Privacy Policy

Last updated: January 1, 2026

BullyAlert ("we," "us," or "our") is committed to protecting the privacy of students, parents, and school staff who use our application. This Privacy Policy explains how we collect, use, and protect information in connection with BullyAlert.

1. Our Core Privacy Commitment

BullyAlert is designed with a zero-identity architecture. We do not collect, store, or process any personally identifiable information (PII) from students. Anonymous reports cannot be traced back to the reporting student — not by school staff, not by us.

2. Information We Collect

From students (anonymous reporters): We collect only the content of the incident report — incident type, location within the school, description, and any attached media. No name, email address, student ID, or device advertising identifier is ever collected or stored.

From school staff: Staff accounts require a name and email address for authentication and notification purposes. This information is used solely to operate the staff dashboard and deliver push notifications.

From parents: Parents who submit reports on behalf of their child may optionally provide contact information. This is never shared with students or third parties.

3. FERPA Compliance

BullyAlert is designed to comply with the Family Educational Rights and Privacy Act (FERPA). We do not collect or maintain education records as defined by FERPA. No student PII is ever transmitted to or stored by BullyAlert systems. **Sentinel Beacon Labs LLC acts solely as a data processor and custodian, adhering to FERPA standards. We will not sell, commercialize, or otherwise monetize student data or school databases.**

4. COPPA Compliance

BullyAlert complies with the Children's Online Privacy Protection Act (COPPA). We do not knowingly collect personal information from children under 13. The anonymous reporting feature requires no account creation and collects no personal information from any user, regardless of age.

5. Data Retention

Incident reports are retained for the duration of the school's active subscription. Schools may request deletion of all incident data at any time by contacting privacy@bullyalert.app.

6. Data Sharing

We do not sell, rent, or share any data with third parties for advertising or marketing purposes. Incident data is accessible only to authorized staff members at the reporting school.

7. Security

We use industry-standard encryption (TLS 1.3) for all data in transit. Data at rest is encrypted using AES-256. Access to production systems is restricted to authorized personnel only.

8. Contact

For privacy-related questions or data deletion requests, contact our Privacy Officer at privacy@bullyalert.app. We respond within 5 business days.

Sentinel Beacon Labs
Capitola, CA