Student Data Privacy Policy
Our commitments for student information, student records, and student-generated content.
This policy adds to our Privacy Policy and Terms of Service. Where they differ on student data, this policy controls.
Sections 1–11 are our commitments everywhere. They apply to every child's records, wherever the child lives, and are built to meet the federal Family Educational Rights and Privacy Act (FERPA, 20 U.S.C. § 1232g), the Children's Online Privacy Protection Act (COPPA), and the student data privacy laws of every U.S. state and the District of Columbia. State-specific terms lists what each state's law adds. Where a state's law or a school's contract is stricter than this policy, the stricter rule applies.
1. Scope
This policy covers student information, student records, and student-generated content, as each state's law defines them — and, where a state uses different terms such as "covered information" or "student data," the information those terms cover. That includes information entered by a child's family or by school or program staff, and information RoundUp gathers while operating the service. Examples are names, dates of birth, contact details, attendance, health and medication records, incident reports, developmental observations, photographs, messages, and documents.
It applies when RoundUp is used by a school, a local or regional board of education, a preschool program, or a child-care program, and by the families of the children enrolled there. In this policy, "the school" means whichever of these holds the relationship with the family.
2. Ownership & control
- Student information and student records are not RoundUp's property and are not under RoundUp's control. They belong to, and are controlled by, the school and the child's family.
- Student-generated content — for example a child's artwork, writing, recordings, or photographs of their work — is the property of the student or the student's parent or legal guardian.
- RoundUp holds this data only to provide the service the school has contracted for.
3. How we use student data
We collect, store, and use student data only for school purposes and only as authorized by our agreement with the school. Within those purposes, we use it to:
- provide the service: attendance, ratios, daily reports, family messaging, billing, health and incident records, and required reporting;
- maintain, support, evaluate, diagnose, and improve the service;
- respond to a request for information or feedback from a student, parent, or guardian. No response is ever influenced by payment from a third party.
Our AI-assisted features, such as lesson plans, development summaries, and translation, process student data only to produce the result the user asked for. Children's names are replaced with placeholders before a request leaves our systems. Student data is never used to train AI models.
We may use de-identified or aggregated information — altered so that no individual student can be identified — to develop and improve our services and to show how well they work.
4. No advertising, no sale
- We do not engage in targeted advertising, in our apps or anywhere else. There is no advertising in RoundUp.
- We do not use student information, student records, student-generated content, or persistent unique identifiers to target advertising or build advertising profiles. We use no advertising or cross-site tracking SDKs.
- We do not sell, rent, or trade student information, student records, or student-generated content.
- The only exception the law allows is a merger or acquisition of RoundUp. In that case the successor must remain bound by this policy and by the law for all student data it receives.
5. When we disclose student data
We disclose student data only:
- to people the school authorizes, such as the child's family and program staff, to carry out school purposes;
- to service providers that host or operate the service for us, such as cloud hosting and payment processing. Each provider is bound by written terms that (i) prohibit using the data for anything except providing its service to us, (ii) prohibit disclosing it to further third parties, and (iii) require security that meets industry standards. The current list is in our Privacy Policy;
- to comply with federal or state law or regulations, or in response to a court or judicial order. Where the law allows, we tell the school first;
- to protect the safety or integrity of users or others, or the security of the service;
- for a school, educational, or employment purpose that a student, parent, or guardian asks for, and for no other purpose.
Integrations a school chooses to connect, such as accounting or e-signature tools, send data only while the school keeps them connected, under the school's own agreement with that provider.
6. Security
We keep security procedures that meet or exceed industry standards, scaled to how sensitive children's records are:
- Encryption at rest (AES-256) and in transit (TLS 1.2 or higher), consistent with the U.S. Department of Health and Human Services guidance under § 13402(h)(2) of Public Law 111-5.
