Privacy policy

ClassMapr is committed to the privacy of students and staff.

Effective September 16, 2026

What that means in your classroom

  • Rooms, class lists and seating rules are held by this browser, on this device. On the free tier there is no server side for them to sit on.
  • There is no sign-in today. When accounts open, signing in turns sync on: a room is saved to the server as you change it, storing the least it can, encrypted in transit and at rest.

Who this covers

ClassMapr is a seating-chart tool for teachers, built by Classhelpr in Alberta, Canada. This page covers ClassMapr — the app you're in — at mapr.classhelpr.com.

It doesn't matter what country you teach in. On the free tier, your data doesn't reach ClassMapr at all.

Classhelpr is based in Alberta, so two Canadian privacy laws govern it as a company: PIPA (Alberta) and PIPEDA (federal). If you teach in the US, UK, or EU, FERPA, COPPA, GDPR covers what they mean for you here.

The rest of the Classhelpr suite — tools that upload files or call an AI model — has its own policy at classhelpr.com/privacy. ClassMapr does neither of those things, which is why it gets this separate page.

What stays in your browser

Everything built in ClassMapr is stored by your own browser, on your own device. That includes:

  • Your rooms — names, room numbers, whether they're archived
  • The furniture in each room — desk positions, pods, pairs, off-limits seats
  • Your class list — student names, typed or imported
  • Your seating rules and pins — keep apart, sit near, front row, fixed seats
  • A short-lived backup of whatever you're editing, so a crashed tab doesn't cost you the room

Tags are the one place sensitive info can end up.

A tag is free text — you write it yourself. In practice, some say "IEP," "504," "ELL," or a diagnosis. That's the most sensitive thing in ClassMapr, and how much it says is your choice: a tag is a colour and a word you pick, and ClassMapr never asks what the word means. A short code only you can read works just as well as spelling the condition out.

Seating rules can't carry that kind of info at all. There are five kinds — keep apart, sit near, front row, near the teacher, on their own — and none of them has a field for why. A rule records that two students are separated. Never the reason.

None of this is sent anywhere. There is no server copy — which also means there is no backup ClassMapr can restore for you if you lose it. The one backup that exists is the file you save yourself, and it stays on your computer until you move it.

Rooms stay in this browser until you delete them or clear your browsing data. On a shared staff computer, anyone using the same browser profile can see them.

Clearing your browsing data, using private browsing, or a school machine that wipes profiles at logout — any of these takes your rooms with it. If a room matters, export it or rebuild it on the machine you actually teach from.

What leaves your browser, and when

Three things are sent without you pressing anything:

  • A crash report, if ClassMapr breaks. You'll know — the error screen tells you and gives you a reference code. It includes what failed, which page, your browser and screen size, and the last few things you did as plain labels ("imported 31 students," "pressed Auto Fill"). Students appear as positions in your list, never as names. Tag names, room names, anything else you typed — stripped out before it is sent. It goes to ClassMapr's own database in Montreal, not to a third-party error company, and is deleted 90 days after the bug is fixed.
  • Two counts. ClassMapr records that someone landed on the page, and that someone built their first room. That's it — nothing you do afterwards is tracked. No cookie is set for it. No consent banner is needed, because there is nothing to consent to. If your browser sends Do Not Track, or you run an ad blocker, nothing is recorded at all.
  • A version check. While ClassMapr is open, it asks the same site which version it is serving — every five minutes, and when you come back to the tab — so a tab left open for weeks does not keep running an old build. The request carries nothing from your rooms, and the answer is a version number. When a newer one is out, ClassMapr reloads or offers to, and remembers for the rest of that tab's life that it already has, so it can never reload over and over. That memory is a version number too, and it is gone when the tab closes.

Everything else takes you pressing something on purpose:

There is no newsletter and no signup box. Nothing in ClassMapr asks you for an email address, so there is nothing here that could send one. If a list ever opens, this page says so before it does.

