Canoa // edu Student Privacy Policy
Effective date: 6 August 2026 · Version 1.0 · Contact: privacy@canoanumis.org
This policy covers Canoa // edu — the educational module at canoanumis.org/edu/ — used by schools through their learning management systems (LMS). It is written in plain language on purpose: parents, teachers, and district reviewers should all be able to read it in ten minutes.
A separate, shorter section at the end covers teachers' data (lesson-plan subscriptions and pilot requests). Everything before that is about students.
The short version
- We don't know who your students are. We never receive names, emails, or photos.
- Grades live in your school's LMS, not with us.
- Student work is deleted automatically after the school year.
- No ads. No trackers. No profiling. No sale of data. No use of student data to train AI. Ever.
1. What we collect about students — the complete list
When a student opens a Canoa // edu assignment from their school's LMS, we receive and store:
| Data element | What it is | Why we need it |
|---|---|---|
Opaque LTI identifier (sub) |
A random-looking code your LMS creates specifically for our tool. It is not a name, not an email, and means nothing outside your LMS. | So the same student sees the same assignment variant when they return. |
| Course context id | A code identifying the class within your LMS. | So teachers see their own class's work and nothing else. |
| Assignment answers | The student's responses: expanded abbreviations, translations, dates, short essays. | Grading and teacher review. |
| Scores | Points from automatic checking and teacher grading. | Returned to your LMS gradebook, then kept briefly for teacher review. |
That is the entire list. We do not receive or store: student names, email addresses, photos, usernames, dates of birth, addresses, phone numbers, demographic information, disability status, class rosters, device fingerprints, or precise location.
This is not just a promise — it is architecture. During LTI tool registration we instruct the LMS to use the anonymous privacy level, so identifying fields are never sent to us in the first place. Your LMS administrator can verify this in the tool's configuration; the registration values are published at how it works.
2. What we never do with student data
- No advertising of any kind on /edu/ pages, and no use of student data for marketing.
- No third-party trackers or analytics on any /edu/ page. You can verify this yourself with your browser's network inspector.
- No profiling and no automated decisions about students beyond scoring the specific assignment.
- No sale, rental, or trade of any data, to anyone, under any circumstances.
- No use of student data to train AI models — ours or anyone else's. Student submissions are never included in training datasets, never shared with AI vendors, and never used for model evaluation. Where Canoa // edu curricula involve AI (such as the research-agent track), the AI works with our open coin catalog — public scholarly data — never with student work or identifiers.
3. How long we keep student data
| Data | Retention |
|---|---|
| Answers, scores, assignment variants | Deleted automatically at the end of the school year + 90 days (a rolling 455-day window, purged daily; a district's NDPA may set a different date). |
| Grades | Passed to your LMS gradebook; the gradebook copy is your school's, not ours. |
| Server logs | No longer than 30 days; standard web-server fields only, with no tokens. |
| Encrypted backups | Rotate out within 35 days. Deletions are re-applied if a backup is ever restored. |
Districts can request earlier deletion at any time — of one student's records, one class, or everything. The full procedure, timelines, and a copy-paste request template are published at Data Deletion Procedure.
4. Who can see student data
- The student's teacher — sees answers and scores for their own classes, through a launch from the same LMS.
- Our staff — a small number of engineers, only when necessary to operate or fix the service, under confidentiality obligations. Note what they would see: a random code and an answer about a Roman coin.
- Our subprocessors — infrastructure providers who host the service. The current list, with what each one touches, is always published at Subprocessor List.
- No one else. We disclose data only if legally compelled, and where lawful we will notify the district before complying.
5. Legal framework
FERPA. When a district uses Canoa // edu, we act as a school official with a legitimate educational interest under the district's direct control, as defined in our agreement. The district owns its students' records; we process them only to provide the service.
COPPA. Students do not create accounts and we collect no personal information directly from children; schools authorize use of the tool and act as agents for parental consent, consistent with FTC guidance for school-based edtech.
State student privacy laws. We comply with applicable state laws including California's SOPIPA and New York Ed Law 2-d; the New York Parents' Bill of Rights is published, and a Data Security and Privacy Plan is available to New York districts on request.
NDPA. We sign the National Data Privacy Agreement (SDPC Standard Version), with an Exhibit E General Offer where available — see NDPA for Districts. For international schools, our standard GDPR Article 28 DPA applies.
6. Security
All traffic is encrypted in transit (TLS 1.2+); data is encrypted at rest. Every LTI launch is validated against your LMS's cryptographic keys — there is no password to phish because there are no passwords. Data is isolated per LMS deployment. Access by our staff is limited and logged.
If a security incident affects student data, we will notify affected districts within the timeframe set in our agreement, with a description of what happened, what data was involved, and what we are doing about it — and we will not wait for districts to ask.
7. Parents' rights
Because we cannot identify students, requests about a specific child must go through the school or district — they hold the mapping between your child and the anonymous identifier. Your school can, at any time: review your child's submissions, request their deletion, and receive confirmation. If you have questions we can answer directly — about our practices, this policy, or anything on this page — email privacy@canoanumis.org and a human replies within two business days.
8. Teachers' data (the only personal data we hold by choice)
Teachers may voluntarily give us their email for two purposes: lesson-plan mailings (double opt-in; the confirmation link expires after 72 hours and unconfirmed addresses are removed; unsubscribing is one click and immediate) and pilot requests (name, school email, role, school, LMS — used only to coordinate the pilot). Teacher emails are never shared, never sold, and never used for advertising. Teachers can request deletion of their data at privacy@canoanumis.org.
9. Changes to this policy
We will not weaken student privacy protections mid-agreement. Material changes are announced to district contacts by email at least 30 days in advance, and prior versions remain archived at this address. The version and effective date are at the top of this page.
Contact
Privacy questions and requests: privacy@canoanumis.org
Accessibility: accessibility@canoanumis.org · General: edu@canoanumis.org
We answer district privacy reviews within two business days.