- Technical safeguards consistent with 45 CFR 164.312:
- unique user accounts and role-based access that limits staff to their own program and families to their own children;
- audit logs of access to records;
- integrity controls and authenticated access, with hardware-key multi-factor authentication for our engineers' access to production systems;
- encrypted transmission.
- Production access limited to a small number of authorized engineers, with continuous monitoring and regular vulnerability scanning.
7. Review, correct & export
A parent or legal guardian — or an eligible student — can review the personally identifiable information we hold about the student and correct anything that's wrong:
- In the app: open My child's data to see the child's records and request a copy.
- Through the school: program staff can correct most records directly and are often the fastest route.
- By email: write to privacy@roundupece.com. We coordinate corrections with the school, which controls the record.
Nothing in our terms limits a student's or family's ability to download, export, or keep a copy of their student information or student-generated content.
8. Deletion
- A student, a parent or legal guardian, or the school or board of education that controls the data can ask us to delete it, in the app or by emailing privacy@roundupece.com. We complete deletion within 30 days.
- We keep data after a deletion request only where state or federal law prohibits deleting it or requires us to retain it. We tell you what was kept and why.
- Copies in our encrypted disaster-recovery backups are not accessible to the public and are not used in the normal course of business. They expire on a 90-day cycle. If a backup is ever used to restore live data, you may ask us to delete the restored data again, and we will.
- When a school's contract ends, we do not keep student data or have access to it beyond the return-and-deletion period in the contract. The school can export its data first. A family may choose to keep its own separate account with us to store student-generated content.
9. Breach notification
If we discover a breach of security that results in unauthorized release, disclosure, or acquisition of student data, we notify without unreasonable delay:
- The school, program, or board of education — no later than 30 days after discovery, and sooner wherever a state's law or our contract with the school sets a shorter deadline (see State-specific terms).
- The affected students or their parents or guardians — directly, wherever a state's law requires the operator to notify them, within that law's deadline. Otherwise we notify them directly or through the school, as the school prefers.
During that period we may investigate the nature and scope of the breach, identify the students involved, and restore the integrity of our systems. We will not wait until an investigation is finished to send a first notice.
10. Contracts with schools & boards of education
When a school district, board of education, or public program shares student data with us, we sign the written data privacy agreement its state requires. That includes state-specific agreements and the Student Data Privacy Consortium's National Data Privacy Agreement with its state exhibits. Every such agreement states that:
- student data is not our property or under our control;
- we will not use it for any purpose the agreement doesn't authorize;
- the school can request deletion, and families can review and correct records;
- we will protect it and notify the school of breaches as described above;
- we will not keep it after the agreement ends;
- we and the school will ensure compliance with FERPA.
For those agreements, the law of the school's state governs, and it controls over any different choice-of-law term in our standard Terms of Service. Schools can request our data privacy agreement at privacy@roundupece.com.
11. Contact
Questions, review or deletion requests, and agreement requests: privacy@roundupece.com.
By mail: RoundUp LLC, PO Box 7102, Springfield, OR 97475.
If we change this policy in a way that reduces protections for student data, we will notify schools and families in advance. Such a change will not apply to data already collected without the school's agreement.
State-specific terms
Everything above applies in every state. Open a state to see its student data privacy law and what that law adds. Most states' laws overlap heavily with the commitments above. Where a state has no dedicated student data privacy statute, sections 1–11, FERPA, and COPPA still apply in full.
AlabamaNo dedicated student data statute
Alabama has no statute regulating how ed-tech operators or vendors handle student data. Student records are governed by FERPA and State Board of Education policy. Sections 1–11 of this policy apply in full.
AlaskaNo dedicated student data statute
Alaska has no statute regulating how ed-tech operators or vendors handle student data. Its general Personal Information Protection Act (AS 45.48) covers breaches of personal information. Sections 1–11 of this policy apply in full.
ArizonaA.R.S. § 15-1046
Law: Arizona Revised Statutes § 15-1046, Student data privacy. It covers operators of services used primarily for, and designed and marketed for, school purposes.
