1. Scope and school control
Classroom Guardian is a school-managed educational service. A participating school or district chooses the accounts, students, devices, classes, policies, features, and authorized personnel that use the service. For student information processed on a school's behalf, the school is the primary point of contact for students and parents.
2. Information we collect
Account and organization information
- Names, email addresses, usernames, roles, school and district membership, class membership, and sign-in records.
- Verified possession of a guardian email address and the school-approved relationship to a student when a school enables guardian access.
- Google identity identifiers and profile information supplied during Google sign-in.
- Google Classroom authorization tokens and Classroom information when an authorized teacher connects that integration.
Student and device information
- Student name, email, classes, groups, licensing status, and policy assignments.
- Browser and extension identifiers, user agent, configuration status, current page URL, page title, website host, timestamps, and technical request information.
- Browsing events, active time, blocked attempts, unknown-site activity, blocked-word signals, and policy versions.
- Safety reports, sensitive-signal matches, assigned reviewers, review notes, status changes, and resolution history when the Safety Center is enabled.
- Screen images and current-tab information when screen viewing is active for an authorized teacher.
Documents and assignments
- Google Docs notice information, document links, extracted text, detected links, and keyword signals when enabled.
- Essay assignments, submission files, extracted submission text, student identity, timestamps, model results, and teacher review or deletion actions.
Administrative information
- School policies, category choices, custom allow and blocked lists, teacher-created class rules, extension packages, report preferences, trial requests, guardian invitations, and communications.
3. How information is used
- Authenticate users and enforce school, district, class, group, and student permissions.
- Apply filtering policies and report website activity.
- Provide live classroom screen viewing when requested by an authorized teacher.
- Present safety reports and sensitive signals to authorized school staff for human review, assignment, escalation, and documented resolution.
- Create school reports, class rosters, browsing-history exports, and monthly summaries.
- Process assignments and provide probabilistic essay-review signals.
- Maintain licensing, diagnose problems, secure the service, and prevent abuse.
- Communicate about service operation, reports, trials, and account administration.
Student information is not used for targeted advertising and is not sold for advertising or other commercial data-broker purposes.
4. Screenshots and essays remain limited to the approved service
Student screenshots are stored only for school-authorized classroom visibility and review. Essay files, extracted text, and detection results are processed only for approved writing features. Classroom Guardian does not sell these materials or send them to unrelated third-party AI, advertising, analytics, or data-broker companies.
Authorized teachers, school administrators, and limited operator personnel supporting the service may access this content according to role and legitimate operational need. Disclosed infrastructure providers may transmit or store encrypted service data only to provide their contracted function and not for their own advertising or unrelated use.
5. Other disclosures
Information other than the protected content described above may be disclosed only as needed to operate the service:
- To authorized school and district personnel according to role.
- To the providers listed in the current Service Provider Schedule, limited to the information necessary for their stated function.
- To Google when a user chooses Google sign-in or Google Classroom integration.
- When required by law or necessary to protect users, rights, safety, and service security.
- As part of a business restructuring, subject to applicable school agreements and continued protection obligations.
6. Student privacy, safety, and school responsibility
Classroom Guardian is intended for school and district deployment for educational purposes. Before managed devices may send student information, an authorized school administrator must record the school's authority, signed data protection agreement, required notices, specific educational purpose, and approved features. Classroom Guardian remains responsible for its own COPPA obligations as the operator; recording school authorization does not transfer or waive those obligations.
FERPA evaluation
The service supports school-controlled education records through role and organization boundaries, legitimate-interest audit records, verified access requests, full student-record export, correction, stop-collection, and deletion workflows. The school must determine whether its deployment meets FERPA requirements, including its school-official criteria, annual notice, legitimate educational interests, disclosure records, redisclosure limits, and signed data terms. Classroom Guardian does not present FERPA as a product certification.
