A teacher I know found a fun little app that turned spelling lists into a game. It was free. Signing up took about thirty seconds. She typed in her class list, the first names, the last initials, the reading group each kid was in, clicked the box that said I Agree, and got on with her afternoon. Nothing about that is wrong. It is what any of us would have done. It is also what happens in a few hundred thousand classrooms every single week.
I have spent more than twenty years working in IT and cybersecurity, so I will admit the first thing that went through my head when I heard that story had nothing to do with spelling. It was more like, I wonder where that class list just went. A lot of my career has been spent on the other side of the glass, and I have a pretty good sense of what tends to happen after someone clicks I Agree. Most of the time it is not sinister. It is just a business model doing what it was built to do. The catch is that the business is sometimes the kids themselves.
I am not writing this to make anyone paranoid, and I am definitely not writing it to talk you out of using technology. Good tools are worth every minute they hand back to you. I just want to walk through one question that every teacher, principal, and district leader ought to be able to answer before a child's name gets typed into anything. Is this actually safe?
The quiet math of "free"
Software is expensive to build. Servers, engineers, support, security, none of that is free to the company that is handing you a free app. So whenever I see something with no price on it, I find myself asking the oldest question in my line of work. Then how does this thing pay for itself?
Sometimes the answer is perfectly reasonable. Maybe the company raised money, or the free version exists to sell you the paid one down the road. But sometimes the answer is the one nobody wants to say out loud. The product is not the app. The product is the data flowing through it. Names, grade levels, device information, location, browsing habits, which kids are falling behind. Stack all of that up and you have a profile. And profiles of children happen to be worth quite a bit, mostly because they are supposed to be nobody's business.
What bothers me is not that one company somewhere might sell student data. It is that so many apps are wired to share it automatically, and no one in the building ever hears a word about it.
The numbers are worse than most educators think
I do not love scaring people with statistics. These ones are hard to look past, though, and they come from serious researchers rather than clickbait.
Back in late 2022, Internet Safety Labs looked at the apps being used across 663 schools, which added up to roughly 455,000 students. They found that 96% of those apps shared children's personal information with outside parties. 78% of them handed it specifically to advertising and analytics companies, usually without the school or the family knowing a thing. Almost a quarter showed children ads right there inside the app.
That same year, Human Rights Watch studied 163 learning apps and platforms used around the world. Their conclusion was that 89% of them either surveilled children or had the ability to, often long after the school day was over and nowhere near a classroom.
And when data does get out, it gets out at scale. Comparitech counted more than 3,700 data breaches at schools here in the United States, which exposed over 37 million records.
Read that first number one more time. Ninety-six percent. This is not a handful of shady apps hiding in the corners of the app store. This is much closer to how the whole free app economy around our classrooms simply operates. Almost none of the teachers using those tools had any idea, and really, why would they. Nobody goes into teaching to moonlight as a security expert.
Why this matters more for a child than it does for you or me
When my data leaks, it is a headache. I change a few passwords, I keep an eye on my credit, and life moves on. When the same thing happens to a nine year old, it is a different story, and a worse one, for a reason that is easy to miss. A child has their whole life still in front of the data.
Think about what a profile on a second grader can grow into. Their name, their school, the fact that reading is hard for them, the device they use, where they tend to be at three in the afternoon. All of that can be bought, sold, stitched together with other data sets, and used to target them for years before they are anywhere near old enough to agree to it. A stolen Social Security number belonging to a kid is basically a gift to an identity thief, because nobody thinks to check a seven year old's credit report for another decade. This is the whole reason we have laws like FERPA, which protects the privacy of student education records, and COPPA, which limits what companies can collect from children under 13. Those laws exist because kids cannot look out for themselves here. The adults have to do it for them.
And here is the part that keeps the district folks I talk to up at night. When a teacher signs up for some free tool on her own and starts feeding student data into it, the school can end up being the one on the hook for the compliance mess, even though nobody in the district ever approved it or even knew it was there.
How to tell the safe ones from the risky ones
You do not need any of my certifications to make good calls here. You need a few questions and the nerve to walk away when the answers are bad. Here is what I actually pay attention to, in plain language.
Who is paying for this? If you cannot figure out how a free product keeps its lights on, go ahead and assume the data is the payment until somebody proves otherwise. A company with nothing to hide will just tell you. We are grant funded. There is a paid plan for schools. We charge the district. Clear answers are a good sign.
Does it actually say the words FERPA and COPPA? Tools made for schools should come right out and say they follow student privacy laws. They should not hand you a generic privacy policy that reads like it was copied off an online store. Vague is a bad sign. Specific is a good one. A lot of the trustworthy ones have also signed something called the Student Privacy Pledge, which is a nice signal on its own, even if it is not a guarantee.
Does it sell or share data with advertisers? Open the privacy policy and search it for a few words. Third parties. Advertising. Sell. A good policy will say plainly that it does not sell student data and does not use it for ads. If instead it reserves the right to share with partners, that door was left open on purpose.
Can you get the data back, and can you delete it? The tools worth trusting let a school pull its data out and erase it for good whenever it asks. If there is no obvious way to make the information disappear, then it never really leaves.
Did anyone whose actual job is to check ever look at this? The single most protective habit a school can build is almost boring in how simple it is. Student data only goes into tools the district has already vetted. One short list of approved tools will do more good than a hundred well meaning decisions made one classroom at a time.
