


Effective Date: June 19, 2026
schoolOS provides software services exclusively to K-12 educational institutions. This Privacy Policy explains how schoolOS collects, uses, stores, shares, and protects information — including data obtained through third-party sign-in providers — and how we comply with the Family Educational Rights and Privacy Act (FERPA) and the Children's Online Privacy Protection Act (COPPA).
schoolOS is not a consumer-facing service. Our platform is used only under the supervision and direction of a school or school district ("School"). Schools retain ownership and control of their data; schoolOS processes that data solely on the School's behalf and for the purpose of providing its services.
Our Role and Commitments
When providing services to a School, schoolOS acts as a service provider and as a School Official under FERPA. The School is the owner and controller of all student data, and schoolOS processes that data only on the School's behalf and under its direction.
Across everything described in this policy, schoolOS commits that:
• We never sell, rent, or monetize student data or any personal information.
• We never use student data for advertising, marketing, behavioral profiling, or targeting.
• We never use student data to train, develop, or improve general-purpose AI or machine learning models.
• We never share data with any outside organization except as necessary to provide the service to the School, or as required by law.
• We collect only the data reasonably necessary to provide the service, and we request only the minimum permissions our features require.
FERPA Compliance
schoolOS acts as a School Official with a legitimate educational interest under FERPA (34 CFR § 99.31(a)(1)) when providing services to Schools and school districts.
• Student education records are processed only on behalf of, and under the direction of, the educational institution.
• Access to student data is limited to authorized users with a legitimate educational interest.
• Schools retain full ownership and control of all student data.
• Student data is never sold, rented, or used for advertising.
• schoolOS remains under the direct control of the School regarding the use and maintenance of education records, and uses student data only for the purposes for which access was provided.
schoolOS will assist Schools with their FERPA obligations — including the access, correction, and deletion of student records — consistent with applicable law and our contractual commitments.
COPPA Compliance & School Consent
schoolOS is intended for use only under the supervision of a School. When schoolOS collects personal information from students under the age of 13, it does so on behalf of and with the consent of the educational institution, consistent with COPPA's school consent exception. The School consents, as agent for parents and guardians, to the collection, use, and disclosure of student personal information for educational purposes.
In accordance with COPPA:
• Student data is collected solely for educational purposes.
• There is no behavioral advertising, marketing, or profiling of students.
• There is no sale or monetization of student personal information.
• Data collection is limited to what is reasonably necessary to provide the service.
Schools may review, modify, or request deletion of student data at any time. If we learn we have collected a student's personal information without the required School consent, we will promptly delete it.
Sign In With Google
schoolOS offers "Sign in with Google" as an authentication option for authorized users of the institutions we serve. This section discloses how schoolOS accesses, uses, stores, and shares data obtained through Google APIs.
Data We Access
When a user chooses to sign in with their Google account, schoolOS requests only the following limited, non-sensitive OAuth scopes:
• Email address (.../auth/userinfo.email) — the user's primary Google Account email address.
• Basic profile (.../auth/userinfo.profile) — the user's name, profile picture, Google account identifier, and basic profile information the user has made publicly available.
schoolOS does not request access to Gmail, Google Drive, Google Calendar, Google Classroom, Chrome device or directory data, or any other Google Workspace content. We request only the minimum scopes necessary to authenticate users.
How We Use This Data
schoolOS uses this Google user data solely to authenticate the user and provide secure access to the schoolOS platform. We use the email address to identify the user and to match or create their schoolOS account within their institution's environment, and we use basic profile information (name and profile picture) to populate their display name and profile within the application. We do not use Google user data for any purpose other than providing this sign-in feature.
How We Store and Protect This Data
The email address and basic profile information are stored as part of the user's schoolOS account record within our access-controlled, tenant-isolated environment, encrypted in transit and at rest. Access is limited to authorized personnel with a legitimate need. We do not create separate or permanent copies of Google user data beyond what is necessary to maintain the user's account.
How We Share This Data
schoolOS does not sell, rent, or transfer Google user data to third parties, data brokers, or advertisers. This data is not used for advertising, marketing, or profiling, and is not transferred to any application outside of the schoolOS services.
Limited Use
schoolOS's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking Access
Users may revoke schoolOS's access to their Google account at any time through their Google Account permissions at myaccount.google.com/permissions. Upon account deletion or termination of services, schoolOS will delete the associated Google profile data within a commercially reasonable timeframe, unless retention is required by law.
