School Memoria is built for FERPA compliance from the ground up. We never sell data, never train AI on student records, and give districts the option to keep AI processing entirely on their own servers.
Every piece of student data has a clear owner, a clear path, and a clear boundary it never crosses.
Teachers authorize School Memoria to read grades from Google Classroom or Canvas using OAuth. We read only what's needed: grade entries, assignment names, and course identifiers. No email contents, no documents, no student PII beyond what's in the gradebook.
The sync daemon runs on Railway infrastructure (US region), matching Classroom/Canvas course entries to PowerSchool section records using your district's rostering data. No student data is persisted beyond what's needed for the sync operation — records are processed in memory and immediately written to PowerSchool.
When course names or assignment structures differ between systems, Claude AI helps resolve them. In our standard cloud tier, the AI sees only anonymized structural data (e.g., "Course A has 12 assignments, Course B has 11 — do these match?"). In our School Secure and self-hosted tiers, AI processing never leaves your district network at all.
Every sync operation is logged with timestamp, teacher, course, and result status. Logs are retained for 90 days and exportable on request. You can revoke access at any time and we will delete all cached data within 24 hours.
Every district has different data governance requirements. We support both models without changing the user experience.
AI processing runs on Anthropic's infrastructure. Student data is anonymized before any AI call. Recommended for districts without dedicated IT resources.
AI processing runs inside your school network. Student data physically never leaves your district. For compliance-sensitive districts and state-regulated environments.
Click between the two modes to see the data flow for each hosting option.
What AI never sees: student names, IDs, grades, email addresses, or any personally identifiable information. AI receives only anonymized course structure data (e.g., assignment counts and date ranges).
Everything stays inside your network. The AI sandbox is deployed to your district's servers. School Memoria's cloud infrastructure only receives sync status signals (success/failure counts) — never student data. Each school's sandbox is fully isolated from all others.
We don't treat compliance as a checkbox — it's baked into how we architect data flows.
The questions we actually get from district IT teams before they approve us.
No. In our cloud-hosted tiers, AI receives only anonymized structural data — things like "Course A has 12 assignments that don't match Course B's 11 assignments." Student names, IDs, grades, and email addresses are never sent to any AI model.
In the self-hosted tier, AI processing runs entirely on your servers and never contacts Anthropic's cloud at all, so the question is moot — the AI is under your complete control.
Yes. We have a standard DPA that meets FERPA requirements and most state-level student data privacy laws. We countersign within 2 business days. Email privacy@schoolmemoria.com to request a copy.
For districts in California, we also comply with SOPIPA and CCPA as they apply to student records.
We request the minimum necessary scopes: classroom.coursework.students.readonly, classroom.courses.readonly, and classroom.rosters.readonly. We do not request access to Drive files, Gmail, Calendar, or any other Google service.
Teachers authorize their own account only. We do not request domain-wide delegation unless your district specifically requires it for a custom rollout.
Our cloud infrastructure runs on Railway (US-West region, hosted on Google Cloud Platform GCP US-West). All data is stored and processed in the United States. We do not use servers outside the US for any student data processing.
For self-hosted deployments, your data stays on whatever servers you designate — we have no visibility into that infrastructure.
Any teacher can revoke their OAuth authorization from their Google or Canvas account settings at any time — no contact with us required. This immediately stops all sync operations for that teacher.
For district-wide offboarding, email support@schoolmemoria.com and we will delete all district data within 24 hours and provide written confirmation.
Never. We do not sell, license, rent, or share student data with any third party for any purpose, including advertising, analytics services, or data brokers. Student data is used exclusively to provide the grade sync service you authorized.
We use Stripe for billing (no student data involved), Telegram for internal ops alerts (no student data), and Anthropic's API for AI processing (anonymized structural data only in cloud tier, zero data in self-hosted tier).
The self-hosted sandbox is a containerized (Docker) deployment of the AI inference layer that runs on your district's servers. It requires a Linux server with at least 8GB RAM and 4 CPU cores. We provide the Docker image, docker-compose configuration, and full setup documentation.
Your IT team does a one-time setup (~2 hours), and School Memoria's cloud sync engine is configured to route AI calls to your local sandbox instead of Anthropic's cloud. After setup, student data processing stays entirely on your hardware.
Download our one-page IT brief — written for principals and IT directors, not engineers. Or schedule a 20-minute security review call.