Policy version 2026-07-18
Privacy Policy
Plain-language summary: We collect only the information needed to review applications, communicate with families, operate cohorts, document consent, and protect the service. We do not sell applicant data, run advertising trackers, or put application records in public website files.
1. Scope
This policy explains how Compute Forward, a student-led computer science education organization founded by Anish Koppula and Kaushik Atla, handles information submitted through this website. It covers prospective students, participating students, parents or guardians, and people who contact us about privacy.
The policy does not cover third-party websites linked from our pages. If a cohort uses an external classroom, video, or code-hosting tool, families will receive the tool list and relevant privacy information before enrollment.
2. Information we collect
Application information
- Applicant name, student email, selected grade from 6th through 12th, and age range.
- Preferred program level and cohort/application period.
- Short answers about current coding experience, languages or tools tried, optional project experience, and learning goals.
- Parent or guardian name, email, authorization, and under-13 submitter confirmation when applicable.
- Optional consent to future cohort-opening announcements.
Consent and operational records
- The versions of the Privacy Policy, Terms of Participation, and Student Safety Policy accepted.
- Consent timestamp, application reference, application status, and status-update timestamps.
- Confirmation and internal-notification delivery status.
- A one-way hash derived from the request network address for abuse investigation. We do not store the raw address in the application record.
Minimal service logs
The server records a random request ID, route, method, response status, response time, and non-sensitive error codes. Application names, email addresses, guardian details, form contents, and admin tokens are excluded from structured logs. Security logs are intended to be retained for no more than 30 days.
Information we do not intentionally collect
We do not request payment details, Social Security numbers, precise location, health records, government identification, passwords, school disciplinary records, or demographic profiling information through the application form.
3. How we use information
- Receive, de-duplicate, and review an application.
- Recommend or discuss an appropriate program level.
- Send an application reference, status messages, and operational communications.
- Contact a parent or guardian where required.
- Plan cohort capacity and communicate an offer or waitlist decision.
- Document consent and respond to safety or privacy concerns.
- Prevent spam, rate-limit abuse, diagnose failed submissions, and secure administrative access.
- Send future cohort-opening announcements only when optional communications consent was selected.
Admissions decisions are made by people. We do not use automated profiling to admit or reject applicants.
4. Students and minors
Compute Forward is designed for K–12 students, so minor privacy is central to the intake process.
- Applicants under 18 must provide parent or guardian information and authorization.
- A parent or legal guardian must submit the form for an applicant under 13. If the student does not have email, the parent address may be used as the student contact address.
- The operational receipt and application copy are sent to both the student and parent or guardian addresses provided, with duplicate addresses removed.
- We do not create public student profiles or require publicity consent to participate.
- Recordings, screenshots, testimonials, names, images, and student work require separate, specific consent before public use.
If we learn that information from a child under 13 was submitted without appropriate parent or guardian involvement, we will suspend use of the record and delete it after confirming the circumstances.
5. When information is shared
We do not sell or rent personal information. Access is limited to founders and authorized admissions or operations personnel who need it for the purposes above.
Production operation may require carefully selected service providers for:
- Website and server hosting.
- Managed PostgreSQL database hosting.
- Transactional email delivery.
- Privacy-safe error alerting or uptime monitoring.
Providers process information only to deliver their contracted service. The production provider list, locations, and retention settings must be recorded in the operational data inventory before launch. We may also disclose information when legally required or when reasonably necessary to address an immediate safety threat.
6. Retention
- Unsuccessful, declined, or withdrawn applications: deleted within 12 months after the relevant decision unless the applicant asks for earlier deletion.
- Accepted and enrolled applications: deleted within 24 months after the student’s program participation ends, unless a shorter period is requested or a documented legal/safety need requires limited retention.
- Security logs: targeted for deletion within 30 days.
- Completed deletion requests: the email and confirmation token are removed. A one-way email hash, completion time, and deletion count may remain to document fulfillment without retaining the readable address.
Optional cohort-announcement consent can be withdrawn at any time by contacting us.
7. Security
Production safeguards include encrypted HTTPS transport, a protected PostgreSQL database, least-privilege access, strong environment-managed secrets, token-protected administrative routes, rate limiting, input allowlists, anti-spam controls, security headers, private consent records, and audit events for administrative changes.
No system can guarantee absolute security. If a breach creates a material risk to applicants, we will investigate, contain it, preserve necessary evidence, and notify affected people as required.
8. Your choices
Applicants and parents or guardians may ask us to:
- Confirm whether application information is held.
- Correct inaccurate contact or application information.
- Withdraw an application.
- Stop optional future-cohort announcements.
- Delete application and consent records, subject to a narrow legal or safety retention need.
We verify deletion requests through access to the email associated with the application. This prevents someone else from deleting a student’s records by entering their address.
9. Request deletion
Enter an applicant or guardian email associated with the record. If a match exists, we will email a one-hour verification link. The response is intentionally the same whether or not a record exists.
10. Contact and changes
For privacy questions, corrections, or requests that cannot use the form, contact both founders:
Material changes will receive a new policy version and effective date. Applicants will be asked to accept the current version when submitting a new application.