Data Privacy & Security

Student data stays where it belongs.

School Memoria is built for FERPA compliance from the ground up. We never sell data, never train AI on student records, and give districts the option to keep AI processing entirely on their own servers.

0
Student records sold or shared
100%
FERPA compliant by design
AES-256
Encryption at rest & in transit

How your data flows — and where it stops

Every piece of student data has a clear owner, a clear path, and a clear boundary it never crosses.

1

Teacher connects their gradebook

Teachers authorize School Memoria to read grades from Google Classroom or Canvas using OAuth. We read only what's needed: grade entries, assignment names, and course identifiers. No email contents, no documents, no student PII beyond what's in the gradebook.

2

Our sync engine matches and maps grades

The sync daemon runs on Railway infrastructure (US region), matching Classroom/Canvas course entries to PowerSchool section records using your district's rostering data. No student data is persisted beyond what's needed for the sync operation — records are processed in memory and immediately written to PowerSchool.

3

AI resolves mismatches — without seeing PII

When course names or assignment structures differ between systems, Claude AI helps resolve them. In our standard cloud tier, the AI sees only anonymized structural data (e.g., "Course A has 12 assignments, Course B has 11 — do these match?"). In our School Secure and self-hosted tiers, AI processing never leaves your district network at all.

4

Grades land in PowerSchool. Logs are yours.

Every sync operation is logged with timestamp, teacher, course, and result status. Logs are retained for 90 days and exportable on request. You can revoke access at any time and we will delete all cached data within 24 hours.

Cloud-hosted or self-hosted — you choose

Every district has different data governance requirements. We support both models without changing the user experience.

☁️

Cloud-Hosted

AI processing runs on Anthropic's infrastructure. Student data is anonymized before any AI call. Recommended for districts without dedicated IT resources.

  • Zero infrastructure to manage
  • Automatic updates and patches
  • 99.9% uptime SLA
  • AI sees anonymized structural data only
  • Data encrypted at rest (AES-256) and in transit (TLS 1.3)
  • SOC 2 Type II in progress
  • FERPA-compliant data processing agreement

Where exactly does your data go?

Click between the two modes to see the data flow for each hosting option.

👩‍🏫
Teacher
Google Classroom
or Canvas
🔄
Sync Engine
Railway (US)
OAuth token
🎓
PowerSchool
Grades written
directly
Mismatch resolution only (anonymized)
🤖
Claude AI
Anthropic cloud
Anonymized only
🔍
Mismatch Detector
Structural data
no PII

What AI never sees: student names, IDs, grades, email addresses, or any personally identifiable information. AI receives only anonymized course structure data (e.g., assignment counts and date ranges).

District Network Boundary — No data crosses this line
👩‍🏫
Teacher
Google Classroom
or Canvas
🔄
Sync Engine
Your servers
OAuth token
🤖
AI Sandbox
Your servers
Isolated per-school
🎓
PowerSchool
Grades written
directly

Everything stays inside your network. The AI sandbox is deployed to your district's servers. School Memoria's cloud infrastructure only receives sync status signals (success/failure counts) — never student data. Each school's sandbox is fully isolated from all others.

Built for the compliance requirements you already have

We don't treat compliance as a checkbox — it's baked into how we architect data flows.

📜
FERPA
Family Educational Rights and Privacy Act. Students' educational records are protected and never disclosed without written consent.
Compliant
🧒
COPPA
Children's Online Privacy Protection Act. No collection of personal information from students under 13 without verifiable parental consent.
Compliant
🏛️
SOPIPA
Student Online Personal Information Protection Act (CA). We don't sell student data or use it for targeted advertising, ever.
Compliant
🔐
SOC 2 Type II
Security, Availability, and Confidentiality trust service criteria. Audit in progress — report available Q3 2026.
In Progress
🔒
AES-256 Encryption
All data encrypted at rest with AES-256 and in transit with TLS 1.3. Encryption keys managed per-district with rotation every 90 days.
Active
📝
DPA Ready
Data Processing Agreement available for district signature. We countersign within 2 business days and maintain a signed copy on file.
Available

Questions from IT directors & privacy officers

The questions we actually get from district IT teams before they approve us.

No. In our cloud-hosted tiers, AI receives only anonymized structural data — things like "Course A has 12 assignments that don't match Course B's 11 assignments." Student names, IDs, grades, and email addresses are never sent to any AI model.

In the self-hosted tier, AI processing runs entirely on your servers and never contacts Anthropic's cloud at all, so the question is moot — the AI is under your complete control.

Yes. We have a standard DPA that meets FERPA requirements and most state-level student data privacy laws. We countersign within 2 business days. Email privacy@schoolmemoria.com to request a copy.

For districts in California, we also comply with SOPIPA and CCPA as they apply to student records.

We request the minimum necessary scopes: classroom.coursework.students.readonly, classroom.courses.readonly, and classroom.rosters.readonly. We do not request access to Drive files, Gmail, Calendar, or any other Google service.

Teachers authorize their own account only. We do not request domain-wide delegation unless your district specifically requires it for a custom rollout.

Our cloud infrastructure runs on Railway (US-West region, hosted on Google Cloud Platform GCP US-West). All data is stored and processed in the United States. We do not use servers outside the US for any student data processing.

For self-hosted deployments, your data stays on whatever servers you designate — we have no visibility into that infrastructure.

Any teacher can revoke their OAuth authorization from their Google or Canvas account settings at any time — no contact with us required. This immediately stops all sync operations for that teacher.

For district-wide offboarding, email support@schoolmemoria.com and we will delete all district data within 24 hours and provide written confirmation.

Never. We do not sell, license, rent, or share student data with any third party for any purpose, including advertising, analytics services, or data brokers. Student data is used exclusively to provide the grade sync service you authorized.

We use Stripe for billing (no student data involved), Telegram for internal ops alerts (no student data), and Anthropic's API for AI processing (anonymized structural data only in cloud tier, zero data in self-hosted tier).

The self-hosted sandbox is a containerized (Docker) deployment of the AI inference layer that runs on your district's servers. It requires a Linux server with at least 8GB RAM and 4 CPU cores. We provide the Docker image, docker-compose configuration, and full setup documentation.

Your IT team does a one-time setup (~2 hours), and School Memoria's cloud sync engine is configured to route AI calls to your local sandbox instead of Anthropic's cloud. After setup, student data processing stays entirely on your hardware.

Ready to share with your IT director?

Download our one-page IT brief — written for principals and IT directors, not engineers. Or schedule a 20-minute security review call.