The EdTech App Privacy Audit: How to Check What School Apps Collect
Table of Contents

The EdTech App Privacy Audit: How to Check What School Apps Collect

Your child's school apps collect more data than most parents realize. Here's a step-by-step audit guide—plus a template letter to send the school today.

Your child’s school gave them a Chromebook loaded with a dozen apps. You signed a stack of forms at the start of the year, one of which almost certainly included blanket permission for the district to use approved third-party educational technology providers. You probably don’t know what data those apps collect, who those providers sell it to, or how long they retain it. Most parents don’t, and most schools don’t know either. EdTech has expanded faster than school privacy governance, and the gap between what these apps collect and what families understand has become significant. This guide shows you how to close that gap — specifically, practically, without needing a law degree.

Key Takeaways

  • The average US K–12 school uses 1,400+ digital tools annually, but most districts formally review fewer than 200 of them for privacy compliance.
  • FERPA and COPPA provide a legal framework, but enforcement is largely complaint-driven — parents who know their rights get more protection.
  • The Student Privacy Pledge database lists vendors who have made binding commitments not to sell student data; you can check your school’s apps in minutes.
  • Common Sense Media’s Privacy Not Included ratings give consumer-grade privacy assessments for popular EdTech apps.
  • You have the right under FERPA to review your child’s educational records and request deletion of information from third parties who received it from the school.

Why This Matters More Than You Might Expect

EdTech adoption accelerated dramatically during the pandemic and never fully retreated. A 2023 analysis by the nonprofit Center for Democracy and Technology found that the average US public school student’s data is handled by over 50 different vendors in a given school year — and that figure rises above 100 in some districts. The data categories collected routinely include:

  • Academic performance and grades
  • Behavioral data (keystrokes, scroll patterns, time-on-task, “engagement scores”)
  • Communications (school email, messaging on learning management platforms)
  • Device usage logs
  • In some cases, audio and video (for proctoring and reading assessment tools)
  • Location data when apps are used off school property
  • Mental health screening data (from social-emotional learning platforms)

The Electronic Frontier Foundation’s 2023 report on student surveillance found that 89% of apps recommended for school use had data practices that went beyond what was necessary for the educational function. Many shared data with advertising networks, data brokers, or analytics firms.

Step 1: Build Your App Inventory

Before you can audit, you need a list. Here’s how to get it:

Ask your child. Have them open their school-issued device and list every app, browser extension, and website they use for school. Include the learning management system (Google Classroom, Canvas, Schoology), math and reading platforms, testing tools, and communication apps.

Ask the school. Most districts have an IT department that maintains a list of approved EdTech vendors. Email or call and ask for a complete list of third-party software providers with access to student data. You are legally entitled to this information under FERPA — you don’t need to cite the law to ask, but it helps to know you have the right.

Check your district’s website. Many districts now post their EdTech vendor lists publicly, sometimes under “Student Data Privacy” or “Technology Resources.” California, Colorado, New York, and several other states require public disclosure.

Step 2: Check the Student Privacy Pledge Database

The Student Privacy Pledge (studentprivacypledge.org) is a voluntary commitment made by EdTech vendors to the Future of Privacy Forum and the Software & Information Industry Association. Signatories agree to:

  • Not sell student personal information
  • Not use data for behaviorally targeted advertising
  • Not build personal profiles for non-educational purposes
  • Use data only to support authorized educational purposes
  • Allow schools to delete student data upon request

The database is searchable by company name. Pull your app list and check each vendor. A non-signatory is not necessarily violating your child’s privacy, but it means there is no external accountability binding their promises. For non-signatories, you need to go directly to their privacy policy.

Step 3: Read the Privacy Policy (Yes, Really)

Privacy policies are deliberately long and difficult. Here’s what to scan for in 10 minutes:

Search for “sell” or “share.” Look for language like “we may share your information with third-party partners for analytics and advertising purposes.” This language in an app your school mandated is worth flagging to your district.

Search for “child” or “COPPA.” The policy should specify how they handle data from users under 13. If the policy says only “we comply with COPPA” without specifying how, that’s vague.

Search for “retain” or “retention.” How long do they keep data after a student stops using the platform? “Indefinitely” or “until deleted by the school” are very different answers. A standard data retention period for school-year data is 12–24 months after account closure.

Search for “law enforcement” or “government.” This clause tells you under what circumstances they’ll share your child’s data with authorities without a subpoena. Some policies give platforms broad discretion; others require a court order.

Search for “biometric.” If any proctoring, reading assessment, or attendance tool uses a camera, check whether it captures and stores biometric data. Several states (Illinois, Texas, Washington) have specific biometric privacy laws that apply.

Step 4: Use Common Sense Media Privacy Ratings

Common Sense Media’s Privacy Not Included (privacynotincluded.org) and their EdTech privacy evaluations (commonsense.org/education/privacy) rate popular apps on a consistent rubric including:

  • Does it share data with third parties?
  • Does it use data for advertising?
  • Can you delete your data?
  • Does the company have a history of data breaches?
  • Is the privacy policy clear and specific?

Apps receive a rating from “Passes” to “Warning” to “Fail.” Search your child’s apps here and note the ratings. Apps rated “Warning” or “Fail” are worth discussing with the school — not necessarily to remove them, but to understand what controls exist.

Tool/PlatformCommon Sense Rating (2024)Key Concern
Google ClassroomPasses (school accounts)Personal Google data separation required
Canvas LMSPassesThird-party integration data handling varies
ClassDojoWarningParent/student data commingling with ad network
Duolingo (consumer)WarningBehavioral data used for ad targeting
Kahoot!WarningThird-party cookie use; limited deletion rights
NearpodPasses (school accounts)Data shared with parent company; school controls data
SeesawPassesStrong school data controls; personal account risks
Prodigy MathWarningUpsell targeting to parents based on student data

Note: Ratings reflect school/education account configurations. Consumer versions of the same apps often have weaker protections. Always verify the version your school has licensed.

