Privacy Notice
This notice explains what information the Arcade collects about the students who use it, how we use that information, who receives it, how long we keep it, and what parents can do about it. The Arcade is offered to students of Sports Academy 78734, LLC.
Who operates the Arcade
The Arcade is provided by Sports Academy 78734, LLC and Superbuilders.
For any question or request about your child's information, contact Superbuilders at legal@arcade.school, by phone at (512) 301-8589, or by mail at 600 Congress Ave, Austin, Texas 78701, US. This contact answers for both operators.
What we collect
From your child's school records, through the school's Timeback system:
- your child's name, school email address, grade, and roster identifier;
- the email address of each parent or guardian on the roster, when we ask for consent;
- whether your child is under 13, from the birth date on the roster. We store only the yes or no, never the date.
Automatically, when your child uses the Arcade:
- a sign-in cookie that keeps your child signed in for up to 7 days;
- the internet address (IP address) of the connection, and the country, region, and city it points to;
- the type of browser and device in use;
- the pages your child opens and the actions they take in the Arcade;
- a recording of your child's screen while they use the Arcade, including what they type, apart from passwords, and the technical messages the Arcade sends and receives;
- technical records of each request the Arcade handles, tagged with your child's account.
What your child enters or creates:
- a short profile description;
- feedback they send us, with any screenshot they attach;
- their Roblox username, if they join the Roblox program. Roblox then tells us the account's identifier and avatar;
- a Minecraft player name that we create for your child, what your child builds and does on our Minecraft servers, and anything they type into the game's chat or commands. The game does not deliver that text to other players, but the server keeps a record of it;
- reports they make about other students, and the students they block.
From the school laptop:
- the laptop's serial number and the version of the Arcade launcher installed on it, checked about once an hour.
What other students can see
Other signed-in students can see your child's name, handle, avatar, whether they are online, the game they are playing, the games they have played most this week and how long they played them, the month they joined, and the friends the two of them have in common. Students in the Roblox program can see your child's Roblox username and avatar. Your child's Minecraft player name is visible to the other students on our Minecraft servers. The Arcade does not show your child's profile description to other students, and it does not carry messages between students.
How we supervise the Arcade
The Arcade is a supervised place, and students should expect that what they do in it can be seen by adults. Anything the safety check flags, and anything another student reports, can be reviewed by Arcade staff and safety moderators, and by school staff for their own school's students. Arcade staff can also review the screen recordings described above and the record of what your child types on our Minecraft servers. Staff who see something that puts a student at risk act on it. If we turn on a feature that carries messages or voice between students, we will describe in this notice how it is monitored, and we will ask for a parent's consent before your child uses it.
How we use it
We use your child's information only for these purposes:
- to run your child's account: who they are, their profile, their game identities, and their friends;
- to deliver notifications, show who is online, and record play sessions as they happen;
- to show your child which other students are playing near them, by city, once that feature is turned on;
- to check the profile description your child writes for safety before it is saved, and to let the staff named under "How we supervise the Arcade" review anything the check flags;
- to investigate and document a safety matter that staff escalate out of routine review;
- to meet our legal obligations, including reporting to the National Center for Missing and Exploited Children when the law requires it;
- to run, debug, and secure the service;
- to recover the service from a failure, using backups;
- to ask for and record a parent's consent.
Who receives it
We share your child's information only with the parties in this table, only for the purpose stated, and never for advertising.
