Privacy Policy

Last updated: August 25, 2026

SurveyorSim is a browser-based land surveying simulator with an optional classroom tier for instructors and their students. This policy describes exactly what we collect, why, and what we will never do with it. It is written to be read, not skimmed — it is short because we collect very little.

The short version

What we collect

WhoWhatWhy
Instructors Email address, a password (stored only as an argon2 hash), plan level, and the classes, rosters, and assignments they author. Sign-in, account verification, and running their classes.
Students The display name their instructor put on the roster; an 8-character sign-in code the instructor issues them (held in readable form so it can be reprinted, revealed or emailed to that student — see Security); a self-chosen PIN (stored only as an argon2 hash); optionally an email address, but only if their instructor added one; coursework — simulated measurements, digital field book entries, attempt telemetry from inside the simulator — and grades. Letting a student sign in to their own seat — with their personal code and their PIN — and letting their instructor see and grade their work. An email address, where one was added, is used for one thing only: sending that student their own code. Nothing else.
Everyone Standard transient server logs, including IP addresses, kept briefly for rate limiting and abuse prevention. Keeping the service up and secure.

We never ask a student for an email address, a date of birth, a photo, a location, or any contact information, and there is no field anywhere in the product where a student can enter them. The one optional exception is instructor-supplied: a teacher may add a student's email address to the roster so the service can send that student their own sign-in code. It is optional per student, used for nothing else, never shown to classmates, and deleted with the roster row. Classes work end to end with no addresses at all — the codes can simply be printed and handed out. Instructors are invited to use nicknames or aliases on rosters — the service never needs legal names.

What we never do

For schools: the school-official basis (FERPA)

Where a class roster comes from an educational institution's records, SurveyorSim operates as a school official with a legitimate educational interest under 34 CFR §99.31(a)(1):

For Texas schools: the Student Privacy Act

Where a Texas school district uses SurveyorSim for a school purpose, we act as an operator under Texas Education Code, chapter 32, subchapter D (HB 2087, in force since 1 September 2017). We hold to it as policy whether or not a particular district asks:

We collect almost none of the covered information a district usually worries most about: no date of birth, no demographics, no attendance, conduct, health or transcript records, and no parent or guardian contact details. There is no field anywhere in the product that asks for them. The single exception is an OPTIONAL student email address, which only an instructor can enter, which exists solely so the service can send that student their sign-in code, and which a class never has to use at all.

If your district requires a signed data privacy agreement before a tool may touch student records — the Texas Student Data Privacy Agreement (TX-NDPA), or your own — write to us and we will work through it with you.

Age

SurveyorSim is built for college and career-technical surveying programs. It is intended for users 13 and older, or younger students only where a school has authorized use under its own authority consistent with COPPA guidance. We do not knowingly collect personal information from children under 13 outside that school authorization, and we collect no birth dates from anyone.

Service providers

These are every third party your browser or our server contacts. The first two hold account data on our instructions; the rest are network services that see an IP address and nothing about who you are.

Multiplayer crews connect browser-to-browser (WebRTC). Two kinds of helper are involved, and neither is used at all if you play solo:

The optional real-world site picker involves two different kinds of request, and the distinction matters for what anyone can see:

No account, roster, or coursework data is sent to any of them — only the coordinates of the place being loaded.

Where we operate

SurveyorSim is built, hosted, and offered in the United States. The application and its database run in a US region; the product is in English, defaults to US survey feet, and is aimed at US college and career-technical surveying programs. We do not direct it at, advertise it in, or seek users from the European Economic Area, the United Kingdom, or Switzerland — and we monitor no one's behaviour anywhere, because there is no advertising, no analytics, and no tracking in this product at all.

If your institution is in the EEA, the UK, or Switzerland and wants to use SurveyorSim with students, write to us first at rickasmith@gmail.com, so the right agreement is in place before any student data exists.

Retention and deletion

Security

All traffic is encrypted in transit (TLS). Passwords and student PINs are stored only as argon2 hashes and cannot be recovered — only reset. A student's 8-character sign-in code is the one deliberate exception: it is stored readably, because an instructor has to be able to look it up and hand it over again when a student loses the slip it was printed on. That is safe by design rather than by accident — the code alone opens nothing, since signing in also needs the PIN, and resetting a PIN issues a new code, which stops the old one working. Accounts lock after repeated failed sign-ins. The single most effective protection is structural: we minimize what exists to breach — no legal-name requirement, no payment card data (there are no paid checkout flows in the product today), and student email addresses only where an instructor deliberately added one.

Changes and contact

If this policy changes in a way that affects student data, we will post the change here with a new date, and material changes will be announced to instructors on sign-in. Questions, deletion requests, or institutional agreements: rickasmith@gmail.com.