Privacy policy
What's in here
1. What we collect
In short: your sign-in details, your profile, your practice activity, and — if you're a parent using the SEA Family Hub — your child's first name or nickname and practice results, kept under your account.
The site at kerwinspringer.com is operated by Student Hub Ltd, a company incorporated in the Republic of Trinidad and Tobago ("we", "us", "our"). Kerwin Springer is the brand ambassador and content creator; Student Hub Ltd is the legal operator and the entity responsible for your data. Here is everything we collect, in one place:
Sign-in and account
- If you sign in with Google: we receive your name, email address, and profile picture from Google. No password is created or stored with us.
- If you sign up with email and password: your email address and your password stored as a salted hash — we never see or store your plain password.
- A record of when you accepted our legal terms and which version.
Your profile
- Username, display name, full name (optional), date of birth, gender (M/F), country, and an optional short bio and avatar.
Practice and tool activity
- When you practise while signed in: subject, questions answered, correct/wrong/skipped totals, XP, streaks, and session times.
- Tool-usage events — which study tool you opened and when — which power the live community feed and help us see which tools are worth improving.
Children's records (through a parent's account)
- If you add a child in the SEA Family Hub: the child's first name or nickname, and the child's practice results and readiness estimates. These are stored under your (the parent's) account — the child has no account of their own. See Children & parental supervision.
Schools
- The school you claim as yours, and your rating of that school (shown only in aggregate — see What's public).
- School suggestions you submit, which are visible only to our admin team and are never published as submitted.
Student Hub membership
- If you link your paid Student Hub membership from mystudenthub.online: your membership tier, status, and expiry date, so we can show your Hub badge here. Linking is optional and flows in both directions between the two services.
Messages
- Direct messages you send through the site inbox (text only). DMs are logged and retained so moderators can review reported conversations.
- Anything you send us by email or WhatsApp, kept as long as needed to help you.
Preferences and technical data
- Your marketing preference (off by default — see Marketing) and your cookie-consent choice.
- Standard technical information received automatically when you visit: IP address, device and browser type, language, time zone, and pages visited.
Stored on your device (localStorage)
- A small cache of your username, display name, and avatar so the navigation bar loads instantly.
- Your personal bests in some study tools, guest XP if you play signed out, and your cookie-consent choice (
ks_cookie_consent_v1).
We do not collect credit card numbers on this site, financial account information, biometric data, precise location, or voice or video recordings.
2. What's public
In short: your username, avatar, and study wins are part of the public community feel. School ratings are only ever shown as averages — never with your name on them.
This is a community study site, and the live community surfaces are a core part of how it works. When you use the site while signed in, the following are visible to other visitors:
- Username, display name, and avatar — on the live Ticker, the live feed, leaderboards, and your public profile page.
- XP, tier, and leaderboard position, plus positive activity such as sessions finished, perfect runs, and tier promotions — with your country flag if you provided one.
- Your public profile page: activity heatmap, tier, favourite subjects, bio, and your Student Hub badge if you linked a membership.
The Ticker shows positives only — how many you got right, never how many you missed. We never publish your email address, date of birth, full name, direct messages, or raw answers.
School ratings are shown only in aggregate. Other users see a school's average score — never who rated it or what any individual said.
Public display of signed-in activity is part of the core service and has no per-account opt-out. If you'd prefer your activity not to appear, you can use the site signed out (sessions then aren't tied to any account), or delete your account at any time, which removes your name from these surfaces.
3. Children & parental supervision
In short: children under 13 use the site through their parent's account, with the parent in charge. Children are never publicly identified — the community feed says "the camp of parent's handle", never a child's name. No ads, no selling data, no profiling of children.
We built the primary-school side of this site — including the SEA Family Hub — around parental supervision, and we're proud of that model:
- Parents hold the account. Children under thirteen never open their own account. A parent or guardian opens and holds the account, adds their child inside the Family Hub, and supervises the child's use of the primary-school tools. Adding a child is the parent's decision and the parent's action — the child's record lives under the parent's account and stays under the parent's control.
- What we store about a child is minimal: a first name or nickname (so the dashboard makes sense to the family), practice results, and readiness estimates. We do not collect a child's email, photo, or contact details.
- Children are never publicly identified. When a child's practice appears on the live Ticker, the child is shown anonymously — for example, "a quiet grinder from the camp of parent's handle". The attribution is always to the parent's public account handle, never the child's name. No child's name or identifying information appears on any public surface.
