Privacy and security

Privacy Policy

How CC Community Hub protects the information your community puts into it, who can see that information, and what you can do with it.

Effective 28 August 2026. Last updated 28 August 2026.

At a glance

  • Your community's information is visible only to your community. Separation is enforced by the database itself, not by the screen.
  • No card numbers, bank accounts, or other payment details are stored, for any family, tutor, or director.
  • Nothing is sold, rented, shared with data brokers, or used for advertising.
  • There is no tracking, analytics, or advertising software anywhere in the app or on this website.
  • Your records stay yours. Export them whenever you like, and have them deleted on request.

Who this policy covers

CC Community Hub is a subscription app that homeschool community directors use to run their communities. This policy applies to everyone who uses it: directors, tutors, and member families, along with anyone who submits a membership application through a community's public application page.

Each community is kept entirely separate from every other. The director of a community controls the information her community enters, and decides what is shared internally within it, such as a member directory or a calendar.

Where information is stored and how it is protected

Data is held in a managed Postgres database operated by Supabase and hosted on Amazon Web Services infrastructure in the United States. Supabase acts as a data processor, handling the information on instruction, and states in its privacy policy that it will not access database contents without permission. Supabase is SOC 2 Type 2 audited and ISO 27001 certified.

Uploaded files, including receipts, documents, and photographs, are held in private storage buckets that are not publicly accessible and cannot be reached by an unauthenticated link.

The database is backed up daily, so an error or an outage does not cost a community its records.

Should a security incident affect a community's information, the affected directors are notified directly and promptly, with a description of what occurred, what information was involved, and what is being done in response.

Information collected

Every record in CC Community Hub is entered by a director, a tutor, or a parent in that community. No information is purchased, imported from outside sources, or gathered in the background.

  • Family and contact details. Family name, parent names, phone numbers, email addresses, and a mailing address where a director records one.
  • Student details. First name, last name where it differs from the family, date of birth, program and class placement, and any note a parent adds for a tutor, such as an allergy.
  • Emergency contacts entered by a director or a parent.
  • Financial records for the community's own fees. What a family was charged, what has been paid, the payment method a family reports, and any related note. These are bookkeeping records, not payment instruments.
  • Uploaded files. Supply receipts and their images, community documents, and photographs families choose to add for used books or a member directory.
  • Community activity. Attendance, signups, announcements, calendar dates, class notes, lunch orders, and similar records a community keeps.
  • Sign-in credentials. Director and tutor account passwords, and family sign-in PINs, are stored only as cryptographic hashes. Passwords are handled by the authentication service and PINs are hashed with PBKDF2-SHA256 at 100,000 iterations. Neither can be read back out of the system.

How information is used

Information in CC Community Hub is used for one purpose: operating the community that entered it. That includes displaying rosters and schedules, calculating and tracking fees, sending a community's own announcements, and providing technical support when something needs fixing.

Community information is never used for marketing, never sold or rented, never shared with data brokers or advertisers, and never combined across communities to build profiles of any kind.

Who can see what

Access is enforced in the database through row-level security policies, so a request for information a person is not entitled to is refused at the data layer. It does not depend on a screen choosing what to display.

  • Communities are fully separated. No director, tutor, or family in one community can reach any record belonging to another.
  • Families see their own household's information, together with whatever the community publishes to its members, such as the calendar, announcements, and a directory the community has chosen to turn on.
  • Tutors see the students in their own class and the tuition records for those students.
  • Directors see their own community, and may delegate a single area, such as attendance or lunch, to a helper without granting access to anything else.
  • Visitors who are not signed in can reach no personal information at all. The only publicly readable page is a community's application form, which displays that community's fee schedule and policies and contains no personal data. This was last verified on 19 August 2026 by issuing the application's data requests as an anonymous visitor; all returned empty.

Administrative access

As with any hosted software, the operator of the service can access production data. That access is limited to one person, the developer who builds and maintains CC Community Hub, and is used only to provide support, diagnose faults, and keep the service running correctly.

It is never used for marketing, never shared with anyone else, and never used to contact your families. CC Community Hub is independently built and operated. It carries no advertising and has no business model that depends on your information.

Payments

Community fees. CC Community Hub records what a community charges and what has been paid. It does not process money. Families pay through whatever method the community already uses, such as its own Cheddar Up or Venmo account, and payment details are handled entirely by that provider.

Subscriptions. A director's subscription is billed through Stripe. Card details are entered on Stripe's own secure checkout and are never transmitted to or stored by CC Community Hub. The only billing data held here is Stripe's reference identifier for the subscription, which tells the app that a community is active.

Children's information

CC Community Hub holds the information a homeschool community needs in order to run classes: a child's name, date of birth, class placement, and any note a parent chooses to share with a tutor.

Children do not have accounts and do not sign in. Every login belongs to a parent, a tutor, or a director. No information about a child is publicly accessible or shared outside the community, and a parent can review and correct everything held about her own children directly from her own screen.

Messages and notifications

When a director or tutor sends an invoice or a reminder, CC Community Hub prepares the message and hands it to the sender's own text or email application. The message is sent by that person, from their own device and their own address. The app does not send mail on anyone's behalf and does not retain copies of these messages.

The service itself emails a director only about her own account: a welcome message when her community is created, and a password reset when she asks for one. These go to the address she signed up with and to nobody else.

Announcements can be delivered as notifications to member devices using the standard web push service built into the device's browser. Any member can turn notifications off on her own device at any time.

Advertising, analytics, and tracking

There is no advertising anywhere in CC Community Hub, and no advertising or analytics software in the app or on this website. No cookies are used to track visitors, no behavioral profiles are created, and no information is shared with advertising networks.

Service providers

CC Community Hub relies on a small number of established providers, each performing a specific technical function:

  • Supabase, on Amazon Web Services, for the database, authentication, and file storage.
  • Stripe for subscription billing.
  • Netlify for hosting the application and this website.
  • Public code libraries loaded by the app from jsDelivr and Cloudflare, and a web font on this website from Google Fonts. These deliver software and typefaces only. No community information is sent to them.

No other third party receives community information.

Retention, export, and deletion

Information is retained for as long as a community uses CC Community Hub, since a community's records are the point of the service. A director can export her community's roster, fees, and receipts to a spreadsheet at any time, without asking for assistance.

On request, a community's data will be exported and its records permanently deleted rather than archived. Requests are answered by email at the address below.

Reviewing and correcting information

Parents can view and update their own contact details, their children's details, and their emergency contacts from within the app. Directors can correct any record in their own community. Anyone who believes information held about them is inaccurate can ask their community's director to correct it, or contact us directly at the address below.

Changes to this policy

If this policy changes in a way that materially affects how community information is handled, directors will be notified by email and the effective date at the top of this page will be updated.

Questions about privacy or security?

Specific questions are welcome, including detailed ones, and they are answered directly.

Email us

Kinzi Herron · CC Community Hub

Back to the main page