Effective Date: April 8, 2024
Last Updated: September 2, 2026
Play With ASL, LLC ("Play With ASL," "we," "us," or "our") is a Delaware limited liability company. This Privacy Policy explains what information we collect, how we collect it, who owns it, how long we keep it, how we protect it, and the choices you have when you use:
- our website at https://www.playwithasl.com;
- the Play With ASL consumer mobile application (iOS and Android);
- Play With ASL: School Edition; and
- our 1EdTech-certified LTI 1.3 Tool (production: https://lti.playwithasl.com / https://api.playwithasl.com).
Together, these are the "Services."
Related public documents: Terms of Use (also at /terms), AI Policy, Trust & Accessibility, and data deletion.
If a written agreement with a school or institution conflicts with this policy for that institution's users, the written agreement controls for those users.
1. Who we are
Play With ASL, LLC
30352 Sanderling Rd
Clarksville, DE 19970
United States
Privacy and security contact: privacy@playwithasl.com (also reaches our founder). General: jon@playwithasl.com.
2. Information we collect
What we collect depends on how you use the Services.
2.1 Information you give us
- Consumer accounts. If you create an account in the consumer app, we collect the email address and password you use with Firebase Authentication, and any name or profile photo you choose to add.
- Staff / teachers (School Edition). Name, email address, school, and class details used for account management and class rosters.
- Support and contact. If you email us or use a website form, we receive the name, email, phone number (if you include one), and message contents you send.
- Deletion requests. Email and any account identifiers you submit on /delete-data.
2.2 Information collected automatically
- App functionality. Game progress, preferences, settings, and which features you use, so the app works and progress can be restored.
- Performance analytics. Feature use and interaction counts used to improve the Services. Mobile analytics uses Firebase Analytics.
- Website analytics. If you accept cookies, Google Analytics 4 (GA4) records pages visited, time on site, and referral sources. See Cookies below.
- Purchases. Subscription and pack entitlement status via RevenueCat (consumer App Store / Google Play). Apple and Google process consumer store payments. School Edition web checkout is processed by Stripe. We do not store payment card numbers.
- Diagnostics. Crash and performance data, not used for advertising.
2.3 Information we do not collect as a condition of using the Services
We do not require Social Security numbers, home addresses, government IDs, precise GPS location, or biometric identifiers. We do not show third-party advertising. We do not operate public student profiles, chat, or public leaderboards.
3. Students, School Edition, and LTI — read this section carefully
This section is the student-data statement for 1EdTech and for schools. It replaces any older "we collect no student PII" shorthand. That shorthand was true of how we ask students to sign up. It was not a complete description of what an LMS may send us.
3.1 What we do not require from students
- We do not require a student to type a legal name, personal email, or home phone into Play With ASL in order to play.
- School Edition student accounts may use initials or a pseudonym.
- LTI students do not create a Play With ASL password. They arrive through their school's LMS using LTI 1.3 single sign-on.
3.2 What a school may send us (LTI 1.3)
When a school launches Play With ASL from an LMS (Canvas, Brightspace, Blackboard, Moodle,
Schoology, or another LTI 1.3 platform), the LMS sends a signed launch. We always receive an
opaque user identifier (the LTI subject, sub), roles, and course/context
identifiers needed to open the right activity. Our certified Tool also supports:
- Names and Role Provisioning Services (NRPS) 2.0 — roster information the
school enables. If the school (or its LMS settings) includes name and/or email, we receive
those values. If the school does not send name or email, the launch still works using
subonly. - Assignment and Grade Services (AGS) 2.0 — we may send completion or score data back to the school's LMS gradebook.
- Deep Linking 2.0 — teachers pick which game or vocabulary set to assign.
We do not scrape extra student records from the LMS beyond what the school configures the launch and NRPS to send. The school decides whether name and email are included.
3.3 How we use LMS identifiers
We derive an application user id from the LMS issuer plus sub so entitlements and
progress stay tied to that learner without requiring a separate password. Instructor name and
email, when the LMS sends them, are stored on the instructor record so the school can manage
the class. Launch sessions may carry name and email in the signed token when the LMS provided
them, so the app can display the right user and course.
Pseudonymous usage metrics (time in app, content interactions) are also collected to improve
the product. They are tied to the opaque LMS user identifier (issuer plus sub),
not to a legal name. That lets us restore progress and entitlements without requiring the
student to create a Play With ASL password or type identifying details. Those metrics are not
used to advertise to students.
3.4 Who controls school data
Education records the school provides remain the school's. We process them to provide the Services to that school. See Ownership and FERPA below.
