Legal documents

Student Privacy Policy

Last updated

This policy explains what Berdee Learning ("Berdee", "we") collects about students, many of them under 13, who use Berdee lessons, and the choices their parents and schools have. It is written for parents, guardians and school staff. Educators' own information is covered by our Privacy Policy.

In short

  • Students never sign up on their own. An educator adds them: a teacher or other staff member acting for a school, or a parent teaching their own children. Private tutors and therapists who are not acting for a school may not add students.
  • We keep a student's name and email address, their classes, and their work in lessons assigned to them. We do not collect birth dates, photos, addresses or phone numbers.
  • Student information is used only to run lessons for the educator and school. It is never sold, never used for advertising, and never sent to AI providers.
  • Product analytics and session recording are switched off on student pages.
  • A school, or a parent through the school, can ask us to erase a student. See how.

How students come to use Berdee

An educator adds each student, either by typing the student's name and email address or by importing a class from Google Classroom. Berdee then emails the student a sign-in link, which names the educator and the class.

Only two kinds of educator may add students: a teacher, therapist, tutor or other staff member acting for a school or district, and a parent or guardian teaching their own children. An educator who works with students privately, outside a school (a private tutor or a therapist in private practice, for example), must not add students to Berdee. See COPPA.

For each lesson an educator assigns, the student gets an access code. The student opens the lesson with that code or with their emailed link; there are no passwords. Students see a generated robot avatar instead of a photo.

Inside Berdee, students can only play the lessons assigned to them and see their own results. They cannot upload files, record audio, message anyone, use AI features, make purchases, or connect other apps.

What we collect about students

From the educator

  • The student's name and email address.
  • For students imported from Google Classroom: their name, email address and Google account ID, read from the class roster. We keep the Google ID so the next import recognizes the same student. We only read rosters; we never change anything in Google Classroom.
  • Which of the educator's classes the student belongs to.
  • Which lessons are assigned to the student, and their access codes.
  • Feedback comments and grade changes the educator writes about the student's work.

From the student, while they do a lesson

  • Their answers, in whatever form the lesson asks for, and the score each answer earned.
  • How long they spent on each question, and what they tapped or chose along the way.
  • When they started and finished each attempt.

Automatically

Like any website, our servers receive the student's IP address and browser details with each request. Our hosting provider keeps these in logs for about a week. A sign-in cookie keeps the student signed in.

What we do not collect

Birth date, age, grade level of the individual student, photo, home address, phone number, location, voice recordings, special-education plans, or any information from other websites the student visits.

How we use student information

Only to provide Berdee to the educator and school that added the student:

  • to sign the student in and show them the lessons assigned to them;
  • to score their answers and show the educator their results;
  • to send the student's sign-in link;
  • to keep the service secure and fix problems.

We do not use student information to advertise to anyone, to build profiles for any purpose other than the student's teaching, to train AI models, or to market products to students.

No analytics, recording or ads on student pages

Our product analytics service (PostHog) does not load at all on student pages: the lesson player and the access-code pages. Session recording never runs there either. This is enforced in the code and covered by automated tests, not just written down as a rule. Berdee shows no ads anywhere.

A few services do load on student pages because the page needs them:

  • Cloudflare, which hosts Berdee and so handles every request.
  • Sentry, which receives error reports so we can fix crashes. Reports from the browser carry no user or request details. Reports from our servers identify a student only by account ID, never by name or email, and drop the details of the web request. Our servers also send their log lines to Sentry, identifying a student by account ID only; unlike error reports, those lines are not stripped of request details.
  • Google Fonts, which serves the typefaces lessons use. Google receives the student's IP address when the font loads.
  • YouTube, only if the educator put a video in the lesson. Videos use YouTube's privacy-enhanced (no-cookie) player.

Students and AI

Students do not use AI features. Their answers, and anything taken automatically from their records, are never sent to an AI provider. The one exception is what an educator types: educators use AI to build lessons, and whatever they type into a request is sent as written, so a student's name an educator types reaches the provider. We ask educators not to.

