Start with the system
Ask where the data goes before asking which acronym applies.
A productive review starts with the actual deployment: which accounts are created, what student and educator information is collected, why each field is needed, who can access it, which service providers receive it, how long it is retained, and how export or deletion works. FlashMath’s Trust Center and education policies are the starting documents for that review.
- Identify the minimum roster and account data needed for the planned use.
- Trace practice, activity, support, and optional feature data separately.
- Confirm access roles, retention, deletion, incident, and subprocessor terms.
- Document any configuration assumptions made for the pilot or contract.
Product pages explain the intended experience. The Education Terms, Education Privacy Policy, and signed agreement govern the service.
Control the experience
“Can we turn that off?” should have a specific answer.
FlashMath’s school offering includes managed education accounts and organization or classroom controls for parts of the student experience. A review should map each requested boundary—competitive, social, AI-assisted, voice, or other optional behavior—to the controls available in the plan and configuration being evaluated.
- List the student-facing features the district permits, prohibits, or wants to pilot narrowly.
- Confirm which role can change each setting and how that change is recorded.
- Do not infer a control from marketing copy; verify it in the current product and agreement.
Separate commitment from conclusion
A privacy posture is not the same thing as a legal determination.
FlashMath can describe its data practices, contractual commitments, security measures, and product controls. Whether a particular deployment satisfies FERPA, COPPA, a state student-privacy law, a district policy, or a contractual requirement depends on the facts, the parties’ roles, the selected configuration, and the district’s legal review.
- FERPA obligations attach to covered educational agencies and institutions and include conditions for disclosing education records to outside parties.
- The FTC’s COPPA guidance addresses when schools may act on behalf of parents in a limited educational context.
- State laws and local policies may add requirements beyond federal guidance.
Plain-language boundary
FlashMath’s documentation can support a compliance review. It cannot declare the district compliant or replace the district’s counsel and approval process.
Instructional and accessibility fit
Do not turn “standards” or “accessible” into an unsupported blanket claim.
State requirements are the foundation for curriculum fit. FlashMath will work with curriculum staff to review the actual operations, difficulty, tasks, and grade use proposed for students, document where the content maps, and identify gaps rather than rely on broad alignment language. An accessibility team should likewise evaluate the current experience against the district’s learner needs and procurement criteria. Section 508 applies to federal information and communication technology; other schools may use its procurement resources as a useful reference, but their own obligations can come from different laws and policies.
- Build or review a state-specific crosswalk with district curriculum staff before using formal alignment language.
- Request current accessibility documentation and test the workflows that students will actually use.
- Include assistive-technology users and staff who understand local accommodations in the evaluation.
- Record gaps and remediation commitments instead of converting intent into a certification claim.
A useful review
Bring the questions your team is worried will make the sales call uncomfortable.
A trustworthy conversation should make room for gaps, configuration limits, roadmap items, and questions that require follow-up. FlashMath should answer from the current product and current documents, distinguish available capability from planned work, and avoid treating silence as approval.
- Which student data is required, optional, derived, or shared with a subprocessor?
- Which product controls exist now, and at what organization, school, class, or user scope?
- What evidence supports each instructional, privacy, security, or accessibility statement?
- What would the district need to validate itself before launch?