COPPA notice and authorization boundary
A school may authorize collection from a child under 13 only for a school-approved educational purpose and only where the school is permitted to act for the parent. School authorization does not cover unrelated commercial use. If use occurs outside that school context, verifiable parental consent may be required before collection. Participation is not conditioned on disclosing more personal information than is reasonably necessary for the approved feature.
Parents may ask the school to review the child's information, request correction or deletion, refuse further collection or use, or withdraw permission. The school verifies the requester and opens an audited request in the Privacy & compliance workspace. A stop-collection request immediately disables that student's managed-device session. Privacy questions may also be sent to [email protected].
Safeguarding responsibility
The school retains responsibility for student supervision, child safeguarding, content suitability, responding to alerts, parent and student communications, disciplinary decisions, and emergency response. The service provides information and controls but does not replace trained school personnel or the school's duty of care.
Parents and students should direct requests to access, correct, or delete school-controlled student records to their school or district. Authorized school administrators can export the student's record classes, record corrections, stop future collection, and complete deletion from the Privacy & compliance workspace. The Security and Student Data guide provides a consolidated evaluation checklist.
7. Google data
Google sign-in requests basic identity information used to authenticate registered users and identify their assigned role. The optional Google Classroom connection requests only read-only course, roster, and class-member email access needed to synchronize classes and student identities. Classroom Guardian does not request Gmail, Google Drive, or Google Workspace domain-administrator permissions. Disconnecting Classroom removes the locally stored Classroom tokens and stops future synchronization; previously created school roster records remain subject to the school's retention requirements.
8. Retention and deletion
Information is retained for as long as needed to provide the service, follow school instructions, maintain security and records, resolve disputes, and meet legal obligations. Current application controls include:
- Live screen frames are deleted when authorized viewing stops; a five-minute stale-frame threshold and recurring cleanup act as a fail-safe unless recording is explicitly enabled and started.
- Explicit screen recordings use a default 30-day retention setting that can be configured from 1 to 90 days.
- Raw browsing activity and completed transport copies use a default 90-day retention setting configurable from 1 to 365 days. A visit tied to an unresolved school safety review is preserved until that review is resolved.
- Unflagged Google Docs notice captures are scheduled for cleanup after three days.
- Expired or revoked temporary-access records are cleaned after the school's raw-activity retention window.
Deactivating or removing a school may disable credentials without immediately deleting historical records. Schools may request export or deletion, subject to contractual, backup, security, and legal requirements. The signed agreement controls when it requires a different period or process.
9. Security and incident responsibility
We use administrative and technical safeguards designed to protect information and restrict access by role. Current controls include role and tenant authorization, expiring signed sessions, salted password hashing, encrypted stored service tokens, request identifiers, response hardening, audit records for selected sensitive actions, and service monitoring. See the public security guide for implementation and validation details. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur.
Schools must secure their passwords, Google accounts, administrator access, managed devices, networks, role assignments, and local configurations; remove access when personnel leave or change roles; install available updates; and promptly report suspected compromise. The school is responsible for unauthorized access, disclosure, loss, or misuse arising from school-controlled credentials, devices, networks, permissions, configurations, third-party systems, or acts or omissions of its users, to the extent permitted by law.
We will investigate verified reports affecting the service, contain and recover affected service components, preserve appropriate evidence, communicate as required by applicable law and signed agreements, and review corrective actions. No general public incident-response time or breach-notification deadline should be inferred when it is not stated in the signed agreement. Nothing in this Policy disclaims obligations or responsibility that cannot legally be excluded.
10. Automated signals
Blocked-word matches, category classifications, website decisions, and essay-detection scores can be inaccurate. They support human review and should not be treated as conclusive evidence or used alone for disciplinary or academic decisions.
11. Third-party websites
Classroom Guardian may link to school-selected and third-party websites. Their privacy practices are controlled by those services. The official game library may contain content that has not been fully reviewed for violent content.
12. Changes and contact
We may update this Policy to reflect product, security, legal, or operational changes. Material changes may be communicated to the school's designated administrator. Privacy questions and school data requests may be sent to [email protected]. Students and parents should generally begin with their school or district.