Step 5: Check for the Student Privacy Compass and Transparent Schools

The Future of Privacy Forum’s Student Privacy Compass (studentprivacycompass.org) provides state-by-state analysis of student data privacy laws. Understanding what your state requires gives you a stronger basis for your requests to the school.

Transparent Schools (transparentschools.org) is a newer platform where some districts publish their EdTech vendor contracts, privacy impact assessments, and data sharing agreements. If your district is listed, you can review the actual contracts — not just vendor promises.

Step 6: Write the School

Most schools respond constructively when approached directly. Here is a template:


[Date]

[Principal / Superintendent Name] [School / District Name]

Dear [Name],

I am writing to request information about the third-party software and applications currently used by my child, [Child Name], grade [X], in connection with their education at [School Name].

Specifically, I would like:

1. A complete list of EdTech vendors who currently have access to my child’s educational records or data. 2. A copy of the data sharing agreements or privacy assessments for each vendor. 3. Clarification on the school district’s data retention policy for student data held by third parties. 4. Confirmation of how parents can request deletion of student data from third-party providers upon the student’s departure from the school or upon parental request.

I understand that FERPA grants me the right to inspect and review my child’s educational records and to request correction or deletion of information. I appreciate any information you can provide about how these rights apply to data held by authorized representatives under 34 C.F.R. § 99.31(a)(1).

Thank you for your time. I am happy to discuss this further.

Sincerely, [Your Name] [Contact Information]


Most schools will respond within two to three weeks. Follow up if you don’t hear back. Connecting with other parents who have the same questions accelerates the process — districts take more notice of five letters than one.

Your Rights Under FERPA

The Family Educational Rights and Privacy Act gives parents of minor students the right to:

  • Inspect and review educational records within 45 days of a request
  • Request correction of inaccurate records
  • Consent to disclosure of records to third parties (with exceptions for “school officials” with “legitimate educational interests” — which is how EdTech vendors get authorized)
  • File a complaint with the US Department of Education at ed.gov/about/offices/list/sro/ if a school violates these rights

The key limitation: FERPA applies to records held by the school or its authorized representatives. Once data leaves the school’s control under certain circumstances (breach, subpoena, vendor sale), FERPA’s protections become difficult to enforce. This is why state-level student data privacy laws matter, and why the Student Privacy Pledge database is a useful secondary layer.

For a broader look at how COPPA interacts with school app data collection, our piece on kids’ online privacy and COPPA covers the federal framework in detail.

What to Watch For Over the Next 3 Months

  • The Department of Education is expected to publish updated FERPA guidance on cloud services and EdTech vendor accountability in Q3 2026, which may tighten what qualifies as a “legitimate educational interest.”
  • Several states including Massachusetts and Washington have student data privacy bills advancing that would require schools to publish vendor agreements publicly and conduct annual privacy impact assessments.
  • Watch for notifications from your district about new AI-powered learning tools — these often introduce new data collection categories (voice, keystrokes, learning pattern inferences) not covered by older privacy assessments.

Frequently Asked Questions

Can the school mandate an app that I’ve decided I don’t want my child to use?

Schools can require use of certain tools for educational purposes. However, you can request an alternative accommodation under most districts’ policies, particularly if the tool collects data you consider sensitive. Frame this as a privacy concern, not a general technology objection, and be specific about what data category concerns you. Some districts will provide a non-digital alternative; others won’t.

What if my child’s school doesn’t know which vendors it uses?

This is more common than you’d expect. Start by asking the IT department rather than the principal — they’re closer to the technical decisions. If the district genuinely doesn’t know, that’s itself a significant governance gap worth surfacing to the school board.

How do I know if an app is using my child’s school account vs. their personal account?

On Google Workspace for Education, apps signed in with a school Google account are governed by the school’s domain settings. On personal devices, children often inadvertently use personal Gmail accounts with school apps, losing the protections of the school contract. Check which account your child uses to log into each app — the email address shown in the profile tells you.

My child uses school apps on our family iPad. Does that create privacy risks?

Yes. When school apps run on a family device, data may commingle with other apps, backup systems, and family accounts. Check whether the school’s app licenses cover personal devices (many don’t). At minimum, set up a separate user profile on shared devices for school work. See our full guide to protecting kids when they use shared devices for practical steps.


About the author Ricky Flores is the founder of HiWave Makers and an electrical engineer with 15+ years of experience building consumer technology at Apple, Samsung, and Texas Instruments. He writes about how kids learn to build, think, and create in a tech-saturated world. Read more at hiwavemakers.com.


Sources

  1. Center for Democracy and Technology. (2023). Student Privacy and Ed Tech: 2023 Policy Update. cdt.org
  2. Electronic Frontier Foundation. (2023). Behind the One-Way Mirror: A Deep Dive Into the Technology of Corporate Surveillance. eff.org
  3. Future of Privacy Forum. (2023). Student Privacy Pledge Signatory Database. studentprivacypledge.org
  4. Common Sense Media. (2024). Privacy Evaluations for EdTech. commonsense.org/education/privacy
  5. US Department of Education. (2023). Family Educational Rights and Privacy Act (FERPA). ed.gov/ferpa
  6. Reidenberg, J. R., et al. (2022). Student Privacy and Third-Party Technology Providers. Fordham Center on Law and Information Policy.
Ricky Flores
Written by Ricky Flores

Founder of HiWave Makers and electrical engineer with 15+ years working on projects with Apple, Samsung, Texas Instruments, and other Fortune 500 companies. He writes about how kids learn to build, think, and create in a tech-driven world.