$ Privacy Policy

> Effective Date: September 20, 2026

privacy-policy.md

This Privacy Policy explains how Fig STEM, Inc. ("Company," "we," "us," or "our") collects, uses, stores, and protects information when you visit or use the FigLab service ("Service" or "Services") at figlab.app.

1. Information We Collect

• Account and Authentication Information: When you register directly or authenticate via Single Sign-On (such as Google, Microsoft, or Apple), we collect your name, email address, and unique provider identifier. If you set a password, we store only a secure hash of it, never the password itself. If you request a sign-in link via email, we record that the link was requested and used.

• User-Generated Content and Project Files: We may collect and store the content you create while using the Service, including code snippets, project configurations, workspace notes, terminal logs, and lesson progress to enable cloud storage and multi-device access.

• Lesson Progress: We store information about your progress in each lesson, such as your current page and step, answers and scores from any Learning Check quizzes or challenges, whether you finished the lesson, and when you use our AI hint system, Figgy. We collect this data to enable cross-device progress tracking. While you work through a lesson, we may, in certain cases, record time-based interaction information, such as when you start and finish lessons, and time spent on each page.

• Classes: If you join a class via a code or are externally enrolled, we record your membership and the timestamp of when you joined. Class join attempts are logged to prevent abuse. If you create or manage a class, or are otherwise deemed a Class Administrator, we store the class's name, join code, lesson due dates, and your favorite lessons.

• Figgy (AI Code Help): When you interact with Figgy, our AI hint system, for help, we may send the contents of your code editor, the lesson task, challenge results, your program output to our AI provider to generate an answer. We keep a record of each request, including the type of help requested, the lesson and page, input and output, and response time. We also collect your interaction frequency with Figgy to enforce usage limits.

• Events: If you reserve a seat or join the waitlist for a FigLab-associated event, we may collect your name, email, and any additional details necessary to create an account for you. When you attend the event, you may be required to sign a liability release waiver, which may require you to provide additional information.

• Communications, Inquiries, and Feedback: If you contact customer support, report a bug, submit feedback, or participate in a user survey, we collect your message content, contact details, and any diagnostics or screenshots you voluntarily provide to assist you.

• Service Usage and Interaction Data: We collect aggregated, non-personally identifiable telemetry regarding how you interact with the Service using a privacy-focused analytics service (Umami). This includes page views, feature usage patterns, referring URLs, browser and device specifications, and general regional location. Umami operates cookieless without cross-site tracking or personal profiling.

• Payment & Transaction Details: If you purchase a paid tier, your payment transactions are processed directly by Stripe. Fig STEM, Inc. does not receive, store, or process raw payment card numbers or sensitive financial identifiers.

2. Tracking & Cookies

We do not use third-party advertising cookies or cross-site tracking technologies for our Services.

We use browser local storage and session tokens for strictly necessary and functional activities, such as maintaining your authentication, preserving your active workspace, remembering your preferences, and recording referral codes where applicable.

3. How We Use Information

We use your information strictly to deliver and secure our Services, provide customer support, prevent misuse and abuse, and send essential transactional notices (receipts, password resets).

If you create an account or make a purchase with a referral code attached, we use the referral code to credit referrers for that action. Referrers do not have access to any personally identifying information as a result of your action.

If you reserve a seat or join a waitlist for an event, your name and email may be used to contact you about any updates related to the event and to verify your attendance. If you sign a liability release waiver, any information collected on the form may be shared with the event venue in accordance with their policies.

If you are enrolled in a class, we may permit Class Administrators to view your name and lesson progress, as described in the Lesson Progress section under "Information We Collect." Class Administrators may see how often you interacted with Figgy but are not able to view questions and responses. If you are removed from a class, that class's administrators will no longer be able to see any additional activity. To be removed from a class, ask your Class Administrator or contact support@figstem.net.

We may send occasional product updates to the email address linked to your account. You may opt out at any time.

We do not sell, rent, or trade your personal information to third parties for marketing purposes, and we do not use your data to train AI models.

We may provide information as required by law to comply with legal requests.

4. Service Providers

We share data with the following providers only as needed to operate our Services and fulfill your requests: Cloudflare (hosting, routing & security), Supabase (database and authentication), Stripe (billing), Resend (email delivery), Umami (analytics), Groq (AI processing for Figgy), and Google, Microsoft, and/or Apple (sign-in, if you choose them).

When you interact with Figgy, Groq receives only the necessary information to fulfill your request, such as the contents of the code editor and lesson task. We do not provide your personal information to Groq, but Groq may receive such data along with any additional details you include in the code editor. Groq may use web search tools to answer, and it processes requests under its own privacy terms.

5. Data Retention & Deletion

We may keep the information we collect for as long as your account is active. We retain raw inputs and outputs from your interactions with Figgy for seven days from the interaction time to ensure safety and prevent abuse.

To update your information or delete your account, email support@figstem.net. When we delete your account, we remove your profile, progress, lesson activity, class memberships, event registrations, and referral records from our production databases. Any feedback you provided may be kept to improve the Service, but is no longer linked to an account. Figgy interaction records will also be kept in accordance with our retention policy, but are no longer linked to an account. Backups are purged on our normal backup cycle.

Data residing directly on your local hardware (e.g., a Raspberry Pi) is outside our access or control and cannot be deleted by us.

We may keep payment records as required by law.

6. Security & Breach Notification

We implement standard technical and organizational measures (including HTTPS/TLS encryption and restricted database access) to protect your personal data.

In the event of a confirmed data breach impacting unencrypted personal data, we will notify affected account holders via email in accordance with applicable laws.

7. Children's Privacy

Our Services are designed for individuals aged 13 and older, and we do not knowingly collect information from those under age 13. As such, you must be at least 13 years old to create an account and interact with our Services.

If we discover that an individual account was created by a child under 13, we will promptly deactivate the account and delete any associated data. Contact support@figstem.net to report an unauthorized account.

8. Geographic Scope & Transfers

FigLab is hosted and operated in the United States.

If you access the Service from outside the United States, your information will be transferred directly to and processed in the United States under the protections outlined in this Privacy Policy.

9. Changes & Contact

We may update this Privacy Policy periodically by updating the "Effective Date" above.

For questions or data requests, contact us at support@figstem.net.