Privacy Policy
Your classroom, your data. Last updated August 6, 2026.
Overview
OrganizeClass is a classroom assessment tool for individual teachers. We collect the minimum information needed to run the product, we never sell it, and you can export or delete it at any time.
Every account that holds student data is covered by our Student Data Addendum, including a teacher who signed up on their own. It is the enforceable version of the commitments on this page.
Schools and districts: our Data Privacy Agreement sits on top of that, aligned with the SDPC National Data Privacy Agreement and Oregon SB 187.
Found a vulnerability? Our security disclosure policy covers how to report it, what we commit to in return, and the safe-harbor terms for your research.
What we collect
From teachers
- Email address, for login
- Name
- School or district name (optional)
- Your password, stored as a one-way hash we cannot reverse, and your two-factor secret if you turn two-factor on
- If you confirm you are school personnel, what you confirmed: the school or district you named, the date, and which version of the terms you accepted.
- Access log entries recording actions taken in your account, each with a timestamp, your IP address, and your browser's user agent
- If you subscribe: your Stripe customer and subscription identifiers, which plan and billing period you chose, its status, and the date the current period ends. We never see or store your card. Payment happens on Stripe's own checkout page, and your card details do not reach our servers.
About students
What we store about students depends on your plan.
For one teacher, after you confirm you are school personnel
- Student names and any notes you write, once you have turned student names on. They are encrypted on our servers with managed keys, and we never sell them, use them for targeted advertising, or build advertising profiles from them.
- Grade level (set per class, not per student)
- Assessment scores, performance levels, and rubric ratings you enter
Photos and documents are on once you confirm. District student IDs are not: they are a district identifier, so they stay limited to schools and districts under a signed agreement. Until you confirm, we hold no student names at all, and scoring, standards, and insights work either way.
For schools and districts, under a signed data privacy agreement
- First name (last name optional)
- District student ID, if entered
- Grade level, assessment scores, and rubric ratings
- Free-text observation notes about a student's work
- Photos or document files of student work attached as evidence
- We do not record audio or video. Recordings are refused by the service, not merely left out of the app.
Classroom data is stored on encrypted disks, with strict access controls and a per-record audit log so we can answer "who viewed this student's records and when". See How we protect your data below for details.
How we use it
- To provide the assessment tracking service
- To authenticate your account
- To generate progress reports you ask for
- To debug and improve the platform, using aggregate usage data
We do not use student work to train AI models, and we do not share it with any third party for advertising.
How we protect your data
We use industry-standard practices to keep classroom data safe.
- Everything you send to us travels over encrypted (TLS) connections.
- A class holds no student names until you turn them on, so the strongest protection is the one that applies by default: we do not have the data.
- Sensitive student information, including names, identifiers, written observations, and uploaded evidence, is encrypted at multiple layers. We use industry-standard encryption practices and customer- managed encryption keys, and we keep a record of every read of student data. Photos and document evidence are stored in encrypted object storage with access only via short-lived signed URLs.
- Passwords are stored as one-way hashes, never as plain text. Auth tokens are kept in HttpOnly cookies that JavaScript running on the page cannot read.
- We support two-factor authentication (TOTP) for teacher accounts.
- We rate-limit sensitive endpoints to prevent abuse, and login sessions expire after 24 hours of inactivity.
- We keep an internal access log so we can answer questions about who viewed a student's records and when.
- Backups are encrypted and access is limited to OrganizeClass staff with a need to maintain the service.
No system is perfectly secure, but we work to follow best practices and update them as our understanding improves.
Data sharing
We do not sell, trade, or share your data with third parties for advertising, marketing, profiling, or any non-educational use. Student data is only accessible to teachers you have invited to the class. District administrators cannot view a teacher's assessments unless the teacher explicitly shares access.
Service providers we work with
Amazon Web Services runs OrganizeClass for us in the United States. It follows its own privacy commitments and only handles data on our behalf.
- Amazon Web Services hosts our application, database, and website in the United States. It also stores uploaded files and delivers transactional email like password resets and class invitations.
- Stripe processes subscription payments for teachers on the Individual plan. It receives your name, email address, and payment details directly, on its own checkout page. Stripe never receives student data.
If we add a new service provider, we will update this list within 30 days. We do not use third-party analytics, advertising networks, or session-replay tools.
Our commitments to schools and families
These promises apply to every school and teacher using OrganizeClass, in line with the Oregon Student Information Protection Act (SB 187) and similar state student-privacy laws.
- We never sell student data.
- We don't use student data for targeted advertising on or off our service.
- We don't build student profiles for anything other than the educational service the teacher is using.
- We don't use student work or observation notes to train AI or machine-learning models.
- We delete student data within 30 days of a request from the school, including photos, notes, and assessment records.
- We follow security practices that are appropriate for the kind of data schools trust us with, described in the section above.
These promises apply to every school and teacher using OrganizeClass, whether or not the school has signed a separate data privacy agreement with us.
If something goes wrong
If we discover a security incident that affects student data, we will notify affected schools and teachers as soon as we reasonably can, and no later than 72 hours after we confirm it. We will tell you what happened, what data was involved, and what we have done about it.
Keeping and deleting data
Your data is yours. You can export or delete it at any time from inside the app. School administrators can request a full deletion by emailing privacy@organizeclass.com.
- Removing a student or deleting a class hides them right away. We keep a recoverable copy for up to one year so accidental deletions can be undone, then remove it permanently. Schools and parents can request immediate permanent deletion at any time.
- We process deletion requests from schools or parents within 30 days and confirm by email when they're done.
- Closing your account deactivates it immediately: you are signed out everywhere, your classes are removed from the product, and your email address is freed up right away. We retain an internal copy of the account record for up to one year for security, audit, and dispute purposes, then delete it permanently. You can request earlier deletion by emailing privacy@organizeclass.com.
- The internal access log works differently, because it is the record we rely on to answer "who saw this, and when." We don't delete it on a schedule. When an account is closed, its entries stay but stop pointing at the person, and the entry recording the closure keeps a copy of the account details so we can answer questions about it later.
Children's privacy
OrganizeClass is used by teachers, not children. Account holders must be 18 or older and working in an educational role. Students don't have accounts, and there is no student login: nothing in a student record holds a password or an email address. Anything we know about a student is what their teacher chose to enter while tracking learning progress.
Students don't use OrganizeClass directly. We have built features that would let a teacher share a link with a student, such as completing a self-assessment, and they are switched off. We will update this policy before we turn any of them on.
We follow the federal student privacy laws, FERPA and COPPA. When a school uses OrganizeClass, we act on behalf of the school, and the school provides the parental consent COPPA requires for using the product with children under 13.
Parents who want to see, correct, or delete their child's data should reach out to their school. Schools can forward requests to privacy@organizeclass.com and we will respond within 30 days.
Student names, notes, and evidence turn on when a teacher confirms they are school personnel, or when a school or district signs a data privacy agreement with us. Either way the data is encrypted on our servers with managed keys. District student IDs stay limited to schools and districts under a signed agreement.
Your rights
- Access your data at any time
- Export your data as CSV or PDF
- Delete your data
- Request corrections to your data
- Close your account
Cookies
We use essential cookies only for authentication and to keep you logged in. We do not use tracking or advertising cookies.
Changes to this policy
We may update this policy from time to time. We will notify users of any material changes by updating the "Last updated" date at the top of this page.
Contact
Questions about this policy or your data? Email privacy@organizeclass.com and a real person on our team will get back to you.