Charger Tools
Home
Institutional Data Governance & Google Cloud OAuth Compliance

Privacy Policy & Data Protection.

Effective: September 8, 2026 Audit Cycle: 2026 Academic Year FERPA & COPPA Compliant Google OAuth 2.0 Verified

This Privacy Policy details how Charger Tools (“we”, “us”, or “our”), hosted at https://chargertools.com, collects, accesses, processes, protects, and handles user information. It establishes our absolute commitment to student privacy, educational data minimization, and statutory compliance with FERPA, COPPA, and the Google API Services User Data Policy (including Limited Use requirements).

01 Purpose & Zero-Monetization Mandate

Charger Tools is engineered exclusively as a high-performance, non-commercial academic enhancement suite, bell schedule tracker, grade forecasting engine, and educational utility index for students and educators. We operate under an absolute, non-negotiable operational standard: educational software must never exploit, monetize, track, or harvest the personal data of learners.

We do not sell, rent, license, trade, or exchange student or user data with commercial data brokers, advertising networks, or third-party behavioral targeting firms under any circumstance. Zero commercial monetization is hardcoded into our architectural model.

02 Data Minimization & Local Client-Side Execution

Our platform adheres strictly to the Principle of Data Minimization established under NIST SP 800-63B guidelines and the Fair Information Practice Principles (FIPPs). Computational utilities, GPA modeling algorithms, bell schedule countdown timers, citation compilers, and interactive solvers execute locally within the client's browser sandbox without transmitting student coursework or raw calculations to external servers.

The platform functions with zero third-party tracking cookies, zero advertising beacons, and zero cross-site fingerprinting scripts. Network requests are limited strictly to fetching application bundles, static documentation, and verified institutional APIs.

03 Information Categories Collected & Stored

When users register an account or sign in via Google OAuth, Charger Tools stores only the minimal attributes required for credential validation, session integrity, and Role-Based Access Control (RBAC):

Data Field Technical Purpose Storage Layer
Google Email Address Retrieved via Google Sign-In (email scope) for student identity verification, institutional domain validation (@students.nacs.k12.in.us), and account recovery. Firebase Auth / User Profile
Google Profile Name & Avatar Retrieved via Google Sign-In (profile scope) strictly to display the user's name and avatar in navigation headers and greeting interfaces. Client Session / User Profile
Google Account UID Unique OpenID Connect subject identifier (openid) used for stateless cryptographic token validation. Firebase Auth Store
Local Username / Handle Unique handle for optional non-Google credentials and role permission matrix lookup. Auth Registry
Password Hash PBKDF2-HMAC-SHA256 salted hash (100,000 iterations) for local accounts. Plaintext passwords are never stored. Not applicable to Google SSO users. Encrypted Store
Role Authorization Tier Permission classification (Student, Teacher, Yearbook Staff, Administrator) dictating tool access. Access Matrix
Security Forensics & Intrusion Telemetry Client IP address, device platform (ChromeOS, Windows, macOS, Linux, mobile), browser environment, viewport dimensions, hardware concurrency and memory indicators, automated bot markers, canvas security fingerprint hashes, and tamper attempt counters recorded strictly for intrusion prevention, spam mitigation, and cybersecurity defense under statutory internal operations exceptions. Encrypted Audit Logs

Exclusions: We never collect Social Security Numbers, biometric identifiers, home addresses, phone numbers, payment card data, financial information, or GPS geolocation telemetry.

04 Google API Services & OAuth 2.0 User Data Policy

Limited Use Compliance

Charger Tools integrates Google Identity Services (Google Sign-In / OAuth 2.0) to provide students and staff with streamlined, passwordless authentication. This section explicitly defines our Google API scopes, data handling practices, and adherence to Google Cloud OAuth verification requirements.

4.1 Google OAuth 2.0 Scopes & Information Accessed

Charger Tools requests only basic, non-sensitive identity scopes necessary to authenticate users:

  • openid: Used to receive a cryptographically signed JSON Web Token (JWT) validating user authentication state.
  • https://www.googleapis.com/auth/userinfo.email (email): Used to access the user's primary Google account email address to confirm institutional school affiliation (@students.nacs.k12.in.us).
  • https://www.googleapis.com/auth/userinfo.profile (profile): Used to access basic public profile information: user display name, given name, family name, and profile avatar picture.
No Sensitive Scopes Requested: Charger Tools does not request, access, read, or modify any sensitive or restricted Google API scopes. We do not access Google Drive files, Gmail messages, Google Classroom coursework or grades, Google Calendar events, Contacts, or Photos.

