Back to home

Privacy and terms

Plain language, current practice. Last updated September 19, 2026. Privacy says what we keep and when it is deleted; Terms says what you and we agree to.

How an activity works

A teacher projects a host screen and students join from their own devices with a short room code and a first name (or nickname). Everything students type or draw goes to the game server, appears where the activity needs it (the projector, classmates' screens, the teacher's console), and is discarded when the activity is over. There is nothing to sign up for and nothing to log into.

What we keep, why, and when it is deleted

WhatWhy we have itWhere it livesWhen it is deleted
Student first names, as typed at join So the teacher and the class can see who said what during the activity Server memory, plus a snapshot that lets a game survive a server restart When the activity ends or the room closes. Any leftover snapshot is swept within 6 hours.
Student answers, drawings, votes, and scores They are the activity Same as above Same as above
Reconnect tokens Let a student rejoin after a wifi drop without losing their place Same as above Same as above
Teacher room PIN Pairs the teacher's private console with the room Same as above Same as above
Activity run counts: activity id, player count, start time Tells us which activities actually get used Database Kept as usage statistics. Contains no names and no student work.
Rooms log: one line per room with the activity (a built-in's name, or the teacher's own name for an activity they made), the room code, the headcount, which step the room reached, whether it ended, how long it ran, whether the students were real or pretend, and a random id the teacher's browser minted for itself Lets the site owner see which rooms ran, how far they got, and how many different teachers hosted one, so problems in a room we were not in can be found and fixed Database, read only by the site owner Kept as usage statistics. Contains no names and no student work. The random id holds nothing about the person; clearing site data in the browser resets it.
Teacher-created activities and recipes Teacher-authored content, so it survives redeploys Database Until the teacher or the site owner deletes them. A structural rule keeps student work out of saved activities: nothing students submit is ever folded into a saved object. Each saved activity also carries a scrambled (hashed) copy of a random key the teacher's browser made for itself, so only that browser, or the site owner, can change or delete it. The key identifies a browser, never a person. Saved activities are not listed publicly: only the browser that saved one (and the site owner) sees it in the yard, and anyone else can open it only with its link, such as a share link the teacher sends.
Site usage events from teacher pages: which page was opened and when it was left, grouped into a visit by a random per-tab id, which door was pressed, how an idea landed on the Create page, where the visit came from (the referring site's name, and the campaign tag when the link was one of ours), the country and region of the connection, plus one line when a room opens, starts, ends, or closes without ending (activity name for built-in activities, "custom" for anything a teacher made, headcount, minutes, which step of how many the room was on, and whether the students were real or pretend) Tells us which parts of Jamyard teachers actually use and how they found it, so we can improve them PostHog (US), an analytics service, reached only through our own server Kept as usage statistics. Contains no names, no student work, and no room codes. Nothing is sent from the student screen or the projector. For events from teacher pages, our server passes the connection's address to PostHog for a country and region lookup and PostHog discards the address after the lookup; room events carry no address at all. A random id minted in the teacher's browser counts repeat visits; it holds nothing about the person. Browsers sending Do Not Track or Global Privacy Control send nothing.
Session recordings of six teacher pages: the home page, the activity library console, the make page, the Create page, the editor, and the guide Watching how teachers move through the pages where they set up an activity shows us where they get stuck PostHog (US). This is the one place a PostHog script runs in a browser. It never runs on the student screen, the projector, the teacher's live console or its report, Try it out, or inside any frame. Kept for the shortest period the service allows. Everything typed is masked in the recording (every text box, the question and field boxes on the make page, the Ask AI conversation, the names on your own shelf), every embedded frame is blocked, and the address of the page is recorded without its query. These pages carry no student content by design: nothing students submit is ever folded into a saved activity. The recording runs under the same random browser id as the usage events. Browsers sending Do Not Track or Global Privacy Control are not recorded.
Site feedback from the feedback widget Suggestions and bug reports from visitors Database Until the site owner deletes it. Anonymous by design: the form has no name or email fields and asks you not to include personal information.
Ideas typed into the Create page: the idea as written (email addresses, phone numbers, and links removed), how it landed (a match, an existing activity, a plan built from steps, or nothing we could build and why), and the name of the activity if the teacher saved it, with the same random browser id as the usage events Shows us what teachers try to make, what is new, and what we could not build yet, so the builder can grow toward it Database, read only by the site owner Until the site owner deletes it. Teacher-typed, never student work. Do not type student names into an idea; if you did, email us and we will delete the entry.

About the AI

Some activities send the class's collected answers to Claude, an AI service by Anthropic, to do one job: summarize, group, compare, or judge them for the next step of the activity. Student submissions may also be scored by OpenAI's automated moderation service, which does one job: catch harmful or unkind messages before the class sees them. Before anything is sent to either service:

Honest limit: if a student types personal information inside an answer, that text is part of the answer. Teachers can hide any submission from the live moderation panel before it is shown to the class or sent to the AI, and drawings always pass a teacher review before anyone sees them.

