txtra Paper Rush

Cameron Low · Ontario, Canada

Privacy and classroom data

Effective 19 September 2026

Who is responsible

Txtra is a product operated by Cameron Low, an individual in Ontario, Canada. This notice covers txtratyping.com, optional cloud accounts and hosted classrooms. Contact hello@cameronlow.com for privacy questions, access, correction or deletion help.

Local play, a cloud account and a classroom are different choices. You can use local play without creating an account or joining a class. No payments are accepted, and there are no advertising or third-party analytics integrations.

Local play and private writing

Your browser stores named player profiles, scores, settings, progress, typing aggregates and classroom retry receipts. You can export a player save or erase a local profile in Settings. Other people using the same browser may be able to open its local profiles, so use a nickname on shared devices.

Custom Copy and Freewrite prose stay in memory and are excluded from cloud saves and classroom results. Raw keystrokes are not sent as classroom records. Clearing site data removes local profiles, cached offline files and pending receipts; export progress first if you want to keep it. Browser or device backups may contain their own copies.

Optional cloud accounts

An account stores a username, one-way password and recovery-code hashes, session records, timestamps and a filtered player save containing progress, scores, settings and typing aggregates. No email address is needed. Essential cookies support sign-in; the service also keeps a one-way browser identifier with session records.

Signing in combines local and cloud progress. Account deletion removes active account, session and cloud-save records, but leaves the local profile on your device unless you erase it separately. Sessions expire after 30 days. Accounts remain until deleted. Recovery uses the code shown when it is created; there is no email password-reset service. Keep that code private.

Classroom information and visibility

A teacher supplies a class label and assignment content. A student joins with a class code, display name and pencil-pal colour. The server stores membership credentials, assignment progress, speed, accuracy, words completed, baseline, sticker identifiers, recent activity and opaque result IDs that prevent duplicate submissions.

Teachers can view their roster and aggregate results. Students can view their own record. A peer improvement board shows display names and improvement values only when the teacher enables it and the student opts in. A projector or shared screen can expose what its operator displays to people in the room. Do not use full names or identifying assignment text when a nickname will do. A shared class code permits joining; distribute it only to the intended class.

Children, parents and schools

Children should ask a parent, guardian or responsible teacher before using cloud or classroom features. Local play is available without sending a player save to an account. A school must establish its authority to use the hosted service, inform families and obtain parent or guardian consent where required before adding students. A teacher’s checkbox acknowledges the notice; it is not universal consent on behalf of every child.

For children unable to understand the privacy decision, a parent or guardian must be involved. Canadian privacy guidance generally treats children under 13 as unable to give meaningful consent themselves. Older youth also need an explanation they can understand. Contact Cameron before institutional use if your school requires a data-processing agreement, different retention or a particular hosting location.

Txtra is not certified under COPPA, FERPA or school procurement policies. School authorization and any required parental-consent process need separate review; this notice does not create that authorization. Parents can contact Cameron or the teacher for access, correction or removal of a child’s records.

Retention, recovery and deletion

Classes become eligible for removal after 180 days without activity and are purged during classroom API maintenance. A student can leave and remove their roster record; a teacher can remove a student or delete the class. Active data and the current recovery snapshot are updated, and short-lived deletion journals prevent retained snapshots from restoring those records.

Classroom recovery snapshots use a 30-day retention window, with expired files removed on successful writes or routine maintenance. These local JSON snapshots are access-restricted; they are not individually encrypted by the classroom software. Encrypted database backups for cloud accounts are made separately on a daily schedule and normally retained for about a month. A failed cleanup or incident can require operator follow-up. Deleted records may remain in those backups until expiry; a restore must respect deletion requests.

Damaged classroom files kept for incident investigation and any infrastructure-provider backups require separate operator review. There is no verified instant-erasure promise for every backup. Contact Cameron for a complete request or if an in-product deletion fails. We verify ownership proportionately and explain any necessary legal or security retention.

Hosting, logs and contact messages

Txtra uses Cameron-managed servers on Hostinger infrastructure, including servers in the United States. Classroom data and account databases are on managed infrastructure, not exclusively on your device. Information processed outside Canada may be accessible under the laws of those countries.

Hosting receives IP addresses, request paths, browser information and timestamps to deliver and secure the service. Normal web-server logs rotate daily with 14 rotations retained; necessary incident records may be kept longer. These records are not used for student advertising or AI-model training.

Contact email is forwarded through Cloudflare to Google’s email service. Messages are used to answer the inquiry and handle follow-up or necessary legal records, then reviewed for deletion. Do not include passwords, recovery codes or identifiable student lists in your first message. Sending an inquiry does not subscribe you to marketing.

Questions and changes

Email hello@cameronlow.com to withdraw consent where applicable or request access, correction or deletion. You may also contact the Office of the Privacy Commissioner of Canada. Material changes will be reflected in the effective date and communicated with additional notice or consent where required.