Who sees student information

  • The educator who added the student sees their name, classes and results. Educators they share a lesson with do not see the students.
  • Berdee staff, only to support the educator or school, investigate a problem, or act on an erasure request. Erasures are recorded in an audit log.
  • Service providers that run Berdee for us: Cloudflare (hosting, file storage and email), PlanetScale (our database, in the United States), Google (if the educator connected Google Classroom), and Sentry (error reports that identify a student by account ID only). The full list is in our Privacy Policy.
  • Authorities, only when the law requires it. Where allowed, we tell the school first.

We do not sell, rent or trade student information. If Berdee is ever sold or merged, the buyer must keep these promises for the information already collected, or schools and parents will be told and given the chance to have it deleted.

COPPA: consent through the school or parent

The Children's Online Privacy Protection Act requires verifiable parental consent before collecting personal information from a child under 13. Berdee relies on two routes, and only these two:

  • Schools. When a teacher or other staff member uses Berdee for their school or district, the school consents on parents' behalf, for an educational purpose only. We use the information only for that purpose and for no commercial purpose of our own.
  • Families. A parent or guardian teaching their own children signs up as the educator and adds them, which is the parent's consent.

Berdee does not yet offer a way for a parent to give consent directly to us. So an educator who is neither acting for a school nor the student's parent, such as a private tutor or a therapist in private practice, may not add students, whatever the student's age. If you learn that a student was added outside these two routes, contact us and we will erase the student's information.

Schools can ask us at any time what we collect and how we use it. A parent may review their child's information, ask for it to be erased, and refuse further collection (which means the child stops using Berdee), through the child's school or educator. See your rights.

FERPA: we act for the school

For schools covered by the Family Educational Rights and Privacy Act, a student's information in Berdee is part of their education record, and the record belongs to the school. We act as a "school official" with a legitimate educational interest, under the school's direct control over how the records are used, and we disclose them only as this policy describes or the school directs.

Parents who want to inspect or correct their child's records should ask the school; we help the school respond.

How long we keep student information

  • Each answer, score and interaction inside a lesson: deleted automatically one year after we receive it.
  • Overall lesson results, grades and educator feedback: kept while the educator's account is open, so the educator can look back over the school year.
  • Name, email and class membership: until the educator removes the student or the student is erased.
  • Records of an erased student (anonymous attempts and scores): as long as the school's or educator's account, then deleted with it.
  • Server logs: about a week with our hosting provider; log lines sent to Sentry are kept as long as Sentry keeps them.

Seeing, correcting and erasing a student's information

Parents

Your child's school or teacher can show you your child's information in Berdee and correct it. If you teach your own children with Berdee, you are the educator and can see it yourself.

To have your child's information erased, ask the school or teacher. You can also email us at support@berdee.app: we pass your request to your child's educator or school and act once they confirm it. We cannot erase a student on a parent's request alone, because students join through their educator and we hold no parent contact details that would let us confirm you are the child's parent.

Schools and educators

An educator can remove a student from their own account at any time, in Berdee. If no other educator on Berdee has the student, that erases the student as described below. If another educator still has them, the student keeps their account with that educator, and the first educator's records of them are kept with no name or email attached. Educators can also correct a student's name and email themselves.

Email support@berdee.app to ask us to erase a student. We confirm the request with the school or educator before acting, because the records belong to the school. Erasing a student:

  • removes their name, email address and any picture;
  • signs them out everywhere and unlinks their Google account;
  • removes them from every class;
  • replaces their access codes, so old codes stop working.

The student's lesson attempts and scores are not deleted. They stay, with no name or email attached, as part of the school's education records, and are deleted when the school's or educator's account is. If the student is still on a Google Classroom roster, the school must also remove them there, or the next import adds them back as a new student.

When an erasure runs, we automatically email the student's educator to say it happened. The email contains no details about the student.

Security

All traffic is encrypted with HTTPS. Educators see only their own students, and students see only their own work. Guessing access codes is rate-limited, and a code stops working once its lesson is unassigned. More detail is on our security page. If a breach affects student information, we will tell the affected schools (and, for families, the parent) as the law requires.

Changes to this policy

We update the date at the top whenever this policy changes. We will not use student information in a materially different way without first telling schools and educators, and getting consent where the law requires it.

Contact

Questions about students' privacy: support@berdee.app, or the contact form (choose "Security / privacy").