Here's what actually matters when you're shopping for an AI tool for your classroom: does it keep your kids' data out of the public internet?
FERPA and COPPA in plain English
- FERPA (Family Educational Rights and Privacy Act): The feds say your school owns student grades, IEPs, test scores, attendance. You can't put those in a random tool and hope it's fine.
- COPPA (Children's Online Privacy Protection): Under 13? That kid's parent has to opt in before the tool collects any data. Yes, really. Yes, even a username.
Most AI tools you use? Not designed for K-12 classrooms. They're made for adults. If you dump student data in there, you're the one who bears the legal risk.
What to actually check
1. Does the company store your data? Ask explicitly. Look for: "We do not store conversations for model training" or "Your data is encrypted and isolated." Vague language = red flag.
2. Do they have a FERPA BAA? (Business Associate Agreement). Most don't. If they do, great. If not, proceed with caution—anonymize everything first.
3. Is there a COPPA exception for schools? Some tools do have one if your school has a contract. Most don't.
4. Who can see what? Can the tool vendor see your anonymized chat logs? Can a random employee read your lesson plan? Read the privacy policy like it matters, because it does.
The workflow that keeps you safe
- Don't paste student work into cloud AI tools unless they explicitly FERPA-BAA you and you've read the whole thing.
- When you do use a tool, anonymize first: remove names, dates, identifying details.
- Use school-authorized tools when possible (your district often has contracts that include FERPA protection).
- If you use a personal tool: create lesson materials with it (fine), but not assessments of actual students.
Use the [classroom management tool](/classroom-management) to document your policies, and [parent communication](/parent-communication) templates to tell families what you're doing.


