Skip to content

Privacy and school use

Draft for the owner's legal review — not yet in force

This page describes how Para Schedule is built today. It has not been reviewed by a lawyer and is not an agreement yet. Last drafted September 2026.

Para Schedule is for adults organizing their own school workday. It is built to work without information about students. This page says what it stores, who can see it, and what you can do with it.

Before you enter student information

Your school or district decides what information about students may go into any tool, including this one. Check with them before you enter anything that identifies a student. Accepting this page is not that permission.

  • Para Schedule works without student names. Rooms, group labels such as Group B, and your own role are usually enough.
  • Initials are not the same as removing identifying information. A room, a time, and a distinctive assignment together can still point to one student.
  • The product has no fields for health, diagnosis, behavior, evaluations, or education records, and it does not accept attachments.
  • Keep notes short and about the work: where to be, what to prepare, who hands off to whom.

Para Schedule does not claim to meet any particular school, district, state, or federal requirement, and it is not approved by any school. A permitted-data policy will be published here after review. Until then, do not enter information that identifies a student.

What the product stores

Only what the product needs to work:

  • Your account: your email address, your password stored only as a one-way hash (the password itself is never kept), an optional display name, and your display and print preferences.
  • Sign-in sessions: a random token kept in a cookie in your browser. The server keeps only a hash of it, when it expires, and a short description of the browser that signed in.
  • Your schedule: its title and settings, the adult labels you type, duties (times, titles, places, group labels, roles, notes, handoffs), day types, changes for particular dates, times an adult is unavailable, saved versions and the copies made current from them, saved templates and duties, and the notes you add when you review a check.
  • Sharing: for each person you invite, their email address, which adults, dates, and details they may read, and when access ends or was revoked.
  • Product events: a short list of steps such as a schedule being made current, recorded with random ids and coded values only. Titles, labels, rooms, and notes are never part of them.
  • Plan records: which plan a schedule is on. No payment is collected at this time.

When you import rows, the pasted text or file is read in your browser; only the rows you choose to add are sent and saved. The fictional sample on the demo runs entirely in your browser and is never saved.

Cookies and browser storage

  • One sign-in cookie, which scripts on the page cannot read. It ends when you sign out or when the session expires.
  • Your theme and text size may be remembered in this browser for convenience; your account keeps the real setting.
  • While you set up a schedule, your starting choice is kept in this browser tab until setup is done.
  • No advertising, and no third-party tracking scripts.

Who can see your schedule

  • You, when signed in to the account that owns the schedule.
  • People you invite by name, only after they sign in with the invited email address, and only the adults, dates, and details you chose, until access ends or you revoke it. They can read, never edit, and they never see drafts.
  • The people who run the service, when they need to operate or repair it.

Adding an adult label such as Casey gives that person nothing: a label is not an account. Schedule content is never sold, and it is not used for advertising.

Export, deletion, and retention

In the app, Settings, Account & data is where you download a full backup or a CSV of a date range, sign out, and delete your schedule.

  • Deleting a schedule removes it right away: its routine and every saved version, dated changes, day types, adult labels, saved templates and duties, and everyone's viewer access.
  • Your account stays, so you can set up a new schedule. Files you downloaded and pages you printed are not affected.
  • Para Schedule keeps no separate backup copies of schedules. If the hosting provider keeps database backups, a deleted schedule can remain in them until they expire.
  • How long old versions, sign-in sessions, product events, and host backups are kept has not been decided yet. This section will state each period once it is set, and Settings will say the same.
  • Deleting the account itself is not yet a step in Settings.

Security

  • Every saved schedule needs a signed-in owner, and every read and change is checked on the server.
  • Passwords are hashed, sign-in attempts are rate-limited, and sessions can be ended with Sign out, which matters on shared school devices.
  • Invitation links are not permission on their own; they open only for the invited account.

Still to be decided

  • The hosting provider and where the data is stored.
  • The retention periods listed above.
  • The permitted-data policy for student information.
  • A monitored contact address for privacy questions and requests.