What Arizona adds: no duties beyond the commitments in sections 3–8 (no targeted ads, no profiling, no sale, school purposes only, reasonable security, deletion when the school asks).
Source: azleg.gov
ArkansasArk. Code Ann. § 6-18-109
Law: Student Online Personal Information Protection Act, Ark. Code Ann. § 6-18-109. It covers operators of services used primarily for, and designed and marketed for, public school purposes.
What Arkansas adds: no duties beyond sections 3–8. Deletion is due within a reasonable time after a school or district asks; we complete it within 30 days.
Source: Ark. Code § 6-18-109
CaliforniaBus. & Prof. Code §§ 22584, 22586 · Ed. Code § 49073.1
Laws:
- Student Online Personal Information Protection Act (SOPIPA), Bus. & Prof. Code § 22584, for K–12 operators.
- Early Learning Personal Information Protection Act, Bus. & Prof. Code § 22586. It applies the same protections to preschool and prekindergarten operators, so it reaches RoundUp directly.
- Ed. Code § 49073.1, which sets required terms for contracts with local educational agencies.
What California adds, and how we meet it:
- Deletion when the school asks. Also, deletion of a child's information when a parent asks, once the child has been unenrolled for at least 60 days (§§ 22584, 22586, as amended by AB 801, effective 2025).
- Service providers are contractually barred from other uses of the data (section 5).
- Contracts with a local educational agency include every § 49073.1 term. Records stay the agency's property, and students can keep content they created. We describe how parents review and correct records, and name who is responsible for security and how they are trained. The contract describes how parents are notified of an unauthorized disclosure, certifies that records are not kept after the contract ends, sets out joint FERPA compliance, and bans targeted advertising.
Sources: § 22584 · § 22586 · Ed. Code § 49073.1
ColoradoC.R.S. § 22-16-101 et seq.
Law: Student Data Transparency and Security Act, C.R.S. § 22-16-101 et seq. It covers school service contract providers of public education entities, including preschool services used at a public school's or district's direction.
What Colorado adds, and how we meet it:
- We give each contracting district a plain-language list of every data element we collect, why, and how it is used and shared, for the district to post. We keep it current.
- We give clear notice before any material change to our privacy policy.
- We maintain a comprehensive information security program (section 6).
- If we disclose data for legal, safety, or court reasons, we tell the district as soon as possible.
- Subcontractors are bound to the same rules by contract.
- Deletion during the contract happens as soon as practicable. After the contract ends, we destroy the data within the contract's period and tell the district the date it was destroyed.
Breach notice: to the contracting public education entity as soon as possible after we discover misuse or unauthorized release.
Source: Colorado Department of Education
ConnecticutC.G.S. §§ 10-234aa – 10-234dd
Law: Connecticut General Statutes §§ 10-234aa to 10-234dd, the student data privacy law (P.A. 16-189, as amended by P.A. 17-200 and P.A. 18-125).
Who it covers: Connecticut residents enrolled in a preschool program that participates in the state-wide public school information system, in public school grades K–12, receiving special education under an IEP, or otherwise the responsibility of a local or regional board of education.
What Connecticut adds, and how we meet it:
- Written contract with every board of education (§ 10-234bb(a)). We sign a contract containing all ten required provisions, or the uniform terms-of-service addendum under § 10-234ff. Connecticut law governs it, and it includes a severability clause.
- Student-generated content belongs to the student or parent (§ 10-234bb(b)) — see section 2.
- Security consistent with HHS guidance and 45 CFR 164.312 (§ 10-234bb(c)) — see section 6.
- Deletion on request by a student, parent, guardian, or board of education, within a reasonable time (§ 10-234cc(a)(2)). We complete it within 30 days, subject to the legal-retention and disaster-recovery exceptions in section 8.
- No targeted advertising, no sale, and no use beyond school purposes, including persistent unique identifiers (§ 10-234cc(b)) — see sections 3–5.
