CrisisCheck ("we," "our," or "us") operates the CrisisCheck platform, including our web application, mobile interfaces, and related services (collectively, the "Service"). This Privacy Policy describes how we collect, use, store, and disclose information when you or your organization uses the Service.
This policy applies to school and district administrators, staff members, and any other individuals whose information is processed through the Service ("Subscriber Personnel"). It also describes how we handle student education records and guardian contact information provided by Subscriber institutions.
By using the Service, you agree to the collection and use of information as described in this policy.
Subscriber institutions that have entered into a Subscription Agreement with CrisisCheck are also governed by a Data Processing Agreement ("DPA") incorporated into that Agreement. Where there is any conflict between this Privacy Policy and the DPA with respect to the processing of institutional data, the DPA controls.
1. Information We Collect
Account and Administrator Information
When a Subscriber organization creates an account, we collect information such as the organization name, address, administrator name, email address, and billing details. Administrators may create additional staff accounts by providing names and email addresses for those individuals.
Personnel and Drill Data
The Service is designed to support emergency accountability operations. In connection with this purpose, Subscribers may upload or input personnel rosters, drill schedules, real-time check-in records, drill outcome data, compliance documentation, and incident notes. This data is provided by and belongs to the Subscriber institution.
Student Education Records
Subscriber institutions may import student roster information, including names and assigned homeroom or class data, for the purpose of personnel accountability during drills or emergency events. This information constitutes student education records under FERPA and is handled in accordance with Section 4 of this policy.
CrisisCheck does not collect information directly from students and does not knowingly create accounts for individuals under the age of 18. Student data is provided solely by and on behalf of the Subscriber institution.
Guardian Contact Information
Subscriber institutions may upload guardian (parent or legal guardian) phone numbers for the purpose of sending automated SMS notifications during emergency events or drills. This information is provided by the Subscriber institution and is used solely to deliver those communications. CrisisCheck does not independently collect or verify guardian contact information.
Usage and Technical Data
We automatically collect certain technical information when you access the Service, including IP address, browser type, operating system, referring URLs, pages visited, and timestamps of activity. This data is used for security monitoring, error diagnosis, and improving platform performance.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service;
- Deliver guardian SMS notifications authorized by the Subscriber institution;
- Generate compliance reports and drill documentation;
- Process billing and subscription payments;
- Respond to support requests and communicate service-related notices;
- Monitor for security incidents, unauthorized access, or abuse;
- Improve and develop platform features using aggregated, de-identified usage data.
We do not use student data, guardian contact information, or personnel records for advertising, marketing, or any purpose unrelated to providing the Service to the Subscriber institution.
3. Guardian Emergency Notifications (SMS and Email)
CrisisCheck uses Twilio, Inc. to deliver automated SMS messages to guardians on behalf of Subscriber institutions during emergency events or authorized drill notifications. Messages are sent only when triggered by an authorized administrator within the platform.
The Subscriber institution is responsible for ensuring that guardian phone numbers are accurate and that appropriate consent has been obtained under applicable law, including the Telephone Consumer Protection Act (TCPA) where applicable. CrisisCheck transmits this information to Twilio solely for message delivery and does not retain it for other purposes.
Guardians who receive an SMS and wish to opt out may reply STOP to the message. Opt-out requests are processed by Twilio in accordance with their messaging policies.
CrisisCheck also delivers the same category of emergency and drill notifications to guardians by email, using Twilio SendGrid Inc. as the primary email delivery provider and Resend as an automatic failover if SendGrid is unavailable. Guardian email addresses and alert content are transmitted to these providers solely for message delivery and are not retained by them for other purposes.
4. FERPA and Student Data
To the extent that the Service processes student education records on behalf of a Subscriber institution, CrisisCheck functions as a "school official" with a legitimate educational interest as defined under the Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. § 1232g, and its implementing regulations.
CrisisCheck will:
- Use student education records only to provide the Service to the Subscriber institution;
- Not disclose student education records to third parties except as necessary to operate the Service (e.g., cloud infrastructure providers) or as directed by the Subscriber;
- Not sell, rent, or use student education records for advertising or commercial purposes;
- Maintain appropriate technical and organizational safeguards for student data;
- Support the Subscriber institution in responding to FERPA-related requests from parents and eligible students.
The Subscriber institution retains ownership of all student education records and is solely responsible for compliance with FERPA, including providing appropriate notices to parents and eligible students regarding the use of third-party service providers.
CrisisCheck's status as a "school official" applies only where the Subscriber institution has designated CrisisCheck as such under its own annual FERPA notification and internal policies, and only within the scope of that designation. CrisisCheck operates under the direct control of the Subscriber institution with respect to the use and maintenance of education records for this purpose, consistent with FERPA's school official exception.
