Guide

The 10-Minute Student-Data Privacy Check

You do not need to read the whole privacy policy. You need to answer five questions — about two minutes each — before an AI tool touches anything connected to a student. Here they are.

The stakes, briefly: student information in most US schools is protected by FERPA, which governs education records, and tools used with young children run into COPPA, which restricts data collection on users under 13. You are not personally responsible for interpreting either law — that is your district's job — but you are the person deciding what gets typed into a box tonight. This check makes that decision a careful one. It is practical guidance, not legal advice.

Question 1: What data will I actually put in? (2 minutes)

Inventory it concretely. Names and student IDs are obvious, but the list is longer than it first appears: a photo of student work with the name in the corner, a class roster for a seating chart, a writing sample with a distinctive personal story, a behavior incident description, a recording of student voices, an IEP excerpt. Indirect identifiers count too — "the only wheelchair user in fifth grade" identifies a child as surely as a name does. Write down what would actually leave your hands. If the honest answer is "nothing about any specific student," most of this check is already done and the tool is being used teacher-only, like the research listings in our research category.

Question 2: What does the tool say happens to that data? (3 minutes)

You are looking for three specific answers in the privacy policy or terms: Does the vendor train its models on user inputs? How long is data retained? Can you delete it, and does deletion actually propagate? Search the policy for "training," "retain," and "delete" rather than reading it linearly. A consumer chat product that trains on what you type has a different risk profile than an education product that contracts not to — and vendors change these terms, so re-check at the start of each school year. If the policy is unreadable or silent on inputs, treat silence as a no.

Question 3: Is there a school-level agreement behind this? (2 minutes)

This is the single biggest difference between "fine" and "problem." When a district approves a tool, it typically signs a data-privacy agreement that puts the vendor in the FERPA school-official role, with contractual limits a consumer signup never gets you. So: is the tool on your district's approved list? If your district has a request process, have you used it? A teacher-account signup on a consumer website — even the same product with the same logo — is not the same legal situation as the district-contracted version. This is exactly the distinction behind our district-ready signal versus check first privacy flags, and why the flag text always says to verify your district's approval list anyway.

Question 4: What is the worst realistic outcome? (1 minute)

Imagine the text you are about to submit appearing somewhere it should not — in a vendor's training corpus, in a breach, in another user's output. Not because that is likely, but because that is the case you are accepting on the student's behalf. A generic quiz prompt leaking is nothing. A kindergartner's speech-therapy notes leaking is a family conversation you do not want to have. If you would not be comfortable explaining the exposure to that student's parent, do not make the exposure. This one-minute gut check catches what policies never spell out.

Question 5: Is there a no-data version of this task? (2 minutes)

Almost always, yes. Describe the pattern instead of the child ("a student who reads two years below level and refuses to start long assignments") and let the tool work generically. Strip names and redact identifying details before uploading anything. Aggregate first — "here are the three topics the class missed most" instead of the raw assessments. Many of the strongest teacher workflows in this directory are teacher-only by design: the IEP goal-bank and accommodation-brainstorm entries exist precisely because the no-data version of those tasks captures most of the value with none of the exposure.

If any answer came back shaky

Then the tool waits. Switch to the no-data version of the task, use something already on the district list, or ask your instructional technology office — "can we evaluate this tool" is a completely normal question they answer weekly. What you do not do is proceed because the deadline is Friday. The deadline will feel urgent again next week; a student's privacy, once out, does not.

The two-minute version, for the future. Whose data? Does it train on inputs? Is the district behind it? Worst realistic case? A no-data alternative? Five questions, in order. When in doubt, leave the data out.