AllowList Privacy Policy

Last updated: 7/30/2026

Overview

AllowList provides a Chrome extension and backend service that restricts YouTube on school devices to content approved by a student's teachers. This policy explains what information we collect, why we collect it, how we protect it, and the choices available to schools and families.

AllowList is built for use by schools and school districts. We act as a service provider to the school. We process student data only on the school's behalf and under its direction, consistent with FERPA and COPPA.

Information We Collect

Information We Do Not Collect

We do not collect general browsing history. We do not use advertising networks, ad trackers, or third party analytics SDKs. We do not build advertising or behavioral profiles of students. We do not sell, rent, or trade personal information.

How We Use Information

We use the information above only to:

We do not use student information for any purpose other than providing this service to the school.

How We Use Google User Data

AllowList requests access to your Google Account data through Google APIs only to provide the features described in this policy. Specifically:

We request read only access wherever possible. AllowList never grades, deletes, or changes existing content in Google Classroom, and only posts material at a teacher's explicit direction.

Limited Use Disclosure

AllowList's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

We use Google user data only to provide and improve the features described in this policy. We do not use Google user data for advertising. We do not sell Google user data. We do not transfer Google user data to third parties except as necessary to provide the service, to comply with applicable law, or as part of a merger or acquisition. We do not allow humans to read Google user data unless we have your consent for specific messages, it is necessary for security purposes such as investigating abuse, to comply with applicable law, or the data has been aggregated and anonymized.

How Information Is Stored and Protected

Data is stored in a Supabase Postgres database, and our backend runs on Google Cloud Run. Each district's data is kept separate from every other district's data. Teacher sign in tokens are encrypted where they are stored. Access to the service requires a verified Google sign in, which we check with Google on our servers rather than trusting what a browser reports. Students never see other students' data.

Data Retention and Deletion

Watch time analytics are automatically deleted after approximately 180 days.

Other information is kept only as long as needed to provide the service to the school. When a school stops using AllowList, or at the school's request, we delete that school's data. A school can request deletion at any time by emailing ethan@getallowlist.com.

Who We Share Information With

We do not sell personal information and we do not share it for advertising.

We rely on a small number of service providers to run AllowList: Google, for sign in and Google Classroom data, and Google Cloud and Supabase, for hosting and data storage. These providers are bound to protect the data and may use it only to provide services to us.

We may disclose information if required by law, or to protect the rights, safety, and security of users and the service.

Children's Privacy and COPPA

AllowList is used in schools where students may be under 13. Where required, the school provides consent on behalf of parents for the collection of student information for educational purposes, consistent with COPPA. We collect only what is needed to provide the service and use it only for that purpose.

Student Records and FERPA

We handle student data as a school official with a legitimate educational interest, under the direction and control of the school, consistent with FERPA. Parents and eligible students can exercise rights regarding their information by contacting their school, which can direct requests to us.

Data Processing Agreement

For schools and districts, we enter into a data processing agreement governing how we handle student data, including any state specific requirements. We are able to sign the applicable state agreement, including through the Student Data Privacy Consortium where available.

Changes to This Policy

We may update this policy from time to time. We will let schools know about material changes. Continued use of the service after a change takes effect means the updated policy applies.

Contact

Questions about this policy or our data practices:

Email: ethan@getallowlist.com
AllowList, operated by Ethan Star