Skip to the waitlist

Privacy

What we hold, and why.

Howl is a place for a professor to talk to their class. This page says exactly what that involves, in the order you’d want to ask.

Effective 10 September 2026.

The short version

  • We don’t sell your data, and we don’t run ads.
  • There is no advertising or analytics SDK in the iOS app, and no third-party tracker on this website.
  • We never ask for your location, contacts, camera, microphone or photos. The app cannot request them.
  • You can ask for a copy of everything we hold about you, or have it deleted, by emailing us.

If you join the waitlist

When you put an address into the form on this site, we store:

  • Your email address, and a normalised copy of it so the same address can’t be added twice.
  • Where you teach, if you choose to fill it in afterwards. It is optional and the form says so.
  • Which form you used and, if you arrived from a link with campaign parameters on it, those parameters.
  • A one-way hash of your IP address, used to rate-limit the form. It is hashed with a secret we hold and then truncated. Your actual IP address is never written down.
  • Your browser’s user-agent string, and the time you signed up.

We use that address for one thing: telling you when professor access opens. Every email we send will have a working unsubscribe link, and leaving takes one click. If you want off the list before then, email us and you’re off.

If you use the app

  • Your account. You sign in with Apple. Apple gives us an identifier for you, plus your name and an email address if you choose to share them — and you can use Apple’s Hide My Email so we never see your real one. We do not ask for a password and could not store one.
  • Your profile. A display name, whether you’re a professor or a student, and a face. The face is a set of choices — hair, glasses, headwear, a backdrop — that the app draws. It is not a photograph, and there is nowhere in Howl to upload one.
  • Your classes. The names you give them, who is in them, and whether each person is a professor, a TA or a student.
  • What gets posted. Messages, announcements, questions, to-dos and polls: the text, who sent it, when, replies, reactions, poll answers, and who has acknowledged what.
  • A notification token for each device you turn notifications on for, so we can send them. Turn notifications off and we stop.

Anonymous questions, precisely

When a student asks anonymously, the name is removed before the message leaves our servers. Nobody in the class can see who asked, and neither can the professor or a TA — the app is not given the information, so there is no screen anywhere that could reveal it.

The record in our database does still identify the sender. We keep it so that a class has a way to deal with abuse or a threat, and because a question that genuinely cannot be traced is a question nobody can be protected from. If you are weighing whether to ask something anonymously, that is the honest answer: hidden from everybody you know, not erased from our systems.

What we don’t do

  • We do not sell personal data, and we have never shared it for advertising.
  • There is no advertising SDK and no third-party analytics SDK in the iOS app.
  • This website sets no cookies for ordinary visitors. It keeps campaign parameters in your browser’s session storage so the signup form knows where you came from, and that is cleared when you close the tab. The only cookie we set is a session for our own staff dashboard.
  • We do not track you across other apps or websites.
  • We do not read your email, and we are not connected to your inbox.

Who else touches it

Three companies, all acting on our instructions and none of them permitted to use your data for their own purposes:

  • Google, for Firebase — sign-in, our server functions, the database and notification delivery. Data is stored in the United States (us-central1).
  • Apple, for Sign in with Apple.
  • Our web host, which serves this site and stores the waitlist requests that reach it.

There are no advertising networks, no data brokers, and no analytics vendor. If that ever changes, this page changes first.

How long we keep things

Messages expire by kind, and this is a property of the product rather than a policy we apply afterwards:

  • Announcements are kept, so somebody joining in week three can still read week one.
  • Ordinary chat expires after seven days.
  • A question leaves the feed once it has been answered.

Expired messages come out of the feed and are reachable on the History screen until the class is archived. Waitlist addresses are kept until you unsubscribe or ask us to remove them.

Your rights

Wherever you are, you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it. If you are in the UK, the EU or a US state with its own privacy law, you also have the right to complain to your regulator, and you do not have to go through us first.

Email hello@meethowl.com and we will answer within 30 days. Deleting your account removes your profile, your memberships and the messages you sent. Where a message you sent is part of a conversation other people are relying on, we may keep the text and remove your name from it — we will tell you which applies.

Students, professors and universities

A professor signs up on their own and gives their class a join code; no administrator has to enable anything. That is a description of how the product works, not advice about your institution’s rules, and some universities do require software touching student data to be reviewed first. If yours does, we will help — email us and we will send whatever your IT or privacy office asks for.

We are not claiming FERPA compliance or a SOC 2 report. Neither has been audited, and we would rather say so here than have a university discover it later. Under FERPA the institution is the responsible party, and we will sign whatever agreement makes that relationship explicit when a university wants one.

Children

Howl is built for higher education and is not directed at children under 13. We do not knowingly collect their data; if you believe a child has an account, email us and we will delete it.

How it is kept

  • Sign-in is handled by Apple. We never see or store a password.
  • The app has no direct connection to the database. Every read and write goes through a server function that checks who you are and what your class allows before it does anything.
  • Traffic is encrypted in transit, and data is encrypted at rest by Google.
  • Sensitive requests are rate-limited, and nothing secret ships inside the app.

No system is perfect. If you find a security problem in Howl, email us and we will take it seriously and credit you if you want the credit.

Changes

If we change this page in a way that matters, we will say so at the top and tell anybody on the waitlist by email. The date at the top is the date the current version took effect.

Contact

Email hello@meethowl.com.