5. COPPA
CrisisCheck does not direct any portion of the Service to children under 13 and does not knowingly collect personal information directly from children under 13. Consistent with FTC guidance recognizing that a school may consent to the collection of a student's personal information on behalf of a parent when the information is used solely for a school-authorized educational purpose and no other, student data processed through the Service is provided entirely by Subscriber institutions acting as the parent's agent for that limited purpose — not collected by CrisisCheck directly from students. If you believe we have inadvertently received personal information from a child under 13 outside of the Subscriber institution relationship, please contact us at privacy@crisischeck.app and we will promptly address the matter.
6. Third-Party Service Providers
We work with a limited set of trusted third-party providers to operate the Service. These providers process data only as necessary to perform services on our behalf and are contractually bound to protect the information they handle. Current providers include:
- Supabase, cloud database and authentication infrastructure;
- Amazon Web Services, underlying cloud infrastructure (via Supabase), USA (us-east-1);
- Cloudflare, Inc., web application hosting and content delivery;
- Twilio, Inc., SMS message delivery for guardian notifications;
- Twilio SendGrid Inc., transactional email delivery, including emergency guardian alert email;
- Resend, transactional email delivery (failover for emergency alerts; primary for account, billing, and administrative email);
- Stripe, Inc., payment processing and subscription billing;
- Sentry, application error monitoring and diagnostics.
This list is kept in sync with Schedule C of our Data Processing Agreement, which institutional Subscribers may refer to for the complete, contractually binding sub-processor list.
We do not sell, rent, or share personal information with third parties for their own marketing or commercial purposes.
7. Data Retention
We retain Subscriber data for as long as the subscription is active. Following termination or expiration of a subscription, we retain data for 30 days to allow the Subscriber to export records. After this period, data is permanently deleted from our systems unless we are required by law to retain it longer.
Exception, Emergency Drill Records: Drill event logs and compliance documentation may be retained for up to seven (7) years following the date of the drill to satisfy state-mandated emergency drill record retention requirements. Institutional Subscribers should refer to their Data Processing Agreement (DPA Schedule D) for the complete retention and deletion schedule applicable to their account.
Anonymized, aggregated data (with no individual identifiers) may be retained indefinitely for product improvement and benchmarking purposes.
Billing records and transaction logs may be retained for up to seven years as required for tax and financial reporting compliance.
8. Data Security
We implement industry-standard technical and organizational measures to protect the data processed through the Service. These include encryption of data in transit using TLS 1.3, encryption of data at rest using AES-256, row-level access controls, multi-factor authentication requirements, and continuous security monitoring.
No system is completely secure. In the event of a data breach affecting personal information, we will notify affected Subscriber institutions within seventy-two (72) hours of becoming aware of the incident, and will notify relevant regulatory authorities where required by applicable law.
9. Data Ownership and Portability
Subscriber institutions own all data they import into or generate through the Service. Upon request, we will provide Subscriber data in a structured, machine-readable format within a reasonable time. Requests for data export should be submitted to support@crisischeck.app.
10. Cookies and Tracking
The Service uses session cookies and locally stored tokens to maintain authenticated sessions. We do not use third-party advertising cookies or cross-site tracking technologies. Analytics, if used, are limited to aggregate, anonymized data about platform usage and do not include student, guardian, or personally identifiable personnel data.
11. State Privacy Laws
Many states have enacted laws governing student data privacy and the use of educational technology services. CrisisCheck is committed to complying with applicable state student privacy laws, including but not limited to:
- Illinois Student Online Personal Protection Act (SOPPA), 105 ILCS 85, which imposes specific obligations on operators of online services used by K–12 students;
- New York Education Law § 2-d, governing the privacy and security of student, teacher, and principal data;
- Student Online Personal Information Protection Act (SOPIPA) and similar statutes in California and other states;
- Other applicable state student data privacy statutes enacted in states where our Subscriber institutions operate.
If your state imposes specific requirements on service providers handling student data, please contact us to discuss how we can support your institution's compliance obligations.
11a. Other State Privacy Laws (Non-Student Personal Information)
Separate from the student data privacy statutes described above, a number of states have enacted general consumer privacy laws — including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the Virginia Consumer Data Protection Act (VCDPA), and the Colorado Privacy Act (CPA) — that may apply to personal information we process about administrators, staff, and other individuals outside the student-data context described in Sections 4–5 above, such as billing contacts. Where these laws apply to you, they may provide rights to know, access, correct, delete, or opt out of certain processing of your personal information. To exercise any such right, contact privacy@crisischeck.app.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Material changes will be communicated to Subscriber administrators via email or in-app notice at least 14 days before taking effect. The "Last updated" date at the top of this page reflects the most recent revision.
Continued use of the Service following the effective date of any update constitutes acceptance of the revised policy.
13. Contact
Questions, concerns, or requests related to this Privacy Policy may be directed to: privacy@crisischeck.app
For data export requests or questions related to student education records, please contact: support@crisischeck.app
CrisisCheck
30 N Gould St Ste N
Sheridan, WY 82801
United States