1. Overview
Nexus Connect powers real-time polling, quizzes, and live games to build school spirit. We built the platform with privacy in mind from the ground up, and this policy explains exactly what data we collect, how we use it, and how long we keep it.
2. Student Participant Data
By default, students don't need to give us any personal information to play. We don't require or collect real names, email addresses, or phone numbers from students to participate in games, polls, or assemblies.
When a student joins a session, they get a temporary, randomly generated username tied only to that event. What happens to that data afterward is entirely up to your school's administrator:
- If the session isn't saved: The moment an administrator ends a session without saving it, all participant data — usernames, leaderboards, and scores — is permanently deleted from our systems.
- If the session is saved: Administrators can choose to save event results. If saved, the randomized usernames, scores, and response times are stored securely in our database. This lets administrators review results, see leaderboard winners, and export data as a CSV from their dashboard. Saved data stays stored until the administrator deletes it.
We never use this data for advertising, public tracking, or profiling.
Optional school email sign-in. Some schools turn on an optional "Email Sign-In" feature — it's off by default, and we only enable it for a school at that school's request. When it's on, students sign in with their school-issued Google or Microsoft account instead of getting an anonymous username. In that case, we receive and store the student's verified school email address, their display name from that sign-in provider, and a stable (non-reversible) account identifier, scoped only to that school. We use this solely to (a) confirm the student belongs to that school's email domain and (b) automatically detect their grade level from their school email, so they don't have to enter it every time. Depending on how the school configures things, a student's in-game display name may be an auto-generated fun name (the default), their school email, or their sign-in profile name — the school administrator makes that choice, not us. We never use this data for advertising or profiling, and we delete it if the school later turns off Email Sign-In and asks us to remove it.
3. Administrative Media Libraries & Image Storage
Authenticated school administrators can upload and manage images — school logos, mascot photos, community pictures, staff graphics — in a persistent library used by features like Mascot Hunt, Yearbook, and Name Game.
These files are transmitted over encrypted connections and stored in secure cloud storage located in the United States (US West region). Only verified administrators from your school can access your school's media library. We only use these images to run the features your school has enabled — never for our own marketing, public distribution, or to train machine learning models. Uploaded images stay in our system until a school administrator removes them.
4. Third-Party Service Providers
We work with a few trusted external providers to run the platform securely:
- Authentication (Clerk): School administrator accounts and logins are handled by Clerk, Inc. Clerk securely manages passwords and login tokens — we never see or store raw passwords ourselves.
- Billing (Stripe): All payments, subscriptions, and invoicing go through Stripe, Inc. Card numbers and banking details go directly to Stripe — we only see payment status, the last 4 digits of a card, and billing zip codes.
- Student sign-in verification (Google & Microsoft): For schools using the optional Email Sign-In feature (Section 2), student sign-in is verified directly through Google's or Microsoft's own systems. We never see a student's password — only the verified email, display name, and account ID that Google or Microsoft send us after sign-in.
5. Infrastructure, Analytics, & Hosting
Our platform runs on a secure, serverless edge network. All app logic, subdomains, and admin interfaces run on distributed servers located in the United States (US West region). Live session data and system state are stored in encrypted databases.
While student profiles contain zero identifying information, our network automatically logs standard technical data (like request patterns) to keep events running smoothly during high-traffic moments and to prevent abuse.
Our public marketing website uses a privacy-first analytics tool to track general traffic trends. It doesn't use cookies, doesn't collect personal information, and doesn't track users across other websites. These logs exist only to protect the site from bot traffic and denial-of-service attacks, are kept separate from any advertising system, and are automatically cleared on a rotating schedule.
6. Changes to This Privacy Policy
We may update this Privacy Policy as our practices change or to stay current with the law. If we make a significant change, we'll notify registered administrators at the email tied to their Clerk account and update the "Last Updated" date above. Continuing to use Nexus Connect after a change means you accept the updated policy.
7. Contact Us
For questions about this policy or how we handle data, reach out to:
- Email: support@nexusconnect.live
- Website: nexusconnect.live