---
title: "School Data Privacy"
url: "https://nerd-notes.com/school-data-privacy/"
date_modified: "2026-07-25T02:29:42+00:00"
---

# School Data Privacy Policy

*Applies to accounts provisioned by a school, district, or other local education agency*

**Effective Date: July 24, 2026**

## 1. Scope and Purpose

This School Data Privacy Policy ("School Policy") describes how Nerd Notes ("Nerd Notes," "we," "us," or "our") collects, uses, stores, and discloses student information when our Service is provided to a school, school district, or other local education agency ("School") through a School-provisioned account.

This Policy applies across the Nerd Notes platform, including all products built on our shared underlying system — currently Phy (our AI physics assistant), UBQ (the Ultimate Bank of Questions), UBQ Quiz Lab, FRQ Atlas, and our self-paced course platform — whenever they are accessed through an account created or authorized by a School.

### Staff accounts

Where a School also provisions accounts for its teachers or staff, we protect those users' personal information with the same security, confidentiality, retention, deletion, and breach-notification practices this Policy describes, as a matter of contract. Staff account data is not "Student Data" as that term is used in student-privacy laws such as FERPA, COPPA, or SOPPA, and this Policy's legal references to Student Data apply to student records only — but the practical protections in Sections 6 through 10 apply to School-provisioned staff accounts equally.

This Policy does not apply to accounts created independently by individual users outside of a School relationship. Those accounts are governed by our [General Privacy Policy](https://nerd-notes.com/privacy/). Section 14 below explains how the two policies relate to each other.

If a School has entered into a Data Privacy Agreement ("DPA") with Nerd Notes, and any term of that DPA conflicts with this Policy, the DPA controls.

## 2. Our Role as a School Official

When we provide the Service to a School, Nerd Notes acts as a "School Official" with a legitimate educational interest, as that term is used under the Family Educational Rights and Privacy Act (FERPA). This means:

- We perform a service the School would otherwise perform using its own employees.
- We remain under the direct control of the School with respect to the use and maintenance of Student Data.
- We use Student Data only to provide the Service to the School, and for no other purpose.
- We are subject to the same limits on redisclosure of personally identifiable information from education records that apply to the School itself.

Reference: [FERPA regulations, 34 C.F.R. Part 99](https://www.ecfr.gov/current/title-34/subtitle-A/part-99) · [U.S. Department of Education, Student Privacy Policy Office](https://studentprivacy.ed.gov/)

## 3. Information We Collect Through School Accounts

We only collect the categories of Student Data needed to provide the Service. The specific categories collected for a given School are documented in Exhibit B of that School's signed DPA. In general, this may include:

| Category | Examples |
| :---- | :---- |
| Identifiers | Student name, username, School-assigned or Nerd Notes-assigned ID number, login credentials |
| Contact information | School-issued email address, where applicable |
| Usage and performance data | App engagement, study session activity, quiz and practice responses, scores, and progress (such as completed questions and bookmarks) |
| Student-generated content | Typed answers and questions, written work submitted for AI grading (typed or photographed), and messages exchanged with AI study tools |
| AI interaction data | Prompts submitted to AI features, AI-generated responses and feedback, and saved study-session threads |
| Assessment integrity data | For proctored quizzes, a summary of in-session events used for academic-integrity purposes (for example, leaving or returning to the quiz tab). We do not access a device's camera or microphone. |
| Technical and security data | IP address, device and browser type, session cookies used for login and security |

We do not collect demographic information (such as race, ethnicity, or gender), disciplinary records, health or disability information, or family income status through School-provisioned accounts unless a School specifically directs us to and it is documented in that School's DPA.

## 4. How We Use Student Data

We use Student Data only to:

- Deliver, operate, and maintain the Service for the School's benefit
- Provide adaptive and personalized learning features, such as recommending practice material based on performance
- Grade student work and provide automated feedback and explanations
- Provide customer support to School staff and Students
- Maintain the security and integrity of the Service, including academic-integrity features the School enables

**We do not:**

- Sell Student Data
- Use Student Data to serve targeted advertising to Students
- Build advertising profiles of Students or their families
- Use Student Data to train or improve generalized artificial-intelligence models
- Use Student Data for any purpose outside the Service described in our agreement with the School

No advertising is served within School-provisioned accounts. Advertising and marketing tools used on our public marketing website are not active within the School product experience and do not receive Student Data. School-provisioned sessions use cookies necessary for sign-in, security, and core preferences, plus first-party analytics cookies used solely to understand and improve how the Service is used. No advertising cookies are set, and analytics data from School accounts is never used for advertising or ad profiling.

We may use Student Data that has been de-identified, so that it can no longer reasonably be linked to a specific Student, to improve the Service, conduct research, and demonstrate the effectiveness of our tools, consistent with the terms of the applicable DPA.

## 5. AI-Powered Features and Student Data

Nerd Notes uses artificial intelligence to power features such as problem-solving assistance, automated grading of written work, and study recommendations. When a Student uses an AI-powered feature, the content they submit (such as a typed question, a typed answer, or an uploaded image of written work) is transmitted to an AI model provider to generate the response, and the response is returned to the Student.

