Privacy policy
Last updated: September 1, 2026 · Products: CenterFlow (centerflowapp.com) and the Class-Navi+ browser extension
This policy describes how CenterFlow collects, uses, and shares information when you use our websites, apps, and browser extensions, including check-in, Student Roster, the account hub, and the Class-Navi+ Chrome extension for Kumon Class-Navi and KSIS. It applies alongside the Terms of Service.
Information we collect
- Account data: Email address and authentication data via Supabase when instructors sign up or sign in, including Google sign-in where you choose it.
- Center operations data: Student roster details, attendance events, worksheet levels, staff accounts, kiosk settings, and family contact details that instructors or staff enter or sync to run their learning center. Instructors control this data; CenterFlow processes it on their behalf.
- Synced roster data: If your center connects ClassNavi or KSIS, we receive the student list and study information those features import. Our browser extension reads those pages in your own signed-in browser session and sends only roster and study data to CenterFlow, never your browsing history and never your Kumon password. The extension is the only way we sync this data.
- Class-Navi+ extension activity: The grading, worksheet planning, and reporting tools run locally on the Kumon page you are viewing. Page content is not sent to us. For subscription billing the extension reports only a count of subject enrollments, plus your center id and center name.
- Kumon credentials: We do not ask for, receive, or store your ClassNavi or KSIS password. Syncing happens entirely through the extension, using the session you are already signed in to on your own machine.
- Billing data: Subscription status and Stripe customer identifiers when billing applies. Full payment card numbers are handled by Stripe and never touch CenterFlow servers.
- Technical data: Standard server logs (IP address, browser type, timestamps) used for security, rate limiting, and debugging.
How we use information
- Provide attendance and roster features to your center
- Authenticate users and enforce access permissions between centers, staff, and families
- Keep your roster in sync with the systems you connect
- Process payments and support billing inquiries when applicable
- Respond to support requests and improve reliability and security
We do not sell personal information, and we do not use student or family data for advertising or profiling.
Cookies and local storage
We use cookies and browser storage only to keep you signed in, remember preferences such as theme and kiosk settings, and cache pages so the apps load fast. We do not use advertising or cross-site tracking cookies.
Service providers
We use trusted processors to run the Service: Supabase (authentication and database), Stripe (payments, when used), Cloudflare (hosting and content delivery), and Resend (transactional email such as sign-in codes). They process data only to provide their service to us. We may also disclose information if required by law, or to protect the security of the Service and its users.
Data retention and deletion
We retain account and center operations records as long as needed to provide the Service and meet legal obligations. Instructors can export their roster at any time and may request deletion of their account and their center’s data by contacting support; we delete or de-identify it within a reasonable period after closure, except records we must keep (such as billing records).
Security
All traffic is served over HTTPS. Passwords are stored only as salted hashes, and API access is scoped per center. No method of transmission or storage is 100% secure, but we review and improve our practices on an ongoing basis, and we will notify affected centers of any breach as required by law.
Children
CenterFlow is intended for adult instructors, staff, and parents/guardians; children are not end users of the Service. Student information is entered or synced by centers to operate their programs, and each center is responsible for its notices to families. We collect no information directly from children, and we process student data only on the center’s instructions.
Your choices and rights
- Instructors can view, correct, export, or delete their center’s data from the apps or by contacting support.
- Parents and guardians should direct questions about their student’s records to their center, which controls that data; we will assist the center in honoring such requests.
- Depending on where you live, you may have additional rights to access, correct, or delete personal information. Contact us and we will honor them as the law requires.
Changes to this policy
If we make material changes, we will update the date above and give notice in the app or by email before the changes take effect.
Contact
Privacy questions: support@centerflowapp.com.
CenterFlow