This Privacy Policy covers three things run by Douglas Matheny / Capital High Robotics (together, "we," "us," or "the Program"):
capitalhighrobotics.us address, the public website for the robotics program.[INVENTORY SYSTEM DOMAIN], a login-restricted internal tool for tracking parts, orders, and usage. It is not public and is not intended for use by anyone outside the team.The short version: The App and the Website have no user accounts, run no data-collecting server of ours, use no analytics or advertising SDKs, and sell no data. The App stores everything you enter locally on your device, and the Website is a static, informational site. The Inventory Manager is different: it's a private, login-only tool for authorized team members, and it does have accounts, a session cookie, and a database, described in Part 3 below. None of the three properties runs analytics or advertising software, and none of them sells or shares data with anyone.
The App stores the following locally on your device only, using standard device storage. This data never leaves your device unless you personally choose to export or share it (e.g., using the App's backup/export or QR-share features):
You can delete this data at any time by clearing the App's storage in your device settings, or by uninstalling the App.
The App requests camera access for two optional features you control:
Photos and scanned data stay on your device as part of your local team notes. We do not access, upload, or receive copies of anything captured through the camera.
If you enable notifications, the App schedules local reminders directly on your device (e.g., for an upcoming event). These are generated and delivered entirely on-device. We do not operate a push notification server and do not receive any information when a reminder fires.
The App displays game manuals, field diagrams, Q&A, and the scoring calculator published by the Robotics Education & Competition Foundation (RECF) at games.recf.org and recf.org. When the App loads this content, your device communicates directly with RECF's servers, the same as if you visited those pages in a browser. That exchange is governed by RECF's own privacy practices, not this policy, and we do not see or store that traffic.
The Website is hosted on Cloudflare Pages. Like virtually any website, loading a page causes your browser to send Cloudflare's servers standard technical information needed to deliver the page, such as your IP address, browser type, and the page requested. This is generated automatically by the hosting infrastructure, not something we set up ourselves, and we do not use it for tracking or profiling visitors. It is governed by Cloudflare's privacy policy.
The Website uses your browser's local/session storage, not cookies, to remember a couple of small preferences on your own device:
None of this identifies you personally, and none of it is sent to us. It stays in your own browser and can be cleared at any time through your browser's site-data settings.
To display and run correctly, the Website loads a small number of third-party resources. Your browser communicates directly with these services when a page loads, the same as it would if you visited them yourself:
| Service | Purpose |
|---|---|
| Google Fonts | Loads the site's typefaces. |
| cdnjs (Cloudflare's public CDN) | Loads the Font Awesome icon set and the PapaParse library used to read schedule/news data. |
| Google Sheets (published, read-only CSV feeds) | Populates the Events, News, and Support Us pages with current content we maintain. These feeds are public and contain no visitor data, only the schedule/news/funding content itself. |
| countapi.mileshilliard.com | A free, third-party hit-counter service that stores a running number for each news post's view/like count, so every visitor sees the same accurate count rather than a per-browser one. It receives only a request to increment or read a counter, with no personal information. |
| PayPal | The Support Us page links out to PayPal.Me for donations. If you choose to donate, that transaction happens entirely on PayPal's site under PayPal's own privacy policy. We never see your payment details. |
The Website also links out to our Instagram, YouTube, GitHub, and email. Following those links takes you to those platforms' own sites, governed by their own privacy policies, not this one.
The Inventory Manager is a private, login-restricted tool at [INVENTORY SYSTEM DOMAIN] that the team uses to track parts, place and receive orders, and print bin labels. Unlike the App and the Website, it is not intended for the public: there's no self-service sign-up, and accounts exist only for team members, coaches, and mentors who need access.
Signing in requires a username and password. Passwords are never stored in plain text: each one is hashed with a unique, randomly generated salt before it's saved, so even we can't see your actual password by looking at the database. Accounts are created and removed by an administrator; there is no public registration page.