- Nothing kept after the contract expires (§ 10-234bb(a)(7)), except an account a family chooses to keep for its own student-generated content.
- Breach notice to the board of education (§ 10-234dd(a)): within 30 days of discovery for student information (excluding directory information), and within 60 days for directory information, student records, or student-generated content.
- Breach notice to students and parents, directly (§ 10-234dd(b)): the same 30-day and 60-day deadlines.
Delaware14 Del. C. §§ 8101A – 8106A
Law: Student Data Privacy Protection Act, 14 Del. C. §§ 8101A to 8106A. It covers operators serving K–12 school purposes.
What Delaware adds, and how we meet it:
- Deletion within 45 calendar days of a request. We complete it within 30.
- Security consistent with the Delaware Department of Technology and Information's Cloud and Offsite Hosting Policy.
- Enforced by the Consumer Protection Unit of the Delaware Department of Justice.
Source: delcode.delaware.gov
District of ColumbiaD.C. Code §§ 38-831.01 – 38-831.06
Law: Protecting Students Digital Privacy Act of 2016, D.C. Code §§ 38-831.01 to 38-831.06. It covers operators of services designed, marketed, and primarily used for pre-K through 12 purposes.
What D.C. adds, and how we meet it:
- We delete data under a local education agency's control within a reasonable time after services end, and require anyone we disclosed it to to delete it too.
- We notify the local education agency of any unauthorized access, consistent with D.C.'s breach law.
Source: code.dccouncil.gov
FloridaFla. Stat. § 1006.1494
Law: Student Online Personal Information Protection, Fla. Stat. § 1006.1494. It covers operators serving K–12 school purposes.
What Florida adds, and how we meet it:
- We collect only the information reasonably necessary to provide the service.
- We delete a student's information at the end of the program, and no later than 90 days after the student is no longer enrolled.
- Third parties that receive data are contractually bound not to disclose it further and to maintain security.
- Violations are deceptive and unfair trade practices, enforced by the Department of Legal Affairs.
Source: flsenate.gov
GeorgiaO.C.G.A. § 20-2-666
Law: Student Data Privacy, Accessibility, and Transparency Act, O.C.G.A. §§ 20-2-660 to 20-2-668. Operator duties are in § 20-2-666.
What Georgia adds, and how we meet it:
- Deletion of school-controlled data within 45 days of a request. We complete it within 30.
- Service providers are contractually barred from other uses (section 5).
- Georgia allows behaviorally targeted ads with written consent. We don't use that exception: we show no advertising at all.
Source: Georgia Department of Education
HawaiiHRS §§ 302A-499, 302A-500
Law: Student Online Personal Information Protection, HRS §§ 302A-499 and 302A-500. It covers operators serving K–12 school purposes.
What Hawaii adds: deletion within a reasonable time when a school or complex area asks, and security appropriate to the information. Both are met by sections 6 and 8.
Source: capitol.hawaii.gov
IdahoIdaho Code § 33-133
Law: Student Data Accessibility, Transparency and Accountability Act of 2014, Idaho Code § 33-133. It reaches vendors through required terms in contracts with the state and districts.
What Idaho adds, and how we meet it: our contracts ban secondary uses of student data (sales, marketing, advertising), include privacy and security safeguards, and set a data-destruction timeframe.
Source: legislature.idaho.gov
Illinois105 ILCS 85 (SOPPA)
Law: Student Online Personal Protection Act (SOPPA), 105 ILCS 85, as amended by P.A. 101-516. Its definition of "school" expressly includes any preschool, public or private.
What Illinois adds, and how we meet it:
- We sign a written agreement with each school before any student data moves. It lists the data categories and the product, states that we act as a FERPA school official, allocates breach costs, and sets the deletion and return period.
- This page is our public disclosure of our data practices.
- Every fiscal year we give each school a list of the third parties we share its data with.
- Parents may ask the school to have us delete their child's data. We complete it within 30 days.
Breach notice: to the school within 30 calendar days of determining a breach.
