Effective July 30, 2026 · How StormHub collects, uses, protects, and deletes information.
StormHub is a school-community platform for clubs, events, opportunities, and club coursework. When a school authorizes StormHub, the school controls its educational use and determines who may participate. StormHub operates the application and processes information only to provide, secure, support, and improve that school use.
This notice applies to StormHub accounts, school workspaces, support forms, email delivery, and optional Google Drive connections. Logged-out visitors see fictional demonstration content rather than real school records.
StormHub does not request official transcripts, report-card grades, disciplinary records, precise location, private student-to-student messages, advertising profiles, or payment-card information.
Roles never authorize access outside their stated school or club scope. StormHub does not publish a searchable public student directory.
Every new account must verify its email and enter the current private access code for the selected school. A school may accept its official email domain or allow other verified email domains, but the school code is required in either case. Administrators can rotate a compromised code without affecting existing accounts. Staff and administrative roles are assigned only by authorized administrators.
The current rollout is limited to high-school communities and people age 13 or older. Signup requires that assurance, and any grade entered must be 9 through 12. StormHub does not use a birth date or publicly expose the assurance.
StormHub uses service providers only to operate the application: Supabase for authentication, database, and private file storage; Vercel for application hosting and scheduled retention; Resend for enabled email delivery; hCaptcha for abuse prevention; and Google when a user chooses Google sign-in, connects Drive, or sends a direct email to a Google-hosted support mailbox. hCaptcha and hosting providers may process network, browser, device, and request information needed to secure and deliver their services.
Information may also be disclosed when directed by the authorizing school, required by law or valid legal process, or necessary to protect users and the service. StormHub does not sell or rent student information and does not disclose it for behavioral or targeted advertising.
Drive is optional. StormHub requests the limited drive.file permission, which covers files selected or created through StormHub rather than a user's entire Drive. Tokens are encrypted at rest and removed when Drive is disconnected or the account is deleted. Google may retain files in the user's Drive until the user or school deletes them there. External links are governed by the destination service.
External AI processing is disabled for the pilot. StormHub does not send student prompts, school records, submissions, or account information to an AI provider. Any future AI feature requires separate school approval and an updated notice before it is enabled.
The following pilot defaults are enforced for transient operational information. School record requirements, a security investigation, or a valid legal hold may require limited information to be preserved longer. Aggregate statistics that no longer identify a person may be retained.
| Information | Period | What happens |
|---|---|---|
| Active account and profile | While the person is enrolled, employed, or otherwise authorized by the school | Deleted on an approved account request or school instruction, subject to required school records. |
| Policy acceptance and age-eligibility assurance | While the account remains active | Stored with the accepted policy versions and deleted with the authentication account. A birth date is not collected. |
| Google Drive connection credentials | Until the user disconnects Drive or the account is deleted | Encrypted tokens are deleted. Files already created in Google Drive remain under the user's or school's Google controls. |
| Club memberships, RSVPs, attendance, coursework, grades, and submissions | While needed for the school activity and its approved record schedule | Account deletion removes or detaches private user content where permitted; school-authored records may remain without the deleted identity. |
| Signup and abuse-prevention attempt hashes | 30 days | Automatically deleted. Raw IP addresses and signup emails are not stored in these attempt tables. |
| Email delivery and weekly-digest records | 90 days | Automatically deleted, including stored email bodies and delivery errors. |
| In-app notifications | 12 months | Automatically deleted. |
| Resolved contact and support messages | 12 months after resolution | Automatically deleted. |
| Completed or rejected deletion-request records | 12 months after review | Automatically deleted. |
| Identifiable product and participation analytics | 13 months | Automatically deleted. Aggregate counts that no longer identify a person may be retained. |
| Administrative audit and platform support-access records | 24 months | Automatically deleted unless a security investigation or legal hold requires temporary preservation. |
| Account-deletion execution records | 24 months | A pseudonymous execution identifier and outcome are retained for deletion verification, then automatically deleted unless a legal hold applies. |
A daily automated task removes expired operational records. Deactivated accounts and school-authored educational records are reviewed before permanent deletion so the system does not destroy information the school is required to preserve. A recorded active legal hold pauses automated deletion; tenant deletion cannot be scheduled or marked complete while a matching hold remains active.
StormHub is intended for school-authorized educational and extracurricular use. The present pilot and production configuration does not permit accounts for children under 13. A future elementary or middle-school deployment that may include a child under 13 must remain disabled until StormHub and the authorizing school establish an age-appropriate notice, school authorization and any required parental-consent process. StormHub uses student information only for the school purpose described here and not for an unrelated commercial purpose.
Protections include verified email, school access codes, scoped roles, row-level database security, private file storage, short-lived download links, encrypted Drive tokens, request throttling, CAPTCHA, protected service credentials, administrative audit records, automatic retention, and short-lived upload authorizations bound to an exact user, assignment, path, type, and size. File-type and signature checks reduce accidental or disguised unsupported uploads, but they are not malware scanning. No online service can promise absolute security. Suspected unauthorized access should be reported immediately so StormHub and the affected school can investigate and provide any required notice.
Contact stormhubsupport@gmail.com or use the contact form. For school-record questions, also contact the applicable school administrator.
Contact-form details are stored in StormHub for authorized review. The support mailbox is notified that a request exists but is not sent the student's name, reply address, school, or message body. A person who instead sends a direct email chooses to send that email's address, subject, and body through the configured mailbox provider.
Material changes will be posted on this page with a new effective date. When a change meaningfully affects school-controlled student information, StormHub will seek school approval before applying it to that school's use.