Student data privacy
What Mokxi collects from a student, why, who else handles it, and how a school gets it back or deleted.
Last updated September 27, 2026.
This page is for schools, teachers and parents. It is written from the code that runs Mokxi, and it sits alongside the general privacy notice, which covers everybody else. Mokxi is run by Mokxi LLC of Colorado Springs, Colorado. We sign school data privacy agreements, including the Student Data Privacy Consortium's National Data Privacy Agreement and the state versions of it: see section 10.
1. The short version
- The simulator, the CPU cores and the compiler run in the browser. A student’s circuit is never uploaded to be run.
- A student can use the editor and the lessons with no account at all. An account is only needed to save work, join a class and submit work.
- We collect only what the class needs, and use it only to provide Mokxi to the school. Student data is never sold, never used for advertising, and never used to build a profile of a student for any other purpose.
- No analytics or advertising tag loads on the class pages, on the sign-up that leads into a class, or on any page for an account that is in a class as a student.
- A student in a class has no invite link, is never shown an invite offer, and neither earns nor gives invite rewards. Joining a class as a student deletes any record of an invite the account came in on.
- Our own activity record keeps only account and class actions for a student in a class, such as signing in or handing in work. How a student uses the editor is not recorded unless the teacher turns on usage stats for the class, which is off by default.
- When a teacher closes a class, its roster and submissions are deleted right away. A school can have its students’ data exported or deleted by asking us.
2. What we collect from a student
| What | Exactly | Why |
|---|---|---|
| Sign-in | Either the email address and a salted hash of a password (never the password), or the account id Google or GitHub gives us when the student signs in with it. | To sign the student in. |
| Name, email address and picture | As the sign-in provider gives them, or as the student types them. The picture is a link to the one on their Google or GitHub account. | So the teacher recognizes the student on the roster. |
| Projects | The circuits and code the student saves, their saved versions, and the projects they heart. | The student’s own work, kept so they can come back to it. |
| Class membership | Which classes the student joined, and when. | To run the class. |
| Account activity | A dated list of account and class actions only: the account was made, signed in or out, confirmed its email, turned two-factor on or off, joined a class, handed in work, or reached a plan limit. Each entry is the account id, the action, the time and at most a short label such as the sign-in method. Nothing about how the student uses the editor is recorded unless the teacher turns on usage stats for the class, and never code, circuits, messages, IP addresses or email addresses. | To keep the account secure and to help the school when something goes wrong. Deleted with the account, and after 13 months. |
| Submissions | The project submitted, the lesson progress at the moment of submitting, the results of any automatic checks the teacher set, and the teacher’s note back. | So the teacher can see and grade the work. |
| Learning progress | Lessons done, points, level, streak, daily quests and badges, and a record of what earned each point (a short name for the action, such as a board run for the first time, and the day). A student in a class never appears on the public leaderboard, even if they check the box, and cannot join a weekly league. The weekly board, which only signed-in learners who opted in can see, shows a first name or handle only if the student opts in. | To show the student, and their teacher, how far they have got. |
| Optional profile | A handle, a one-line bio and links, only if the student fills them in. Showing progress publicly is off until the student turns it on. | A public page, if the student wants one. |
| Ask keys (optional) | An API key from an AI provider, only if the student chooses to save one for Ask. Kept encrypted; no page shows it again, only its last four characters, to the student. Teachers and classmates never see it. | So Ask can pass the student’s questions to the provider the student picked. |
| Support messages | What the student writes to us through the help panel, the email address they give, and our replies. | To answer them. |
| Country signed up from | The country (and, in the US, the state) the student’s connection came from when the account was made, as Cloudflare reports it. Never the IP address or city. | To see where Mokxi is used. |
| Technical records | Cloudflare’s request logs (connection address, page, browser), kept a short time, and two necessary cookies: the signed session and the page to return to after sign-in. | To keep the service up and secure. |
That is the whole list. We do not ask for or keep a date of birth, gender, ethnicity, home address, phone number, school ID number, grades from the school’s own systems, location finer than the country and state above, photos, audio or video. A student who signs up through a class join code is not offered our newsletter.
3. Who can see it
- The teacher of a class sees its roster (names, email addresses and when each student joined), everything submitted to it, and can open, but never change, a project owned by a student in the class.
- Classmates see each other’s names on the class page, never each other’s email addresses or submissions.
- In a live collaboration room, the people in the room see each other’s names or handles and each other’s edits.
- A project the student makes public can be seen by anyone, with their handle or name on it. Every project starts private.
- Mokxi staff see account data only to support the school or keep the service running, and only the owner and named staff have that access.
4. What we never do with it
- Sell it, rent it or trade it.
- Use it for advertising, or let anyone else use it for advertising. No analytics or ad tag on our marketing pages (Google Analytics, Google Tag Manager, and the Google Ads, Meta, Pinterest or LinkedIn tag of any place we advertise) is ever loaded for a student in a class, whatever they click.
- Build a profile of a student for anything other than running Mokxi for their school.
- Put a student on our mailing list. The newsletter is not offered on the sign-up that leads into a class, and nothing is ever sent to an address that has not confirmed it wanted it.
- Use it for anything the school has not asked for, except where the law requires it.
