Skip to content
Nullgen AI Blocker

Trust Center

Data handling and privacy

Whose data we hold, how long it lives, what happens to student and child data, and how our work lines up with FERPA, COPPA, and GDPR.

Last reviewed: September 23, 2026

Whose data

  • Administrators

    The parent, teacher, or IT administrator who creates the Pro account: email address, name, and sign-in method.

  • Managed people

    Children, students, or staff an administrator adds so devices can be assigned: a name and, optionally, an email address that receives only request notices. No logins are created for them.

  • People using a protected device

    The extension and the app do not collect names, email addresses, or browsing activity from the people using a protected device. A device is linked to a name only when an administrator assigns it. The only free text a managed user can send is the optional justification on an access request.

Retention and deletion

  • Administrators delete their account from Dashboard → Settings, or from the Mac or iOS app when signed in with Apple. Deletion requires confirmation and cannot be undone.
  • When the account owner deletes, the organization goes with it: memberships, managed people, device enrollment, access requests, and policies.
  • Deleting a device revokes its credentials immediately. Credentials that go unused for 90 days expire on their own.
  • Unsubscribing stops marketing email at once; transactional notices continue only while an account exists.
  • Prompt text, keystrokes, browsing history, and DNS lookups are never collected, so there is nothing of that kind to retain or delete.

Schools and student data

  • No student accounts, logins, or profiles are created by the extension or the app.
  • No student prompt text, browsing history, or lookups are collected.
  • The school administers the deployment, decides what is blocked, and owns its policy configuration, deployment records, and metrics.
  • Nullgen processes that data only on the school’s behalf and only to provide the service: no advertising, no profiling, no other use.
  • Schools can review, export, or delete data for their deployment by writing to privacy@nullgen.ai.

Privacy law compliance

FERPA, COPPA, and GDPR

Nullgen complies with the requirements of FERPA and COPPA and is aligning with the requirements of GDPR. Certification under the programs that exist for these laws is on our roadmap, and Nullgen is not certified under any of these programs today.

  • FERPA

    Compliant
    What the law asks
    Schools control disclosure of education records and hold vendors to using student data only for the school’s purposes.
    How Nullgen is designed for it
    No student accounts, no prompt or browsing data, deployment data processed only on the school’s behalf, and deletion on request.
    On the roadmap
    A student-privacy seal from a recognized program.
  • COPPA

    Compliant
    What the law asks
    No collection of personal information from children under 13 without verifiable parental consent, or only under a school’s authorization for educational purposes.
    How Nullgen is designed for it
    The extension and the app collect nothing that identifies a child. Family child profiles are created by the parent, hold a name and an optional email address, and receive only request notices.
    On the roadmap
    Participation in an FTC-approved COPPA Safe Harbor program.
  • GDPR

    In progress
    What the law asks
    A lawful basis, data minimization, data-subject rights, processor contracts, and safeguards for international transfers.
    How Nullgen is designed for it
    Minimization by design, self-service deletion, and the rights described in the GDPR section of the Privacy Policy. Nullgen AI Blocker is distributed in the EEA and the United Kingdom.
    On the roadmap
    A Data Processing Addendum with Standard Contractual Clauses for organizations that need one.

Service providers

Personal data is shared only with these providers, and only to operate the service. The Privacy Policy carries the same list.

Service providers
ProviderWhat it does for NullgenData involved
Amazon Web Services (AWS)Hosting and account authentication in the United StatesAll account, organization, device, policy, and request records
StripePayment processing and subscription billingBilling details entered at checkout; Nullgen receives identifiers
AppleSign in with Apple, and App Store billing for Family subscriptionsEmail address (possibly relayed), name if shared, subscription identifiers
ResendTransactional email, product notices, and product marketingEmail addresses and message content
SentryCrash and error reportingTechnical error details; no prompt text or browsing data
GoogleWebsite analytics and advertising measurement, optional Google sign-in, and YouTube video embedding on the websiteAnalytics identifiers subject to consent; sign-in email address and name; video playback data once a video plays

The Privacy Policy and Terms of Service are the binding documents. These pages explain how the product works so a security review can move faster.

Privacy Policy · Terms of Service