Draft — Pending Legal ReviewThis K-12 Privacy Notice is a working draft. The binding legal terms governing any district's use of The Student Blueprint are the executed Data Privacy Agreement (typically the SDPC National Data Privacy Agreement v2.2 with the applicable state exhibit) and the FERPA Addendum signed with that district.

K-12 Privacy Notice

For school districts, students, parents, and staff

1. Scope

This K-12 Privacy Notice applies when a U.S. public, charter, or independent school, local education agency ("LEA"), or school district licenses The Student Blueprint for use by its students, parents, counselors, and staff. The public-facing Privacy Policy governs all other uses of the Service. Where this Notice and the public Privacy Policy differ, this Notice controls for district-licensed deployments.

2. Our Role Under FERPA

When a district licenses The Student Blueprint, we operate as a "school official" with a legitimate educational interest under the Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g, and the implementing regulations at 34 CFR § 99.31(a)(1)(i)(B). Specifically:

  • We perform an institutional service or function for which the district would otherwise use employees;
  • We act under the direct control of the district with respect to education records;
  • We use education records only for the purposes for which we were engaged and as permitted by the parties' Data Privacy Agreement;
  • We do not re-disclose education records to any other party except as authorized by the district or required by law.

We do not require students or parents to waive FERPA rights as a condition of using the Service. Parents and eligible students retain all access, correction, and consent rights provided by FERPA.

3. Data Ownership

Student data is owned by the district, not by The Student Blueprint. We process student data solely on behalf of the district and only for the educational purposes authorized in the Data Privacy Agreement. Aggregated, de-identified data may be used to improve the Service, but only in a form that cannot reasonably be re-identified.

4. Information We Collect From or About Students

In a district deployment, student data is provided by the district (via roster integration where available) and supplemented by the student during the assessment. Categories may include:

  • Identifiers: name, grade level, school identifier, district-issued email or student ID.
  • Academic data: GPA, coursework, standardized test scores, extracurricular activities, leadership history.
  • Self-reported profile data: interests, career aspirations, strengths, personality archetypes, time availability.
  • PPRA-protected categories (only with appropriate notice or consent): family income range, parent occupations, ethnicity, and self-reported responses that may touch on mental, emotional, or psychological characteristics. See Section 7 below.
  • Technical data: IP address, browser, session information used for security and rate-limiting.

We do not knowingly collect Social Security numbers, biometric identifiers, religious or political affiliations, sexual orientation, or precise geolocation.

5. How Student Data Is Used

Student data is used solely to provide the licensed educational service: generating personalized college and career planning analyses, recommending activities and scholarships, producing PDF reports, and providing administrative dashboards to counselors and authorized district staff. Specifically, we will not:

  • Sell student data;
  • Use student data for targeted advertising on or off the Service;
  • Build a non-educational profile of any student;
  • Use student data to train AI or machine-learning models;
  • Disclose student data to any third party except authorized subprocessors.

6. COPPA (Students Under 13)

For students under 13, the district acts as the school authorizing collection of limited personal information for the educational purposes described above, consistent with FTC guidance on the "school authorization" pathway under the Children's Online Privacy Protection Act, 15 U.S.C. § 6501 et seq. Districts remain responsible for providing required parental notice. Parents may, at any time, review their child's information, request corrections, or request deletion.

7. PPRA — Surveys and Assessments

Certain questions in The Student Blueprint touch on categories protected by the Protection of Pupil Rights Amendment, 20 U.S.C. § 1232h, including family income, parent profession, and self-reported emotional or psychological characteristics. When such questions are presented to students of a district that licenses the Service:

  • The district is the controller of any notice and opt-out obligations under PPRA;
  • Students and parents may opt out of any PPRA-protected category individually, and opted-out fields are excluded from both the assessment input and any downstream AI prompt;
  • Where the district uses Department of Education funds covered by PPRA, written parental consent is required before any opted-in PPRA-protected questions are presented.

8. Artificial Intelligence

The Student Blueprint uses large-language-model providers (Google Gemini, with Anthropic Claude as a fallback) to generate personalized analyses. By contract with both providers, customer data submitted via the commercial API is not used to train their underlying models. Districts may, at their option:

  • Disable AI-generated content for their tenant entirely; or
  • Require PII redaction so that names, contact information, and direct identifiers are stripped from any payload before it leaves our infrastructure.

AI-generated content is presented as guidance for student and counselor review, not as an educational, psychological, or medical determination. Counselors and students retain full discretion to accept, modify, or disregard any recommendation.

9. Subprocessors

The Student Blueprint engages a limited number of subprocessors (cloud database, hosting, payment, transactional email, AI providers). See our Subprocessors page for the current list, purposes, and data residency. Districts under an active Data Privacy Agreement receive advance notice of any subprocessor change.

10. Security

We maintain administrative, technical, and physical safeguards designed to protect student data, including TLS in transit, AES-256 encryption at rest, multi-tenant isolation via row-level security, audit logging of administrative actions, and distributed rate-limiting. SOC 2 Type II readiness is in active progress. See our Trust & Security page for the current control inventory.

11. Data Retention and Deletion

We retain student data only as long as needed to provide the licensed service. Upon district termination, request from an authorized district administrator, or transition of a student out of the district, student data is deleted from primary storage within 30 days; backup copies are purged within an additional 30 days. Aggregated, de-identified statistics with no reasonable risk of re-identification may be retained.

12. Parent and Student Rights

Parents and eligible students may, through their district, request to:

  • Inspect and review the student's information held by The Student Blueprint;
  • Request correction of inaccurate or misleading information;
  • Request deletion of the student's account and associated assessment data;
  • Request a portable export of the student's assessment data;
  • Opt the student out of any PPRA-protected category or out of AI-generated content where the district permits.

Requests should be directed to the district's designated FERPA officer, who can relay them to us at privacy@thestudentblueprint.com.

13. Breach Notification

In the event of a confirmed unauthorized acquisition of district student data, we will notify the district's designated security contact within 24 hours of discovery (or sooner where required by state law), with a detailed follow-up including affected records, remediation steps, and corrective measures within 72 hours. Notification obligations to parents and individuals remain with the district unless otherwise agreed in writing.

14. State-Specific Provisions

For districts in California, this Notice is intended to operate consistently with California Education Code § 49073.1 (AB 1584) and California Business and Professions Code § 22584 et seq. (SOPIPA), and the parties' Data Privacy Agreement (typically the SDPC California exhibit) controls any inconsistency.

For districts in Texas, this Notice is intended to operate consistently with Texas Education Code § 32.151 and the Texas Student Privacy Alliance Data Privacy Agreement.

For districts in Georgia, this Notice is intended to operate consistently with the Georgia Student Data Privacy, Accessibility, and Transparency Act and the GADOE Data Privacy Pledge.

For districts in other states, the SDPC National Data Privacy Agreement v2.2 and the applicable state exhibit control.

15. Contact

Districts may request our SDPC NDPA v2.2 General Offer signature page, a fully completed security questionnaire, or any other procurement document by writing to privacy@thestudentblueprint.com. Security vulnerabilities may be reported at security@thestudentblueprint.com.

See also: Privacy Policy · Subprocessors · Trust & Security · Terms of Service