Trust is part of the product.
Generation STEM is built for families — so account safety, student privacy, payment protection, and responsible admin access aren't features bolted on later. They're core requirements.
Security designed around families.
We protect the surfaces families actually use: parent accounts, student profiles, billing, progress tracking, and learning workspaces.
Least-privilege access
Parent, student, and admin areas are separated so each user sees only the information and tools meant for their role.
Secure account sessions
Authenticated areas use protected sessions, server-side validation, scoped API access, and rate-limited password reset and OTP flows.
Payment isolation
Payments are handled through Stripe. Generation STEM never stores raw credit card numbers.
Learning data controls
Student progress, enrollments, submissions, and achievements are tied to household records and protected by access checks.
Safe technical environments
Guided, browser-native workspaces with isolated execution let students practice safely — without installing tools on family devices.
Responsible admin tooling
Administrative actions use server-validated admin sessions and audit logs, including any support access into parent or student views.
What we protect — and what we don't collect.
We collect only what's needed to operate family accounts, deliver courses, show progress, support billing, and improve learning. Nothing more.
Family account information
Parent names, emails, household structure, plan information, and account settings.
Student learning records
Student profiles, course enrollments, progress, achievements, activity status, and certificates.
Project & workspace activity
Course-specific code submissions, outputs, and learning interactions needed to support progress and feedback.
Billing status
Subscription tier and payment status — with sensitive payment details managed by Stripe, never us.
Support tooling should increase trust, not weaken it.
Admin access exists to operate the platform and help families — and it's gated, logged, and reversible by design.
Protected admin sessions
Admin routes are guarded by server-side session checks backed by persisted session tokens. Legacy entrypoints are disabled.
Start & end access logs
Support access records the target type, target id, household context, and the admin who initiated the action.
Clear return controls
Admin support sessions include a clean way back to the portal and clear temporary user cookies when ended.
Authentication that fails safely.
What never ends up in a log.
A few habits keep your account safe.
Security is a partnership. These take a minute and matter the most.
Use a strong, unique password for the parent account.
Keep parent login details separate from student access.
Review student progress and activity from the dashboard.
Use supported, up-to-date browsers on shared devices.
Contact support if you see unfamiliar account activity.
Report a security concern.
See suspicious account activity or think you've found a vulnerability? Tell us — we investigate quickly and responsibly.