Privacy Policy & Student Data Privacy
Last updated: August 12, 2026
Who we are
MoneyQuest is a K-12 financial literacy learning platform operated by Lean Engineering. This policy explains what information we collect, how we use it, and the rights schools, parents, and students have over that information.
Information we collect
- Educator and parent accounts: email address, display name, and role.
- Student accounts: a username created by the educator, display name, grade level, and (for student logins) a school-issued internal identifier. Students are never asked for a personal email address, phone number, or home address.
- Learning data: module progress, quiz and assessment answers, scores, coins earned and spent, badges, streaks, and savings goals.
- Operational data: sign-in timestamps and error logs used to keep the service reliable.
How we use information
We use information only to operate the service: to display lessons, save progress, award points and badges, produce educator and parent reports, and secure accounts. We do not sell personal information, we do not use student data for behavioral advertising, and we do not build advertising profiles of students.
COPPA and school consent
Student accounts are created by an educator or a school under the school-consent provisions of the Children's Online Privacy Protection Act (COPPA), or by a parent who has linked to their own child. Schools act as the parent's agent when authorizing collection of the limited data listed above. Parents may review or request deletion of their child's data at any time by contacting their educator or us.
FERPA and school records
Where student data constitutes an education record, we act as a school official with a legitimate educational interest under FERPA. The school remains the owner of that data; we process it only on the school's instructions and return or delete it on request.
Data retention and deletion
Accounts and learning data are retained while the account is active. Educators can delete student accounts from the roster, and any account holder can permanently delete their own account from Settings → Data & Privacy. Deletion removes profile, progress, purchase, and reward records.
Data export
Educators can export gradebooks, growth reports, and SIS-friendly rosters as CSV. Any account holder can download a JSON copy of their own data from Settings → Data & Privacy.
Security
Data is stored in a managed Postgres database with row-level security so each user can read only the records they are entitled to. Passwords are hashed and never stored in plain text, and breached-password checking is enabled at sign-up.
Third parties
We use infrastructure providers for hosting, database, authentication, and transactional email. These providers process data only to deliver the service. We do not share student data with advertisers or data brokers.
Contact
Questions or data requests: andrew@leanengineering.io.