  • Feedback form — opens a Google Form in a new tab. What you type reaches Google, and then Classhelpr, only if you go there and submit. Please leave student names out — describe the room, not the class.
  • Any link off ClassMapr — following a link to Timr or classhelpr.com is a normal visit to that site, covered by their policy, not this one.

Emailing support@classhelpr.com sends whatever you put in the email. Same as any email, anywhere.

What ClassMapr doesn't do

  • No behavioural tracking. Nothing follows you between visits or sites. No profile. No Google Analytics.
  • No third-party error tracking. No Sentry. Crashes go straight to ClassMapr's own database — no other company ever sees one.
  • No AI. Nothing you type goes to an AI model. Auto Fill runs entirely in your browser — it's a solver, not a chatbot.
  • No Google Drive, Docs, Forms, or Slides access. ClassMapr holds no permission to touch any of it.
  • No file uploads. There is nowhere to upload a file to.
  • No ads. Nothing sold. No student names sold — which ClassMapr never has in the first place.
  • No tracking cookies. Signed out, which is everyone today, there is exactly one cookie — it only clears out logins left behind by an old version of the app.

Want to check for yourself? Open your browser's network tab. You won't find a room, a class list, or a tag leaving this browser.

The host, and what a server sees

ClassMapr is hosted by Railway, in the United States. Loading any page means a server sees the basics — what page, when, your browser type, your IP address. That is true of every website you visit, not just this one.

What those logs don't have is anything from a room. Your layouts, lists and rules are never sent, so they cannot show up in a log.

No extra logging is added on top, and nothing is copied out of Railway's. They clear those records on their own schedule — days to a few weeks — and once they are gone, they are gone.

Every company involved

The whole list. No analytics vendor, no ad network, no data broker beyond this:

  • Railway (hosting, US) — gets basic request info on every page load. Never gets room data.
  • Buttondown (newsletter, US) — receives nothing while signup is switched off. It still holds an address given while it was open, until you unsubscribe.
  • Google (feedback form) — gets what you type, only if you open and submit the form.
  • Umami (the two counts, EU servers) — gets the event and basic request info. No cookies, nothing tied to you.
  • Supabase (the database, Montreal) — holds crash reports. When accounts open, would also hold the rooms of signed-in teachers.

If this list ever changes, this page changes with it — same day.

Keeping it safe — including the part that's on you

The biggest protection here isn't technical, it's structural: there is no server copy of your rooms to leak, breach or hand over. Nobody can lose data they were never given.

Everything ClassMapr serves travels encrypted (HTTPS).

Browser storage itself isn't encrypted — that is the honest tradeoff of a local-first tool. Your class list sits as plain text on your device. Anyone who can use your unlocked computer, or sign into the same browser profile, can open it — same as a spreadsheet left open on your desktop. What protects it is your screen lock, your own login, and not building rooms on a shared staffroom profile. ClassMapr can't do that part for you.

An exported PNG or PDF is a plain file with names on it. Once it is downloaded, emailed or printed, treat it like any printed class list.

When accounts open, synced rooms would be encrypted in transit and at rest, and only your own account could read your rows. No system is perfectly secure — but if anything ever happened to data Classhelpr holds, you would hear it from Classhelpr first, not read about it.

Charts you export

Exporting as PNG or PDF happens right in your browser and goes straight to your downloads. It is never uploaded, never rendered on a server, never passes through ClassMapr.

Saving your rooms to a file — the “Moving computers” button on your rooms list — works the same way: written by your browser, straight to your downloads, never near a server. It is how you get your rooms onto a second computer, and it is the only backup of a local room that exists. Unlike a chart, that file holds the full class list as plain text, along with your rules, pinned seats and jobs. Moving it on a USB stick or emailing it to yourself moves real student names, so treat it exactly as you would a printed roster, and delete it once it has arrived.

Tags don't print as words. A tagged student shows a small coloured dot next to their name — nothing else. A chart handed to a sub shows a purple dot, not a diagnosis. Hit "Hide tags" and the dots disappear too.