When you sign in, the IMS sets a single cookie (named session) containing a random session token, not your username or password. This cookie is strictly necessary to keep you signed in. It is HttpOnly and Secure, meaning it can't be read by page scripts and is only ever sent over HTTPS, and it expires automatically (12 hours normally, or 30 days if you check "Remember me"). This is the one cookie used anywhere across the App, the Website, or the IMS, and it exists purely to keep you logged in, not for tracking or advertising.
The IMS stores, in a database we control:
None of this is sold, shared outside the Program, or used for advertising. It's used only to run the inventory system itself.
A small number of administrator accounts have additional tools to manage the system directly, including creating or removing other accounts. Administrator actions are restricted to that role and are not available to ordinary team-member accounts.
The IMS is hosted on Cloudflare Pages with a Cloudflare D1 database, the same infrastructure family as the Website, governed by Cloudflare's privacy policy. The label-printing page loads the bwip-js barcode library from a public CDN (jsDelivr) to render barcodes in your browser; this doesn't send any inventory data anywhere, it's purely a code library.
The federal Children's Online Privacy Protection Act (COPPA) regulates the collection of personal information from children under age 13 specifically, not minors generally. We state plainly: we do not knowingly collect personal information from children under 13 through any public-facing feature of the App, the Website, or the IMS. The App and the Website have no accounts and no server-side data collection at all. The IMS does have accounts, but there is no public sign-up. Every account is created directly by an administrator for a specific, known team member, coach, or mentor. It is not a mechanism by which a child (or anyone) can submit their own information to us.
RECF robotics programs include participants younger than 18 more broadly (including some under 13, depending on the program level), and some IMS accounts may belong to students under 18. Because those accounts are administrator-provisioned rather than self-registered, and because a username alone (chosen by an administrator, not collected from a public form) does not by itself trigger COPPA, we don't believe the IMS collects "personal information from children" in the sense COPPA regulates. If your interpretation differs, or if you want to restrict IMS accounts to adult coaches/mentors only, revisit this section.
Capital High School Robotics operates as a school-affiliated program, and student photos or names tied to a school program can count as FERPA-protected "education records" depending on context. This isn't automatic, but it's a real enough possibility that it's worth handling carefully rather than assuming a robotics team site falls outside it. The App and Website themselves do not collect or store student education records. For anything published publicly on the Website (team rosters, photos, names, gallery content), the safest practice is to confirm with the school's administration or registrar whether those students are covered by the district's own "directory information" designation and annual opt-out list, and to only publish what that policy allows, rather than relying on an informal understanding of what's "consistent with school practices."
We want capitalhighrobotics.us to be usable by everyone, including visitors using screen readers or other assistive technology. Because this site represents a program of a public school, note that the U.S. Department of Justice's ADA Title II rule requires public school districts' websites and mobile apps to meet the WCAG 2.1 Level AA accessibility standard, on a phased timeline depending on the district's population (public entities have until April 2027 or April 2028 to comply, depending on size, per the DOJ's 2026 extension). Whether that requirement extends to a student-run program site hosted outside Kanawha County Schools' own domain is worth confirming directly with the district. As good practice regardless, if you encounter a page or feature on this site that isn't accessible to you, please let us know using the contact info below and we'll do our best to fix it.
App data stays on your own device, so its security depends on your device's own security (passcode, encryption, etc.). Any backup file you export from the App is a plain file under your control, so store and share it accordingly. The Website is served over HTTPS by Cloudflare and contains no visitor accounts or stored personal data for us to secure on our end. The IMS is also served over HTTPS, requires sign-in for any access, stores passwords only as salted hashes (never in plain text), and uses an HttpOnly, Secure session cookie that expires automatically.
If this policy changes, the "Last updated" date above will change. Continued use of the App, the Website, or the IMS after an update means you accept the revised policy.
Questions about this policy: [email protected]