4. How data is collected
- Directly from you — account forms, in-app settings, emails, and the deletion form.
- Automatically — app and website telemetry, cookies (if accepted), crash logs.
- From the LMS — LTI 1.3 launch claims, optional NRPS roster fields, AGS grade passback.
- From stores and entitlement vendors — Apple, Google, and RevenueCat tell us whether a consumer subscription or pack is active. They do not give us your card number. Stripe tells us whether a School Edition web checkout completed. Stripe holds the card number; we do not.
5. Who owns the data
- School / institution data (rosters, LMS identifiers, grades sent to the LMS, class context) is owned by the institution. We process it to provide School Edition and the LTI Tool.
- Consumer account data (your email, progress, purchases) is yours. We process it to provide the consumer app.
- We do not claim ownership of student education records. We do not take an unlimited license to use personal data for advertising or resale.
6. How we use information
We use information only to provide, secure, and improve the Services, including to:
- authenticate users (Firebase for consumer accounts; LTI 1.3 SSO for LMS launches);
- restore progress and entitlements;
- provision School Edition / LTI access when an institution license is active;
- return scores to the LMS when AGS is enabled;
- respond to support, deletion, and security reports;
- understand product performance (app analytics and, if consented, website GA4);
- meet legal obligations (tax, accounting, lawful requests).
We do not use personal information to train public generative-AI models. See our AI Policy.
7. Retention and deletion
7.1 While an account or license is active
We keep personal data for as long as the account remains open or the institution license remains active, whichever applies, plus the short period needed to close the record after it ends.
7.2 After deletion or closure
There are two deletion paths, and they do different things:
- In the consumer app (Account Management → Delete Account → type DELETE): we immediately delete that Firebase Authentication account. You are signed out and that login cannot be used again.
- Website form and school requests (https://www.playwithasl.com/delete-data, or privacy@playwithasl.com for LTI / School Edition users): after we verify the request, we delete or irreversibly de-identify the personal data we hold within 30 days. That is the timeline we operate to for remaining account, progress, and related records.
We may retain:
- aggregated analytics that cannot reasonably identify you; and
- records we are required to keep for tax, fraud prevention, dispute, or other legal reasons.
Deleting a Play With ASL account does not cancel an Apple or Google subscription. Cancel those in the store. See the Terms of Use.
8. How we protect data
We host the Services on Amazon Web Services in the United States (AWS us-east-1). Safeguards in production include:
- encryption in transit using TLS 1.2 or later;
- encryption at rest for databases, object storage, backups, and secrets;
- private networking so application tasks are not directly on the public internet;
- a web application firewall (AWS WAF) on public load balancers and CloudFront;
- role-based access control in the product and for our staff;
- federated SSO for vendor administrative access, with multi-factor authentication at our identity provider;
- logging and threat detection (including AWS CloudTrail and GuardDuty).
8.1 Passwords and sign-in
- LTI / School Edition via LMS: users sign in through the institution's LMS (LTI 1.3). Play With ASL does not create a separate password for that launch. If the school requires MFA, that MFA is the school's.
- Consumer app: email and password via Firebase Authentication. We do not offer social-media login. We do not currently require consumer multi-factor authentication.
8.2 Incidents
If a security or privacy incident affects customer data, we notify affected institutions within 72 hours of confirmation, as published on Trust & Accessibility. Report concerns to privacy@playwithasl.com.
We are not SOC 2 certified. AWS, our hosting provider, publishes its own SOC 2 Type II reports under AWS's customer agreement. Do not read this policy as a Play With ASL SOC 2 attestation.
9. Cookies
We use cookies and similar storage as follows:
| Cookie / storage | Purpose | Required? |
|---|---|---|
pwa_cookie_consent (localStorage) | Remembers whether you accepted or declined website analytics cookies. | Yes — strictly necessary to honor your choice |
| Google Analytics 4 cookies | Website usage (pages, referrers, approximate unique visitors). Measurement ID G-CR3HMZ9PT5. Loaded only after Accept. | No — decline and they are not set |
| LTI launch token (signed, short-lived, in the launch URL — not an advertising cookie) | Completes LMS single sign-on and opens the assigned activity. Deep Linking uses a similar signed session token. Not used for advertising. | Yes — needed for the Tool to function |
Decline website analytics on first visit, or clear this site's local storage to see the banner again. The consumer app and LTI Tool do not show ads and do not use advertising cookies.
