Privacy Policy

isolace · effective 2026-08-15

isolace is software that learning centers use to check students in and out, keep a record of the day, and tell families about it. This page says what the system stores, who can see it, who else it is sent to, and how to make it stop.

Who the account holders are

Accounts belong to parents, guardians and center staff. A child never has an account, never signs in and is never addressed by the product. A child appears as a name on a roster their own center entered, and taps a lobby tablet that holds no session for them.

Accounts are created by a center for the people that center already knows. The apps do not self-provision an account: an identity a center has never heard of is refused rather than given a session, because the alternative is a stranger reaching a center's children.

Who is responsible for a child's record

The learning center decides what is recorded about its students and why. isolace holds and processes that record on the center's behalf and under the center's instructions — we are the center's service provider, not the owner of its students' records. A request to see, correct or remove a child's record goes to the center; we act on what the center asks for.

Because the record is created and held for the center, we do not seek consent from children, and we do not direct any part of the product at children. A center's own consent obligations to its families are the center's to meet; the product's job is to make them enforceable, which is the photo-consent flag below.

What the mobile apps collect

These are the same five types declared in the App Store privacy labels and in the app's PrivacyInfo.xcprivacy manifest. All are linked to the account. None is used for tracking.

Name

The signed-in adult's own name, as their center has it. Used to address them and to attribute a staff action.

Email address

The sign-in address. It is how the server finds which children a guardian is a guardian of. With Sign in with Apple this may be Apple's private relay address.

User ID

The account identifier the session is issued for, and — if you sign in with Apple — Apple's stable per-app identifier, stored so that changing your Apple ID's email does not lock you out. Never an advertising identifier; the apps never read one.

Photos and videos

Check-in photos and staff-captured moments, and the short weekly film assembled from them. Taken only where a family's photo-consent flag is on, and only after an explicit tap at the moment of capture.

Audio

Only the audio inside a moment video. There is no separate audio capture and no microphone use outside recording a clip.

The apps also register a push token so the center can notify a household, and store the session token and the last screen you were on in the app's own storage on your device.

What the center's own record holds

Separately from what the app collects about you, the center records what it needs to run: a student's name and the identifier the center uses, guardian contacts, attendance (arrival, departure, and who collected the child), curriculum level and progress the center enters, tuition status, and staff time-clock punches. Those are the center's records, entered by the center.

What is never collected

Tracking, advertising and sale of data

isolace does not track you. Nothing collected is used to follow a person across other companies' apps or websites, and nothing is shared with a data broker. Nothing is sold. Nothing is shared for advertising, with or without consent. The apps declare NSPrivacyTracking = false and an empty tracking-domains list, and there is no App Tracking Transparency prompt because there is nothing to ask permission for. We do not build advertising profiles of parents and we will not build them of children.

SMS consent and mobile information are never sold, rented, shared, transferred or disclosed to third parties or affiliates for their own marketing or promotional purposes. A phone number and the related consent record may be shared only with a messaging provider such as Telnyx when that provider is needed to deliver the messages the center is authorized to send. The provider may use that information only to provide messaging services for isolace and the center, not to market its own or another party's products or services.

Photos and consent

A photo of a person is taken only when two things are true: the family's consent flag is on, and the person holding the device tapped to confirm at the moment of capture. The flag is checked again every time a photo is shown or sent, so withdrawing consent today changes what goes out tomorrow. A child whose family has not consented checks in exactly like everyone else and is never shown anything that would tell them they are the one without photos.

Who else the data is sent to

Everything that is or describes a person goes to isolace's own servers at isolace.net. The apps hold no API keys and talk to no other host for that data. These are the only other parties involved, each doing one job:

Apple

Sign in with Apple (name and email scope only), and Apple Push Notification service, which carries a notification with no personal content in it.

Google

Google Sign-In, for accounts that use it — Google sees an email address, never a child. Google Cloud hosts the service: Firebase Authentication holds sign-in credentials, Firestore holds the records, Cloud Storage holds photos and videos, and Firebase Cloud Messaging delivers the push ping.

Telnyx

Delivers the text messages a center chooses to send its own families (for example "Ana checked in at 3:47pm"). It receives the phone number and the message, and nothing else.

Stripe

Processes the center's subscription and, where a center uses it, tuition payments. Card details go to Stripe and are never held by isolace. No payment happens inside the mobile apps.

Push notifications carry no content. A notification is an opaque ping; the app fetches what to display from isolace.net over the signed-in session. On iOS a notification service extension rewrites any payload before it is shown, so a child's name cannot arrive on a lock screen by way of a third-party message bus.

No content is sent to any AI or machine-learning service. Weekly films are assembled by our own code from the center's own photos; no model is prompted with, and no model is trained on, a child's name, face or record.

Separation between centers

One center cannot read another's students, attendance or photos — not for benchmarks, not for aggregated insight, not to train anything. Which center a request belongs to is derived from who is asking, never from anything the browser or app sends. A parent's account reaches the children they are a guardian of and nothing else.

Deleting your account

In the app: More → Account → Delete account. It completes inside the app — no email, no phone call, no support ticket — and it is immediate and irreversible. It destroys your sign-in credential, your name, email address and profile, your registered devices and queued notifications, and your saved app settings.

It does not delete the center's record of a child. A child's enrollment and attendance history is an education record that belongs to the center and that the center is obliged to keep; one guardian deleting their own login must not erase a child's history, including a co-guardian's child's. To withdraw a child, contact the center.

A deletion is logged so a center can confirm one happened. That log holds the account identifier, a timestamp, counts, and a one-way hash of the email address — not the address itself. A deletion log that stored the address would be a copy of the thing just deleted.

Center directory

Separately from any account, isolace keeps a directory of learning-center businesses — the kind of public business-contact information a directory holds — used to reach operators about the product. It contains no student or family data. To be removed from it, use the removal form or write to hello@isolace.net.

Security

Traffic runs over HTTPS. Credentials for every service live server-side in a secrets manager; no client — browser, app, or lobby tablet — ever holds one. A lobby tablet in kiosk mode can check students in and out at its one center and can do nothing else: no roster export, no billing, no settings, no other center. Staff time-clock punches are written append-only.

Regions

The apps and the service behave the same in every country and region. There is no region-specific feature, content or data practice. Data is stored on Google Cloud infrastructure in the United States.

What this page does not yet contain

Specific retention periods, a data-processing agreement, a named governing law, and formal GDPR / PIPEDA / CASL positions are not stated here, because they have not been reviewed by a lawyer and inventing them would be worse than their absence. If your center, insurer or franchisor needs one of those documents, write to hello@isolace.net and you will get a straight answer about whether it exists yet.

Changes

If this page changes in a way that affects what is collected or who it goes to, the effective date above changes with it and centers are told.

Contact

Privacy questions: hello@isolace.net. Questions about a particular child's record go to that child's center, which holds it.

isolace is an independent product built for the operators of Kumon-branded learning centers. It is not affiliated with, endorsed by, sponsored by or operated by Kumon. No Kumon trademark is used in the isolace apps, and a center's own name and branding reach the product only as data that center entered about itself.