4.2 Technical Purpose of Data Collection & Processing

Data received from Google APIs is used strictly to provide core, student-facing application functionality:

Authentication & Session State

Enables single sign-on without storing plaintext passwords, establishing secure encrypted sessions.

Role-Based Access Control (RBAC)

Verifies district email enrollment to grant appropriate tier permissions (e.g. Student, Yearbook Staff, Educator).

User Profile Personalization

Renders user display name and profile picture in navigation headers and greeting dialogs.

Security & Abuse Prevention

Protects against account impersonation and validates account ownership for statutory deletion petitions.

4.3 Zero Third-Party Sale & Non-Commercial Data Sharing

Charger Tools enforces an unequivocal prohibition on commercial data sharing:

  • We do NOT sell, rent, lease, trade, or transfer Google user data to any commercial third parties.
  • We do NOT share Google user data with advertising networks, data brokers, or behavioral analytics providers.
  • Google user data is only transmitted to authorized cloud infrastructure providers (specifically Google Cloud Platform / Firebase Authentication & Firestore) solely to operate secure authentication and database persistence under enterprise data protection terms.

4.4 Prohibition on Artificial Intelligence (AI) and Machine Learning (ML) Model Training

Explicit AI/ML Guarantee: Google user data received through Google APIs is NOT used, transferred, or disclosed to develop, train, retrain, improve, or fine-tune generalized artificial intelligence (AI) models or machine learning (ML) models, including large language models (LLMs), neural networks, or generative foundation models.
Mandatory Limited Use Compliance Disclosure
“Charger Tools’ use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.”

This commitment governs all aspects of data handling across the entire lifecycle of Google user data accessed by the application.

4.6 Data Retention, Google Permission Revocation & Deletion

Retention Period: Google user profile attributes and session records are retained only for the duration of the active user session or active authorized account.

Revoke Access Anytime: Users can revoke Charger Tools’ access to their Google account at any moment through Google’s official security portal:

Permanent Deletion: You can permanently purge all stored account data and Google profile records from our databases by clicking the Request Data Deletion button below or emailing support@chargertools.com.

05 Statutory Legal Frameworks & Declarations

Full Statutory Conformance

Charger Tools is architected in rigorous compliance with federal educational and minor protection statutes. The platform implements non-commercial data minimization, school official institutional governance, and client-side computational sandboxing:

Family Educational Rights and Privacy Act (FERPA)
Student Record Privacy & Institutional Governance
34 CFR § 99.31(a)(1)

Charger Tools operates strictly under the federal “School Official with Legitimate Educational Interest” exception (34 CFR § 99.31(a)(1)(i)(B)). Educational records remain under the direct institutional control of school authorities, with an absolute prohibition on unauthorized re-disclosure to external commercial entities.

Direct School Control: The district maintains exclusive governance over student authorizations and records.
Zero Commercialization: Student records, GPA calculations, and coursework are never monetized, rented, or sold.
Audit Segregation: Security forensic logs are strictly segregated from academic records.
Children's Online Privacy Protection Act (COPPA)
Child Privacy Protection • Under-13 Minor Safeguards
16 CFR Part 312

Charger Tools is designed to exceed FTC COPPA standards. Where utilized in school environments, the platform relies upon institutional educational consent pursuant to FTC guidance solely for academic instructional activities, completely insulated from commercial tracking.

FTC Educational Exception: School institutional consent is leveraged strictly for non-commercial pedagogical benefits.
Zero Behavioral Ads: Completely free of commercial advertising beacons, remarketing pixels, and data brokers.
Internal Operations Exemption (16 CFR § 312.2): Operational IP telemetry is used solely for system security defense.
Children's Internet Protection Act (CIPA)
Content Moderation & E-Rate Safety Standards
47 U.S.C. § 254(h)

All interactive modules, community suggestion boards, and emulation runtimes incorporate automated content safety filters, administrative moderation gates, and real-time lockdown sentinels to ensure full alignment with district E-Rate technology protection requirements.