Source: ilga.gov
IndianaNo dedicated student data statute
Indiana has no statute regulating how ed-tech operators or vendors handle student data. Student records are governed by FERPA and district contracts, and the Indiana Consumer Data Protection Act (IC 24-15) took effect January 1, 2026. Sections 1–11 of this policy apply in full.
IowaIowa Code § 279.71
Law: Student online personal information protection, Iowa Code § 279.71. It covers operators serving K–12 school purposes.
What Iowa adds, and how we meet it:
- Security consistent with current industry standards (section 6).
- Subprocessor contracts carry the same duties (section 5).
- Deletion on a district's request as soon as reasonably practicable. We complete it within 30 days.
Source: legis.iowa.gov
KansasK.S.A. 72-6312 et seq. · 72-6331 et seq.
Laws: Student Data Privacy Act, K.S.A. 72-6312 to 72-6320, and Student Online Personal Protection Act, K.S.A. 72-6331 to 72-6334.
What Kansas adds, and how we meet it:
- Kansas restricts collecting biometric data and using tools that assess a student's psychological or emotional state. We do neither.
- The Attorney General enforces these laws.
Breach notice: the holder of the data must immediately notify affected adult students or the parents of affected minors, and investigate (K.S.A. 72-6318). We do so directly, or through the school where it asks.
Sources: K.S.A. 72-6333 · K.S.A. 72-6318
KentuckyKRS 365.734 · KRS 61.931 – 61.934
Laws: KRS 365.734, which covers cloud computing providers to K–12 institutions, and KRS 61.931 to 61.934, which covers vendors of public agencies, including every public school district.
What Kentucky adds, and how we meet it:
- We process student data only to provide, improve, develop, or maintain the service, and never for any commercial purpose.
- We certify our compliance to each institution in writing.
- We maintain security procedures (section 6).
Breach notice: to the contracting agency, such as a school district, without unreasonable delay and within 72 hours of determining a breach (KRS 61.932).
Sources: KRS 365.734 · KRS 61.932
LouisianaLa. R.S. 17:3914
Law: La. R.S. 17:3914, which sets terms for contracts between local school systems and private entities.
What Louisiana adds, and how we meet it: our contracts include access guidelines, privacy compliance standards, privacy and security audits, breach planning, notification and remediation procedures, and retention and disposal policies. They also require disposal of all student data from our servers when the contract ends. We never use student data for predictive modeling that limits a student's opportunities, or for commercial or marketing purposes.
Source: La. R.S. 17:3914
Maine20-A M.R.S. §§ 951 – 953
Law: Student Information Privacy Act, 20-A M.R.S. §§ 951 to 953. It covers operators serving K–12 school purposes.
What Maine adds: deletion within 45 days of a school's or school administrative unit's request. We complete it within 30.
Source: legislature.maine.gov
MarylandMd. Code, Educ. § 4-131
Law: Student Data Privacy, Md. Code, Educ. § 4-131. It covers operators under contract with a public school or local school system, PreK–12.
What Maryland adds, and how we meet it:
- "Covered information" is broad. It includes photographs, voice recordings, health records, and food purchases, all of which this policy protects.
- Deletion within a reasonable time when the school asks. We complete it within 30 days.
- A successor after a merger or acquisition stays bound for data already collected (section 4).
Source: mgaleg.maryland.gov
MassachusettsNo dedicated student data statute
Massachusetts has no enacted statute regulating ed-tech operators or vendors; a student data privacy bill is pending in the Legislature. Student records are governed by 603 CMR 23.00. We follow the state's data security regulation, 201 CMR 17.00, and its breach law, M.G.L. c. 93H. Sections 1–11 of this policy apply in full.
MichiganMCL 388.1291 – 388.1295
Law: Student Online Personal Protection Act, 2016 PA 368, MCL 388.1291 to 388.1295. It covers operators serving K–12 schools.
