Legal
Privacy Policy
Effective June 5, 2026
This Privacy Policy explains how AmplifyED ("AmplifyED", "we", "us") collects, uses, and safeguards information when schools and districts ("Customers") use the AmplifyED Coaching Portal (the "Service"). For student education records, Customers remain the data controller under FERPA and AmplifyED acts as a "school official" with a legitimate educational interest under 34 CFR § 99.31(a)(1)(i)(B).
Privacy at a glance
School Owns the Data
Schools and districts retain ownership and control of all student records submitted to AmplifyED.
FERPA-Aligned Processing
AmplifyED acts as a school official or service provider under customer direction, consistent with FERPA.
Student Data Is Never Sold
Student information is never sold and is not used for advertising or profiling.
AI Privacy Protections
Identifying information is removed or minimized by default, and student data is never used to train public AI models.
1. Information we collect
Account & Organization Data
Name, email, role, school or district affiliation, and sign-in credentials for authorized users.
Student Records
Information entered by Customer staff or submitted via intake forms — for example legal or preferred name, grade level, course, teacher, requested-help details, case notes, and status history.
Usage & Audit Data
IP address, user agent, timestamps, route paths, and audit events such as view, edit, export, role change, and AI generation.
Billing Information
Plan tier, billing contact, and invoice history. Payment card details are handled by our payment processor and are not stored on AmplifyED servers.
2. How we use information
- • To provide and operate the Service the Customer requested.
- • To route, triage, and document academic coaching support cases.
- • To produce notifications, digests, and reports for authorized staff.
- • To meet our legal, contractual, and audit obligations.
- • To detect fraud, abuse, or violations of our Terms.
3. Student privacy & FERPA
Access control
Access to student records is controlled by role, organization, and authorized student relationships. Users may only access information permitted by their assigned permissions.
- • All access, edits, exports, role changes, and AI-assisted drafts are logged with actor, timestamp, and IP.
- • Sensitive actions such as exports, deletions, and role changes require fresh password re-authentication.
- • Sessions auto-expire after 30 minutes of inactivity.
4. Data ownership
Schools and districts retain ownership of all student records and educational data submitted to AmplifyED. AmplifyED processes data solely to provide the services requested by the customer.
5. AI usage & safeguards
By default, identifying student information is removed or minimized before content is processed by AI services. If an organization enables workflows that include identifying information, those actions are governed by the organization's policies and are recorded in audit logs.
Student data is never used to train public AI models, and our subprocessors are contractually prohibited from doing so.
6. Data retention
Active cases are retained while the student is active. Closed cases are retained for the period configured by your school (default 3 years) and then automatically purged. Anonymized, aggregate statistics may be retained indefinitely for reporting. See our Data Retention Policy for details.
7. Data export & cancellation
Customers may export available records and data prior to cancellation, subject to the capabilities of the Service. Following termination, Customer Data is retained and deleted according to the organization's configured retention settings and AmplifyED's Data Retention Policy.
8. Subprocessors
AmplifyED uses a limited number of carefully selected service providers ("subprocessors") to support platform operations, communications, billing, and optional AI-assisted features.
- • Hosting & database: Cloud infrastructure and managed database providers used to operate the AmplifyED platform, including application hosting, authentication, and data storage.
- • Email delivery: Mailgun — transactional email delivery on a delegated subdomain.
- • Payments: Stripe — subscription billing and customer portal.
- • AI processing services: Third-party AI providers used to generate optional AI-assisted drafts, summaries, and recommendations. Student data is handled in accordance with the organization's configuration and AmplifyED's privacy safeguards.
An up-to-date subprocessor list is available on request via support@amplifyed.app.
9. Children's privacy
The Service is not directed to children for marketing. Where applicable under COPPA, AmplifyED relies on the Customer (the school) to provide consent on behalf of parents for school-authorized educational use.
10. International transfers
The Service is operated in the United States. By using the Service from outside the U.S., you consent to processing in the U.S. subject to U.S. law and our contractual safeguards.
11. Security
AmplifyED uses TLS 1.2+ in transit and AES-256 at rest, and employs commercially reasonable safeguards designed to protect Customer Data. See our Security page for the full list of safeguards, including audit logging, role-based access, and re-authentication for sensitive actions.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated via in-product notice or email to admins. The "Effective" date above reflects the most recent revision.
13. Contact
For privacy questions or to request a Data Processing Addendum, contact support@amplifyed.app. For security reports, use security@amplifyed.app.
See also: FERPA & Student Privacy · Data Retention · Security · Terms
