MediaLab.org is a set of creation tools for students, built and run by one teacher. This page says what we store, who can see it, and how to delete it.
The short version
- No ads, ever. We never sell data or share it with advertisers or data brokers.
- No tracking. No analytics, no tracking cookies or scripts, no location tracking, and nothing that follows you to other sites.
- No watching. We do not record what students click or how long they spend. What we keep is listed below, and the list is short.
- Students at a school sign in with a seat number and two pictures. We never ask a student for a name, email, birthday, or photo.
- A student's work can be seen by their teacher, by families through a link the teacher shares, and by the person who runs MediaLab.org. Nobody else.
- No profiles of students, and nobody's work is ever used for marketing or to train AI.
- Everything can be deleted: by the teacher, by you, or by asking us.
Who we are
MediaLab.org is owned and run by Zachary Brewer, a teacher in New York City. When this page says "we," it means him. There is more on the About page, and the Contact page says how to reach him.
Students using a class seat
Schools use MediaLab.org through a teacher account. The teacher creates classes, and each class has up to forty numbered seats. A student signs in with the school's six-digit code, their class, their seat number, and two pictures they pick as a password. Students have no accounts, no usernames, and no email addresses. That is everything a student ever enters about themselves.
For each seat we store:
- The seat number and the two pictures that work as its password.
- The work itself: drawings, animations, stop motion, videos and voice recordings, coding projects, vector drawings, 3D designs, typing progress, media analysis answers, and pictures saved from the Image Library.
- Which projects were turned in to the teacher.
- When the seat was used, and what kind of device it was on (an iPad, a Chromebook, a laptop).
We never collect a student's name, email address, birthday, home address, photo, or location, and we never collect anything about a student from outside MediaLab.org.
Camera and microphone. Stop motion, video, and the voice recorders use the camera and microphone only while a student is taking a picture or recording, and only after a tap. Nothing is ever captured in the background. A student's own face or voice can end up in their project, and the teacher decides whether that project is shared with families.
Who can see a student's work. The teacher. Families, through a class link the teacher creates, which shows seat numbers rather than names, is hidden from search engines, and can be replaced by the teacher at any time. And Zachary Brewer, who runs the site, when he is helping a school or checking that the site is working. Nobody else. Work is never public, never shared between schools, and never shown to other students.
Students under 13. Schools give permission for students to use MediaLab.org in class, the same way they do for other classroom tools. We use what students make only to run the tool for the school, never for anything else. Parents can ask the teacher to see or delete their child's work at any time, or ask us through the Contact page.
For schools and districts
Everything above is what a school is agreeing to: a seat number and the work, with no names, no ads, no sharing, and no use beyond the school's own purposes. The data is stored on Google Cloud in the United States, and a school can stop using MediaLab.org at any time and have everything deleted. For the laws schools ask about:
- COPPA (the U.S. children's online privacy law). Schools may give permission for classroom tools that collect only what the tool needs and use it only for the school. MediaLab.org is built to fit that.
- FERPA. The school stays in control of its students' records. We act only on the school's instructions and never pass student information to anyone else.
- New York Education Law 2-d. We will sign a district's data privacy agreement and Parents' Bill of Rights supplement. What it requires, encryption, no sale or marketing use, a breach notice within seven days, and deletion when the agreement ends, is already how the site works.
- California SOPIPA and similar state laws. The same promises: no targeted ads, no profiling, no sale of student information, and use only for school purposes.
To ask a question or send an agreement, use the Contact page. We answer ourselves, and we sign agreements that match how the site actually works.
Teacher and personal accounts
Adults create accounts: teachers for their school, and parents, teachers, or students 13 and older for use at home. For an account we store:
- Your email address and a password. Sign-in is handled by Google's Firebase, and we never see your password. If you sign in with Google, we receive the name and email address on your Google account.
- For teachers: your school's name and country, your class names and room numbers, a grade band for each class, and the class passwords.
- Optional answers, if you choose to give them: your role, roughly how many students you have, and how you heard about MediaLab.org.
- A few details from signup, such as the page you came from and your time zone.
- Basic usage: when you sign in, how many projects you have, and how much storage they use.
- For personal accounts, your projects.
- Messages you send through Send Feedback, with your email address so we can reply and the kind of device you were on.
Services we rely on
MediaLab.org runs on Google Cloud (Firebase), in data centers in the United States. It hosts the site and holds the database, the files, and sign-in. Two other services touch small, specific pieces of data:
- Pixabay provides the Image Library's search results. Search words go to Pixabay through our server, so Pixabay never learns who searched.
- Google's text-to-speech service turns a typed voice line into speech in the video editor. Only the typed words are sent.
That is the whole list. No advertising or analytics company receives anything.
Keeping and deleting
- Student work stays until the teacher deletes the project, the class, or the school account. Deleting the school account removes every class, every student's work, and the account itself.
- A personal account can be deleted from its Account tab, which removes all of its projects.
- Families ask the teacher to delete a child's work. A school can also stop using MediaLab.org and ask us, through the Contact page, to delete everything.
- Troubleshooting logs and sign-in protection records expire within a day.
- After an account is deleted, we keep a short internal note of its email address and the date it was deleted.
Keeping it safe
Everything travels over an encrypted connection and is encrypted where it is stored. Each school's data is kept separate, so one school can never see another's. Only Zachary Brewer has administrative access. Wrong-password attempts are limited, and the server slows down anyone guessing codes. If we ever learn of a breach that affects your data, we will tell you and the school within seven days of confirming it.
Changes to this policy
If this policy changes, we will update the date at the top. If a change matters, for example a new service that would handle student data, teachers will hear about it by email before it takes effect.
Questions
Use the Contact page. A person reads every message.
