/ Legal
Privacy Policy
Effective September 2, 2026
Hi! Your privacy, and your students', matters to us. We wrote this policy to be read, not to hide behind.
NIX helps schools run phone-free events and phone-free school days. Doing that means handling information about students, and students are kids. So we built NIX around a single rule: collect as little as possible, use it only to run the school's program, and never sell it or turn it into advertising. Here, in plain language, is how that works.
/ The short version
- We don't sell data, run ads, or track anyone across other apps or websites. There are no advertising or analytics SDKs in NIX.
- We don't build a location history. NIX stores a single reading that overwrites itself, so there is no map and no trail of where a student went. Each event check-in additionally stores a one-time location snapshot for that event, used to confirm the scan happened on site, which is automatically deleted 90 days after the scan.
- The school is in charge. For student records the school decides; NIX carries out its instructions as a “school official” under FERPA.
- You can leave anytime. A student can delete their account from the app or at nix.management/legal/delete-account, which clears its location and disables it. The school keeps its own attendance records.
The rest of this page is the detail behind those promises.
This Privacy Policy explains how NIX Development LLC (“NIX,” “we,” “us,” or “our”) collects, uses, and shares information when a school and its staff and students use the NIX platform: our website at nix.management and the NIX mobile apps for iOS and Android (together, the “Service”). It is written to be read by the schools that adopt NIX and by the students and families they serve.
1. Our role: schools direct, NIX processes
NIX is a platform that schools use to run phone-free events and, where a school chooses, to support a phone-free school-day policy. A school decides to adopt NIX, configures how it works, and directs how student information is used within it. For the student records processed through NIX, the school is the data controller and NIX acts as a service provider (a “school official” under FERPA) carrying out the school's instructions. We do not use student information for our own purposes, and we do not sell it.
2. Information we collect
We collect only what is needed to run the Service for a school:
Students
- Full name and the school-issued student ID number used to identify the student at events and during the school day.
- A password the student sets to sign in to their account (stored only as a securely hashed value, never in plain text).
- Grade level, if the school provides it. We do not collect a student's date of birth.
- A recovery email address, so the student can reset their own password if they forget it. Students provide one when they register, and a school's roster import can also supply one. It is used only for password reset and account notices, never for marketing.
- Device location, used as described in Section 3.
- In the events experience, friend connections a student chooses to make with other students at their school.
- A device push-notification token, so the school can notify the student about events.
School staff (admins)
- Name, work email address, and a securely hashed password.
- When a staff member scans student IDs at an event, the scanning device's location at the moment of the scan (used to confirm the scan happened on site).
- Event content the staff member uploads, such as marketing or prize images, and the school's branding (logo and colors).
- A device push-notification token.
School configuration
- School name, the campus boundary and time zone, bell schedule and no-school calendar, and (for the school-day model) classes and rosters the school sets up.
Walk-in attendees who do not use the app
Some events let staff scan a student's physical ID even if that student has no NIX account (for example, a printed coupon card). In that case we record only the scanned ID number and the event, so the school can issue the reward. The school remains the controller of those records.
Automatically
- Basic technical information needed to keep accounts secure and the Service working (for example, a device identifier used to deliver push notifications, and security and error logs).
NIX uses no advertising identifiers, no cross-app or cross-site tracking, and no third-party analytics or advertising SDKs. We do not collect contacts, photos library, health, or biometric data.
3. How location works
Location is the core of how NIX verifies that a phone was left behind. How and when it is used depends on how the school runs NIX, and the school controls this:
- Events model: location is checked around an event window to confirm, against that event's geofence, whether the phone was away from the event.
- School-day model: if a school adopts a phone-free school-day policy, NIX checks whether the phone is off campus during school hours on school days, against the campus boundary the school sets. How the check runs depends on the device. On iOS, the app asks for “Always” location permission so the check can run while the app is in the background. On Android, the app does not ask for background location at all. Instead the student starts each check themselves, either from inside the app or by tapping Arm on the reminder notification NIX sends before a window opens, and while it runs the app shows a permanent notification that says location is being shared and offers a Disarm button to stop it at any time.
