Skip to main content
ClassQuip

Effective date: October 7, 2026

Last updated: October 7, 2026

Privacy Policy

How ClassQuip collects, uses, discloses, and safeguards personal information and Student Data for schools, educators, and students.

Introduction

ClassQuip Inc. (“ClassQuip,” “we,” “us,” or “our”), a Delaware corporation, is committed to protecting the privacy of educational institutions, educators, and students. This Privacy Policy outlines how we collect, use, disclose, and safeguard personal information and Student Data when you access or use the ClassQuip browser-native virtual classroom platform, our website at classquip.com, and related software services (collectively, the “Services”).

ClassQuip operates in strict compliance with applicable United States federal and state student privacy laws, including the Family Educational Rights and Privacy Act (FERPA), the Children’s Online Privacy Protection Act (COPPA), the Student Online Personal Information Protection Act (SOPIPA), and the Student Privacy Pledge.

1. Important definitions & framework

“Educational Institution” or “District”: A public, private, or charter school, school district, or local educational agency (LEA) that contracts with ClassQuip to provide the Services.

“Student Data”: Personally Identifiable Information (PII) maintained by an Educational Institution or provided to ClassQuip by an Educational Institution, teacher, or student in connection with the Services.

“School Official”: ClassQuip acts as a designated “School Official” under FERPA with a legitimate educational interest in performing outsourced institutional services, subject to the direct oversight and control of the District regarding the use and maintenance of education records.

2. Information we collect

ClassQuip limits data collection to only what is necessary to fulfill our educational purpose, provide compliant attendance verification, and deliver real-time interactive classroom experiences.

A. Information provided via district integration & rostering — We do not permit direct consumer student account creation. All student and educator accounts are rostered and managed directly by the contracting District through standardized integrations, including directory and roster data: first and last name, district-assigned email address, user role (e.g., student, teacher, administrator), school affiliation, course enrollments, and roster assignments imported via OneRoster, LTI 1.3, or OpenID Connect (OIDC) frameworks.

B. Classroom operational & compliance data — To provide defensible attendance logging, audit compliance, and interactive learning tools, we collect attendance and time-in-room logs (timestamped entry and exit metrics, session duration, and active participation indicators used by Districts to verify state Full-Time Equivalency (FTE) and funding compliance); audio and video data (real-time audio and video streams transmitted over our WebRTC infrastructure — streams may be recorded or archived only when explicitly enabled by a teacher or administrator in accordance with District policies); and in-class activity (student responses to live polls, chat messages, breakout room metadata, and whiteboarding interactions submitted during an active session).

C. Technical telemetry & device data — System and performance metrics: device type, operating system (e.g., ChromeOS), browser type, network status, bandwidth metrics, packet loss, and IP addresses required for media engine optimization and troubleshooting.

3. How we use information

ClassQuip processes Student Data and personal information solely for authorized educational purposes directed by the District.

We use collected information to: authenticate authorized users via District Single Sign-On (SSO); deliver low-latency WebRTC video, audio, and interactive classroom tools; generate automated attendance reports, time-in-room metrics, and compliance logs for District administrators; provide technical support, monitor system stability, and diagnose media connection errors; and enable AI-assisted teaching tools (such as lesson plan and poll generation) as detailed in Section 4.

Strict prohibitions — No advertising: we do not sell, rent, or lease Student Data or personal information. No targeted ads: we do not build behavioral profiles of students or use Student Data to serve targeted advertisements. No commercial exploitation: Student Data is never monetized or used for commercial purposes unrelated to providing the contracted educational services.

4. Artificial intelligence & PII scrambling safeguards

ClassQuip incorporates Generative AI tools (e.g., automated lesson plan, poll, and quiz generation) to assist educators during live instruction. To ensure complete privacy and compliance:

In-house PII stripper architecture: Before any prompt, classroom text, or lesson material is processed by Large Language Model (LLM) sub-processors, it passes through ClassQuip’s proprietary PII anonymization layer. This system automatically strips and scrambles all Personally Identifiable Information (such as student names, emails, and school names) into randomized synthetic reference codes.

