Skip to main content

Privacy

What we collect, who sees it, and what we will never do.

This page is written to be checked, not skimmed. Every statement about the product is one your district's own review can verify — and we expect you to review it with your counsel.

Last updated August 25, 2026

The short version

  • A student check-in records which of five words a student tapped about their morning, an optional topic, and whether they asked to talk to an adult. That is the whole record.
  • Students never type anything. There is no free text, no photo, no camera, no microphone, no location.
  • Teachers never see what a student said — only that a support request exists and who is handling it. This is enforced in the database, not hidden in the interface.
  • Your district owns its records. We never sell student information, never use it for advertising, and never use it to train AI models.
  • Families can decline through the school, and a parent can receive their child's complete record through the district.

1. Who this policy covers

WellSeen is used by school districts. Three groups of people appear in it, and this policy treats them separately: students, whose records exist because their district adopted WellSeen; district staff, who sign in to respond to students; and visitors to this website. Districts are our customers — student information is collected for the district, under the district’s direction, and governed by a written agreement with the district in addition to this policy. Where that agreement says more than this page, the agreement wins.

2. What we collect about a student

The district provides the roster: first name, last name, grade level, classroom, and optionally the district’s own student ID number. Using the check-in kiosk then creates:

  • Check-ins. Which of five options the student tapped about how they are arriving (from “Great” to “Having a hard day”), an optional topic tapped from a fixed list (school, friends, home, tired, could use breakfast, worried, don’t feel well, something else), whether they asked for an adult, and when. Skipping the topic is recorded as exactly that — a skip, not a gap.
  • Support records. When a student asks for an adult: who took the request, when a conversation happened, follow-up dates, and how it was resolved.
  • Access records. An audit trail of which staff member did what, so the district can answer “who saw this?” The audit trail records who acted — never what the student said.

Students have no accounts, no passwords, and no email addresses in WellSeen. They tap their first name and last initial on a classroom roster, answer up to three questions by tapping, and are done.

3. What we never collect

These are not settings a district can enable. The fields do not exist:

  • Date of birth
  • Race, ethnicity, gender, or any demographic category
  • Disability, IEP, or 504 status
  • Free text written by a student
  • Photographs or any biometric data
  • Location or device tracking
  • Discipline or behaviour records
  • Any diagnosis, score, risk rating, or prediction

WellSeen also does not do the things a worried parent might imagine a product like this doing: no facial recognition, no emotion detection, no social-media monitoring, no comparing a student to their classmates, and no automated decisions about any student. A support request goes to a person. Every consequential decision is made by a human at the school.

4. Who can see what

  • Counseling and support staff at the student’s school see check-ins and support requests — they are the people the product exists to reach.
  • Teachers see that one of their students asked for an adult and who is handling it — never the student’s answers. This boundary is enforced by the database itself: a teacher’s account receives zero check-in records, and our test suite fails if that ever changes.
  • School and district administrators see what support staff see, plus school-level response reporting that contains no individual student information.
  • Other districts see nothing. Every record belongs to one district, isolated at the database layer.
  • WellSeen’s own operator role — the account we use to set districts up — can read no student data at all. Our tests assert it holds zero student rows.

One honest caveat, stated here because most vendors leave it out: like any hosted service, infrastructure-level access to the database exists at our providers and, in break-glass circumstances, for us. What limits that access is the design above — there is no free text, no demographic data, and no clinical field to see. The most such access could reveal is which of five words a child tapped on a given day. Our trust page describes this in full.

5. The half-finished check-in

While a student is mid-check-in, the in-progress state lives on the server for at most 120 seconds (240 on kiosks configured for extended timing). It is readable by nobody — not staff, not administrators, not us — and when it expires it is deleted, not archived. Nothing a student does at the kiosk is ever stored in the browser, so there is nothing on a shared classroom tablet for the next student to find.

6. Where the data lives

WellSeen runs in the United States. The application is hosted on Vercel (Washington, D.C. region) and the database on Supabase (AWS us-east-1, Northern Virginia). Connections use TLS in transit and the database is encrypted at rest by the hosting provider. Those two providers are our only subprocessors — this list is complete as of the date above, and if it changes, this page changes with written notice to districts. We run no advertising trackers and no third-party analytics on any page, and this site’s fonts are served from our own servers, so pages send nothing to anyone else.

7. How long records are kept

Retention of student records is the district’s decision, not ours — a vendor choosing how long a school keeps its students’ wellbeing records would be making a governance decision that belongs to the district. We impose no expiry of our own, and we commit to the other direction: when a district leaves, its data is deleted on a written schedule agreed before the pilot starts, with written confirmation when it is done.

8. Families

  • Notice. Before check-in starts, families are told, in a letter from their own district — including how to decline.
  • Declining. A family that declines is honoured in the software, not just on paper: the student’s name does not appear on the check-in screen, and the system refuses to record a check-in for them even if something tries. The student looks like any other member of the class — never singled out, never marked.
  • Seeing the record. A parent or guardian can request their child’s complete WellSeen record through the district. The export contains everything we hold about that student, in plain language — and it also lists what we do not collect, because the boundaries are part of an honest answer.

9. Children's online privacy

WellSeen is used by students only at school, on school-managed devices, under their district’s authorization and supervision. We collect no information directly from children beyond the taps described in section 2, create no child accounts, and never use student information for any commercial purpose beyond providing the service to the district. This website itself is written for the adults who run schools, not for children.

10. District staff

For staff, we hold what sign-in requires: name, work email, role, school assignment, and the audit trail of actions taken in WellSeen. Staff accounts support multi-factor authentication, and access ends when the district deactivates the account.

11. Website visitors

Browsing this site requires no account and creates no marketing profile. Standard web server logs (IP address, page requested, timestamp) exist at our hosting provider for security and operations. If you email us, we have your email — we use it to reply, and for nothing else.

If you use the request-information form, we receive exactly what you typed: your name, work email, role, district, state, and — only if you choose to give them — an enrollment range and a message. It is delivered to us as an email, is never written to the product database, and is used for one purpose: replying to you. It is not added to a mailing list, not shared, and not sold. Ask us to delete it and we will.

12. What this page is, and is not

This page states, accurately, what WellSeen collects and does. It does not declare WellSeen “compliant” with FERPA, COPPA, PPRA, or any state student-privacy law — no honest vendor self-certifies, and whether a product meets your obligations is a judgment for your district and its counsel. What we owe you is a product whose actual behaviour matches every sentence above, an agreement that puts it in writing, and straight answers to your review. Ask us anything.

13. Changes and contact

If this policy changes materially, districts receive written notice before the change takes effect — and because what a check-in asks is part of what families were told, changes to the questions themselves are treated with the same weight. Questions, requests, or concerns: hello@wellseenschools.com.