Privacy Policy

Effective Date: April 8, 2024

Last Updated: September 2, 2026

Play With ASL, LLC ("Play With ASL," "we," "us," or "our") is a Delaware limited liability company. This Privacy Policy explains what information we collect, how we collect it, who owns it, how long we keep it, how we protect it, and the choices you have when you use:

Together, these are the "Services."

Related public documents: Terms of Use (also at /terms), AI Policy, Trust & Accessibility, and data deletion.

If a written agreement with a school or institution conflicts with this policy for that institution's users, the written agreement controls for those users.

1. Who we are

Play With ASL, LLC
30352 Sanderling Rd
Clarksville, DE 19970
United States

Privacy and security contact: privacy@playwithasl.com (also reaches our founder). General: jon@playwithasl.com.

2. Information we collect

What we collect depends on how you use the Services.

2.1 Information you give us

2.2 Information collected automatically

2.3 Information we do not collect as a condition of using the Services

We do not require Social Security numbers, home addresses, government IDs, precise GPS location, or biometric identifiers. We do not show third-party advertising. We do not operate public student profiles, chat, or public leaderboards.

3. Students, School Edition, and LTI — read this section carefully

This section is the student-data statement for 1EdTech and for schools. It replaces any older "we collect no student PII" shorthand. That shorthand was true of how we ask students to sign up. It was not a complete description of what an LMS may send us.

3.1 What we do not require from students

3.2 What a school may send us (LTI 1.3)

When a school launches Play With ASL from an LMS (Canvas, Brightspace, Blackboard, Moodle, Schoology, or another LTI 1.3 platform), the LMS sends a signed launch. We always receive an opaque user identifier (the LTI subject, sub), roles, and course/context identifiers needed to open the right activity. Our certified Tool also supports:

We do not scrape extra student records from the LMS beyond what the school configures the launch and NRPS to send. The school decides whether name and email are included.

3.3 How we use LMS identifiers

We derive an application user id from the LMS issuer plus sub so entitlements and progress stay tied to that learner without requiring a separate password. Instructor name and email, when the LMS sends them, are stored on the instructor record so the school can manage the class. Launch sessions may carry name and email in the signed token when the LMS provided them, so the app can display the right user and course.

Pseudonymous usage metrics (time in app, content interactions) are also collected to improve the product. They are tied to the opaque LMS user identifier (issuer plus sub), not to a legal name. That lets us restore progress and entitlements without requiring the student to create a Play With ASL password or type identifying details. Those metrics are not used to advertise to students.

3.4 Who controls school data

Education records the school provides remain the school's. We process them to provide the Services to that school. See Ownership and FERPA below.

4. How data is collected

5. Who owns the data

6. How we use information

We use information only to provide, secure, and improve the Services, including to:

We do not use personal information to train public generative-AI models. See our AI Policy.

7. Retention and deletion

7.1 While an account or license is active

We keep personal data for as long as the account remains open or the institution license remains active, whichever applies, plus the short period needed to close the record after it ends.

7.2 After deletion or closure

There are two deletion paths, and they do different things:

We may retain:

Deleting a Play With ASL account does not cancel an Apple or Google subscription. Cancel those in the store. See the Terms of Use.

8. How we protect data

We host the Services on Amazon Web Services in the United States (AWS us-east-1). Safeguards in production include:

8.1 Passwords and sign-in

8.2 Incidents

If a security or privacy incident affects customer data, we notify affected institutions within 72 hours of confirmation, as published on Trust & Accessibility. Report concerns to privacy@playwithasl.com.

We are not SOC 2 certified. AWS, our hosting provider, publishes its own SOC 2 Type II reports under AWS's customer agreement. Do not read this policy as a Play With ASL SOC 2 attestation.

9. Cookies

We use cookies and similar storage as follows:

Cookie / storage Purpose Required?
pwa_cookie_consent (localStorage) Remembers whether you accepted or declined website analytics cookies. Yes — strictly necessary to honor your choice
Google Analytics 4 cookies Website usage (pages, referrers, approximate unique visitors). Measurement ID G-CR3HMZ9PT5. Loaded only after Accept. No — decline and they are not set
LTI launch token (signed, short-lived, in the launch URL — not an advertising cookie) Completes LMS single sign-on and opens the assigned activity. Deep Linking uses a similar signed session token. Not used for advertising. Yes — needed for the Tool to function

Decline website analytics on first visit, or clear this site's local storage to see the banner again. The consumer app and LTI Tool do not show ads and do not use advertising cookies.

10. Third parties (subprocessors)

We do not sell personal information. We do not share personal information with third parties for their advertising. We use the following companies only to operate the Services.

Third party What we share Why
Amazon Web Services (AWS) Application data, logs, backups, and files stored to run the Services Hosting, database, storage, CDN, encryption, monitoring — US region us-east-1
Google Firebase (Authentication and Analytics) Account email/UID for sign-in; app analytics events Consumer (and some School Edition) authentication; mobile product analytics
RevenueCat App user ids and entitlement / subscription status — not card numbers Consumer subscriptions and pack unlocks across Apple and Google Play
Google Analytics 4 Website usage if you accept cookies — not sold by us Improve this marketing website
Apple / Google (stores) Purchase receipts they already process as the merchant of record Consumer billing. We never receive PAN / card numbers from them.
Stripe Checkout session and payment status for School Edition web purchase. Stripe holds card numbers; we do not. School Edition student web checkout. We never receive PAN / card numbers.

Web card checkout. School Edition web purchase uses Stripe Checkout. Card numbers are entered on Stripe's hosted page. We do not store PAN / card numbers on our servers.

10.1 Opting out of third-party sharing

10.2 Third-party contracts

Processors are bound by written terms that limit use of the data to providing their service to us. They may not use the data for their own advertising. Where a school has a written agreement with us, we require processors to protect that data at least as strictly as we do under that agreement, including FERPA school-official limits on redisclosure.

10.3 Changes in third parties

If we add or replace a subprocessor that will receive personal data, we will update this policy and the Trust page. For a material change we will give at least 30 days' notice by updating the "Last Updated" date and, where we have an email for affected institutional contacts, by email — unless a shorter period is needed to address a security issue.

11. Advertising

12. FERPA, COPPA, GDPR, and CCPA

We design the Services for schools and families. We do not claim to be "FERPA-compliant," "COPPA-compliant," or "GDPR-compliant" as a certified status. Practices:

13. Changes to this policy

Revision history:

We will change the "Last Updated" date when we revise this policy. For a material change (new categories of personal data, new advertising, or a new subprocessor that receives student or account data), we will provide at least 30 days' advance notice on this page and, where we have contact emails for affected institutions, by email. Continued use after the effective date is acceptance of the updated policy. If you do not agree, stop using the Services and request deletion.

14. Contact and your rights

You may request access, correction, or deletion of personal information, or ask questions about this policy:

Infrastructure and certification detail for procurement teams: Trust & Accessibility. Accessibility: VPAT 2.5 (internal architecture review, not a third-party AT audit). AI: AI Policy.