1. Scope and school control
Classroom Guardian is a school-managed educational service. A participating school or district chooses the accounts, students, devices, classes, policies, features, and authorized personnel that use the service. For student information processed on a school's behalf, the school is the primary point of contact for students and parents.
2. Information we collect
Account and organization information
- Names, email addresses, usernames, roles, school and district membership, class membership, and sign-in records.
- Google identity identifiers and profile information supplied during Google sign-in.
- Google Classroom authorization tokens and Classroom information when an authorized teacher connects that integration.
Student and device information
- Student name, email, classes, groups, licensing status, and policy assignments.
- Browser and extension identifiers, user agent, configuration status, current page URL, page title, website host, timestamps, and technical request information.
- Browsing events, active time, blocked attempts, unknown-site activity, blocked-word signals, and policy versions.
- Safety reports, sensitive-signal matches, assigned reviewers, review notes, status changes, and resolution history when the Safety Center is enabled.
- Screen images and current-tab information when screen viewing is active for an authorized teacher.
Documents and assignments
- Google Docs notice information, document links, extracted text, detected links, and keyword signals when enabled.
- Essay assignments, submission files, extracted submission text, student identity, timestamps, model results, and teacher review or deletion actions.
Administrative information
- School policies, category choices, custom allow and blocked lists, teacher-created class rules, extension packages, report preferences, trial requests, and communications.
3. How information is used
- Authenticate users and enforce school, district, class, group, and student permissions.
- Apply filtering policies and report website activity.
- Provide live classroom screen viewing when requested by an authorized teacher.
- Present safety reports and sensitive signals to authorized school staff for human review, assignment, escalation, and documented resolution.
- Create school reports, class rosters, browsing-history exports, and monthly summaries.
- Process assignments and provide probabilistic essay-review signals.
- Maintain licensing, diagnose problems, secure the service, and prevent abuse.
- Communicate about service operation, reports, trials, and account administration.
Student information is not used for targeted advertising and is not sold for advertising or other commercial data-broker purposes.
4. Screenshots and essays stay under company control
Student screenshots are stored only for school-authorized classroom visibility and review. Essay files, extracted text, and detection results are processed on company-controlled systems. Classroom Guardian does not sell these materials or send them to unrelated third-party AI, advertising, analytics, or data-broker companies.
Authorized teachers, school administrators, and limited company personnel supporting the service may access this content according to role and legitimate operational need. Internet and network providers may necessarily carry encrypted traffic, but they are not given screenshots or essays for their own use.
5. Other disclosures
Information other than the protected content described above may be disclosed only as needed to operate the service:
- To authorized school and district personnel according to role.
- To infrastructure providers supporting networking, authentication, and email delivery, limited to the information necessary for those functions.
- To Google when a user chooses Google sign-in or Google Classroom integration.
- When required by law or necessary to protect users, rights, safety, and service security.
- As part of a business restructuring, subject to applicable school agreements and continued protection obligations.
6. Student privacy, safety, and school responsibility
Classroom Guardian is intended for school and district deployment for educational purposes. Schools are responsible for determining their authority to use the service, providing required notices, obtaining required consent, and limiting access to personnel with a legitimate educational interest.
FERPA evaluation
The service is designed to support school-controlled use of education records through role and organization boundaries, authorized access, export, and school-coordinated deletion workflows. The school must determine whether its deployment meets FERPA requirements, including any school-official criteria, legitimate educational interest, record access, redisclosure, and signed data terms. Classroom Guardian does not present FERPA as a product certification.
COPPA evaluation
Student information is not used for targeted advertising and is not sold for advertising or data-broker purposes. The school controls participating accounts, devices, features, and personnel. The school must determine whether school authorization or parent consent applies, provide required notice, and approve the educational purpose and information collected. Classroom Guardian does not present COPPA as a product certification.
Safeguarding responsibility
The school retains responsibility for student supervision, child safeguarding, content suitability, responding to alerts, parent and student communications, disciplinary decisions, and emergency response. The service provides information and controls but does not replace trained school personnel or the school's duty of care.
Parents and students should direct requests to access, correct, or delete school-controlled student records to their school or district. We work with the organization to address verified requests under the applicable agreement and law. The Security and Student Data guide provides a consolidated evaluation checklist.
7. Google data
Google sign-in data is used to authenticate registered users and identify their assigned role. Google Classroom data and tokens are used only when an authorized user connects Classroom and only to provide that integration. Disconnecting an integration stops future access where supported, but previously stored school records remain subject to retention requirements.
Email Game Monitoring Beta is disabled by default and requires explicit authorization from a school administrator. When enabled, the service reads an authorized Google Workspace mailbox to identify game-site links. It retains only matching URLs and limited message metadata, such as sender, recipients, subject, and timestamp. Email bodies are processed transiently and discarded. Schools are responsible for configuring mailbox routing, providing required notices, and obtaining any required consent.
8. Retention and deletion
Information is retained for as long as needed to provide the service, follow school instructions, maintain security and records, resolve disputes, and meet legal obligations. Current application controls include:
- Live screen frames are intended to remain ephemeral during active authorized viewing unless recording is explicitly enabled and started.
- Explicit screen recordings use a default 30-day retention setting that can be configured from 1 to 90 days.
- Raw activity uses a default 90-day retention setting that can be configured from 1 to 365 days.
- Unflagged Google Docs notice captures are scheduled for cleanup after three days.
- Expired or revoked temporary-access records are cleaned after the school's raw-activity retention window.
Deactivating or removing a school may disable credentials without immediately deleting historical records. Schools may request export or deletion, subject to contractual, backup, security, and legal requirements. The signed agreement controls when it requires a different period or process.
9. Security and incident responsibility
We use administrative and technical safeguards designed to protect information and restrict access by role. Current controls include role and tenant authorization, expiring signed sessions, salted password hashing, encrypted stored service tokens, request identifiers, response hardening, audit records for selected sensitive actions, and service monitoring. See the public security guide for implementation and validation details. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur.
Schools must secure their passwords, Google accounts, administrator access, managed devices, networks, role assignments, and local configurations; remove access when personnel leave or change roles; install available updates; and promptly report suspected compromise. The school is responsible for unauthorized access, disclosure, loss, or misuse arising from school-controlled credentials, devices, networks, permissions, configurations, third-party systems, or acts or omissions of its users, to the extent permitted by law.
We will investigate verified reports affecting the service, contain and recover affected service components, preserve appropriate evidence, communicate as required by applicable law and signed agreements, and review corrective actions. No general public incident-response time or breach-notification deadline should be inferred when it is not stated in the signed agreement. Nothing in this Policy disclaims obligations or responsibility that cannot legally be excluded.
10. Automated signals
Blocked-word matches, category classifications, website decisions, and essay-detection scores can be inaccurate. They support human review and should not be treated as conclusive evidence or used alone for disciplinary or academic decisions.
11. Third-party websites
Classroom Guardian may link to school-selected and third-party websites. Their privacy practices are controlled by those services. The official game library may contain content that has not been fully reviewed for violent content.
12. Changes and contact
We may update this Policy to reflect product, security, legal, or operational changes. Material changes may be communicated to the school's designated administrator. Privacy questions and school data requests may be sent to [email protected]. Students and parents should generally begin with their school or district.
