Trust & privacy

This page is maintained by Oak Ridge Nature School to answer common security and privacy questions about our planning platform. It describes current practices and enabled controls, and is editable project content, not an independent certification or audit report.

Shared responsibility

Our platform is built on Lovable Cloud, which provides managed hosting, the database, authentication, file storage, and serverless functions. Oak Ridge Nature School is responsible for the application code, access rules, and how customer data is used inside the product. Customers are responsible for keeping their account credentials safe and for the content they upload.

Access & authentication

Accounts are protected by email and password sign-in, with Google sign-in available. Sessions are managed by our authentication provider. School owners control which teachers and parents have access to their account, and roles (owner, teacher, parent) determine what each person can see and change.

Sensitive role assignments (such as admin) can only be granted by an existing admin, never self-assigned.

Data & storage

Customer data (students, attendance, lessons, observations, photos, messages, finance entries) is stored in our managed database and object storage. Row-level access rules restrict each record to the account that owns it and the members invited to that account.

Photos and other uploads are stored in private buckets and served through short-lived signed URLs, not public links.

Subprocessors & integrations

We rely on a small set of vendors to operate the product:

  • Lovable Cloud, for hosting, database, auth, storage, and serverless functions.
  • Stripe, for subscription billing and payment processing.
  • Google Maps, for converting your school address into coordinates so the daily calendar can auto-fill weather.
  • Open-Meteo, for daily weather lookups based on those coordinates.

We do not sell customer data, and we do not use student or family data for advertising.

Retention & deletion

Account owners can archive students, remove team members, and delete uploaded photos and records from inside the app. To request full deletion of an account and its data, contact us at the address below.

Security contact

To report a security concern or ask a privacy question, email hello@ornslearning.io. Please include steps to reproduce any issue you'd like us to investigate.

Last updated: August 7, 2026.