Checking starts before a window opens and ends 30 minutes after it closes, so a phone that arrives early or leaves late is still counted correctly. For the school-day model, checking starts up to 45 minutes before the school day. For the events model, it starts up to 90 minutes before the event, which covers travel and arrival.
For events, checking during that window does not depend on how close the student is to the venue. If a student has an event window open, their phone is checked wherever they are, including at home. We do this so a student who leaves their phone behind and arrives without it is still credited as phone-free; a check that only ran near the venue would fail exactly the students who did what we asked. Outside the window, nothing is collected.
Within those windows we are deliberately data-minimizing. The app's live location field keeps a single, overwriting reading, so there is no ongoing location history or trail. For the school-day model, what the school sees is a derived signal, not a map of where a student went: whether the phone was off campus, the time it was first detected on campus, the time it most recently left, whether it is on campus right now, and how many times it came onto campus that day. That last one is a count only. We do not keep the times of those individual crossings, so the school can see that a phone was retrieved and brought back, but not a timeline of the student's movements. All of it is cleared on the same schedule as the rest of the school-day record. For the events model, each check-in additionally stores a one-time location snapshot on that event's record, used to confirm the phone was away from the event; this snapshot is automatically deleted 90 days after the scan. A student can turn off location sharing in their device settings at any time; doing so disables phone-free verification.
On Android specifically, location is collected only while a check the student started is running and its notification is visible. The check stops, and collection stops with it, when the student taps Disarm, when the check window ends, or when the account's sign-in is no longer valid. The app cannot start a check by itself: not in the background, not when the phone turns on, and not when a reminder arrives. A reminder only puts an Arm button on screen; nothing starts until the student taps it. When no check is running, no location is collected.
4. How we use information
We use the information above only to run the Service for the school: to create and manage accounts; to run events and verify phone-free participation; to support a school's phone-free school-day policy where adopted; to issue rewards to eligible students; to send school-related notifications; to provide the admin console; to bill the school; and to keep the platform secure, prevent abuse, and meet our legal obligations.
5. What we never do
We do not sell personal information. We do not share it with advertisers or use it for advertising. We do not build profiles of students for any purpose unrelated to running the school's use of NIX, and we do not track users across other apps or websites.
6. Service providers we share with
We share information only with the vendors that help us operate NIX, and only so they can perform services for us under contract:
- Neon: database hosting (stores the Service data described above).
- Vercel: website and API hosting; processes Service data in transit while requests are handled (it does not retain student data at rest).
- Resend: sending account and notification emails to staff.
- Stripe: processing a school's subscription payments. Card details go to Stripe and are never stored on our servers.
- Object storage (an S3-compatible provider): hosting images staff upload for events.
- Apple Push Notification service (iOS) and Google Firebase Cloud Messaging (Android): delivering notifications to devices.
- Anthropic: AI model provider for the NIX Assistant, the helper built into the staff admin console. When a school admin uses the assistant, their messages, plus the school-level event details and aggregate metrics the assistant looks up, are processed by Anthropic's API. Student personal data never enters an assistant conversation; the assistant can only read information and draft changes, and every change requires the admin's explicit confirmation before anything is created or modified. Under our agreement, Anthropic does not use this data to train its models. We do not store assistant conversations on our servers.
The current, named list of sub-processors is published at nix.management/legal/subprocessors.
We may also disclose information when required by law, to protect the rights and safety of users and the public, or to a successor in a merger or acquisition. Any successor remains bound by this Policy for the information it receives.
7. Children's privacy: COPPA & FERPA
NIX is built for schools, and many students are minors, including children under 13. NIX is intended to be adopted and directed by a school as part of the school's educational program. Under the Family Educational Rights and Privacy Act (FERPA), NIX operates as a “school official” with a legitimate educational interest, processing student information only under the school's direction.
