Privacy at The Impact Classroom

Student privacy is a design constraint here, not an afterthought. In plain language:

Before any AI touches a student's data, that student's family has to say yes.

No AI feature that involves a specific student runs for that student until their family has opted in. The shipped default is off, and a family that does not reply has not consented — silence is not agreement, and nothing of their student's is processed. Families are asked two separate questions, and can say yes to one and no to the other:

  • Sharing what your scholar made and learnedSo you get real updates about what your scholar built this week instead of a generic newsletter, and so our community partners can see the impact of their work. A photo of the work your scholar turns in. It is handwritten, so the name gets covered before the picture is taken. That is a classroom habit, not something the software enforces. This answer covers: Grading a submitted worksheet; Drafting the update we send your family; Drafting the summary we share with a community partner; Reading the reflection your scholar wrote on their worksheet.
  • Helping your scholar plan tasks and join project groupsSo project teams are built around shared interests and complementary strengths, and scholars get specific help turning their group's goals into tasks they can actually do. Your scholar's interests, future goals and self-identified strengths, plus a few sentences they write about their project. Never their name. This answer covers: Breaking a group's build-day goal into tasks; Suggesting student groups.

A family can change its answer at any time, and it takes effect immediately. The form a family answers on accepts a new answer whenever they return to it, and a teacher can send a fresh link on request. There is no waiting period and nothing to cancel.

A student whose family declines is not disadvantaged in any way. They do the same projects with the same community partners, their work is graded the same way, and their family still receives class updates — those updates describe what the class is building rather than that student's own work, and are written without AI and without any information about them.

AI grading is switched off. It ships off and stays off unless the teacher of a class deliberately turns it on. Even then it still requires that student's family to have opted in, which is a separate answer a teacher cannot give on a family's behalf. Both have to be true before a piece of student work is ever read by AI for a score.

What we collect.

From students, only their name and school email. Their classwork, including photos of work they submit, is stored so their teacher can review it. We also store the contact details teachers, families, and community partners need to use the platform.

What we never do.

We never sell or rent student data. We never use it for advertising or marketing. And it is never used to train anyone's AI models — not ours, not a provider's.

Who can see student work.

Nothing about a student, their work, their family, your partners, or your school is public without your school's explicit approval. The public gallery is off by default. Family and partner views are private, read-only links scoped to a single student or partner.

The other companies involved.

Running this platform means a handful of companies handle some of this data on our behalf. Here is every one of them and what each actually receives. None of them are permitted to use it for their own purposes.

  • Anthropicthe AI features. Photos of the work a student submits, and short pieces of text a student wrote. Exactly which, and for which features, is listed below. Anthropic does not use data sent through its API to train its models. It holds SOC 2 Type I and II, ISO 27001 and ISO 42001 certifications.
  • Google (Firebase and Google Cloud)the database, sign-in, and file storage. Everything the platform stores: student names and school emails, classwork including photos of submitted work, and the contact details of teachers, families, and community partners. This data is stored in the United States.
  • Vercelhosting. Every page and API request as it is served, including the usual web-server records — IP address, browser, and which URL was requested.
  • Resendplatform email. The recipient's email address and the message itself, for sign-in links, invitations, and partner notifications. Class updates a teacher sends to families do not go through Resend — those are sent from the teacher's own Google account, as described further down this page.
  • Sentryerror reports. A report when something breaks: the error, and where in the app it happened. Configured to strip identity before anything is sent — no signed-in user record, email addresses masked out of error text, no cookies, no form or request bodies, and no session recording.

Where AI is used, and what it sees.

Some features send data to Anthropic's AI. We think you should be able to see exactly which ones and exactly what goes, rather than a general statement that we "may use AI."

