Privacy Policy
How LessonBoard handles information about teachers, students and visitors to this website.
Last updated: 28 September 2026
The short version
- Your video and audio never reach us. The extension draws the board into your camera picture inside your own browser. We are not in your meeting.
- Students do not get accounts. They type a name they choose and answer questions. We never ask them for an email address, a phone number or a real name.
- We do not sell anything about you, and we do not use your lesson content for advertising.
- Analytics run on the marketing pages only — not in the app, not on student screens, not in the extension.
This policy explains what information LessonBoard collects, why, and what you can ask us to do about it. It covers the mylessonboard.com website, the LessonBoard browser extension, and the pages students open when they join a lesson.
It is written to be read. Where a section is about a specific part of the product, it says so.
1. Who we are
LessonBoard is operated by Damiko Inc., Hallandale Beach, Florida, United States. For the purposes of the GDPR and similar laws, we are the data controller for the information described here, except where we act as a processor on a teacher's behalf — see Students and children.
You can reach us at [email protected].
2. What we collect
Your account
- Your name and email address.
- A password, stored only as a one-way hash (bcrypt). We cannot read it, and neither can anyone who obtains the database.
- Your board settings — where the widget sits in your video, its size, theme and opacity — so the same choices follow you to another computer.
- The date you created the account.
The early-access form
If you sign up from the landing page, we keep what you fill in: your name, your email address, what you teach, whether you teach one-to-one or in groups, and the free-text answer about your biggest challenge if you write one. We use it to plan the product and to email you the link that creates your account.
What you create
- The activities and lessons you build — their titles, questions, answer options and settings.
- Any image you upload to an activity. Uploaded images are stored on our server and served from a random, unguessable address; they are not listed anywhere public.
Live sessions
- The session's title, its six-character join code, and when it started and ended.
- An identifier for the video meeting the session belongs to, when you start one from a meeting tab. For recognised platforms this is something like
meet:abc-defg-hij. For any other site it is the tab's host and path with the query string removed. It exists so a student in the same meeting can join without typing a code. - For each student in the session: the display name they typed, their answers, their score, when they joined, and when they were last seen.
- A random identifier stored in the student's own browser, so that if they reconnect — or type their name slightly differently — they are recognised as the same participant rather than counted twice. It is a random string with nothing derived from the device in it, and it means nothing outside LessonBoard.
What you tell us
If you send us feedback — a problem, an idea, a question, or just how a lesson went — we keep what you wrote, along with the page you were on, your browser and its version, whether the extension is installed and which version, and the lesson it came from if you sent it from one. We attach that automatically so you do not have to describe your setup to us. It is used to answer you and to decide what to build, and for nothing else.
The contact page works the same way for anyone, with or without an account. Because there may be no account to reply to, it also asks for your name and the email address you want the reply sent to.
Technical records
Our servers keep ordinary request logs: IP address, browser user-agent, the address requested and the time. They exist to keep the service running and to investigate abuse and faults, and they are rotated on a short cycle.
Analytics on the marketing pages
The public pages of mylessonboard.com — this one included — use Google Analytics to count visits and see which pages people read. It is not loaded in the signed-in app, on the pages students open, or in the extension. If you block analytics, everything else works exactly the same.
3. What we never collect
- Your video or audio. The extension composites the board into your camera picture inside your browser, on your machine, before your conferencing tool sees it. No frame of it is sent to us, and we have no way to record your meeting.
- The content of the pages you visit. The extension needs permission for any site so it can draw on your camera picture wherever your lessons happen. It does not read page text, form fields or credentials, and it sends nothing about a page to us unless you start or join a lesson from that tab.
- Student accounts. No email addresses, no phone numbers, no passwords, no contact details of any kind.
- Payment details. There is nothing to pay for yet, and we do not handle card data.
4. Why we use it
- To provide the service — signing you in, keeping your library, running a live session and delivering answers to you. Legal basis: performance of a contract.
- To keep it working and safe — logs, rate limits, abuse investigation. Legal basis: legitimate interests.
- To email you what you asked for — the link that sets your password, and account notices. Legal basis: performance of a contract.
- To understand demand while we are in early access — the questionnaire answers and the marketing-page analytics. Legal basis: legitimate interests, and consent where the law requires it.
We do not profile you, we do not target advertising, and we do not sell or rent anything we hold.
5. The browser extension
The extension asks Chrome for four things. This is what each is for:
- Side panel — to show the lesson controls beside your meeting. That panel is the product.