| Recipient | What they receive | Why |
|---|---|---|
| Cloudflare | everything the Arcade stores and serves passes through Cloudflare, which hosts it; Cloudflare also delivers the emails we send to parents | hosting and email delivery |
| Amazon Web Services | our database, game servers, server logs, and backups | hosting and backups |
| PostHog | your child's account identifier, name, school email, roster identifier, role, and location, the actions they take, and the screen recordings described above | to run and debug the Arcade |
| Honeycomb | technical records of each request, with your child's account identifier, roster identifier, role, and handle, a masked form of their school email, their Minecraft player name and Roblox account identifier, the country, region, and city of the connection, and the browser; when we send a consent request, a masked form of the parent's email address | to run, debug, and secure the Arcade |
| Google Fonts | the connection's IP address and browser type, each time a page loads | to load the typefaces the Arcade uses |
| OpenAI and Google | the profile description your child writes, with no name or identifier attached | to check text for safety before it is saved |
| Roblox | your child's Roblox username, when they join the Roblox program; Roblox tells us the account's identifier and avatar in return, and we ask Roblox whether the account is online and which game it is in | to run the Roblox program |
| Timeback, the school's learning system | your child's school email address and roster identifier, so we can read their daily learning progress; Timeback gives us the roster, guardian addresses, and birth-date information described above | to know who your child is and whether they have finished their learning for the day |
| The web games we link to | when your child opens a game that another company hosts, that company's site receives the connection's IP address and browser type, as any website does; we send it nothing about your child's account | to run the game |
| Stripe | when a parent approves a consent request, the parent's card details, entered directly into Stripe; we never see the card number | to confirm that the person approving is an adult |
| Our sign-in service and our feedback service | your child's identity, for sign-in; feedback text and screenshots with your child's name, school email, and account identifier | sign-in, and handling feedback |
We do not sell or rent your child's information, disclose it for advertising, or use it for unrelated commercial purposes.
Identifiers we use only to run the service
- The school laptop's serial number: we use it to confirm the launcher is installed and current and to keep the fleet secure. It is stored apart from your child's account, never joined to it, and deleted 180 days after the laptop last checked in.
- The connection's IP address and browser type, sent to Google when a page loads: Google uses them to serve the typefaces. We send Google no account information.
How long we keep it
| Information | Purpose and need | Deleted |
|---|---|---|
| Account records: name, profile, friends, and game identities, and the usage events PostHog holds about the account | running your child's account | no longer than 90 days after the account ends: the roster no longer lists your child, the school turns the account off, or 12 months pass without a sign-in |
| Notifications, play sessions, and Minecraft join records | delivering them and answering support questions needs only a short window | 30 days after they are created |
| Text held for safety review, and the safety check's own records | letting staff review what the check flags | no longer than 90 days |
| The files of a safety matter | investigating and documenting a matter staff escalated | no longer than 5 years after the matter closes |
| Minecraft server records of what your child builds and types | running the servers and reviewing safety matters | typed text and build history no longer than 90 days; the rest with the account record |
| Consent records: who approved what, and when | proving a parent's consent | no longer than the account record's period |
| Server logs, including Minecraft server logs | diagnosing incidents and investigating abuse | 90 days |
| Request records at Honeycomb | diagnosing incidents and investigating abuse | 60 days |
| Screen recordings at PostHog | running and debugging the Arcade | 30 days |
| The launcher's device records | keeping launcher installs current | 180 days after the laptop's last check-in |
| Backups | recovering from a failure | our main database's backups 7 days; the stores behind the Roblox program, sign-in, and who is online keep a rolling 30-day history; game-server backups about 31 days; any copy kept outside these rotations 90 days after it was made |
| Sign-in cookie | keeping your child signed in | 7 days |
Where a period reads "no longer than", the exact period is still being settled with our counsel; the information is never kept past that ceiling.
How we protect it
- Every connection to the Arcade, and every connection between the Arcade and the services above, is encrypted in transit.
- Our databases and their backups are encrypted where they are stored.
- The credentials we hold for game accounts are encrypted a second time before they are stored.
- Student information can be opened only by named people we have signed in and given a role: Arcade staff and safety moderators, for every student; school staff and school contacts, for their own school's students only; and a parent, for their own children only.
What parents can do
You may review the information we hold about your child, ask us to delete it, and tell us to stop collecting or using it. To do so, contact legal@arcade.school. We will take steps to confirm that you are your child's parent or guardian before we act. If you approved a feature for your child, you can turn it off or withdraw your approval from the page linked in the approval email.