What Michigan adds: no duties beyond sections 3–8. Deletion happens when the school or district asks, and service-provider contracts pass the same duties down.
Source: legislature.mi.gov
MinnesotaMinn. Stat. § 13.32
Law: Minn. Stat. § 13.32, subdivisions 13 and 14, part of the Data Practices Act. It covers technology providers under contract with a public educational agency.
What Minnesota adds, and how we meet it:
- Educational data is not our property (section 2).
- Access is limited to authorized employees (section 6).
- We destroy or return the data within 90 days after the contract ends.
Breach notice: to the agency upon discovery, with the information it needs to meet § 13.055.
Source: revisor.mn.gov
MississippiNo dedicated student data statute
Mississippi has no enacted statute regulating how ed-tech operators or vendors handle student data. Sections 1–11 of this policy apply in full.
MissouriNo operator or vendor statute
Missouri's student data statute, RSMo 161.096, governs the state Department of Elementary and Secondary Education rather than operators or vendors. Districts may apply its terms through their contracts, and we accept them. Sections 1–11 of this policy apply in full.
Source: revisor.mo.gov
MontanaMCA §§ 20-7-1323 – 20-7-1326
Law: Montana Pupil Online Personal Information Protection Act, MCA §§ 20-7-1323 to 20-7-1326. It covers operators who know, or reasonably should know, that their service is used primarily for K–12 purposes, and adds contract terms for district contracts.
What Montana adds, and how we meet it: district contracts state that pupil records stay the district's property and that pupils can keep content they created. They give parents a way to review and correct records, name who is responsible for security and their training, and describe how affected parents are notified of an unauthorized disclosure. They also certify that records are not kept after the contract ends and ban targeted advertising.
Source: mca.legmt.gov
NebraskaNeb. Rev. Stat. §§ 79-2,153 – 79-2,155
Law: Student Online Personal Protection Act, Neb. Rev. Stat. §§ 79-2,153 to 79-2,155. It covers operators serving elementary, middle, and high school purposes.
What Nebraska adds: no duties beyond sections 3–8. Nebraska permits some sales related to a student's education; we sell no student data at all.
Source: nebraskalegislature.gov
NevadaNRS 388.281 – 388.296
Law: NRS 388.281 to 388.296, school service providers. It covers services designed and marketed for public schools and used at a teacher's direction.
What Nevada adds, and how we meet it:
- We disclose in writing to parents and schools what we collect, how we use it, and our security plan. This page is part of that disclosure.
- We notify boards and teachers before a material change to our security plan.
- Parents can review and correct records (section 7).
- We don't keep data beyond the contract period, and we delete within 30 days of a district's or charter school's request.
Source: leg.state.nv.us
New HampshireRSA 189:68-a
Law: Student Online Personal Information, RSA 189:68-a. It covers operators, including cloud services, used primarily for K–12 school purposes.
What New Hampshire adds, and how we meet it:
- No leasing, renting, trading, or selling student information (section 4).
- Disclosure is permitted in narrower circumstances than in most states. We disclose student data in New Hampshire only as that statute permits.
- Deletion when the school or district asks. We complete it within 30 days.
Source: gencourt.state.nh.us
New JerseyP.L. 2019, c. 494 · N.J.S.A. 56:8-215 et seq.
Law: P.L. 2019, c. 494, codified at N.J.S.A. 56:8-215 et seq., within the Consumer Fraud Act. It covers operators serving K–12 school purposes.
What New Jersey adds: deletion at the request of the school or district, or of a student who has reached the age of majority. We complete it within 30 days.
Source: pub.njleg.gov
New MexicoNo dedicated student data statute
New Mexico has no statute regulating how ed-tech operators or vendors handle student data. Its Data Breach Notification Act (NMSA 1978, ch. 57, art. 12C) covers breaches of personal information. Sections 1–11 of this policy apply in full.
