a notification can reach that device — and which platform it is (iOS or Android). Turning notifications off removes it.
2. Why we collect it
Each item above exists because a feature would not work without it. Names identify who earned what. The transaction record is the ledger the whole economy is built on. Attendance counts determine pay. Push tokens deliver the payday notification. That is the whole list — we do not collect data speculatively in case it is useful later.
3. What we don't do
- No advertising. There are no ads in GoodCents and no ad networks in it.
- No analytics or tracking SDKs. The app contains no analytics, attribution, or behavioural-tracking libraries of any kind. We do not build profiles of students and we do not track anyone across other apps or websites.
- No selling or renting data. Not to anyone, for any purpose, ever.
- No targeted advertising to students, and no use of student data to train advertising or recommendation systems.
- No location tracking. The app never requests location.
- No contacts, photos, microphone or camera access beyond scanning a QR code to redeem a store item, which happens on the device and is not recorded.
4. Who can see it
GoodCents is separated by school: nobody at one school can see another school's data. Within a school:
- Students see their own balance, history, savings, loans and investments. They can see classmates' names and, where the teacher enables it, leaderboard standings — but not other students' balances or histories.
- Teachers and administrators see the students in their school, including individual balances and transaction history, because that is the job the app does. What each staff member can see and do is controlled by permissions the administrator sets.
- We — the developer — can access the database for support, backup and debugging. We look only when there is a reason to, such as investigating a fault.
5. Services we rely on
GoodCents uses a small number of service providers. They process data on our instructions and are not permitted to use it for their own purposes.
| Provider | What it does | What it receives |
|---|---|---|
| Supabase | Database, authentication and file storage (hosted in the United States) | All app data described above |
| Sign in with Google | Handles the sign-in; returns email, name and profile picture | |
| Expo | Delivers push notifications | The push token and the text of the notification |
| Cloudflare | Hosts this website | Standard web request logs. This site has no analytics and sets no cookies. |
The app also fetches stock and commodity prices from a market-data provider to power the classroom exchange. Prices flow in only — no student data is ever sent to that provider.
6. Schools, FERPA and student records
When a school uses GoodCents, the school decides what goes in and controls it. We act as a service provider to the school, handling that information on the school's behalf and under its direction — the role a "school official" performs under the Family Educational Rights and Privacy Act (FERPA). We do not use student information for any purpose other than providing GoodCents to that school.
Attendance figures are education records. They enter GoodCents only because staff enter or import them, and they are used solely to calculate classroom pay.
Parents and guardians with questions about their child's records should contact the school first — the school holds the records and can act on them directly.
7. Children's privacy
GoodCents is provided to schools for classroom use, and students access it through an account their school issues. We do not knowingly collect personal information directly from a child for our own purposes, we do not show children advertising, and we do not build profiles of them.
Where a school enrols students under 13, the school is responsible for providing the parental notice and consent that the Children's Online Privacy Protection Act (COPPA) permits it to give on parents' behalf for an educational service. We support that by collecting only what the app needs and by deleting data on request.
8. How long we keep it
- While enrolled. A student's record is kept while they are in a school using GoodCents, because their history is the point of the app.
- When a student leaves. Staff can remove a student, which settles their balances and closes their participation.
- When a student deletes their own account (in the app, under Me → Close account) their sign-in is deleted and their name is removed from the record. The anonymised transactions remain, because a shared ledger cannot have entries erased from its middle without corrupting every balance around it.
- Backups. The database is backed up nightly and backups are kept for 90 days, then discarded. A deletion is reflected in live data immediately; it ages out of backups within that window.
- Price history for the exchange is pruned automatically and holds no personal data.
9. Your choices
- See your data. Your balance, full transaction history, paystubs, loans and investments are all visible in the app.
- Correct it. Ask your teacher or administrator — they can adjust or void transactions.
- Delete it. Me → Close account, in the app. Staff can also remove a student. Schools may request deletion of their whole school's data by writing to us.
- Turn off notifications. In the app under Me, or in your device settings.
Depending on where you live you may have additional rights over your personal information. Write to us and we will honour them.
10. Security
Data is encrypted in transit. Access is enforced in the database itself with row-level security, so a student's device can only ever retrieve that student's own records and the school-wide information they are entitled to — the rules are applied by the server, not by the app. Money-changing operations run as audited database functions rather than direct writes, and the ledger is insert-only: entries can be reversed by a correcting entry, but not quietly edited or deleted.
No system is perfect. If you find a security problem, please tell us — see below.
11. Changes
If this policy changes materially we will update the date at the top and, where the change affects how student data is handled, notify the schools using GoodCents.
12. Contact
Questions, requests, or a security report: privacy@goodcents.school.
GoodCents is built and operated by Andrew Jahan.