Student data is never sold, never used for advertising, and never shared outside your school district except as required to operate the service. This is a working draft — contact privacy@schoolmemoria.com with questions.
1. Who We Are
School Memoria is a grade-sync and at-risk student detection platform for K-12 schools. We sync grades and assignment data from learning management systems (Google Classroom, Canvas LMS) into student information systems (PowerSchool). Our registered address and contact details are available at privacy@schoolmemoria.com.
2. Data We Process
School Memoria processes only the data necessary to operate the grade-sync service. This includes:
- Grades and assignment scores — imported from Canvas or Google Classroom and written to PowerSchool
- Course and roster data — teacher names, course names, student enrollment lists, and section IDs used to match records across systems
- Attendance and behavior indicators — where made available by your SIS, used to generate at-risk flags for counselors
- Teacher account information — email addresses and OAuth tokens used to authenticate with LMS and SIS APIs on behalf of the school
- Administrator account information — name, email, and role for staff who access the School Memoria dashboard
We do not collect data about parents or guardians beyond what is incidentally included in teacher-authored grade comments.
3. FERPA — School Official Exception
School Memoria operates as a school official under the Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. § 1232g. We access student education records under the legitimate educational interest exception (34 C.F.R. § 99.31(a)(1)) solely to perform grade-sync and at-risk detection services on behalf of the contracting school or district.
Under this exception:
- We may not redisclose student education records to third parties without prior written consent from the school
- We maintain the records with the same security standards required of the school itself
- We delete or return records upon contract termination (see Section 7)
Schools remain the data controllers under FERPA. School Memoria is a data processor acting on the school's instructions.
4. No Sale of Student Data
School Memoria does not sell, rent, license, or trade student data to any third party. Student data is never used for advertising, marketing, or behavioral profiling — not for School Memoria's own marketing, and not for any third-party purpose. This applies permanently, including after contract termination.
5. How We Use Data
Data is used only to:
- Sync grades and assignment scores between LMS and SIS systems as configured by the school
- Generate counselor-facing at-risk dashboards and intervention recommendations
- Monitor sync health, detect errors, and alert administrators
- Provide billing and account management for school administrators
- Improve reliability and accuracy of the sync pipeline (aggregated, de-identified signals only)
6. Subprocessors
School Memoria uses a limited set of subprocessors, each of which has agreed to data processing terms consistent with this policy:
- Railway — cloud infrastructure hosting the sync daemon and API server (US-based)
- Vercel — static site hosting for the web dashboard and marketing pages (US-based)
- Stripe — payment processing for school subscription billing. Stripe does not receive student data
- Anthropic — AI inference for at-risk analysis and counselor recommendations. Only aggregated, pseudonymized academic indicators are sent; student names and identifiers are never transmitted to Anthropic
We will notify schools of any changes to this subprocessor list at least 30 days in advance.
7. Data Retention and Deletion
Student data is retained only as long as required to operate the service:
- Active contracts — data is retained and updated on each sync cycle
- Contract termination — all student data is deleted from School Memoria systems within 30 days of contract end
- Deletion on request — schools may request immediate deletion of all student data at any time by contacting privacy@schoolmemoria.com
- Audit logs — anonymized sync event logs (no student PII) may be retained for up to 12 months for reliability monitoring
8. Security
School Memoria uses industry-standard security controls to protect student data, including:
- TLS 1.2+ encryption in transit; AES-256 encryption at rest
- OAuth 2.0 for all LMS and SIS API integrations — we never store teacher passwords
- Role-based access controls limiting data access to authorized school staff
- Multi-factor authentication required for all administrator accounts
For a full technical security overview, contact security@schoolmemoria.com.
9. Your Rights
School administrators may, at any time:
- Request a copy of all data School Memoria holds for their school
- Request correction of inaccurate data
- Request deletion of all school data
- Revoke API access, which immediately stops all data collection
Requests should be sent to privacy@schoolmemoria.com. We respond within 5 business days.
10. Changes to This Policy
We will notify school administrators by email at least 30 days before making material changes to this policy. Continued use of the service after that period constitutes acceptance of the updated policy.
11. Contact
Privacy questions, data requests, and DPA inquiries: privacy@schoolmemoria.com
Security disclosures: security@schoolmemoria.com
This is a working draft and has not been reviewed by legal counsel. It is provided for transparency during the School Memoria pilot program. Schools requiring a signed Data Processing Agreement should contact privacy@schoolmemoria.com.