Privacy Policy

Last updated: 09-09-2026. Covers the OmniScout app, the capitalhighrobotics.us website, and the team Inventory Manager
This Privacy Policy describes our actual data practices for the OmniScout app, the capitalhighrobotics.us website, and the team's internal Inventory Manager. It is provided for informational purposes and does not constitute legal advice. If you have questions about how it applies to you, contact us using the information below.

Overview

This Privacy Policy covers three things run by Douglas Matheny / Capital High Robotics (together, "we," "us," or "the Program"):

  • OmniScout ("the App"), a companion app for RECF robotics competition teams.
  • capitalhighrobotics.us ("the Website"), including its capitalhighrobotics.us address, the public website for the robotics program.
  • the Inventory Manager ("the IMS"), at [INVENTORY SYSTEM DOMAIN], a login-restricted internal tool for tracking parts, orders, and usage. It is not public and is not intended for use by anyone outside the team.

The short version: The App and the Website have no user accounts, run no data-collecting server of ours, use no analytics or advertising SDKs, and sell no data. The App stores everything you enter locally on your device, and the Website is a static, informational site. The Inventory Manager is different: it's a private, login-only tool for authorized team members, and it does have accounts, a session cookie, and a database, described in Part 3 below. None of the three properties runs analytics or advertising software, and none of them sells or shares data with anyone.

Part 1: The OmniScout App

Information We Do Not Collect

  • We do not require or support account creation or login.
  • We do not collect, transmit, or store your data on any server we operate.
  • We do not use analytics, tracking, or advertising SDKs of any kind.
  • We do not sell or share data, because we do not have any of your data to sell.

Information Stored on Your Device

The App stores the following locally on your device only, using standard device storage. This data never leaves your device unless you personally choose to export or share it (e.g., using the App's backup/export or QR-share features):

  • Team numbers, names, ratings, and scouting notes you enter
  • Pit photos you take using your device's camera, if you choose to add one to a team profile
  • Your saved next-event, checklist progress, engineering notebook file reference, and skills-run log
  • App preferences (theme, accent color, notification settings)
  • Cached copies of publicly published RECF game manuals, field diagrams, and the scoring calculator, downloaded so the App still works without internet access at events

You can delete this data at any time by clearing the App's storage in your device settings, or by uninstalling the App.

Camera Access

The App requests camera access for two optional features you control:

  • QR code scanning, to quickly import a team profile that another OmniScout user shared with you as a QR code.
  • Pit photos, to attach a photo to a team's profile in your own scouting notes.

Photos and scanned data stay on your device as part of your local team notes. We do not access, upload, or receive copies of anything captured through the camera.

Notifications

If you enable notifications, the App schedules local reminders directly on your device (e.g., for an upcoming event). These are generated and delivered entirely on-device. We do not operate a push notification server and do not receive any information when a reminder fires.

Third-Party Content in the App

The App displays game manuals, field diagrams, Q&A, and the scoring calculator published by the Robotics Education & Competition Foundation (RECF) at games.recf.org and recf.org. When the App loads this content, your device communicates directly with RECF's servers, the same as if you visited those pages in a browser. That exchange is governed by RECF's own privacy practices, not this policy, and we do not see or store that traffic.

Part 2: The capitalhighrobotics.us Website

Information We Do Not Collect

  • The Website has no accounts, no login, and no forms that submit personal information to us. The only ways to reach us are an email link and, on the Support Us page, an outbound link to PayPal.
  • We do not run analytics or advertising software on the Website, and we do not use tracking or advertising cookies.
  • We do not sell or share visitor data, because we do not collect any.

Hosting & Standard Server Logs

The Website is hosted on Cloudflare Pages. Like virtually any website, loading a page causes your browser to send Cloudflare's servers standard technical information needed to deliver the page, such as your IP address, browser type, and the page requested. This is generated automatically by the hosting infrastructure, not something we set up ourselves, and we do not use it for tracking or profiling visitors. It is governed by Cloudflare's privacy policy.

Information Stored in Your Browser

The Website uses your browser's local/session storage, not cookies, to remember a couple of small preferences on your own device:

  • Whether you've already dismissed the current site announcement banner, so it doesn't reappear on every visit.
  • Whether you've "liked" a given news post, and whether you've already been counted as a view for it in the current browser session.

None of this identifies you personally, and none of it is sent to us. It stays in your own browser and can be cleared at any time through your browser's site-data settings.

Third-Party Content & Services Loaded by the Website

To display and run correctly, the Website loads a small number of third-party resources. Your browser communicates directly with these services when a page loads, the same as it would if you visited them yourself:

ServicePurpose
Google FontsLoads the site's typefaces.
cdnjs (Cloudflare's public CDN)Loads the Font Awesome icon set and the PapaParse library used to read schedule/news data.
Google Sheets (published, read-only CSV feeds)Populates the Events, News, and Support Us pages with current content we maintain. These feeds are public and contain no visitor data, only the schedule/news/funding content itself.
countapi.mileshilliard.comA free, third-party hit-counter service that stores a running number for each news post's view/like count, so every visitor sees the same accurate count rather than a per-browser one. It receives only a request to increment or read a counter, with no personal information.
PayPalThe Support Us page links out to PayPal.Me for donations. If you choose to donate, that transaction happens entirely on PayPal's site under PayPal's own privacy policy. We never see your payment details.