New YorkN.Y. Educ. Law § 2-d · 8 NYCRR Part 121
Law: N.Y. Education Law § 2-d and 8 NYCRR Part 121. They cover third-party contractors of educational agencies, including districts, BOCES, universal and publicly funded pre-K, and approved preschool special-education providers.
What New York adds, and how we meet it:
- Each contract includes our data security and privacy plan and the agency's signed Parents' Bill of Rights for Data Privacy and Security.
- Our security program aligns with the NIST Cybersecurity Framework. Data is encrypted in motion and at rest (section 6).
- Staff are trained on privacy and security before they can access student data.
- We reimburse the educational agency for the cost of notifications a breach we caused requires.
Breach notice: to the educational agency within 7 calendar days of discovery (8 NYCRR 121.10).
Sources: Educ. Law § 2-d · 8 NYCRR 121.10
North CarolinaN.C.G.S. § 115C-401.2
Law: Student Online Privacy Protection, N.C.G.S. § 115C-401.2. It covers operators serving K–12 school purposes.
What North Carolina adds: deletion within 45 days of a school's request or notice that service has ended, unless the parent (or a student 13 or older) consents in writing to keep it. We complete deletion within 30 days. Enforced by the Attorney General.
Source: ncleg.gov
North DakotaNo operator or vendor statute
North Dakota has no statute regulating how ed-tech operators or vendors handle student data. NDCC 15.1-07-25.3 requires each school board to adopt a student-data policy and approve sharing with outside entities, so we work within that approval. Sections 1–11 of this policy apply in full.
OhioORC 3319.325 – 3319.327
Law: Ohio Revised Code 3319.325 to 3319.327, as amended by HB 432 (2024). It covers technology providers handling education records for a K–12 district.
What Ohio adds, and how we meet it:
- No commercial use of education records, and no marketing to students or parents with them.
- We comply with ORC chapter 1347, and destroy or return records within 90 days after the contract ends.
- RoundUp does not access a school-issued device's location, camera, microphone, or student interactions.
Breach notice: to the district following discovery, with what it needs under ORC 1347.12.
Source: codes.ohio.gov
OklahomaNo operator or vendor statute
Oklahoma's Student Data Accessibility, Transparency and Accountability Act (70 O.S. § 3-168) governs the State Department of Education's data rather than operators or vendors. Sections 1–11 of this policy apply in full.
OregonORS 336.184
Law: Oregon Student Information Protection Act, ORS 336.184. It covers operators serving K–12 school purposes.
What Oregon adds: deletion within a reasonable time when the school or district asks, which we complete within 30 days. Violations are unlawful trade practices, enforced by the Attorney General.
Source: oregonlegislature.gov
PennsylvaniaNo dedicated student data statute
Pennsylvania has no enacted statute regulating ed-tech operators or vendors; a student data privacy bill has been introduced in the Senate. Student records are governed by 22 Pa. Code chapter 12, and breaches by 73 P.S. § 2301 et seq. Sections 1–11 of this policy apply in full.
Rhode IslandR.I. Gen. Laws § 16-104-1
Law: Student Data-Cloud Computing, R.I. Gen. Laws § 16-104-1. It covers cloud computing services provided to educational institutions.
What Rhode Island adds, and how we meet it: we process student data solely to provide the service, never for commercial or advertising purposes. We certify our compliance in writing in each contract.
Source: rilegislature.gov
South CarolinaNo operator or vendor statute
South Carolina's student data statute (S.C. Code § 59-1-490) governs the state Department of Education's data rather than operators or vendors. Sections 1–11 of this policy apply in full.
South DakotaNo operator or vendor statute
South Dakota's student data statutes (SDCL 13-3-51 and 13-3-51.1) govern the state's own education data systems rather than operators or vendors. Sections 1–11 of this policy apply in full.
TennesseeT.C.A. § 49-1-708
Law: Student Online Personal Protection Act, T.C.A. § 49-1-708. It covers operators serving K–12 school purposes.