De-anonymization: The LLM processes only the anonymized context. The response is returned to ClassQuip’s secure environment, where the synthetic codes are resolved back into the user’s local session.

No model training: Neither ClassQuip nor its AI sub-processors use Student Data, classroom inputs, or user content to train, retrain, or improve public or commercial AI models.

5. How we share & disclose information

We share personal information and Student Data only in the following limited circumstances:

A. Sub-processors & infrastructure providers — We engage vetted third-party service providers who assist in operating our infrastructure. These sub-processors are bound by strict contractual obligations to keep data secure, use it strictly for specified tasks, and comply with FERPA, COPPA, and applicable state privacy standards. Amazon Web Services (AWS): cloud hosting, data storage, and WebRTC media server infrastructure (United States regions). OpenAI LLC: generative AI processing (operating strictly under enterprise data protection agreements prohibiting model training on input data, receiving only PII-scrambled payloads). PostHog Inc.: product analytics, error tracking, and system performance monitoring (configured to exclude PII and Student Data).

B. Educational institutions & parents — District administrators and teachers have access to student attendance records, time-in-room metrics, and classroom activity associated with their assigned courses. Parental access: parents or legal guardians seeking to review, correct, or request deletion of their child’s Student Data must submit such requests directly to their child’s school or District. ClassQuip will cooperate with the District to fulfill verified parental requests under FERPA and COPPA.

C. Legal compliance & protection — We may disclose information if required to do so by law, court order, or subpoena, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of ClassQuip, our users, or the public.

6. Children’s privacy (COPPA & FERPA compliance)

ClassQuip complies with the Children’s Online Privacy Protection Act (COPPA).

ClassQuip does not knowingly collect personal information directly from children under 13 without school consent. When an Educational Institution contracts with ClassQuip, the District provides COPPA consent on behalf of parents for ClassQuip to collect and process Student Data strictly for educational purposes.

Districts maintain full control over Student Data at all times. If a District or parent requests the deletion of a student’s data, ClassQuip will securely erase the records within 30 days of receiving a written request from the authorized District administrator.

7. Data security & storage

ClassQuip maintains robust administrative, technical, and physical safeguards designed to protect Student Data from unauthorized access, disclosure, alteration, or destruction.

Encryption: All data in transit is encrypted using TLS 1.3 (and Secure Real-time Transport Protocol / SRTP for WebRTC media streams). Data at rest in AWS storage is encrypted using industry-standard AES-256 encryption.

Access controls: Staff access to production systems is restricted based on the principle of least privilege and protected by multi-factor authentication (MFA).

Location: All data is hosted on secure AWS servers located strictly within the United States.

8. Data retention & deletion

ClassQuip retains Student Data only for the duration specified in our agreement with the District or as necessary to fulfill legal and compliance obligations (such as state attendance auditing requirements).

Upon expiration or termination of a District contract, or upon written request from an authorized District administrator, ClassQuip will provide the District with an export of all relevant Student Data and compliance logs, and permanently delete or de-identify all Student Data stored on our servers within 60 days, ensuring secure overwrite or destruction of primary databases and S3 storage.

9. Changes to this Privacy Policy

ClassQuip reserves the right to modify this Privacy Policy. If we make material changes to how we collect, use, or share Student Data, we will notify contracting Districts via email or prominent notice within the application prior to the changes taking effect.

Continued use of the Services following notice of changes indicates acceptance of the updated terms.

10. Contact us

If you have questions, concerns, or requests regarding this Privacy Policy or ClassQuip’s data privacy practices, please contact our Privacy Office:

ClassQuip Inc., Attention: Privacy & Compliance Officer. Email: privacy@classquip.com. Website: classquip.com.