The Website also links out to our Instagram, YouTube, GitHub, and email. Following those links takes you to those platforms' own sites, governed by their own privacy policies, not this one.

Part 3: The Inventory Manager

The Inventory Manager is a private, login-restricted tool at [INVENTORY SYSTEM DOMAIN] that the team uses to track parts, place and receive orders, and print bin labels. Unlike the App and the Website, it is not intended for the public: there's no self-service sign-up, and accounts exist only for team members, coaches, and mentors who need access.

Accounts & Sign-In

Signing in requires a username and password. Passwords are never stored in plain text: each one is hashed with a unique, randomly generated salt before it's saved, so even we can't see your actual password by looking at the database. Accounts are created and removed by an administrator; there is no public registration page.

Session Cookie

When you sign in, the IMS sets a single cookie (named session) containing a random session token, not your username or password. This cookie is strictly necessary to keep you signed in. It is HttpOnly and Secure, meaning it can't be read by page scripts and is only ever sent over HTTPS, and it expires automatically (12 hours normally, or 30 days if you check "Remember me"). This is the one cookie used anywhere across the App, the Website, or the IMS, and it exists purely to keep you logged in, not for tracking or advertising.

Information Stored in the IMS

The IMS stores, in a database we control:

  • Usernames and hashed passwords for authorized accounts.
  • The parts inventory: item names, SKUs, quantities, bin locations, and notes.
  • Purchase orders: vendor, items, cost, and status.
  • A usage log recording each inventory quantity change, which signed-in account made it, and an optional reason. This exists for internal accountability (so the team can tell what happened to a part), not to monitor anyone.

None of this is sold, shared outside the Program, or used for advertising. It's used only to run the inventory system itself.

Administrator Access

A small number of administrator accounts have additional tools to manage the system directly, including creating or removing other accounts. Administrator actions are restricted to that role and are not available to ordinary team-member accounts.

Hosting & Third-Party Services Used by the IMS

The IMS is hosted on Cloudflare Pages with a Cloudflare D1 database, the same infrastructure family as the Website, governed by Cloudflare's privacy policy. The label-printing page loads the bwip-js barcode library from a public CDN (jsDelivr) to render barcodes in your browser; this doesn't send any inventory data anywhere, it's purely a code library.

Children's Privacy (COPPA)

The federal Children's Online Privacy Protection Act (COPPA) regulates the collection of personal information from children under age 13 specifically, not minors generally. We state plainly: we do not knowingly collect personal information from children under 13 through any public-facing feature of the App, the Website, or the IMS. The App and the Website have no accounts and no server-side data collection at all. The IMS does have accounts, but there is no public sign-up. Every account is created directly by an administrator for a specific, known team member, coach, or mentor. It is not a mechanism by which a child (or anyone) can submit their own information to us.

RECF robotics programs include participants younger than 18 more broadly (including some under 13, depending on the program level), and some IMS accounts may belong to students under 18. Because those accounts are administrator-provisioned rather than self-registered, and because a username alone (chosen by an administrator, not collected from a public form) does not by itself trigger COPPA, we don't believe the IMS collects "personal information from children" in the sense COPPA regulates. If your interpretation differs, or if you want to restrict IMS accounts to adult coaches/mentors only, revisit this section.

School Context / FERPA Note

Capital High School Robotics operates as a school-affiliated program, and student photos or names tied to a school program can count as FERPA-protected "education records" depending on context. This isn't automatic, but it's a real enough possibility that it's worth handling carefully rather than assuming a robotics team site falls outside it. The App and Website themselves do not collect or store student education records. For anything published publicly on the Website (team rosters, photos, names, gallery content), the safest practice is to confirm with the school's administration or registrar whether those students are covered by the district's own "directory information" designation and annual opt-out list, and to only publish what that policy allows, rather than relying on an informal understanding of what's "consistent with school practices."

Accessibility

We want capitalhighrobotics.us to be usable by everyone, including visitors using screen readers or other assistive technology. Because this site represents a program of a public school, note that the U.S. Department of Justice's ADA Title II rule requires public school districts' websites and mobile apps to meet the WCAG 2.1 Level AA accessibility standard, on a phased timeline depending on the district's population (public entities have until April 2027 or April 2028 to comply, depending on size, per the DOJ's 2026 extension). Whether that requirement extends to a student-run program site hosted outside Kanawha County Schools' own domain is worth confirming directly with the district. As good practice regardless, if you encounter a page or feature on this site that isn't accessible to you, please let us know using the contact info below and we'll do our best to fix it.

Data Security

App data stays on your own device, so its security depends on your device's own security (passcode, encryption, etc.). Any backup file you export from the App is a plain file under your control, so store and share it accordingly. The Website is served over HTTPS by Cloudflare and contains no visitor accounts or stored personal data for us to secure on our end. The IMS is also served over HTTPS, requires sign-in for any access, stores passwords only as salted hashes (never in plain text), and uses an HttpOnly, Secure session cookie that expires automatically.

Changes to This Policy

If this policy changes, the "Last updated" date above will change. Continued use of the App, the Website, or the IMS after an update means you accept the revised policy.

Contact

Questions about this policy: [email protected]