AllowList Privacy Policy
Last updated: 7/30/2026
Overview
AllowList provides a Chrome extension and backend service that restricts YouTube on school devices to content approved by a student's teachers. This policy explains what information we collect, why we collect it, how we protect it, and the choices available to schools and families.
AllowList is built for use by schools and school districts. We act as a service provider to the school. We process student data only on the school's behalf and under its direction, consistent with FERPA and COPPA.
Information We Collect
- Student names and email addresses. These come from Google Classroom rosters. We use them only to match a student to the classes they are in, so their device shows the content their teachers approved.
- Teacher account information and Google sign in tokens. When a teacher signs in, we store their account information and an access token so we can read their Google Classroom on their behalf and post class materials when they choose to.
- Approved content lists. The videos, playlists, and channels each teacher approves for each of their classes.
- Watch time analytics. We record coarse watch time for approved videos, specifically which approved video was watched, roughly how many seconds it was watched, and which class it belongs to. This is shown to that class's teacher so they can see engagement with the material they assigned. We do not record anything a student watches outside of approved content, and we do not track general browsing.
Information We Do Not Collect
We do not collect general browsing history. We do not use advertising networks, ad trackers, or third party analytics SDKs. We do not build advertising or behavioral profiles of students. We do not sell, rent, or trade personal information.
How We Use Information
We use the information above only to:
- Match students to their classes and deliver the correct approved content
- Let teachers manage approved content for the classes they teach
- Show teachers engagement analytics for their own classes
- Operate, maintain, and secure the service
We do not use student information for any purpose other than providing this service to the school.
How We Use Google User Data
AllowList requests access to your Google Account data through Google APIs only to provide the features described in this policy. Specifically:
- Reading your Google Classroom courses lets a teacher see and manage approved content for each class they teach.
- Reading your Google Classroom rosters and student email addresses lets us match each student to the classes they are enrolled in, so their device shows the correct approved content.
- Posting class materials to Google Classroom is used only when a teacher chooses to share an approved video to a class.
We request read only access wherever possible. AllowList never grades, deletes, or changes existing content in Google Classroom, and only posts material at a teacher's explicit direction.
Limited Use Disclosure
AllowList's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We use Google user data only to provide and improve the features described in this policy. We do not use Google user data for advertising. We do not sell Google user data. We do not transfer Google user data to third parties except as necessary to provide the service, to comply with applicable law, or as part of a merger or acquisition. We do not allow humans to read Google user data unless we have your consent for specific messages, it is necessary for security purposes such as investigating abuse, to comply with applicable law, or the data has been aggregated and anonymized.
How Information Is Stored and Protected
Data is stored in a Supabase Postgres database, and our backend runs on Google Cloud Run. Each district's data is kept separate from every other district's data. Teacher sign in tokens are encrypted where they are stored. Access to the service requires a verified Google sign in, which we check with Google on our servers rather than trusting what a browser reports. Students never see other students' data.
Data Retention and Deletion
Watch time analytics are automatically deleted after approximately 180 days.
Other information is kept only as long as needed to provide the service to the school. When a school stops using AllowList, or at the school's request, we delete that school's data. A school can request deletion at any time by emailing ethan@getallowlist.com.
Who We Share Information With
We do not sell personal information and we do not share it for advertising.
We rely on a small number of service providers to run AllowList: Google, for sign in and Google Classroom data, and Google Cloud and Supabase, for hosting and data storage. These providers are bound to protect the data and may use it only to provide services to us.
We may disclose information if required by law, or to protect the rights, safety, and security of users and the service.
Children's Privacy and COPPA
AllowList is used in schools where students may be under 13. Where required, the school provides consent on behalf of parents for the collection of student information for educational purposes, consistent with COPPA. We collect only what is needed to provide the service and use it only for that purpose.
Student Records and FERPA
We handle student data as a school official with a legitimate educational interest, under the direction and control of the school, consistent with FERPA. Parents and eligible students can exercise rights regarding their information by contacting their school, which can direct requests to us.
Data Processing Agreement
For schools and districts, we enter into a data processing agreement governing how we handle student data, including any state specific requirements. We are able to sign the applicable state agreement, including through the Student Data Privacy Consortium where available.
Changes to This Policy
We may update this policy from time to time. We will let schools know about material changes. Continued use of the service after a change takes effect means the updated policy applies.
Contact
Questions about this policy or our data practices:
Email: ethan@getallowlist.com
AllowList, operated by Ethan Star