Depending on the feature, Student submissions are processed by one or both of the following AI providers, acting as our Subprocessors:

- **OpenAI** — powers certain problem-solving and grading features.
- **Google (Gemini API)** — powers quiz grading, AI chat, and study-session feedback.

Both providers process submissions under their business API terms, which do not permit use of submitted content to train their generalized models.

Data minimization: AI features are designed to work without a Student's identifying details. We do not include a Student's name, School ID, or contact information in the content sent to AI providers, and Students and School staff should avoid typing identifying details into AI features. Uploaded images should show the work being graded, not the Student.

AI session retention: saved AI chat threads are automatically deleted on a rolling basis after 12 months. Grading submissions and feedback are retained with the Student's assessment record for the School, subject to Section 9.

## 6. Subprocessors

We use a limited number of trusted third-party vendors ("Subprocessors") to operate the Service for School accounts. Subprocessors are contractually required to protect Student Data and may only use it to perform the services we ask of them.

| Subprocessor | Function | Receives Student Data? |
| :---- | :---- | :---- |
| Hostinger | Web hosting and database for the core platform (where Student Data is stored at rest) | Yes |
| Railway | Application hosting and data storage for our AI middleware and related platform services | Yes |
| OpenAI | AI problem-solving and grading (see Section 5) | Yes, limited to submitted content |
| Google (Gemini API) | AI quiz grading, chat, and feedback (see Section 5) | Yes, limited to submitted content |
| Stripe | Billing for School purchases | No Student Data — billing contact and payment details of the School only |
| Titan (via Hostinger) and Google | Email services — sending and receiving Nerd Notes email, including support correspondence | Only information included in email correspondence |
| Google Analytics | Product usage analytics, configured without advertising features | Usage and device data, used only to operate and improve the Service |
| BunnyCDN | Course video storage and streaming | Limited — viewer IP addresses and playback requests only |

Marketing and advertising vendors used elsewhere on our platform (such as Google Ads) are not Subprocessors for School accounts and do not receive Student Data.

An up-to-date list of Subprocessors is maintained at [nerd-notes.com/subprocessors](https://nerd-notes.com/subprocessors/) and will be updated at least twice per year, consistent with Illinois SOPPA requirements, and whenever our Subprocessors change.

## 7. Data Security

We maintain administrative, physical, and technical safeguards designed to protect Student Data from unauthorized access, disclosure, alteration, or destruction, including:

- Encryption of data in transit (TLS) and at rest across our hosting infrastructure
- Additional application-level encryption, with Nerd Notes–managed keys, for selected sensitive data fields
- Multi-factor authentication on administrative and vendor accounts
- Role-based access controls limiting Student Data access to those who need it to operate the Service
- API credentials and secrets stored outside the web-accessible environment
- Confidentiality obligations for anyone with access to Student Data, which is limited to the minimum personnel necessary to operate the Service
- Background checks required for any future employee or contractor before they are granted access to Student Data
- Monitoring for unauthorized access and suspicious activity

We maintain a written incident response plan and can provide a summary of our security practices to a School upon request.

### Auditability

Schools and districts may request the following materials from us to verify our practices. We will respond within one week of a verified request:

- Our written data security program (CIS Controls–aligned, mapped to the NIST Cybersecurity Framework)
- Our asset inventory (systems, services, and data classifications)
- Our written incident response plan
- Subprocessor terms and privacy policies (the current list is public at [nerd-notes.com/subprocessors](https://nerd-notes.com/subprocessors/))
- Backup procedures and retention practices
- Hosting vendors and the regions where data is stored
- Sample data records for Students associated with your School or district
- Confidentiality and data-privacy acknowledgments for personnel with access to Student Data

Requests can be sent to **support@nerd-notes.com**.

## 8. Data Breach Notification

If we discover unauthorized access, disclosure, or acquisition of Student Data that compromises its security, confidentiality, or integrity, we will notify the affected School within 72 hours of confirming the incident, unless law enforcement requests a delay to avoid disrupting an investigation.

Our notification will include, to the extent known: the nature of the incident, the categories of data involved, which specific Students were or may have been affected, the date or estimated date of the incident, and the name and contact information of a Nerd Notes representative the School can reach with questions.

## 9. Data Retention and Deletion

We review, at least annually, whether the Student Data we hold is still needed to provide the Service. Data that is no longer needed is deleted or, at the School's direction, transferred back to the School. In general:

| Data category | Retention |
| :---- | :---- |
| Student accounts, performance records, and assessment data | Duration of the School's agreement, then handled per this Section |
| AI chat threads | Automatically deleted on a rolling basis after 12 months, or earlier at the School's request |
| AI grading submissions and feedback | Retained with the Student's assessment record for the School |
| Technical and security logs | Retained for up to 90 days, then automatically deleted |
| De-identified data | May be retained as described in Section 4 |

Upon a School's written request, we will delete or transfer Student Data within 60 days, and will confirm in writing once this is complete. Deletion includes removal from active systems; residual copies in routine encrypted backups are overwritten on our normal backup cycle. If a School's agreement with us ends, we will dispose of all Student Data after providing reasonable prior notice, except data that has been de-identified.