Strict Safety Filtering: Interactive boards and user submissions undergo automated input sanitation and human review.
Instant Lockdown Sentinels: Administrative protocols permit instantaneous site-wide maintenance or shutdowns if threats emerge.
District Network Alignment: Operates safely within Carroll High School and NACS content filtration perimeters.

06 Local Client Storage & Disguise Presets

To deliver zero-latency responsiveness and maintain offline utility, Charger Tools uses browser storage APIs (localStorage and sessionStorage) exclusively scoped to the origin domain.

Locally stored records include session authentication tokens, client accessibility configurations (Large Text Mode, Dyslexia Font, High Contrast, Reduced Motion), and tab disguise presets. Users can purge stored data at any time via the “Sign Out” button or through browser site settings.

07 Data Subject Rights, Deletion Policy & Account Termination

Every student, educator, and parent maintains complete sovereignty over their data profile. Users retain the right under FERPA, COPPA, and state data privacy statutes to inspect account records, request corrections to display aliases, and petition for permanent data deletion.

Statutory Termination Mandate

Mandatory Policy: Data Deletion Constitutes Permanent Account Termination

Because user authentication credentials, RBAC permission tiers, and saved tool preferences are intrinsically tied to your identity record, requesting data deletion constitutes an explicit, irreversible request to permanently delete your account and lock you out of the platform.

Upon administrative approval of a deletion request:
Your user account is permanently locked out and forbidden from future logins.
All permission grants, role tiers, Google OAuth tokens, and access credentials are permanently deleted from user_permissions.
All historical telemetry and session logs associated with your handle or email are purged from login_logs.
If enrolled, your email is immediately revoked and expunged from the yearbook staff whitelist.
Exercise Your Statutory Privacy Rights
Submit a verified data erasure petition for administrative review & purge.

08 Security Infrastructure, Anti-Spam Forensics & Intrusion Defense Sentinels

Platform integrity is safeguarded through transport-layer encryption (TLS 1.3), Content Security Policies (CSP), subresource integrity verification, and dynamic maintenance guards. Master credentials and administrative console access require strict cryptographic validation via authorized Google Identity SSO.

Cybersecurity Telemetry, Anti-Spam & Break-In Prevention Forensics: To protect educational services against unauthorized break-in attempts, credential stuffing, automated bots, and malicious tampering with student administrative tools, Charger Tools operates an automated Security Sentinel. When security events occur—such as unauthorized access attempts to the administration console, developer tools tampering, attempts to bypass emergency blackout locks, or automated bot interactions—the system captures technical forensic telemetry. This forensic data includes: (1) client public WAN IP address; (2) operating system and platform classification (including ChromeOS, Windows, macOS, Linux, iOS, and Android); (3) browser software and engine metadata; (4) display viewport dimensions and pixel ratios; (5) hardware concurrency and memory profiles; (6) automated bot and headless browser detection flags; (7) non-reversible cryptographic canvas security hashes used to correlate distributed spam and brute-force campaigns across changing IPs; (8) consecutive authentication attempt counters; and (9) forensic event timestamps and path triggers.

These forensic security records are maintained strictly for institutional defense, threat deterrence, and incident response under statutory Support for Internal Operations exemptions (COPPA 16 CFR § 312.2) and school official cybersecurity defense provisions (FERPA 34 CFR § 99.31). Security telemetry is encrypted at rest using AES-256, segregated from student academic profiles, and is never shared, licensed, or monetized with commercial profiling entities. All forensic audit logs remain subject to user-initiated statutory erasure upon verified Data Deletion Requests.

09 Project Governance, Developer Identity & Contact Information

For inquiries concerning this Privacy Policy, our Google API Services User Data practices, or data subject rights verification, please contact the development team:

Charger Tools Student Development Team
Application Name: Charger Tools
Official Application URL: https://chargertools.com
Privacy Policy URL: https://chargertools.com/privacy
Developer & Privacy Contact Email: support@chargertools.com
Source Code Repository: Charger Tools GitHub Repository
Disclaimer: Charger Tools is an independent student-led project and is not affiliated with, endorsed by, or operated by Carroll High School, Northwest Allen County Schools, or school faculty.