Sign In With Microsoft
schoolOS offers "Sign in with Microsoft" as an authentication option for authorized users, using the Microsoft identity platform (Microsoft Entra ID). This section discloses how schoolOS accesses, uses, stores, and shares data obtained through Microsoft APIs.
Data We Access
When a user chooses to sign in with their Microsoft or Microsoft 365 account, schoolOS requests only the following limited, sign-in-level scopes:
• openid — to authenticate the user and confirm their identity.
• email — the user's email address.
• profile — the user's name and basic profile information.
• User.Read — read-only access to the signed-in user's basic profile (name, email address, profile picture, and Microsoft Entra account identifier).
schoolOS does not request access to Outlook mail, OneDrive, SharePoint, Teams, calendar, device or directory data, or any other Microsoft 365 content. We request only the minimum scopes necessary to authenticate users.
How We Use This Data
schoolOS uses this Microsoft user data solely to authenticate the user and provide secure access to the schoolOS platform. We use the email address to identify the user and to match or create their schoolOS account within their institution's environment, and we use basic profile information (name and profile picture) to populate their display name and profile within the application. We do not use Microsoft user data for any purpose other than providing this sign-in feature.
How We Store and Protect This Data
The email address and basic profile information are stored as part of the user's schoolOS account record within our access-controlled, tenant-isolated environment, encrypted in transit and at rest. Access is limited to authorized personnel with a legitimate need. We do not create separate or permanent copies of Microsoft user data beyond what is necessary to maintain the user's account.
How We Share This Data
schoolOS does not sell, rent, or transfer Microsoft user data to third parties, data brokers, or advertisers. This data is not used for advertising, marketing, or profiling, and is not transferred to any application outside of the schoolOS services.
Compliance and Revoking Access
schoolOS's use of information received through the Microsoft identity platform and Microsoft Graph adheres to the Microsoft APIs Terms of Use and applicable Microsoft developer policies. Users may revoke schoolOS's access at any time through their Microsoft account permissions at myaccount.microsoft.com. Upon account deletion or termination of services, schoolOS will delete the associated Microsoft profile data within a commercially reasonable timeframe, unless retention is required by law.
AI & Student Data Use
schoolOS may use artificial intelligence features to support educational and operational workflows.
• Student data — and any personal information we process — is not used to train, develop, or improve general-purpose or non-personalized AI or machine learning models.
• AI processing is tenant-isolated by district.
• No cross-district data sharing or learning occurs.
• AI outputs are generated solely to assist authorized school personnel.
How We Share Information
schoolOS does not sell, rent, or monetize personal information. We share data only in the following limited circumstances:
• Service providers. We may share data with vendors and subprocessors (for example, cloud hosting) who perform services on our behalf, under contractual obligations to protect the data and to use it only to provide the contracted service.
• At the School's direction. We share data with the School and its authorized users as needed to provide the service.
Legal requirements. We may disclose data where required by law, regulation, subpoena, court order, or other legal process, or where reasonably necessary to protect the safety, rights, or property of any person.
• Business transfers. In connection with a merger, acquisition, or sale of assets, provided the successor remains bound by equivalent privacy and security commitments and continues to use the data only for educational purposes.
Data Security
schoolOS maintains an information security program designed to protect data against loss, misuse, and unauthorized access, disclosure, alteration, or destruction. Data is encrypted in transit and at rest, environments are tenant-isolated by district, and access is limited to authorized personnel with a legitimate need under the principles of least privilege and need-to-know. If we learn of a security breach affecting personal information, we will notify affected Schools in accordance with applicable law and our contractual obligations.
Data Retention & Deletion
Student data and personal information are retained only as long as necessary to provide services or as required by law. Upon written request from the School, or upon termination of services, schoolOS will delete or return the data within a commercially reasonable timeframe, unless retention is legally required. Schools may request access to, correction of, or deletion of their data at any time.
Changes to This Policy
We may update this Privacy Policy from time to time. If we make changes that materially affect how we handle student or School data, we will notify affected Schools directly. The "Effective Date" above indicates when this policy was last revised, and continued use of the services after an update constitutes acceptance of the revised policy.
Contact Information
Privacy Team
📧 privacy@theschoolos.com


