Version US-SCHOOL-PRIVACY-2026-09-18

U.S. School Edition Privacy Notice

THIS WAS US — School Edition is operated by Pinoks Creator Lab as a private event service. A school or district must configure its own authorised administrator, privacy contact, consent route, image-permission basis, retention settings and vendor-agreement metadata before a U.S. school deployment can accept participant contributions.

Purpose and information collected

The service may store a participant’s account reference, event membership, age band, consent state, profile or page content, stories, messages, photographs, videos, upload attestations, moderation records and limited security audit evidence. Exact dates of birth and guardian identity-document images are not requested by default.

Private event scope and images

U.S. School Mode is invite-only. School-supplied images require a recorded school permission basis. Participant uploads require an authorisation attestation. The service does not perform facial recognition or biometric identification.

Use limits

Student data is used only to operate, secure, moderate and preserve the configured private event. It is not sold, used for targeted advertising in School Mode, or reused for public marketing, testimonials, model training or unrelated product promotion without a separate lawful permission system.

Age eligibility and consent

Participants choose an age band rather than providing an exact birth date. Participants under 18 require active guardian consent by default. A school-authorised route may be used only when the deployment configuration explicitly permits it. Consent is event-specific, affirmative, versioned, revocable and cannot be carried to another event.

Retention and deletion

Student event content is scheduled for deletion after the school closes the event, normally within 90 days or a shorter configured period. Guardian consent evidence and limited security or deletion audit records are generally retained for up to 12 months after closure unless a documented incident, dispute or legal hold requires longer retention.

When a deletion job succeeds, the selected records are removed from the active production database and the corresponding private media objects are deleted from active object storage. Cloudflare R2 direct reads reflect a completed object deletion immediately. Cloudflare D1 Time Travel is always on and may keep a provider-controlled restore history for up to 7 days on the Workers Free plan or 30 days on the Workers Paid plan. The application cannot selectively purge those restore points, and the managed hosting layer does not expose the underlying account tier to the application. We therefore use 30 days as the conservative maximum provider-controlled database restore window, not as a promise that every deployment retains data for that period.

Deletion confirmations and narrowly limited evidence may remain where required to prove the action. A documented legal hold pauses eligible deletion until released. This notice does not promise an unsupported fixed backup-deletion deadline.

Guardian and participant choices

A guardian may withdraw consent using the private consent link. Withdrawal immediately blocks new contribution and starts the configured review, removal and deletion workflow. Access, correction, removal or deletion requests may also be made through the school privacy contact shown for the deployment or through support@pinokscreatorlab.com.

Vendor review

These controls support school and district review. They do not constitute FERPA certification, COPPA certification, district approval, national legal approval or approval by School Photographers of America.