GradeHouse School Management System Privacy Policy
Effective Date: August 1, 2026
At GradeHouse ("we," "us," or "our"), we are committed to protecting the privacy of students, educators, and institutions. This Privacy Policy explains how we collect, use, disclose, and secure information through our multi-tenant school information system (the "Platform").
Because schools use the Platform to manage educational workflows, our data practices are designed to support compliance with the Family Educational Rights and Privacy Act (FERPA) and the Children's Online Privacy Protection Act (COPPA).
1. Our Role: School Official Under FERPA
When a school or district uses our Platform, GradeHouse acts as a "School Official" with a legitimate educational interest under FERPA. All student education records and personally identifiable information (PII) processed by our Platform belong to and remain under the direct control of the contracting school or district. We process this data solely to provide our services and do not use it for our own commercial purposes.
2. Information We Collect
We only collect information necessary to support the educational and administrative functions of the contracting school.
- Account Information: Full name, school-assigned email address, student ID number, and system login credentials.
- Educational Records: Grades, attendance logs, class schedules, assignments, and teacher feedback.
- Technical & Usage Data (Persistent Identifiers): IP address, browser type, device type, and operating system. This data is collected automatically and used strictly for internal operations, such as security auditing, session maintenance, load balancing, and platform optimization.
3. Children's Privacy & COPPA Compliance
Our Platform may be used by students under the age of 13. In accordance with COPPA guidelines for educational software:
- School-Provided Consent: We rely on the contracting school or district to provide consent on behalf of parents for the collection of personal information from students under 13.
- No Commercial Exploitation: We never sell, rent, or lease student data. We never use student data for behavioral tracking, targeted advertising, or user profiling.
- Strict Limitations: Student data collected from users under 13 is used exclusively for the school's educational purposes.
4. Data Security and Multi-Tenant Isolation
We implement industry-standard administrative, physical, and technical safeguards to protect student data.
- Data Isolation: The Platform uses multi-tenant architecture with logical database separation and Row-Level Security (RLS) so one school cannot access another school's data.
- Encryption: Data is encrypted in transit (TLS) and at rest (provider-managed disk encryption on DigitalOcean Managed Postgres / Spaces).
- Security Monitoring: We monitor for unauthorized access and maintain operational runbooks for incident response.
5. Data Retention and Deletion
We retain student data for the duration specified by the contracting school (including campus retention-year settings for withdrawn students) and as needed to provide the service. Upon contract termination or a validated written request from the district administration, we securely delete or permanently anonymize student records within thirty (30) days, subject to legal holds.
Campus administrators may also export school-scoped CSVs (Privacy settings) and run retention purge for withdrawn students past the configured retention years (education records are deleted; household ledger lines are unlinked from the student).
6. Parent and Student Rights
Parents or eligible students who wish to review, correct, or request the deletion of a student's personal information must submit their request directly to their school or district administration. Because the school retains ownership of the educational record, we will work directly with the school to fulfill these requests.
7. Subprocessors
We use limited subprocessors to operate the Platform. GradeHouse uses the following subprocessors to operate the Platform. Schools remain the data controller for student education records.
| Subprocessor | Purpose | Typical data | Region / notes |
|---|---|---|---|
| DigitalOcean | App hosting (App Platform), Managed PostgreSQL, Spaces object storage | Application data at rest; encrypted volumes; private Spaces objects (photos, exports, packets) | Primary: NYC (nyc / nyc3). See DO DPA. |
| Clerk | Authentication (sign-in / sign-up), session management | User email, name, auth identifiers | Clerk cloud (US). Schools require MFA at Microsoft/Google. GradeHouse does not add a second in-product TOTP gate (BER-476 / GH-016). |
| Stripe | Campus Connect payments (family tuition / other / giving checkouts) | Payment method tokens, Connect account metadata, amounts; card numbers stay with Stripe | Stripe Connect connected accounts per campus. |
| Twilio | Campus Office SMS (GradeHouse-provisioned subaccount or school BYO) | Mobile numbers, message bodies, STOP/HELP, A2P Brand/Campaign metadata | One subaccount + Messaging Service per campus. Parent account bills GradeHouse on signup; BYO bills the school. |
8. Text messaging
When a campus enables SMS, families opt in from communication preferences after signing in. The school is the sender. GradeHouse and Twilio process mobile numbers only to deliver those messages and honor STOP/HELP for that campus.
Mobile information will not be shared with third parties or affiliates for marketing or promotional purposes.
Message frequency varies. Message and data rates may apply. Reply STOP to opt out. Reply HELP for help.
Each campus publishes SMS privacy and terms without a login at /s/{campus-slug}/sms-privacy and /s/{campus-slug}/sms-terms. Those pages are the policies submitted for carrier registration.
9. Contact Us
Questions about this Privacy Policy: [email protected]