Trust

Security

Last updated June 18, 2026

Families trust us with their information, and protecting it matters to us. Here is how we keep your account and your child's data safe, in plain language.

Encryption

All data sent between your device and K12 Crafter is encrypted in transit using HTTPS. The information we store is held with hosting providers that encrypt data at rest.

Accounts and access

Passwords are stored as secure one way hashes, never as plain text. Admin access uses a second factor and is limited to the people who need it to run the service. Child profiles have no login of their own and cannot be used to sign in on their own.

Server side checks

We do not trust data from the browser. Practice answers are graded on the server, and the correct answer is not sent to the page ahead of time. Prices and access to paid content are confirmed on the server, so changing data in the browser does not unlock anything.

Secure file delivery

Worksheet files are stored in a private, access controlled bucket. Download links are signed and short lived, so a link cannot be shared to give others lasting access to your files.

Abuse prevention

Sign in, checkout, and practice endpoints are rate limited to slow down brute force attempts and scraping. Repeated failed logins trigger a temporary lockout.

Care for children

We collect as little as possible from children: a first name or nickname, a grade, and practice progress, nothing more. Child profiles cannot start purchases or change account settings, and the kid zone gives a child no way to share personal information with others. We never show ads to children and we never sell personal information. See our children's privacy section for details.

Payments

Payments are handled by Stripe. Card details go directly to Stripe and are never stored on our servers.

Incident response

We monitor for issues and work to detect, contain, and fix security problems quickly. If an incident affects your personal data, we will notify you and take the steps the law requires.

Key providers

Supabase
Database and account sign in
US
Cloudflare
Hosting and file storage
Global
Stripe
Payment processing
Global
Anthropic
AI features such as generated practice
US

Report a vulnerability

If you find a security issue in K12 Crafter, please tell us privately before sharing it publicly. We take every report seriously and aim to respond quickly. Email security@k12crafter.com with the subject line "Security Vulnerability," and we will not pursue good faith researchers who follow this policy.

Questions? Visit our contact page or review our privacy policy.