A short privacy policy, because there is little to say
tilo has no server, no accounts and no analytics. This page explains what that means in practice, in the terms a school data protection officer will want them.
What is stored, and where
| What | Where it lives | Who can see it |
|---|---|---|
| A child's or student's name if you type one onto a header |
Drawn onto the page, and kept in your own browser's local storage so your work survives a refresh | Only you, on that device |
| Your saved worksheets | Your browser's local storage | Only you, on that device |
| Your chosen settings doorway, text size, paper size |
Your browser's local storage | Only you, on that device |
| A shared link | The worksheet definition is encoded into the URL itself | Anyone you send the link to. If you put a name on the sheet, the name is in the link — so treat those links the way you would treat the worksheet. |
Clearing your browser data deletes all of it. There is no copy anywhere else, and no way for us to retrieve it — which also means we cannot recover your saved worksheets if you clear them.
What is not happening
- No accounts. There is nothing to sign into, so there are no credentials and no password database.
- No analytics. No page-view tracking, no session recording, no heatmaps, no product telemetry.
- No advertising and no third-party scripts. The page loads no external resources whatsoever.
- No cookies. Local storage is used for your own saved work; no cookies are set.
- No email collection. There is no newsletter signup, no gate and no lead capture.
- No data sales or sharing. There is no data to sell or share.
You can verify all of this without taking our word for it: open the browser's network tab, or simply disconnect from the internet. The app keeps working, which it could not do if it were sending anything anywhere.
Children's privacy
tilo is designed to be used by an adult — a parent or a teacher — who prints a worksheet for a child to complete on paper. Children do not use the application, do not create accounts and do not enter information into it.
Because no personal information is collected from anyone, the obligations that regimes such as COPPA and FERPA place on operators — around notice, parental consent, access, correction, retention and deletion — have no data to attach to. A child's name typed onto a worksheet header stays on the device it was typed on.
Hosting and logs
The pages have to be served from somewhere, and whichever host serves them will keep standard web server logs — typically IP address, timestamp and requested file — for a short period, as every website does. That is outside the application and unrelated to worksheet content. No worksheet data is ever included, because none is sent.
Changes to this page
If the product ever gains accounts, sync or any feature that genuinely requires a server, this page will change before that feature ships, and the change will be listed on What's new. The current position is a design decision, not an oversight, and it will not be reversed quietly.