Legal

FERPA Compliance

Last updated: April 18, 2026

The Family Educational Rights and Privacy Act (FERPA, 20 U.S.C. § 1232g) protects the privacy of student education records. MyClassDocs is built to support FERPA-compliant use by individual teachers and the schools and districts that authorize them.

How MyClassDocs treats student data under FERPA

When a teacher uses MyClassDocs as part of their assigned duties, MyClassDocs operates as a "school official" with a legitimate educational interest under FERPA's school-official exception (34 CFR § 99.31(a)(1)). We:

  • Only use student data to provide documentation features to the teacher who entered it
  • Do not redisclose student data to any third party except as required to operate the service
  • Do not sell student data, use it for advertising, or use it to train AI models
  • Maintain direct control over the data and the systems that process it

Technical safeguards

  • Row-level security — every database query is scoped to the authenticated teacher's account
  • Encrypted transport — all traffic uses TLS
  • Private file storage — student documents live in a private bucket served via short-lived signed URLs
  • Authentication — accounts are protected by hashed passwords; we recommend strong, unique passwords
  • Audit trail — server-side logs record administrative access for security review

What we do not collect

  • We do not collect data directly from students.
  • We do not require Social Security Numbers.
  • We do not use targeted advertising or behavioral profiling on students.

Teacher / district responsibilities

FERPA compliance is a shared responsibility. As a MyClassDocs user, you agree to:

  • Only enter student information you are authorized to access under your district's policies
  • Follow your district's data-handling, retention, and parental-disclosure procedures
  • Use a strong, unique password and do not share your account
  • Promptly notify us of any suspected unauthorized access

Parent rights

FERPA gives parents (and students 18 or older) the right to inspect and request correction of their education records. Because MyClassDocs is a teacher-facing tool, those requests should be directed to the school or district, which can then export or correct the relevant records in coordination with the teacher.

Data deletion

Teachers can delete any individual record at any time. To request full deletion of an account and all associated student data, email hello@classdocs.app. We will permanently delete the data within 30 days of a verified request.

Subprocessors

We use the following subprocessors to operate the service. Each is bound by their own privacy and security commitments:

  • Supabase — database, authentication, file storage, edge functions (data hosted in the United States)
  • Google Gemini — optional AI features (inputs are not used to train Google's models via the Gemini API)

Breach notification

If we confirm a security incident affecting student data, we will notify the affected teacher account within 72 hours so the teacher and their district can take appropriate action.

Disclaimer

This page describes how MyClassDocs is designed to support FERPA-compliant use. It is not legal advice. Districts and teachers remain responsible for their own FERPA compliance, including any required parental notice or consent and any written agreements your district requires before using a third-party service.

Contact

FERPA questions, district agreements, or DPA requests? Email hello@classdocs.app.

Questions? Email hello@classdocs.app.