5. Who handles it for us
These companies process student data so that Mokxi can work. Each is bound by a contract with us that limits its use to running our service and does not let it sell the data. We tell schools with a signed agreement before we add one.
| Company | What it does | What it sees |
|---|---|---|
| Cloudflare, Inc. | Hosts the site, the Worker that answers every request, the database, live collaboration rooms and the bot check on email sign-up. | Everything in the table above. |
| Resend | Sends our email: sign-in links, address verification and support replies. | The student’s email address and the message. |
| Google LLC | Only when the student signs in with Google, usually their school account. | Google tells us the account id, name, email address and picture. |
| GitHub, Inc. | Only when the student signs in with GitHub. | GitHub tells us the account id, name, email address and picture. |
Stripe handles card payments for a teacher or a school that pays by card. It sees the payer’s details, never a student’s. Our marketing analytics and ad measurement (Google Analytics, and the Google Ads, Meta, Pinterest or LinkedIn tag of any place we advertise) are not processors of student data: they are never loaded for a student in a class.
Ask is optional and runs on the student’s own key from an AI provider they choose. When a signed-in student asks a question with a saved key, the question and the project text with it pass through our Worker to that provider and are not kept or logged by us. The provider handles them under the student’s own account with it, so a school that does not want students using outside AI providers should say so in class; Ask shows the exact text sent before anything leaves.
6. How long we keep it
- A student’s own account and projects stay until the account is closed, by the student from their account page or at the school’s request.
- When a teacher closes a class, the class, its roster, its assignments and every submission, note and check result are deleted at once. The students keep their own projects in their own accounts.
- When a student leaves a class, or the teacher removes them, their membership and their submissions to that class are deleted at once.
- When an account is closed, its profile, projects, learning progress, class memberships, submissions and any saved Ask keys are deleted at once, and the copies in our backups are gone within 30 days.
- A live collaboration room keeps its own working copy of the circuit, a short log of recent edits and the raised hands with Cloudflare. That copy is deleted automatically when the project is deleted or its owner’s account is closed, including on a school’s deletion request.
- A support conversation is kept for two years from its last message. Request logs are kept a short time by Cloudflare.
- Each entry in the account activity record is deleted after 13 months, and all of it when the account is closed.
- Where a signed agreement sets a different schedule, the agreement wins.
7. Children under 13 (COPPA)
A child under 13 may use a Mokxi account only with consent. Through school, the school gives that consent on the parents’ behalf, for the school’s educational purpose and no other, under its Student Data Privacy Agreement with us or, until one is signed, under our terms and this page. The teacher who sets up the class acts for the school in doing so. Outside school, a parent or guardian gives it by writing to us from their own email address, and we confirm it with them before the account is used.
A parent can ask to see what we hold about their child, have it corrected or deleted, or stop any further collection. For a child using Mokxi through school, we pass that request to the school, which decides, unless the school has asked us to answer parents directly. If we learn that a child under 13 has an account without consent, we delete it.
8. Mokxi as a school official (FERPA)
When a school uses Mokxi, we act as a school official with a legitimate educational interest, under the direct control of the school for the use and upkeep of student records. The student data stays the school’s. We use it only to provide Mokxi to the school, we do not disclose it except to the processors above or where the law compels us, and if we are compelled we tell the school first unless the order forbids it. A parent’s or eligible student’s request to review or correct education records goes to the school, and we help the school answer it.
9. Security
What is actually in place today:
- Every connection is encrypted (HTTPS).
- Passwords are salted and hashed with PBKDF2-SHA256 and never stored or logged in the clear. A student who signs in with their school Google account has no Mokxi password at all.
- Sessions are signed cookies that scripts cannot read, sent only over HTTPS, and they expire after 30 days.
- Sign-in and verification links are single use, expire on their own, and are stored only as hashes.
- Any account can turn on two-factor sign-in with an authenticator app.
- Every rule about who may see what is checked on our server, not in the browser: a class you are not in does not exist to you, a student sees only their own submissions, and a teacher can read but not change a student’s project.
- Changes are only accepted from mokxi.com itself, our pages refuse to be framed by other sites, and a bot check and rate limits guard sign-up and sign-in.
- Card numbers never reach our systems, and our keys live in Cloudflare’s secret store, not in our code.
If student data is ever exposed, we tell the affected schools without undue delay, and within 72 hours of confirming it, with what happened, what data was involved and what we are doing about it, so the school can tell families.
10. Agreements, export and deletion
We sign school and district data privacy agreements, including the SDPC National Data Privacy Agreement and state agreements based on it. To start one, or to ask for any of the below, email privacy@mokxi.com with the subject “Student data request” from a school address, or use the support page. A person answers, and we act on a request within 30 days.
- Export. A teacher can download a class roster as a spreadsheet from the class page at any time, and a student can export any project as a file from the editor. For everything we hold on a school’s students, we send the school a file of it.
- Deletion. A teacher can remove a student from a class or close the class, which deletes the class data at once. For a full deletion, send us the students’ email addresses (or the class) and we delete their accounts and everything in them, then confirm in writing.
- Your IT team. The domains to allow, the Google Workspace setting for students under 18, and an email to forward are on the IT setup page.
11. Changes
When this page changes, the date at the top changes. We tell schools with a signed agreement before a change that affects how student data is used, and we do not start using student data in a new way without the school’s agreement.