What Tennessee adds: no duties beyond sections 3–8. Deletion is due within a reasonable time after a school's request; we complete it within 30 days.
Source: T.C.A. § 49-1-708
TexasTex. Educ. Code §§ 32.151 – 32.157
Law: Texas Education Code chapter 32, subchapter D, §§ 32.151 to 32.157. It covers operators serving school purposes, including information from district employees.
What Texas adds, and how we meet it:
- Deletion within 60 days of a district's request. We complete it within 30.
- If Texas's education agency approves an operator, the law requires it to use the Texas Student Data System unique identifier instead of student names. We would do the same if approved.
Source: statutes.capitol.texas.gov
UtahUtah Code § 53E-9-301 et seq.
Law: Student Data Protection Act, Utah Code § 53E-9-301 et seq. Contractor duties are in § 53E-9-309, as amended in 2026. It covers contractors of districts, charter schools, and the state.
What Utah adds, and how we meet it:
- We use student data strictly for the contracted service.
- Our contracts include data-sharing restrictions, a list of who may receive data, deletion on request, a ban on secondary use where the school requires one, and the school's right to audit.
- We return or delete data when the contract ends, if the school asks.
Source: le.utah.gov
Vermont9 V.S.A. §§ 2443 – 2443f
Law: Student Privacy, 9 V.S.A. §§ 2443 to 2443f. It covers operators serving PreK–12 school purposes. "School" expressly includes public and private preschools, so it reaches RoundUp directly.
What Vermont adds, and how we meet it:
- We publicly disclose how we collect, use, and disclose student data, and give that disclosure to each school. This page and our Privacy Policy are that disclosure.
- Deletion within a reasonable time when the school asks. We complete it within 30 days.
Source: legislature.vermont.gov
VirginiaVa. Code § 22.1-289.01
Law: Va. Code § 22.1-289.01. It covers school service providers under contract with a local school division.
What Virginia adds, and how we meet it:
- Plain-language disclosure of the data we collect (this page and our Privacy Policy).
- Prominent notice before any material change to our privacy policy.
- A comprehensive information security program (section 6).
- Access and correction for students and parents, and an electronic copy of a student's data on request (section 7).
- Deletion within a reasonable period after a school division asks. We complete it within 30 days.
Source: law.lis.virginia.gov
WashingtonRCW 28A.604
Law: Student User Privacy in Education Rights Act, chapter 28A.604 RCW. It covers school service providers designed and marketed primarily for K–12 schools.
What Washington adds, and how we meet it:
- Clear, easy-to-understand disclosure of what we collect and how we use it (this page and our Privacy Policy).
- Prominent notice before any material change to our privacy policy.
- Access and correction for students and parents (section 7).
- A comprehensive information security program (section 6).
- No student profiles built for any purpose the school hasn't authorized.
- Deletion within a reasonable time when the school asks. We complete it within 30 days.
Source: app.leg.wa.gov
West VirginiaW. Va. Code § 18-2-5h
Law: Student Data Accessibility, Transparency and Accountability Act, W. Va. Code § 18-2-5h. It mainly binds the state Department of Education and reaches vendors through its contracts.
What West Virginia adds, and how we meet it: contracts involving student data include express privacy and security provisions and penalties for noncompliance. We accept those terms.
Source: code.wvlegislature.gov
WisconsinNo operator or vendor statute
Wisconsin has no statute regulating how ed-tech operators or vendors handle student data. Pupil records are governed by Wis. Stat. § 118.125, which reaches vendors through district contracts, and breaches by Wis. Stat. § 134.98. Sections 1–11 of this policy apply in full.
WyomingNo operator or vendor statute
Wyoming requires the state education department and districts to adopt student data security and privacy guidelines (W.S. 21-2-202), including a ban on selling student data. It puts no duties on vendors directly; we follow district guidelines through our contracts. Sections 1–11 of this policy apply in full.
This summary is kept current as laws change and was last reviewed September 10, 2026. It describes our commitments, not legal advice to schools.