Once the file is saved it is yours — outside this policy. What happens to a chart after you email it or print it for a binder is on you, same as any paper class list.

When accounts open — not today

Accounts aren't open. Nothing to sign up for, nothing to pay for. Sync is built but switched off for everyone.

Here is what it will do, so this page doesn't need a surprise rewrite the day it is turned on:

  • You'd sign in with Google. ClassMapr would receive your name, email and profile picture — never your password.
  • Signing in turns sync on. Rooms are saved to the database (Supabase, Montreal) as you change them — including the student names in a room's class list.
  • You'd only ever be able to read your own rows.
  • Stay signed out and nothing changes: rooms keep living in this browser and nowhere else.
  • Signing out clears the local editing backup, so a shared staff machine isn't left holding a roster.

None of this is happening today. An account will never be required to use what is free right now.

Student names, and children's privacy

ClassMapr is a tool for teachers. Students don't use it — no student login, nothing aimed at children. The only student information in ClassMapr is what you type into a class list, usually a name, and today it stays on your device. When accounts open, it leaves the device once you sign in and the room is saved.

First names, initials, nicknames — all work the same as full names. Nothing needs a legal name, and nothing asks for a birthdate, ID number, address or assessment code.

Following your district's rules on student data is your call and your school's — ClassMapr is built to make that easy, since none of it leaves your device on the free tier.

FERPA, COPPA, GDPR — the short version for your admin

One fact covers most of this: on the free tier, no student data reaches ClassMapr.

FERPA (US): Your seating charts stay on your device. ClassMapr never receives or stores education records, so there is nothing in its hands to disclose or govern. When accounts open and your district wants a formal school-official agreement before syncing, ask — it will be done properly.

COPPA (US): ClassMapr isn't built for children, and no child uses it. Names you type stay on your device and are not collected, so there is no parental consent question for Classhelpr to handle. When accounts open, signing in is the decision that changes that — it puts your class lists on the server — and it is one to make under your school's own consent rules.

GDPR (UK/EU): For your rooms and class lists, Classhelpr is neither controller nor processor — because it never receives them. The only things held: basic request info the host keeps for site security, crash reports with no personal data in them, the two anonymous counts, and an email address only if you gave one while newsletter signup was open (unsubscribe anytime). The mailing list and counting service touch servers in the US and EU; crash reports stay in Canada.

Canada: PIPA (Alberta) and PIPEDA cover Classhelpr as the company. If you work for a Canadian public body, your own FOIP rules apply to student information — easier to meet when it never leaves your device.

Everywhere else: The same fact applies — the free tier keeps your data on your device. If your school needs something specific in writing, email and you will get an honest answer about whether ClassMapr covers it.

Your rights and choices

  • See or export your data — your rooms are already fully in your hands. Export as PNG or PDF in one click. There is nothing to request, because ClassMapr holds nothing of yours.
  • Delete a room — gone from your browser, with no server copy to also clean up.
  • Clear everything — clear your browser's site data and every room goes at once.
  • Unsubscribe — if you joined the list while signup was open: the link in any issue, or just ask.
  • Ask what is held on you — email Classhelpr. Signed out, the honest answer is: nothing, except any email you have sent.
  • Stop the counting — an ad blocker does it, so does Do Not Track. Crash reports have no opt-out, because there is nothing personal in one — but say so if you would rather they didn't go at all, and that will be listened to.
  • Complain to a regulator — EU/UK: your national authority. Canada: the Privacy Commissioner, or Alberta's Information and Privacy Commissioner. You don't have to come to Classhelpr first, though that is the faster way to get it fixed.

Changes to this policy

When the product changes, this page changes with it. Anything big — a new place data goes, accounts opening — is announced in the app, not buried in a paragraph here.

If Classhelpr is ever sold or shut down, there is no stockpile of your rooms to hand over, because there isn't one. Your rooms keep working in your browser no matter what happens to it.

Something here not match what you see?

Both of these pages are written off the running code. If the product does something this page does not say, that is a bug in the page and worth reporting.

support@classhelpr.com