School Apps Are Collecting Kids' Data — Privacy Keeps Getting Delayed
Your child's school software may know more about them than you do
A new study looks at the software your child's school probably uses every day, and finds a pattern the authors call "we'll fix it later." Researchers interviewed 12 people who build and run education technology, then read the privacy policies of 48 different platforms. Again and again, they heard the same thing: privacy is important, everyone agrees, but it gets pushed to the next version, the next funding round, the next school year. Companies focus on features, growth, and getting money in the door first.
The policy audit shows the same gap. These platforms are reasonably good at telling you what data they collect. They're much worse at explaining what happens to it afterward — who sees it, how long it's kept, who it's shared with. One in three (33%) displays AI features without any meaningful disclosure that AI is involved. Those features can include software that grades essays, flags struggling students, or chats with kids. And 73% offer only generic boilerplate about accountability and what happens after a data breach. K-12 platforms did better on getting parents' consent — but only because laws force them to, and that advantage disappears when it comes to AI.
For families, the practical worry is simple: sensitive records about your child — including disability information and behavioral notes — sit inside systems with thin oversight. Responsibility gets passed around like a hot potato, to the cloud provider, to the policy document, to the school district. Nobody really owns the problem, and families have almost no way to give feedback that would change anything.
The authors' conclusion is blunt: voluntary privacy promises aren't enough. Real improvement needs enforceable institutional and regulatory rules. Worth noting the study's limits — 48 policies and 12 interviews is a revealing snapshot, not proof about every platform, and the researchers studied documents and interviews rather than tracking what actually happens to student data.
- Researchers audited 48 school platforms and interviewed 12 EdTech professionals; privacy kept getting postponed in favor of features, growth, and funding.
- One in three platforms (33%) shows AI features with no clear disclosure, and 73% use vague, generic language about accountability and data breaches.
- Rules that require parental consent work — K-12 platforms scored better on that — but those protections don't carry over to how AI is governed.
Why It Matters
Your child's school software may hold sensitive records with little transparency, oversight, or way for you to object.