Student privacy
COPPA compliance, FERPA obligations and how Coeducate is built around them
What we do with student work, what we never do, and which formal attestations we do not yet hold. Written so a reviewer can read it once and decide.
01 The four commitments
Product decisions, not settings
Each of these is enforced in how the product is built, not by a checkbox a teacher can get wrong or an administrator has to remember to turn on.
Not used to train models
Student work is not used to train or fine-tune any model, ours or a provider's. It is processed to produce your evidence card and for nothing else.
No advertising, no resale
There is no advertising anywhere in the product, no advertising identifiers on student-facing screens and no sale or licensing of data to anyone.
Deletable on request
Per student or in bulk. Deletion removes the stored work as well as the derived skills and cards, not just the visible record.
School-controlled
The school or program is the controller of the record. We process it on your instruction, and we return or delete it when you say so.
02 The honest part
What we do not have
Vendors in this category collect badges. A badge is easy to display and hard to check, so here is the list in the other direction: the things we are not claiming.
-
No SOC 2 report
We have not completed a SOC 2 Type I or Type II audit. If your process requires an existing report before a pilot, we are not ready for you yet.
-
No ISO 27001 certificate
Not certified, not in progress as of today.
-
No COPPA safe-harbor seal
We are not a member of an FTC-approved safe harbor program and we do not display a seal from one.
-
No signed state data protection agreement
We have not executed a state DPA or joined a state student-privacy consortium. Enterprise includes DPA review, which is where that conversation starts.
-
No third-party penetration test report to share
We do not have an external test report we can hand to your reviewer today.
Saying this on a marketing page costs us pilots. It costs less than being found out during a review, and it is the same reason the product refuses to invent a confident answer when the model cannot read a piece of work.
03 FERPA and COPPA
How the obligations map onto the product
Neither law issues a certificate to a vendor. FERPA binds the school; COPPA binds the operator of an online service directed to children under 13. What a vendor can do is be buildable into a compliant deployment. Here is where each obligation lands.
- School official exception (FERPA)
- We act under the direct control of the school with respect to education records, we use them only for the purpose the school specifies, and we do not redisclose them. That is the basis on which a district can share records with us without separate parental consent.
- Consent for under-13 users (COPPA)
- Where the service is used by children under 13, the school provides consent on the parents' behalf for educational purposes, which requires that the data is used for that purpose and nothing else. No advertising and no training use is what makes that hold.
- Minimum necessary collection
- We hold the work submitted, the skills derived from it, and whatever roster identity the school supplies. We do not build behavioral profiles, and we do not ask students for personal information.
- No direct marketing to minors
- Students are never emailed marketing, never shown advertising and never asked to create a consumer account.
- Retention and deletion
- Records live as long as the school keeps the account, and are deleted on request at any time. On account closure we export and then delete rather than retaining a copy.
- Subprocessors
- Model inference runs on a third-party provider under terms that exclude training use. The list of subprocessors is available on request and to Enterprise customers as part of DPA review.
04 The public demo
The demo on this site stores nothing
No submission table
Text you type into the Mastery Check is sent to the model and returned as a card. There is no table it is written to and no log line containing it.
Scrubbed in the browser
Before the request leaves your browser, anything that looks like a name after "Student:", an email address or a phone number is replaced. Belt and braces, because people paste things.
Use the sample
The demo ships with realistic sample work for every subject and grade band, so there is never a reason to paste a real student's writing into a public page.
Related reading: ChatGPT for teachers and where it breaks student privacy, and deploying AI in schools without losing student privacy.
05 FAQ
What reviewers ask us
Still stuck on something? Email app@coeducate.ai and a person answers, usually within one business day.
Who is the data controller for student records?
The school or the tutoring program. Coeducate processes student work on your instruction, for the purpose of producing the mastery record, and for nothing else. That is what makes the FERPA school-official framing work: we are acting for you, not collecting on our own behalf.
Is student work sent to a third-party model provider?
Yes, the tutoring and diagnosis run on a commercial model API, and that is stated plainly rather than buried. What we contract for is that the content is not retained for training by the provider, and what we control directly is that we do not train on it, sell it, or use it for advertising. The privacy policy names the categories of processor.
What do you collect about a student under 13?
The minimum needed to attach a mastery record to a roster entry: an identifier the school controls, the work submitted, and the derived skill states. No email address is required for a student, there is no student-facing marketing, and there is no advertising identifier anywhere in the product.
How long is student work retained, and can we delete it?
Session work is retained for the current academic year by default so the mastery record has history behind it, then deleted. You can shorten that, and you can request deletion of an individual student or of everything at any point, including mid-term. Deletion means deletion, not deactivation.
Do you have a SOC 2 report or a signed state DPA?
No, and we will not imply otherwise. There is no completed third-party audit, no compliance seal and no state data protection agreement signed today. Enterprise includes a DPA review, which is a negotiation rather than a certificate. If your procurement process requires an existing attestation, we do not currently clear it.
What happens to the record if we stop paying?
You export it, or we export it for you. The account goes read-only rather than being wiped on the renewal date, and nothing is deleted without you asking. If you would rather it were deleted immediately, say so and it is.
More AI tools for teachers
Send the review questions before the pilot
Email the questions your process requires and you get a written answer, including the ones where the answer is no.
Student work is never used to train models. No card required to try the demo.