FERPA Compliance

Student Data Privacy. Our Commitment.

LessonSaver is built to comply with FERPA and COPPA. Here's how we protect student information and the controls available to your school.

Overview

The Family Educational Rights and Privacy Act (FERPA) is a U.S. federal law that protects the privacy of student education records. LessonSaver is designed from the ground up to be FERPA-compliant when used by schools and districts for educational purposes.

This page explains how LessonSaver handles student data, the safeguards in place, and the controls available to teachers and schools.

Our Role: School Official

When a school or district uses LessonSaver for educational purposes, LessonSaver acts as a "school official" with a legitimate educational interest in the student data it processes on behalf of the school. Student data is collected and used solely to provide the educational service the teacher or school has directed.

LessonSaver does not use student data for commercial advertising.
Student data is not sold to third parties.
Direct, on-behalf-of educational use only — student records remain under the school's control.

What Student Data We Collect

LessonSaver intentionally minimizes the personal information collected from students. When a student participates in a quiz, game, worksheet, or lesson activity, we may collect:

First name and last initial (self-reported by the student).
Optional email address (only when the teacher enables email or the student voluntarily provides it for a study guide).
Anonymous client identifiers stored in the student's browser, used for quick checks and ratings that do not require a name.
Performance data: scores, answers, completion status, and time spent — tied to the teacher who created the activity.

We do not collect student home addresses, phone numbers, Social Security numbers, or parent/guardian financial information.

COPPA: Children Under 13

The Children's Online Privacy Protection Act (COPPA) requires verifiable parental consent before collecting personal information from children under 13. LessonSaver protects younger students with an age/grade gate on every student-facing page that would otherwise collect a name or email.

Students who identify as under 13 (Grades K–7) participate anonymously — no name or email is collected.
Anonymous participation still generates performance data for the teacher's Insights Hub, but no personally identifiable information is stored.
Schools may also rely on the school-consent exception for educational technology when deploying LessonSaver district-wide.

Access Controls & Row-Level Security

Every student-data record in LessonSaver is stamped with the owning teacher's identity and protected by Row-Level Security (RLS). This means:

A teacher can only read, update, or delete student records for activities they created.
One teacher cannot access another teacher's student data.
Students submit responses anonymously through secured backend functions — they never receive credentials or direct database access.
Workspace administrators can manage records for abuse-prevention and support purposes, logged and auditable.

Data Retention

LessonSaver retains student performance data for a defined period to support longitudinal reporting, then permanently deletes it.

Default retention: 365 days after the record is created.
A nightly automated purge securely destroys records older than the retention window across all student-data entities.
Schools may request a shorter or longer retention schedule via a Data Processing Agreement (DPA).

Right to Erasure

Teachers can permanently delete a student's records at any time from Settings → Account & Security → Student Data. A preview confirms every matching record before deletion, and removal is scoped to that teacher's data only.

Schools and parents may also submit erasure requests through their school's designated FERPA official or by contacting us directly.

Data Security

Student data is protected by industry-standard safeguards:

All data in transit is encrypted via TLS; data at rest is encrypted by our cloud provider.
Row-Level Security enforces per-teacher isolation at the database layer.
Student-facing submissions are handled by service-role backend functions — no direct client database access.
Uploaded files are scanned for content; teachers are prompted not to upload documents containing student PII.

Third-Party Processing

LessonSaver uses a small set of vetted subprocessors to deliver the service (cloud hosting, AI generation, email delivery). Student personal information is never sold or shared for advertising. Subprocessors are bound by data-protection agreements and process data only as needed to provide the service.

Requesting Records or Deletion

Eligible students, parents, and school officials may request access to or deletion of student records. Because LessonSaver holds records on behalf of the school, most FERPA requests should be directed to the school's FERPA official, who can coordinate with us. For direct inquiries, including Data Processing Agreements (DPAs) for districts, contact us at support@lessonsaver.ai.

Changes to This Page

We may update this FERPA compliance information as our practices evolve or as regulations change. Material changes will be reflected here with an updated date.

Last updated: August 2026