What stays on your device

Favorites, recently used activities, and the list of activities created on a device are stored in that browser's local storage. They never leave the device and we cannot see them. The exceptions are two random ids (strings of letters and digits, nothing about the person): one that teacher pages send with the usage events described above, and one the projector page sends when it opens a room, so the rooms log can tell one teacher's rooms from another's; clearing site data resets both.

Classroom safety

Security

Connections use TLS. Stored data is encrypted at rest by our database provider (Neon). Production logs contain no student names and no student content. Our hosting provider (Render) may keep standard connection logs, which can include IP addresses, for a short period.


Terms

What you and we agree to when you use Jamyard.

1. Who these terms are for

By opening a room, making an activity, or otherwise using Jamyard, you agree to these terms. You must be an adult. If you use Jamyard with a class, you confirm that your school or district allows you to use classroom tools like this one, and you agree to follow its rules as well as ours. Students do not create accounts and do not accept these terms; the teacher who opens a room is the one who agreed, and the one who decides what happens in it.

2. Your activities

The questions, prompts, and activities you write are yours. You give us permission to store them and run them for you, which is all we need to make the site work. The built-in activities, the prompt banks, and the site's design are ours or their credited sources', and you may run them in your classroom freely. A copy you make of a built-in activity is your copy to edit. Do not upload material you do not have the right to use.

3. What we promise about student information

These promises are written to line up with California Education Code section 49073.1 and the federal student privacy law (FERPA), because that is what schools ask about. They apply whenever a teacher uses Jamyard with students. The table above says exactly what we keep and for how long.

  1. Student records stay the school's. Anything students produce in a room (answers, drawings, votes) remains the property of the student and their school, under the school's control. We hold it only while the activity runs and claim no rights to it.
  2. Students can keep their own work. While a room is open, the teacher can print or save the activity report, which holds everything the class made, and give it to students. Nothing else about student work survives the room, so there is nothing for us to hand over later.
  3. One purpose only. We use student information for exactly one thing: running the activity the teacher opened. Not for marketing, not for building profiles, not for anything else.
  4. Seeing and correcting information. A parent, guardian, or eligible student who wants to review or correct information should ask the teacher, since student work exists only during the activity and only the teacher can see it then. For anything that reaches us, email the address below and we will respond within ten days.
  5. How we protect it. Connections are encrypted (TLS). Stored data is encrypted at rest. Student names never appear in server logs and are never sent to the AI services described above. Teacher controls need a room PIN with a lockout against guessing. The person responsible for security is the site's operator, named below; there is no one else with access.
  6. If something goes wrong. If student information were ever disclosed without authorization, we will notify the affected teacher and their school as soon as we know, and in any case within 72 hours of confirming it, saying what happened, what information was involved, and what we did about it, so the school can notify parents and guardians.
  7. Nothing kept afterward. Student work is deleted when the activity ends, with a six-hour sweep as a backstop. When a teacher or school stops using Jamyard, there is no student data to return or destroy, because none was kept. A teacher's own saved activities are deleted on request.
  8. FERPA. When a teacher uses Jamyard, we act as a school official with a legitimate educational interest, under the school's direct control for the use of student information, and we use it for no other purpose. The teacher's school and we share the job of keeping this true; if your district needs a signed agreement (for California, the student data privacy agreement districts use), email us and we will work through it with you.
  9. No advertising. There is no advertising on Jamyard. Student information is never used to target advertising, here or anywhere else.

4. Rules in the room

We can close a room or remove content that breaks these rules.

5. AI output

The section above says what the AI receives. What it gives back can be wrong or odd. Read it before you show it, and treat it as a first draft that the class and you get to argue with.

6. Availability

Jamyard is provided as it is, without warranties of any kind. We work to keep it available and cannot promise it will always be, or that it will be free of mistakes. We are not responsible for a lesson that did not go as planned because the site was down or an activity behaved unexpectedly. To the extent the law allows, our liability to you is limited to what you paid us.

7. Stopping

You can stop using Jamyard at any time. Email us to have your saved activities deleted. We may stop offering Jamyard, or parts of it, and if we do we will say so on the home page ahead of time.

8. Changes

When this page changes, the date at the top changes, and a meaningful change is announced on the home page for thirty days. Using Jamyard after that means you agree to the new terms.

Who runs Jamyard

Jamyard is operated by Max Cady. For privacy questions or deletion requests, email mccady at gmail dot com. Jamyard is operated in California, United States, and these terms are governed by California law. If your district needs a signed data privacy agreement, email the same address. The project is made with support from assemblycode.org.