These features send information about a specific student:

  • Grading a submitted worksheetThe photos of the work the student handed in, together with the rubric their teacher wrote. Handwritten work often has a name on it.
  • Suggesting student groupsA student's interests, what they want to do after high school, their GPA goal, and the strength they picked for themselves. No names are sent — each student appears only under an internal id.
  • Breaking a group's build-day goal into tasksThe goal the student group wrote for that day, in their own words, plus what they are building and for which community partner.
  • Drafting the update we send your familyWhat the student's group recorded about the project they are building — its title, description, what they are making and the difference they hope it makes for the community partner — together with the student's own end-of-unit reflection, in their own words. No names are sent; each student appears only under an internal id. A teacher reads and can rewrite every draft before it is sent to anyone.
  • Drafting the summary we share with a community partnerWhat student groups recorded about the projects they are building for that partner, together with the reflections scholars wrote by hand about their own work. No names are sent, and the summary describes the class as a whole — a community partner never sees a row, a quotation, or a paragraph about any individual scholar. A teacher reads it and can stop it before the partner sees it.
  • Reading the reflection your scholar wrote on their worksheetThe photos of the completed worksheet your scholar handed in, so the short reflection they wrote by hand at the end of it can be typed up in their own words for the update we send you. Handwritten work often has a name on it. Nothing is judged or described — the answer is transcribed, not summarized.

Each of those runs only for a student whose family opted in, as described at the top of this page. Which answer covers which feature:

  • Sharing what your scholar made and learnedGrading a submitted worksheet; Drafting the update we send your family; Drafting the summary we share with a community partner; Reading the reflection your scholar wrote on their worksheet.
  • Helping your scholar plan tasks and join project groupsBreaking a group's build-day goal into tasks; Suggesting student groups.

These features use AI but send nothing about any student — they work from what a teacher wrote, so there is nothing here for a family to consent to and none of them is gated on a family's answer:

  • Drafting driving questions for a unitThe teacher's academic concept and the community issue for the unit.
  • Drafting the catch-up notes for an assignmentThe teacher's own authored material for that assignment — the questions and tables on the worksheet, the key concepts the unit teaches, what was planned for the class day, and the readings the teacher wrote or collected. Nothing about any student is sent: no names, no roster, no submitted work.
  • Drafting a key concept's definition and practice problemsThe name of the concept the teacher typed from their district pacing guide, the course it belongs to and the subject it teaches, the unit it sits in, and the published academic standards that unit covers. Nothing about any student is sent: no names, no roster, no submitted work.
  • Drawing the model a teacher projects for a key conceptThe name of the concept, the definition and vocabulary the teacher wrote for it, the practice problems it sets, the course and subject it belongs to, and the grade level its published standards cover. Nothing about any student is sent: no names, no roster, no submitted work.
  • Suggesting academic standards for a unitThe teacher's unit title, description, and key concepts, plus the published list of standards to choose from.

Anthropic does not use any of it to train its models. It does hold data sent through its API for a limited period for safety and abuse monitoring; we have asked Anthropic for an arrangement under which nothing is retained at all, and this page will say so plainly if and when that is in place. We would rather tell you what is true today than what we are hoping for.

Sending email from a teacher's Google account.

A teacher can choose to connect their Google account so class updates reach families from their own school address rather than a no-reply one. Connecting is optional, and a teacher can disconnect at any time from their Google Account permissions page.

When a teacher connects, The Impact Classroom uses Google's send-email permission (gmail.send) for one purpose only: to send that teacher's own class-update emails to their students' families, from the teacher's own account, on the teacher's behalf. The app only sends. It never reads, stores, or accesses the contents of a mailbox — no inbox, no sent mail, no drafts, no contacts, no attachments. What we keep is the connection itself: the credential Google issues so we can send on the teacher's behalf, which stops working the moment they disconnect.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Data agreements.

Before we handle student data at your school, we sign your district's standard data-privacy agreement (for example, the SDPC National Data Privacy Agreement) and operate only as a designated school official under FERPA. Your school's data stays yours and is exportable.

Questions.

Email theimpactclassroom@gmail.com.

This page is a plain-language summary. Where a signed data-privacy agreement is in place with your school or district, that agreement governs.