None of that takes a technical background. It takes a few minutes and permission to be a little suspicious on behalf of your students. And that suspicion is not you being cynical. It is you looking out for them.
What good actually looks like
Let me be clear about one thing, because I build software for a living and I do not think the lesson here is fewer tools or more fear. The lesson is tools that earn the trust they are asking you for.
A tool worth trusting is almost boringly open about how it makes money. It tells you what it collects and why, in words a tired human can actually read at the end of a long day. It does not quietly ship your class roster off to a dozen ad networks the second you hit save. It treats a kid's information like it belongs to the kid, which it does. In my experience, when a company is getting this right, they are usually happy to talk your ear off about it rather than hoping you never ask.
Ruby and I did not start Ivaro because the world was short one more app. We started it because we kept bumping into the gap between what technology promised teachers and what it quietly took back in return. Student data privacy sits right in the middle of that gap. When you are the one holding a child's information, saving the security conversation for later is not really an option. It has to be the thing you get right first, not the thing you bolt on at the end.
So how does Ivaro measure up?
It would be a little strange to spend a whole article handing you five questions and then dodge them myself. So here is how Ivaro answers each one. I would rather you hold us to the same standard I just asked you to hold everyone else to.
Who is paying for this? The schools and districts that choose to use Ivaro. We do not run on advertising, and we do not make a single dollar from your students' information. That is the whole point. When the district is the customer, the district never has to wonder if it is secretly the product.
Does it take FERPA and COPPA seriously? We built Ivaro around them from the very beginning instead of treating them as fine print to sort out down the road. Protecting student records is a design requirement for us, not a disclaimer buried at the bottom of a page.
Does it sell or share data with advertisers? No, and it never has. Your students' information is not a product we sell and it does not go to advertisers, full stop. Here is a detail I am actually proud of. When Ivaro helps grade a stack of student work, the student's name is cropped out and blacked over before anything gets processed, and that name badge is never handed to the AI model at all. The tool only ever sees what it genuinely needs to do the job, and nothing more.
Can you get the data back, and can it be deleted? We do not hold onto sensitive material any longer than the moment we need it. The original scanned uploads live in a temporary holding area for less than an hour and are then deleted automatically, on every path, whether the work finished or something failed along the way. Nothing sits quietly in the background collecting dust, or risk.
Can someone whose job is to check actually check? We know the safest tools are the ones a district has looked at with clear eyes, so we try to make Ivaro easy to put under that kind of scrutiny. We are straightforward about where your data lives, which is inside Microsoft's Azure cloud, and about how it is handled. When the person in your district whose job is to ask the hard questions comes calling, we want them to get real answers, not a runaround.
None of that makes us special, and I do not want it to. It should be the baseline. My hope is that a few years from now this list feels obvious, the way seatbelts feel obvious now. Until then, ask every tool in your building these questions. Ivaro included.
From Kevin's Desk
Something I learned pretty early in my career is that most data disasters do not begin with a hacker in a hoodie. They begin with something small and completely well meaning. A handy tool. A fast sign up. A box checked without reading it. The breach is just the last domino to fall.
That is the lens I carry into education technology, and it is why none of this feels abstract to me. Every free app that quietly vacuums up a classroom is one of those small first dominoes. The good news is that the fix is small and human too. Ask who is paying. Read the two or three lines that actually matter. Keep student data inside tools that somebody bothered to check. You do not have to turn into a security professional. You just have to stay a little curious for your students' sake, and expect the companies asking for your trust to go out and earn it.
Frequently Asked Questions
Are free classroom apps safe for student data?
Some are, and plenty are not. Research from Internet Safety Labs found that 96% of the apps it studied across a large group of schools shared children's personal information with outside parties, and 78% shared it with advertising or analytics companies. Free usually means the app is earning its keep off the data moving through it. Before you type in any student information, figure out how the tool makes money and check whether it says clearly that it follows FERPA and COPPA and does not sell student data or use it for ads.
What is FERPA and how does it relate to apps?
FERPA stands for the Family Educational Rights and Privacy Act, a United States law that protects the privacy of student education records. When a teacher puts student data into an outside app, that data can fall under FERPA, and the school can be held responsible for how it is handled. That is why student data should only go into tools the district has looked at first, and why the trustworthy education apps state their FERPA compliance right up front.
How can I tell if an app sells student data?
Read the privacy policy and search it for the words third parties, advertising, and sell. A trustworthy education tool will say plainly that it does not sell student data or use it for advertising. Wording like we may share data with partners is a sign the door was left open on purpose. When you are not sure, just ask the vendor directly and run the tool through your district's approval process.
Why is children's data privacy such a big deal?
A child has their whole life still ahead of the data being collected about them, so a profile or a stolen identity can follow them and cause harm for years before they are old enough to consent to any of it. Laws like FERPA and COPPA exist for exactly that reason. Children cannot protect themselves here, so the responsibility lands on the adults and institutions around them.
Sources
- Internet Safety Labs, "96% of School Apps Send Student Data to Third Parties, Including Advertisers" (2022)
- Human Rights Watch, "Online Learning Products Enabled Surveillance of Children" (2022)
- Comparitech, "US schools data breaches"
- U.S. Dept. of Education, Student Privacy (FERPA)
- FTC, Children's Online Privacy Protection Rule (COPPA)