Security & privacy

Trust is part of the product.

Generation STEM is built for families — so account safety, student privacy, payment protection, and responsible admin access aren't features bolted on later. They're core requirements.

{}Course player● Protected
Parent dashboard● Protected
Payments● Protected
Browser-based learning, no local installs
Stripe-hosted payment processing
Audited admin support access
No student PII in app logs, by policy
// product safeguards

Security designed around families.

We protect the surfaces families actually use: parent accounts, student profiles, billing, progress tracking, and learning workspaces.

Least-privilege access

Parent, student, and admin areas are separated so each user sees only the information and tools meant for their role.

Secure account sessions

Authenticated areas use protected sessions, server-side validation, scoped API access, and rate-limited password reset and OTP flows.

Payment isolation

Payments are handled through Stripe. Generation STEM never stores raw credit card numbers.

Learning data controls

Student progress, enrollments, submissions, and achievements are tied to household records and protected by access checks.

{}

Safe technical environments

Guided, browser-native workspaces with isolated execution let students practice safely — without installing tools on family devices.

Responsible admin tooling

Administrative actions use server-validated admin sessions and audit logs, including any support access into parent or student views.

// data protection

What we protect — and what we don't collect.

We collect only what's needed to operate family accounts, deliver courses, show progress, support billing, and improve learning. Nothing more.

01

Family account information

Parent names, emails, household structure, plan information, and account settings.

02

Student learning records

Student profiles, course enrollments, progress, achievements, activity status, and certificates.

03

Project & workspace activity

Course-specific code submissions, outputs, and learning interactions needed to support progress and feedback.

04

Billing status

Subscription tier and payment status — with sensitive payment details managed by Stripe, never us.

// admin & support access

Support tooling should increase trust, not weaken it.

Admin access exists to operate the platform and help families — and it's gated, logged, and reversible by design.

Protected admin sessions

Admin routes are guarded by server-side session checks backed by persisted session tokens. Legacy entrypoints are disabled.

Start & end access logs

Support access records the target type, target id, household context, and the admin who initiated the action.

Clear return controls

Admin support sessions include a clean way back to the portal and clear temporary user cookies when ended.

// password reset & OTP

Authentication that fails safely.

Password reset links use random, expiring tokens — hashed before storage
Verification codes are hashed before storage
Email auth requests are rate-limited
Reset requests return a neutral response, so account existence is never exposed
// log & analytics hygiene

What never ends up in a log.

No student PII, reset links, OTP codes, or full email bodies in application logs
Marketing analytics are limited to public pages and checkout conversion events
Private dashboards, course-player, and account-auth routes are excluded from ad tracking
Account-auth routes are excluded from tracking
// family best practices

A few habits keep your account safe.

Security is a partnership. These take a minute and matter the most.

01

Use a strong, unique password for the parent account.

02

Keep parent login details separate from student access.

03

Review student progress and activity from the dashboard.

04

Use supported, up-to-date browsers on shared devices.

05

Contact support if you see unfamiliar account activity.

Report a security concern.

See suspicious account activity or think you've found a vulnerability? Tell us — we investigate quickly and responsibly.

● Security reports acknowledged in 2 business days● Support replies within 1 business day