Transfers are provided in a commonly used, machine-readable format (such as CSV or JSON).

## 10. Parent and Student Access Rights

Parents, guardians, and eligible students who wish to review, correct, or request deletion of Student Data should contact their School directly, since the School controls and is responsible for its students' education records. We work with the School to fulfill these requests and will respond to a School's request for Student Data within a reasonably timely manner, and in any case no later than 45 days, or sooner if required by applicable state law.

## 11. Children's Privacy

School-provisioned accounts are created and authorized by the School, not by an individual parent signing up directly with Nerd Notes. Under FERPA and the Children's Online Privacy Protection Act (COPPA), a School may consent on behalf of parents to the collection of a Student's personal information by a service used for school purposes, including for Students under age 13, provided the data is used only for that educational purpose.

This differs from our General Privacy Policy, under which individual users must be 13 or older to create an account directly with Nerd Notes. If a School provisions accounts for Students under 13, this School Policy, together with the School's own notice to parents, governs how that Student's data is handled.

Reference: COPPA, 15 U.S.C. §§ 6501–6506; [FTC guidance on schools consenting on behalf of parents](https://www.ftc.gov/business-guidance/resources/complying-coppa-frequently-asked-questions)

## 12. Compliance with State Law

Where a School is located in Illinois, we comply with the Illinois Student Online Personal Protection Act (SOPPA) and the Illinois School Student Records Act (ISSRA), including their requirements for data minimization, breach notification, and restrictions on the sale and advertising use of Student Data.

References: [Student Online Personal Protection Act, 105 ILCS 85](https://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=3806) · [Illinois School Student Records Act, 105 ILCS 10](https://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=1006)

Where a School is located in another state with a comparable student data privacy law, we will comply with that state's requirements and, where available, sign the applicable state-specific exhibit to the National Data Privacy Agreement (NDPA).

For Schools located in California, we act as a "service provider" under the California Consumer Privacy Act (CCPA/CPRA) with respect to Student Data: we process it only on the School's documented instructions, we do not sell or share it, and we support parents and eligible students in exercising their privacy rights through the School as described in Section 10.

## 13. Where Student Data Is Stored

Student Data collected through School-provisioned accounts is stored within the United States, in our hosting providers' U.S. data centers. Course videos are delivered through BunnyCDN's content delivery network, which receives standard playback requests (such as viewer IP addresses) but is not used to store Student Data records.

## 14. How This Policy Relates to Our General Privacy Policy

Nerd Notes maintains two privacy policies because our General Privacy Policy and this School Policy describe genuinely different practices. Our general, consumer-facing product may use analytics and advertising tools and applies broader data-retention practices appropriate for individual users who sign up directly. School-provisioned accounts operate under contractual obligations to Schools that prohibit advertising and impose the specific security, retention, and breach-notification commitments described in this Policy.

If you are unsure which policy applies to your account: accounts created through a School's rostering process, a School-issued sign-up link, or a School-issued email domain are governed by this School Policy. All other accounts are governed by our [General Privacy Policy](https://nerd-notes.com/privacy/).

## 15. Changes to This Policy

We may update this Policy to reflect changes in our practices or to comply with new legal requirements. We will post the updated Policy here with a new effective date and will notify Schools of material changes before they take effect. Changes will not reduce the protections for Student Data collected under a School's existing DPA without the School's agreement.

## 16. Contact Us

Questions about this Policy, or requests related to a School's DPA, can be directed to:

**Email:** support@nerd-notes.com

Schools that wish to enroll students or complete a DPA (ours or the NDPA with state exhibits) can start with an email to the address above.

## Sources and References

- FERPA (20 U.S.C. § 1232g; 34 C.F.R. Part 99): [ecfr.gov](https://www.ecfr.gov/current/title-34/subtitle-A/part-99)
- U.S. Dept. of Education, Student Privacy Policy Office: [studentprivacy.ed.gov](https://studentprivacy.ed.gov/)
- COPPA (15 U.S.C. §§ 6501–6506) and FTC compliance guidance: [ftc.gov](https://www.ftc.gov/business-guidance/resources/complying-coppa-frequently-asked-questions)
- Illinois SOPPA, 105 ILCS 85: [ilga.gov](https://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=3806)
- Illinois ISSRA, 105 ILCS 10: [ilga.gov](https://www.ilga.gov/legislation/ilcs/ilcs3.asp?ActID=1006)
- Google API Services User Data Policy: [developers.google.com](https://developers.google.com/terms/api-services-user-data-policy)
- NIST Cybersecurity Framework: [nist.gov](https://www.nist.gov/cyberframework)
- Student Data Privacy Consortium / National Data Privacy Agreement: [privacy.a4l.org](https://privacy.a4l.org/)