10. Third parties (subprocessors)
We do not sell personal information. We do not share personal information with third parties for their advertising. We use the following companies only to operate the Services.
| Third party | What we share | Why |
|---|---|---|
| Amazon Web Services (AWS) | Application data, logs, backups, and files stored to run the Services | Hosting, database, storage, CDN, encryption, monitoring — US region us-east-1 |
| Google Firebase (Authentication and Analytics) | Account email/UID for sign-in; app analytics events | Consumer (and some School Edition) authentication; mobile product analytics |
| RevenueCat | App user ids and entitlement / subscription status — not card numbers | Consumer subscriptions and pack unlocks across Apple and Google Play |
| Google Analytics 4 | Website usage if you accept cookies — not sold by us | Improve this marketing website |
| Apple / Google (stores) | Purchase receipts they already process as the merchant of record | Consumer billing. We never receive PAN / card numbers from them. |
| Stripe | Checkout session and payment status for School Edition web purchase. Stripe holds card numbers; we do not. | School Edition student web checkout. We never receive PAN / card numbers. |
Web card checkout. School Edition web purchase uses Stripe Checkout. Card numbers are entered on Stripe's hosted page. We do not store PAN / card numbers on our servers.
10.1 Opting out of third-party sharing
- Website analytics: decline the cookie banner. That is the opt-out for GA4.
- Required processors (AWS, Firebase, RevenueCat, app stores, and Stripe when you use School Edition web checkout): we cannot operate the Services without them. The opt-out is to stop using the Services and delete your account (or have the school request deletion).
- There is no advertising-sharing opt-out because we do not share with advertisers.
10.2 Third-party contracts
Processors are bound by written terms that limit use of the data to providing their service to us. They may not use the data for their own advertising. Where a school has a written agreement with us, we require processors to protect that data at least as strictly as we do under that agreement, including FERPA school-official limits on redisclosure.
10.3 Changes in third parties
If we add or replace a subprocessor that will receive personal data, we will update this policy and the Trust page. For a material change we will give at least 30 days' notice by updating the "Last Updated" date and, where we have an email for affected institutional contacts, by email — unless a shorter period is needed to address a security issue.
11. Advertising
- We do not display advertisements in the consumer app, School Edition, the LTI Tool, or on product surfaces of this website.
- We do not target users with advertisements.
- We do not allow third parties to track or collect information on our Services for advertising.
- We do not use web beacons, pixels, or other tracking technologies for advertising.
- Because we do not share data with advertisers, there is no advertiser opt-out to configure. Website GA4 is analytics, not ads, and is consent-gated.
12. FERPA, COPPA, GDPR, and CCPA
We design the Services for schools and families. We do not claim to be "FERPA-compliant," "COPPA-compliant," or "GDPR-compliant" as a certified status. Practices:
- FERPA (US schools). For School Edition and LTI, we act as a school official / service provider: we use education records only to provide the Services to the school, and we do not redisclose them except as the school directs or as required by law. A signable Data Processing Agreement template is on our compliance roadmap; until it is published, institutions may use their standard DPA and this policy.
- COPPA (US under-13). The consumer app is rated 4+ and does not show ads. A parent or guardian must create the account for a child under 13. See the Terms of Use. We have not joined a FTC COPPA Safe Harbor program.
- GDPR / UK GDPR. We operate from the United States. If you access the Services from the EEA or UK, local law may give you additional rights. Contact privacy@playwithasl.com. Dedicated EU/UK hosting is available only as a separately scoped partnership (see data residency).
- CCPA / similar US state laws. We do not sell personal information. You may request access or deletion via /delete-data or privacy@.
13. Changes to this policy
Revision history:
- April 8, 2024 — first public Privacy Policy.
- September 2, 2026 — expanded for School Edition / LTI, subprocessors, cookies, advertising, security, ownership, 30-day deletion, and 1EdTech TrustEd Apps Data Privacy Rubric coverage. Student LTI section added.
We will change the "Last Updated" date when we revise this policy. For a material change (new categories of personal data, new advertising, or a new subprocessor that receives student or account data), we will provide at least 30 days' advance notice on this page and, where we have contact emails for affected institutions, by email. Continued use after the effective date is acceptance of the updated policy. If you do not agree, stop using the Services and request deletion.
14. Contact and your rights
You may request access, correction, or deletion of personal information, or ask questions about this policy:
- Email: privacy@playwithasl.com
- Deletion form: https://www.playwithasl.com/delete-data
- Mail: Play With ASL, LLC, 30352 Sanderling Rd, Clarksville, DE 19970, United States
Infrastructure and certification detail for procurement teams: Trust & Accessibility. Accessibility: VPAT 2.5 (internal architecture review, not a third-party AT audit). AI: AI Policy.