Conversation
Written by reading the code rather than from a template, so the tables name the actual survey fields, the actual services in the data flow, and what each one receives. Nothing in it describes a control the app does not have. It is a starting point for a lawyer and says so at the top. The second half is the part worth their time: the places where the software and the law have not been reconciled. Chief among them, COPPA. The age question starts at 13 but nothing stops a younger child picking it — no gate, no parental consent, no separate handling. Age is collected and then used for nothing at all, which is its own problem: either it gates something or it should not be asked. Also flagged: no consent checkbox and nowhere to show a policy; race, religion and immigration-status answers collected without the opt-in that several state laws want for sensitive categories; deletion built but no export; no retention rule; and zippopotam.us, a keyless public API with no agreement of any kind, receiving students' ZIP codes — a local lookup table would remove it from the flow.
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Deploying timeline-prototype with
|
| Latest commit: |
fdecff6
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://d101f861.timeline-prototype.pages.dev |
| Branch Preview URL: | https://docs-privacy-policy-draft.timeline-prototype.pages.dev |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Not for publication. A starting point for a lawyer, and a list of the things only you can decide.
The policy text was written by reading the code, so the tables name the fourteen actual survey fields with their real "why" text, the six services that genuinely receive data, and only controls the app actually has. Nothing in it describes a protection that doesn't exist.
The half worth a lawyer's time
The nine open questions at the end. The one to read first:
Also flagged: no consent checkbox and nowhere for a policy to appear; race, religion and immigration answers collected without the opt-in several state laws want for sensitive categories; deletion built but no export; and no retention rule, so an abandoned account keeps its data forever.
One finding that's a code fix, not a legal question
zippopotam.usreceives a student's ZIP code on every profile load. It's a free public API with no key and no agreement of any kind — the only genuinely unbound third party in the data flow. A local ZIP-to-coordinates table removes it.Why it's in the repo
It describes specific files and specific fields, so it will go stale exactly when they change. Keeping it next to the code means the diff that adds a survey question also shows this document needs a line.
A formatted version for sending to counsel: https://claude.ai/artifact/BJGkoGvBUQpaM7wgJmtKqw