Privacy Policy
Effective August 12, 2026
1. Who we are
CurriBloom is a homeschool planning and record-keeping service operated by Calaway Solutions ("CurriBloom", "we", "us"). This Privacy Policy explains what information we collect, how we use and protect it, who we share it with, and the choices and rights you have.
CurriBloom is designed for parents and guardians. Only adults hold accounts. Children are added as student profiles inside a parent-controlled household and never sign in, receive messages, or interact with the service directly. How we handle child-related information is described here and in more detail in our Child & Student Privacy Notice.
2. Information we collect
We collect only what we need to run the service. We do not buy personal information about you, and we do not build advertising profiles.
Account information you provide: your email address, an optional display name, and — if you sign in with email and password — a securely hashed password (we never store your actual password). If you choose to sign in with Google, we receive a provider identifier to link that sign-in method to your account.
Security information we generate: session identifiers and related security metadata used to keep you signed in and to let you sign out and revoke access.
Content you create: your household name and settings (such as timezone), student profiles (preferred name, optional grade or age band), curriculum (grade levels, terms, courses, credits), grades and assignments, planned and recurring activities, completion records and notes, and any files (images or PDFs) you attach to assignments.
Plan and billing information: which plan your household is on, whether it is active, and where it is managed. If you subscribe to a paid plan, payment is processed by Stripe — your card details are entered directly on Stripe’s secure pages and handled by Stripe, so we never receive or store your full card number. We keep only a Stripe customer and subscription identifier and your plan status.
Operational information: limited technical metadata such as request identifiers, routes, status, timing, and app version, used to keep the service reliable and secure. This never includes your private content.
On your Android device: if you record activity completions while offline, a minimal queue (opaque identifiers, status, dates, and retry data — never your notes) is kept on the device until it syncs, then cleared.
3. What we do NOT collect
We do not use advertising identifiers or serve ads. We currently use no product-analytics or crash-reporting SDKs. We do not request access to your contacts, SMS, call logs, microphone, precise or background location, or your broad photo library — file uploads use the system picker for the single file you choose.
We do not knowingly collect information directly from children. Children do not have accounts and do not interact with CurriBloom; a parent provides and controls all student information.
4. How we use your information
To provide and operate the service — create and secure your account, run your household workspace, and store the records you create.
To authenticate you and protect your account — verify your email, let you reset your password, and send account and security notifications.
To keep the service reliable and safe — troubleshoot problems, prevent abuse, and enforce our Terms of Service.
To respond to you — provide support when you contact us.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
5. How your information is shared
We share information only with service providers that help us run CurriBloom, under agreements that limit them to processing it on our behalf:
- Neon — hosts our PostgreSQL database (your account, household, and education records).
- Vercel — hosts our website and application servers.
- Cloudflare R2 — private storage for files you upload; files are stored under non-guessable keys and served only through short-lived, authorized links.
- Resend (delivering via Amazon SES) — sends account emails such as verification and password-reset messages to adults. No child data is ever emailed.
- Stripe — processes subscription payments if you choose a paid plan. Your billing email and card details are provided directly to Stripe on its own secure pages; we never receive or store your full card number. We share only what is needed to manage your subscription (a Stripe customer/subscription reference and your plan). Stripe handles your payment information under its own terms and privacy policy. No student information is shared with Stripe.
- Google — only if you choose Google sign-in, to authenticate you.
We may disclose information if required by law, to protect the rights, safety, and security of our users or the public, or in connection with a business transfer (in which case we will require the recipient to honor this Policy or notify you of any material change).
Anything you deliberately choose to share with a scoped, expiring link is available to whoever holds that link until it expires or you revoke it.
6. How long we keep it
We keep your information for as long as your account and household are active. When you delete your account, we remove your household, students, curriculum, records, uploads, exports, and sessions through a controlled deletion workflow, except where we must retain limited information to meet a legal obligation.
Account deletion runs after a short cancellation window during which you can sign back in to stop it. Generated exports expire after a short period. Operational logs are kept only briefly.
7. Your rights and choices
You control your data. As the account owner you can, at any time:
- Access and export your records (see the Export instructions).
- Correct or update information directly in the app.
- Delete individual records, a student profile, or your entire account and household (see Delete account).
Depending on where you live, you may have additional rights under laws such as the GDPR or U.S. state privacy laws (for example, to access, correct, delete, or port your data, and to complain to a regulator). We honor these rights; contact us to exercise them. We will not discriminate against you for exercising any privacy right.
8. How we protect your information
We apply defense in depth. Data is encrypted in transit. Access to household data is scoped to an authenticated adult and enforced at both the application layer and the database layer (PostgreSQL Row-Level Security). Uploaded files live in private storage reached only through short-lived, authorized links. Passwords are stored only as salted hashes. No security measure is perfect, but we work to protect your information and to respond quickly if an issue arises.
To report a security concern, please use our Security page.
9. Children and students
CurriBloom is intended for parents and guardians, not for use by children. A parent enters and controls all student information, and can review, correct, export, or delete it at any time. Please read our Child & Student Privacy Notice for the details, including how we approach children’s privacy laws such as COPPA.
10. Cookies and local storage
We use a small number of strictly necessary cookies to keep you signed in and to secure the service. We also store a light preference in your browser (such as your light/dark theme choice). We do not use advertising or cross-site tracking cookies.
11. Where your data is processed
CurriBloom is operated from, and its providers process data in, the United States. If you access CurriBloom from outside the United States, you understand your information will be processed there.
12. Changes to this Policy
We may update this Policy as the service evolves or the law requires. When we make material changes, we will update the effective date above and, where appropriate, notify you. Your continued use of CurriBloom after an update means you accept the revised Policy.
Questions about this Policy or your data? Reach us through our Support page, report a security concern on our Security page, and see our Child & Student Privacy Notice.