Data privacy: how MAP handles school and student information

U.S. schools evaluating assessment platforms usually ask the same privacy questions: Who controls student information? Is it used only for instruction? Can families see grades without sharing student logins? How is access limited by role? MAP is designed around those classroom realities.

This article explains what MAP does in the product today to protect account and course data. The public Privacy Notice is the stable URL districts can cite. Neither this article nor that notice is a substitute for a district Data Privacy Agreement (DPA), legal advice, or a formal compliance certification. Schools that need a signed DPA (including state templates such as the Student Data Privacy Consortium / NDPA process) should contact us so terms can be reviewed for their jurisdiction.

What schools typically look for

Across the United States, districts commonly evaluate vendors against:

  • FERPA-minded handling of education records — student identifying information and grades treated as school-controlled records, with vendors expected to use data only for the educational service (see U.S. Student Privacy guidance on school officials and online services)
  • Purpose limitation — no selling student data or using it for targeted advertising (a core theme of many state student-privacy laws modeled on California’s SOPIPA-style rules)
  • Written agreements — contracts or DPAs that spell out ownership, allowed uses, security expectations, breach notice, and deletion when the relationship ends
  • Access control — only the right roles see the right records (teachers vs students vs parents vs IT)
  • Parental / eligible-student access paths — families can review outcomes through school-approved channels rather than shared passwords
  • Security basics — authenticated accounts, HTTPS in production, backups, and clear operational ownership of the system
  • COPPA awareness — extra care when tools are used with children under 13; school-authorized educational use still expects minimized collection and no commercial profiling

How MAP limits who can see what

  • Distinct account types — Student, Teacher, Parent, and IT Support each get different capabilities
  • Course-scoped enrollment — students appear in a course only after an invitation is created and accepted; roster membership is not global across the platform
  • Teacher / co-teacher management — course management (invites, roster actions, grading workflows) is limited to users who can manage that course
  • Student grade visibility is teacher-controlled — score release and related assessment options decide what students can see and when
  • Parent access is invite-only and course-specific — a parent link grants grade summary visibility for a particular student in a particular course, not a teacher account and not unrestricted platform access
  • Closed courses — when a course is closed, live classroom taking pauses while historic grade context can remain available through the intended student/parent paths

How people join MAP (data minimization by design)

  • Students and parents join by invitation — teachers (or authorized managers) create invites; accounts are not harvested from open public signup for those roles
  • Email verification — new or changing emails go through a verification code flow before the account is fully activated
  • Passwords — stored with Django’s password hashing (not plain text)
  • One active session per account — signing in elsewhere ends the previous session, reducing shared-device account sprawl

What MAP uses data for—and what it does not

MAP uses account, course, assessment, and grade information to run the instructional service: authoring, delivery, grading, notifications, and related classroom operations.

  • MAP does not sell student personal information for marketing lists
  • MAP does not use student data for targeted advertising inside the product
  • In-app notifications and transactional email support invites, verification, and operational alerts—not ad targeting

Integrity features vs surveillance

Optional focus-leave lock can pause an attempt when a student leaves the assessment tab, with teacher unlock from the dashboard. That is a lightweight integrity cue—not webcam monitoring, remote desktop spyware, or a claim of perfect cheat-proofing. See the focus-lock Q&A for details.

Hosting, transport, and backups

  • Production site uses HTTPS so browser traffic to MAP is encrypted in transit
  • Dedicated application hosting — MAP runs as its own deployed application stack (not a shared anonymous free host)
  • Scheduled backups — production routines include regular database and media archives with retention windows so operations can recover from failure
  • Sensitive upload paths — certain private files (for example disposition export zips) are stored outside the public media URL space

Related articles

  • What information MAP collects — plain-language inventory of account, course, and assessment data (useful for district questionnaires)
  • Using MAP: accounts, acceptable use, and school agreements — educational use expectations and how a signed district DPA relates to MAP’s public notices
  • District data requests and teacher offboarding — how teachers start an export or optional deletion of classroom records

School / district agreements

Many districts require a written Data Privacy Agreement before classroom adoption. MAP is in active use for early testing while remaining features are finished. If your school or district needs a DPA, state addendum, or security questionnaire filled out:

  • Use Contact Us on the site to reach support
  • Tell us your district, state, and whether you use a standard packet (for example an NDPA / state alliance form)
  • We will work through the agreement process with your procurement or technology team

To export or delete classroom records when a teacher leaves, a school year ends, or a district requests files, see the Q&A article District data requests and teacher offboarding.

FAQ

Is MAP “FERPA certified”?

FERPA is a law that primarily binds schools that receive certain federal funds; vendors are expected to support schools as service providers under school control. MAP implements role-scoped access and educational-purpose use as described above. Formal written agreements are handled with districts that need them—ask via Contact Us.

Does MAP show student data to other schools or the public?

No. Student roster and grade data are scoped to the course and authorized roles. The Public Library is for shared instructional content patterns, not student gradebooks.

Can a parent see every course a child takes?

Only courses where a parent invitation was accepted for that student–course pair. Parent access is not a blanket key to all platform data.

Where should we send a data privacy agreement?

Start with Contact Us and attach or link your district’s preferred DPA / NDPA packet. We will respond with next steps for review.