Under the Children's Online Privacy Protection Act (COPPA), a school may provide consent for the collection of personal information from students under 13 for the use and benefit of the school's educational program, in place of individual parental consent. The school is responsible for providing any notices to parents and obtaining any consent that COPPA or FERPA requires. We collect from children only the limited information described in this Policy, use it only to provide the Service to the school, and never for advertising or any commercial purpose unrelated to the school's use of NIX. Parents may exercise their rights, including reviewing or requesting deletion of their child's information, through their school, and the school may direct us to delete it. Questions can also be sent to contact@nix.management.
The full child-specific disclosure lives in our Children's Privacy Notice.
8. Retention & deletion
We keep information for as long as a school uses NIX and as needed to provide the Service, meet legal obligations, and resolve disputes, after which we delete or de-identify it. When a school's account ends, whether it cancels, its subscription lapses, or it is suspended for non-payment, the school's account and data are retained unchanged for 30 days so they can be restored, then permanently deleted.
How to delete your account
A student can delete their own account from the app (Profile → Delete account), or request deletion at nix.management/legal/delete-account. Deletion clears the account's stored location and the location snapshots attached to its past event check-ins, revokes its sign-in tokens, and disables the account. A school can also direct us to remove a student's information.
School staff accounts delete themselves: a principal, counselor, event manager or Staff scanning account uses Account in the app or in the admin console. A master admin at a school that has more than one can remove just their own login by stepping down to a sub-admin from Team, signing back in (Step down signs them out), and then deleting from Account. A school's last master admin either transfers ownership from Team first and then deletes their own account after signing back in, or deletes the school itself from Settings. The deletion page linked above sets all of this out step by step, and is also the route for anyone who cannot use the app or the console at all.
What is retained after deletion, and why
The school, not NIX, owns its student records, and NIX processes them as a “school official” under FERPA. After an account is deleted, we retain the student's name, school-issued student ID, any recovery email on the account, and the school's attendance and event participation records, for as long as the school uses NIX and needs them for its own records. We keep them only to serve the school, never for advertising, and never to sell. To have those school records removed, ask the school, which can direct us to delete them, and we will.
What the school-day model stores
As noted above, the school-day model stores derived signals (for example, “phone was off campus” and an on-campus timestamp) and a single overwriting location reading rather than a location history.
Automatic coordinate deletion
Raw location coordinates attached to an event check-in are automatically deleted 90 days after the scan, whether or not the account is deleted.
9. Security
We use reasonable technical and organizational measures to protect personal information, including encryption in transit (TLS), hashed passwords, access controls, and a logged, append-only record of every staff view of an individual student record. No system is perfectly secure, but we work to protect information and will notify affected schools of a material breach as required by law.
10. Your choices & rights
Students can turn location sharing on or off in device settings, and can delete their account in the app or request deletion at nix.management/legal/delete-account. After deletion, the school keeps its own attendance and participation records, which it controls as described in Section 8. School staff can update or delete account and school information from the admin console. Because the school is the controller of student records, requests about a student's data are generally handled through the student's school; we will assist the school in responding. You can also contact us using the details below.
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of personal information, and to opt out of its sale or of targeted advertising. NIX does not sell personal information or share it for targeted advertising, so there is nothing to opt out of. To make a request, email contact@nix.management (or, for a student record, contact the school). We will respond as required by applicable law.
11. Where NIX operates
NIX is offered to schools in the United States, and information is processed in the United States. The Service is not directed to individuals in the European Union or United Kingdom.
12. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the “Effective” date above and notify schools where appropriate. Continued use of the Service after a change takes effect means you accept the updated Policy.
13. Contact
Questions, requests, or complaints about this Policy?
- Email: contact@nix.management
- Mail: NIX Development LLC, 12167 W Devis Rd, West Olive, MI 49460-9393, United States