Privacy & Data Protection Policy
overlayroot="tmpfs:recurse=0". No user personal data, browsing history, downloaded files, or session cookies are ever written to physical disk storage. All transient data is instantly and permanently destroyed upon power-off or reboot.
1. Introduction & Educational Commitment
Lab Kiosk OS ("Platform", "we", "us") is architected specifically for organizations, universities, and educational training laboratories. We strictly adhere to user data privacy standards, including the Family Educational Rights and Privacy Act (FERPA) and the Children's Online Privacy Protection Act (COPPA).
2. What We Do NOT Collect
We believe workstation fleets should be safe, distraction-free educational spaces. Specifically:
- No User Accounts: Users do not create accounts, enter email addresses, or log into Lab Kiosk OS.
- No Persistent Browsing Profiles: Browser cookies, local storage, history, and cache exist solely in volatile RAM and are erased upon reboot.
- No Keystroke Logging: We do not log user keystrokes, personal communications, or search queries.
- No Commercial Profiling: User activity is never tracked for advertising, profiling, or behavioral analytics.
3. Information Collected for Lab Management
To enable operators and lab administrators to oversee room learning, the platform ingests minimal operational telemetry:
- Workstation Identifiers: Workstation hostname (e.g.
PC-01), internal IP address, and connection timestamp. - Live Screen Frames: Low-resolution preview frames, taken only while an operator has that workstation on screen and relayed to that operator. They are never saved to storage or shared.
- Errors & Warnings: Problems a workstation reports about its own system, such as an update that failed and was rolled back, kept for 90 days for the organization's administrators.
- Active Navigation Target: The current active page URL to reflect whether users are on the designated educational assignment.
4. Organization Administrator Accounts
Organization administrators and operators provide an email address, organization name, and password for administrative access. Passwords are cryptographically hashed using PBKDF2-HMAC-SHA256 (100,000 iterations). Administrative account details are stored securely in Cloudflare D1 and are never sold or shared.
5. Automatic Bug Reports (Optional)
An organization's administrator may turn on Automatic Bug Reports. Only then, the workstation problems listed in Errors & Warnings are sent, with network addresses, host names, e-mail addresses and identifiers masked, to an AI model on Cloudflare Workers AI for triage, and published as issues in a GitHub repository, which may be public. Organization names, workstation names, staff accounts, browsing and screen content are never sent. The Automatic Bug Report Terms describe exactly what is sent and how to have a report removed.
6. Service Providers
The Platform runs on Cloudflare, Inc. ("Cloudflare"), which processes the data described in this policy as our service provider, under the Cloudflare Privacy Policy and the Cloudflare Customer Data Processing Addendum. Cloudflare may process it in its data centers worldwide. The Cloudflare services we use, and what each one handles:
- Cloudflare Workers: runs the Platform. Every request to the consoles, the User Portal and the workstation interface passes through it, and request logs (including IP addresses) are kept for a sample of about one in ten requests for troubleshooting.
- Cloudflare D1: the database: organization and staff accounts with hashed passwords, the workstation registry, allowlists, User Portal apps, settings, the audit log, and errors and warnings.
- Durable Objects: each organization's live state: which workstations are connected, the command queue (commands expire after 60 seconds), and the screen frames relayed to a watching operator, which are never stored.
- Queues: audit log entries on their way to the database.
- R2: audit log entries older than 180 days, archived.
- Workers Analytics Engine: counts of workstation connections and disconnections per organization.
- Rate Limiting: counts of requests per IP address in front of sign-in, registration and workstation enrollment.
- Workflows and Cloudflare for SaaS: an organization's custom domain name and its TLS certificate.
- Cloudflare Tunnel: carries the remote-control sessions an operator opens to a workstation.
- Workers AI: only for organizations that turned on Automatic Bug Reports, the masked problem reports described in section 5.
Two other providers are involved:
- GitHub, Inc.: only for organizations that turned on Automatic Bug Reports, the masked reports are published as GitHub issues under GitHub's own terms and privacy statement.
- Google Fonts: the consoles and public pages load the Inter and JetBrains Mono typefaces from Google, which receives the visitor's IP address and browser details when the fonts are requested.
7. Super Administrator Privacy Restriction
Platform Super Administrators are architecturally restricted from accessing individual organization consoles, user portal configurations, or live workstation telemetry. Super administrator privileges are restricted strictly to tenant approval, status management, and the platform's own demo organizations used for testing (web-demo, local-demo and docker-demo).
8. Contact Us
If you have questions regarding our privacy practices or educational data protection compliance, please contact our data protection team at privacy@akbhoi.com.