Privacy & FERPA
Built with student privacy in mind.
AmplifyED Coaching is designed to support schools' obligations under the Family Educational Rights and Privacy Act (FERPA, 20 U.S.C. § 1232g) and its implementing regulations at 34 CFR Part 99. The school remains the data controller; AmplifyED Coaching acts as a "school official" with a legitimate educational interest under 34 CFR § 99.31(a)(1)(i)(B).
Safeguards built into the software
Role-based access
Access to student records is restricted to authorized school personnel based on role, legitimate educational interest, and organization-defined permissions.
Encryption in transit & at rest
All traffic is TLS 1.2+. Records at rest are encrypted by our database provider using AES-256.
Audit trail
Views, edits, exports, role changes, and AI generations against a student record are logged with actor, timestamp, and IP address.
Automatic idle sign-out
Staff sessions auto-expire after 30 minutes of inactivity, with a warning at T-60s.
AI privacy guardrails
By default, identifying student information is removed or minimized before content is processed by AI services. Student data is never used to train public AI models, and our subprocessors are contractually prohibited from doing so.
Re-authentication for sensitive actions
Exports, deletions, and role changes require fresh password entry — even within an active session.
Minimum-necessary intake
Admins choose exactly which fields the intake form collects. Nothing is gathered by default that isn't required for triage.
How we handle student data
- • Records are used solely to triage and document academic coaching support requested by your school.
- • Access is governed by role, organization, and authorized student relationships — users only see information permitted by their assigned permissions.
- • We do not sell student data, use it for advertising, or use it to train public AI models.
- • Identifiable data is never shared outside the school's authorized personnel.
- • Parents or eligible students may request access to, correction of, or deletion of records by contacting their school's records officer.
- • Data is retained according to the school's configured retention schedule (default 3 years for closed cases) and deleted on request, subject to applicable law.
School responsibility
Schools remain responsible for FERPA compliance, parent and eligible-student requests, directory-information policies, records-retention schedules, and local privacy obligations. AmplifyED provides technical controls but does not replace district governance responsibilities.
What this software cannot do for you
Software is designed to support — but does not replace — your institution's FERPA program. Your school remains responsible for signed data processing agreements, directory-information notices to parents, breach-notification procedures, staff training records, and records-retention schedules. We're happy to provide a Data Processing Addendum on request.
Contact
For privacy questions, a copy of our Data Processing Addendum, or to file a records request, contact your school's records officer or your AmplifyED Coaching administrator.
See also: Privacy Policy · Data Retention · Security · Terms · Contact
Last reviewed: June 5, 2026