- Analytics on children's pages is aggregate visitor counting only — like a view count on a video — and runs through the same consent banner as the rest of the site (see Cookies & analytics). We show no advertising, we never sell data, and we do no behavioural profiling of children.
- Parents stay in control. You can remove a child's record at any time from the Family Hub, or wipe everything by deleting your account (see Your rights), or ask us and we'll do it for you.
Users aged thirteen to seventeen may hold their own account; they should have a parent's or guardian's permission, and we encourage parents to read this Policy with them. A parent or guardian who believes a minor has provided us information without appropriate permission can contact us to have it reviewed, corrected, or deleted.
5. Where your data lives
In short: account data is stored with Supabase in the United States; pages are delivered through Cloudflare's global network.
Your account data, profile, practice history, and children's records are stored with Supabase on servers in the United States. The site's pages are hosted on GitHub Pages and delivered through Cloudflare's global edge network, so page requests may be handled at locations near you.
This means your information is processed outside Trinidad and Tobago and outside most CARICOM member states, in jurisdictions whose data-protection laws differ from those at home. We choose reputable providers with strong security practices and contractual data-protection commitments, but you should be aware of where the data physically sits.
7. Marketing
In short: marketing email is opt-in only and off by default. Unsubscribe any time.
We send marketing emails — new tools, content drops, exam-season tips — only if you opted in. The toggle is on the Settings page and is off by default. You can opt out at any time with the toggle, the unsubscribe link in any marketing email, or by contacting us. We never share your email address with third parties for their marketing.
Service messages — email confirmations, password resets, security notices, and on-site announcements and inbox messages about the service itself — are not marketing and continue while your account is active.
8. Your rights
In short: see it, fix it, export it, delete it. Deletion is self-serve in Settings — immediate and irreversible.
- Access. You can see most of your data directly on your Profile and Settings pages. For a full copy, just ask (details below).
- Correction. Update your display name, country, bio, and other profile fields yourself on the Profile and Settings pages.
- Deletion — self-serve. Delete your account any time from the Settings page. Deletion is immediate and irreversible: it cascades through everything tied to your account — profile, XP and streaks, practice history, children's records, school ratings and claims, messages, and activity events.
- Export. Email us at ceo@kerwinspringer.com and we'll send you a copy of your data. We aim to respond within 30 days.
- Withdraw consent for analytics (Cookie settings) or marketing (Settings toggle) at any time.
- Complain. Contact us first — we take this seriously and will respond. You may also complain to the data-protection authority in your jurisdiction, including the Office of the Information Commissioner in Trinidad and Tobago and, for EU/UK users, your local supervisory authority.
Where the law allows, we may decline requests that are unfounded, excessive, or would harm the rights of others, and we may need to verify your identity before acting on a request.
9. Retention
In short: we keep your data while your account exists. Delete the account and it goes — only nameless aggregate numbers can remain.
We keep your account data for as long as your account is active. When you delete your account, everything tied to it is removed from the live database immediately, as described above.
Two things can persist after deletion: aggregate statistics that no longer identify anyone (for example, a school's average rating or a tool's total play count), and routine server and security logs, which rotate automatically. Moderation records connected to safety reports may be retained where the law requires or where needed to protect users.
10. Security
In short: row-level security on the database, bot checks on sign-in, and no plaintext passwords, ever.
We protect your information with, among other measures: row-level security policies on the database (each account can only reach its own rows), encryption in transit, Cloudflare Turnstile bot protection on sign-in, salted password hashing (we never store plaintext passwords), restricted admin access, and reputable infrastructure providers.
No internet service can promise absolute security, so please do your part: use a strong unique password (or Google sign-in), sign out on shared devices, and tell us promptly if you suspect unauthorised use of your account.
11. If there's a breach
If a personal data breach occurs that is likely to put affected users at risk, we will notify affected users without undue delay, notify the relevant authorities where the law requires it, and act quickly to contain the breach and prevent a recurrence.
12. Changes & version history
When we change this Policy we post the new version here with a new date and version number, and for material changes we give notice through the site — for example a banner or an inbox message. The version in force when you use the site is the one that applies.
Version history
- v2 — 5 July 2026: Split the Terms of Service into a standalone document; documented the full data inventory (Google sign-in data, children's records, school ratings and claims, Student Hub linking, tool events); stated the children's parental-supervision model in full; described deletion and export as they actually work; firmed up the breach-notification commitment.
- v1 — 29 May 2026: First published as a combined "Privacy, Terms & Disclaimer" document.
13. Contact
Questions, requests, or worries about your data — or your child's? Write to us; a human reads these.
We aim to respond to privacy requests within 30 days.