- Storage — to remember, in your browser only, your sign-in token, your board settings, the session you are in, and the name a student typed.
- Tabs — to know which tab your meeting is in, so the board goes into the right video, and to open the board page when you ask for it.
- Access to websites — because your lessons could be on any conferencing site. It is used to place the board into the camera stream of the tab you are teaching in, and for nothing else.
Your sign-in token is only ever handed to a page whose origin is exactly the LessonBoard site configured in the extension. Any other page asking for it is refused. This is what lets the site and the extension share one sign-in without a password being typed twice.
Consistent with the Chrome Web Store User Data Policy, including the Limited Use requirements: we use the data the extension handles only to provide and improve LessonBoard, we do not transfer it to others except as described in Who else sees it, we never sell it, and we do not use it for advertising or creditworthiness.
6. Students and children
A student joins a lesson by opening a link or typing a code. They choose a display name and answer the questions their teacher puts on the board. That is all we ask of them, and we recommend teachers ask students to use a first name or a nickname rather than anything more.
The information generated in a lesson belongs to the teacher's account. In that respect we act as a processor on the teacher's behalf: the teacher decides what to ask and what to keep, and is responsible for having whatever permission their school or their jurisdiction requires before running a lesson with minors.
LessonBoard is a tool for teachers and is not directed to children under 13. We do not knowingly collect personal information from a child beyond a self-chosen display name. If you believe a child has submitted more than that, write to us and we will remove it.
7. Cookies and local storage
We do not use tracking cookies, and there is no cookie banner because there is nothing to consent to beyond the analytics described above. What we do use is your browser's own storage, which never leaves your device:
- Your sign-in token, so you stay signed in.
- Your board settings and the last session you were in.
- On a student's device, the display name they typed and the random participant identifier described above.
Clearing your browser data clears all of it. Google Analytics sets its own cookies on the marketing pages only.
8. Who else sees it
We share information with a small number of service providers, and with nobody else:
- Our hosting provider, which runs the servers and the database.
- Our email provider (ZeptoMail, by Zoho), which delivers sign-up and account emails.
- Google Analytics, for the marketing pages only.
- Telegram, which we use to notify ourselves when someone signs up for early access or sends us feedback, so that we see it quickly. That message contains what you entered.
We may also disclose information if the law requires it, or to protect our rights or someone's safety. If the business is ever sold or merged, information may transfer with it; we would tell you before that took effect.
9. How long we keep it
- Your account, activities and lessons — until you delete them or ask us to close your account.
- Sessions and answers — for as long as the account exists, because reading last month's exit tickets is the point of keeping them. Deleting your account deletes them.
- Uploaded images — removed automatically once no activity refers to them any more.
- Sign-up links — the stored value is a hash of the link, and it expires 24 hours after we send it.
- Early-access answers — until we finish early access, unless you ask us to delete them sooner.
- Feedback you send us — for as long as the account exists, so we can follow up on it. Deleting your account deletes it.
- Messages from the contact page sent without an account — for up to 24 months after we have answered, so we can see the earlier conversation if you write again. Ask us and we delete them sooner.
- Server logs — a short rotation, measured in weeks.
10. Security
- Everything travels over HTTPS, including the live session connection.
- Passwords are stored as bcrypt hashes and are never written to logs.
- Sign-up links are stored as hashes, so the database alone cannot be used to claim an account.
- Access to production systems is limited to the people who operate the service.
No service can promise perfect security, and we will not pretend otherwise. If something does go wrong, we will tell affected users and, where the law requires it, the relevant authority.
11. Your rights
Depending on where you live, you can ask us to give you a copy of what we hold, correct it, delete it, restrict what we do with it, or object to it. You can also ask us to stop emailing you at any time.
Write to [email protected] and we will answer within 30 days. If you are in the EU or the UK and are not satisfied with our answer, you may complain to your local data protection authority.
If you are a student, or a parent asking about one, the quickest route is usually the teacher who ran the lesson, because it is their account the answers belong to. You are welcome to write to us instead and we will handle it.
12. International transfers
We operate from the United States, and our providers may process information in the United States and in the European Union. Where information moves out of the EEA or the UK, we rely on the safeguards our providers put in place, such as the European Commission's standard contractual clauses.
13. Changes to this policy
We will update this page when the product changes. The date at the top always reflects the current version, and if a change materially affects you we will say so by email or in the app rather than quietly editing this page.
14. Contact us
Damiko Inc.
Hallandale Beach, Florida, United States
[email protected]
Or use the contact form.
See also the Terms of Service and how LessonBoard works.