Trust & student data at FlashMath
Teachers, administrators, and parents put students in our hands. This page explains — without legal jargon — what we collect, why, who touches it, and how to get it deleted. The binding versions live in our Education Privacy Policy and Education Terms.
No ads. No selling data.
We never sell personal information, never show advertising to students, and never build advertising profiles. Our only business model is subscriptions.
Schools stay in control
Schools direct the permitted use of education records in their accounts. Export and deletion workflows are supported, while the governing agreement confirms the parties' roles and any deployment-specific terms.
We collect the minimum
Teacher-created student accounts need only a display name — no student email, no address, no phone number. Practice results exist so teachers can teach.
Covered actions leave a record
FlashEDU records covered roster, permission, export, and administrative events in a district-visible audit history. The audit table is protected from update and deletion at the database layer.
How student data is protected
Districts should not need a security background to understand what happens to their students' information. In plain terms, here is how it is protected — and every statement below is backed by the product itself and the binding education documents, not by this page:
Encrypted while it travels, encrypted where it lives
Student data moves between a student's device and our servers over encrypted connections. The storage that holds student data sits on encrypted disks, the most sensitive fields — like sign-in secrets and student credentials — carry an additional layer of encryption, and scheduled database backups are encrypted as well.
Each district's most sensitive records are kept in their own separate space
A managed student's real name and accommodation details are stored in a district-specific area of our systems that other districts' connections cannot reach. Everywhere else, that student appears under a generated username instead of a real name. And if the system cannot confirm which district a request belongs to, it refuses the request rather than guessing.
Access works on a need-to-know basis
A teacher sees their own classrooms. School and district staff see their own schools and district. These limits are enforced on our servers — not just hidden in the screens people see.
Our own staff have locked doors too
FlashMath personnel must pass multi-factor authentication before using any administrative console, and administrative actions are written to a tamper-evident log that cannot be quietly edited after the fact.
Deletion runs on a clock, not a promise
When a district leaves — or simply asks — student data is deleted or de-identified within 90 days, except records the law requires us to keep. The countdown starts automatically; it does not wait for someone to remember.
We keep watch
Security event logs are retained for 90 days so that if something ever looks wrong, it can be properly investigated — and covered district actions land in the audit history described below.
The technical specifics behind each statement (protocols, encryption standards, retention periods) are written into the education agreements a district signs. Ask us to walk through any of them, with evidence, during your review.
FERPA & COPPA posture
FERPA:where student data counts as an education record, FlashMath is intended to operate as a “school official” with a legitimate educational interest under the school's direct control. The school should confirm that role, the selected configuration, and any state or local requirements through its own review.
COPPA: for students under 13 on school plans, the school may be able to provide consent on behalf of parents for a limited educational use under FTC guidance. The school remains responsible for confirming that the planned use fits that model and for providing any notices or consents required by law or local policy.
What we collect — and what we don't
We collect
- A display name or identifier chosen by the teacher or school
- Username and grade level / classroom assignment
- Practice activity: problems attempted, accuracy, speed, progression
- Game results and in-app achievements
- Technical basics needed to run the service (IP address, device type, logs)
We don't
- No student email, home address, or phone number for teacher-created accounts
- No location tracking
- No advertising identifiers or third-party ad trackers
- No social security numbers, health data, or biometric identifiers
- No sale or rental of personal information — ever
District audit history
FlashEDU writes covered roster, permission, export, access, and administrative events to an organization-scoped audit table. Database controls block updates, deletes, and truncation of those rows, and authorized district staff can review and export the recorded history.
A district should still confirm the exact event coverage, retention, export fields, and staff roles for the deployment it is reviewing. “Append-only” describes the recorded rows; it should not be interpreted as a claim that every possible product event is an audit event.
How AI features handle student data
AI-assisted features are optional and configuration-dependent. Before enabling one, a school should review the current provider, input fields, output use, retention terms, and available organization controls for that exact feature:
- District choice. Confirm which features are available, their default state, and which district or school role can enable them.
- Voice workflows. Voice features operate only where the district enables them — for students and for staff alike. Where a proposed use includes student audio, FlashMath will identify the processor and provide the current processing terms for district review before launch.
- Text workflows. The review should identify which practice context is sent, which direct identifiers are excluded, and how outputs are shown to students or staff.
- Provider commitments.Training, retention, and reuse restrictions must be supported by the current provider terms or agreement supplied for the district's review—not inferred from this summary page.
Subprocessors
These are the vendors that may process data on our behalf, what they do for us, and what student data (if any) they touch:
| Vendor | Purpose | Student data involved |
|---|---|---|
| Anthropic | AI coaching and teacher-facing insights (text) | Practice performance context; exact fields and provider terms are confirmed for the selected configuration |
| OpenAI | Speech features, including student voice practice | Voice audio only when the district enables the relevant feature; current processing terms are confirmed during review |
| Stripe | Subscription billing | None — billing contacts only (teachers, schools, parents) |
| Resend | Transactional email delivery | None for managed students (they have no email address) |
| Optional single sign-on and cloud infrastructure | Sign-in identity only when a school chooses Google SSO |
We notify subscribing schools before adding a subprocessor that would process student data.
Independent assurance status
Student Data Privacy Consortium (SDPC) — National Data Privacy Agreement
FlashMath does not currently represent an executed national or state NDPA on this page. Ask for the current contracting path for your state.
SOC 2
No completed SOC 2 report is represented as available here. Request current security evidence and any audit roadmap directly.
Accessibility Conformance Report / VPAT
No current ACR or VPAT is represented as available here. Schools should test the student and staff workflows they plan to use and request the current accessibility status.
What a district can request
A serious review needs more than this summary. Send the requirements your privacy, security, curriculum, accessibility, and procurement teams use. FlashMath will distinguish documents available now, items that require a written response, and evidence that is not yet available.
Accessibility is a workflow review
FlashMath should not be treated as broadly accessible because a marketing page says so. Ask for the current testing status, known limitations, keyboard and screen-reader behavior, and the exact student and staff workflows your district plans to use. Include assistive-technology users and staff who understand local accommodations in the evaluation.
Data deletion & questions
Schools can request a full export or deletion of their students' data at any time. Parents should start with their child's school (it controls the account), and can also reach us directly. The current Education Privacy Policy describes the default post-termination deletion period and applicable exceptions; a signed district agreement may establish more specific terms.
Contact: education@flashmath.io(subject line “Data request”). Security researchers can use the same address to report vulnerabilities.