My child’s school recently started using several education apps, and I’m concerned about student data privacy. What personal information do edtech apps collect, how is it used, and can parents limit or delete it?
Don’t assume deleting the app deletes your child’s account or data. These services may collect names, school IDs, assignments, grades, messages, device identifiers, IP addresses, usage history, and sometimes audio or video. Schools and vendors may use it for instruction, progress tracking, security, and product maintenance. Ask the district for its approved-app list, vendor contracts, retention schedule, and the exact process to access or delete records. FERPA gives parents access to education records, while COPPA may provide review and deletion rights for children under 13, but school-created accounts often have to be handled through the district rather than the app.
The app itself may be only the first stop for the data. Edtech tools often connect to the school’s student-information system, Google or Microsoft accounts, analytics services, cloud storage, and other vendors. They may create inferred data too, such as reading level, attention patterns, predicted performance, or flags based on behavior. That can be more sensitive than a basic profile.
@carl_tech is right that the district is usually the practical place to start. I’d ask which features are required, whether advertising or profiling is prohibited, which subcontractors receive student data, and whether your child can use a non-digital alternative for optional apps. Turn off unnecessary permissions on the device, especially contacts, location, microphone, and camera.
Deletion may have limits. Schools may need to retain certain records, and vendors may keep backups or de-identified statistics for a while. Ask for written confirmation covering the main account, connected services, and backups, plus a date when deletion will be completed. An app disappearing from the tablet proves very little.
The easiest data to overlook is what kids type or upload themselves: journal entries, chat messages, voice recordings, photos, and open-ended assignments can reveal far more than a profile. Device permissions matter, but blocking the microphone won’t help if recording is part of the lesson. Ask the school for the app’s privacy notice, retention period, and process to view or correct your child’s records. You can request deletion, though required school records may be exempt; for optional tools, ask whether your child can submit work another way.
Do not create a separate “parent” or “home” account just to inspect the app until you know what that account does. Some platforms treat school-managed student accounts differently from consumer accounts. Signing up with a personal email, linking a child profile, or accepting optional terms can create another copy of the data under a different retention policy.
The basic profile is only part of the collection. An app may receive class rosters, teacher names, enrollment status, accommodations, assignment history, grades, login timestamps, search terms, clicks, time spent on each question, and every revision to a document. If it uses automated scoring or AI features, ask whether student submissions are stored for model training, human review, or product testing. “Improving the service” is too vague an answer.
I agree with @bluepixel5644 that connected systems matter, but device permissions can give parents a false sense of control. Turning off location or contacts is sensible, yet most educational tracking happens on the vendor’s servers after the student signs in. A more useful request is a field-level data inventory: what comes from the school, what the child enters, what the app generates, and where each category is sent. Ask whether the login connection grants access only to basic identity information or to files, calendars, email, and other account data.
Before requesting deletion, export or inspect the record first. Otherwise, you may lose the easiest way to identify incorrect grades, behavior flags, messages, or inferred labels. Then make the deletion request specific: close the account, remove uploaded work and recordings, revoke connected-account tokens, delete derived profiles, and identify anything that must remain. If the vendor claims data is anonymous, ask whether identifiers were actually removed or merely replaced with a code. Coded student data can still be linkable when the school or vendor keeps the matching key.
Your realistic control may depend on whether the app is required for class. For a required service, the school usually needs to handle access, correction, retention, and vendor contact. For an optional feature, you have a stronger practical argument for refusing it or requesting an equivalent method. Keep the request in writing and ask for a named person responsible for student privacy. A generic help-desk ticket tends to produce instructions for deleting the icon, not an answer about deleting the data.
Send the school a short written request naming each app and asking whether it is required, what data it receives, and where that data gets exported. Don’t start with the vendor’s generic privacy form. The school chose the tool and should be able to explain what it actually enabled.
A missing issue here is downstream copies. Teachers may download reports, paste scores into the gradebook, email spreadsheets, or move student work into another platform. Deleting the app account will not erase those copies. Ask specifically about exports, shared reports, archived classes, and data synced back to the school’s main records system.
Keep the request narrow enough that someone has to answer it:
- What fields are collected or generated?
- Who receives them, including subcontractors?
- Are submissions used to train or test AI?
- How long is each category kept?
- Which records can be corrected or deleted?
- What happens if you refuse an optional feature?
Inspect the record before demanding deletion, as @foxking suggested. Then request removal from the vendor, connected accounts, teacher-created exports, and any derived profile that is not a required school record. Get the answer in writing. A statement that the account was “deactivated” is not the same as confirmation that the data was deleted.
Nobody’s mentioned the legal reason your options feel so thin for the required apps. Under FERPA there’s a ‘school official’ exception that lets the district hand student records to a vendor without asking you first, as long as the vendor is under the district’s control and only uses the data for the school’s purposes. COPPA has a similar carveout: for classroom tools, the school can give consent on parents’ behalf for kids under 13. So when you go in expecting a veto, you often find the school already signed off legally. That’s not a reason to give up, but it changes what you’re actually arguing about. You’re not asking permission to allow it. You’re asking them to prove the vendor stayed inside those limits.
Which is where I’d push a little on the deletion talk in here. @foxking and @asynccoder are right that ‘deactivated’ isn’t ‘deleted,’ but honestly your stronger lever is the contract, not the delete button. If the district’s agreement says the vendor can’t sell data, can’t advertise, and has to purge records on request or at contract end, that binds them in a way a support ticket never will. Ask for that clause in writing. A lot of the reassurance you want is supposed to already live in the contract the school signed, and half the time nobody at the school has actually read it.
The piece people keep skipping is state law. Depending on where you live, your state may have a student privacy statute that’s tougher than FERPA or COPPA and applies directly to the vendor, with real limits on selling data, targeted ads, and profiling. California, Colorado, and a bunch of others have these. Worth a quick check, because it can give you a cleaner demand than the federal stuff, which was mostly written before this kind of data collection existed.
Two smaller things. Policies change. An app that was clean when the district approved it can update its terms a year later, especially once it bolts on some AI feature, and nobody re-reviews it. And directory information is its own trap. If the school designated things like name, grade level, or photo as directory info, they can release it more freely unless you filed the annual opt-out. Most parents never see that form.
My honest take: focus your energy on the required apps through the district and the contract, and just quietly refuse or opt out of the optional ones. Trying to individually audit and delete from every vendor will burn you out, and the ones that matter most are the ones the school controls anyway.
Deleting this year’s class does not necessarily delete your child’s profile. Many systems keep a longitudinal record across teachers and grade levels, so ask when old classes are archived, who can still access them, and what happens when your child transfers or graduates. “No longer enrolled” is not a deletion policy.