Student Data Privacy Addendum
Student Data Privacy Addendum
Last updated: 2026-07-30
This public addendum describes the student-data safeguards intended for school-authorized Instagrity use. It is prepared for privacy, procurement, and counsel review; it does not by itself create a district contract, make an unauthorized user authorized, or declare legal compliance.
- Scope
- Identifiable student and classroom data supplied for educational workflows
- Control
- Schools and authorized institutions determine permitted educational use and instructions
- External AI
- Optional Native AI and MCP/AI-platform flows have separate data paths and notices
- Review path
- Institutions needing signed or state-specific terms should contact Instagrity
This addendum is intended to describe a narrow student-data framework for school-authorized educational use. A teacher who accepts the acknowledgment represents that they are an adult educator or authorized institutional representative, that their school permits the use, and that they have authority to accept the applicable Terms and this addendum for that use.
Clicking an acknowledgment does not grant institutional authority. If the educator lacks that authority, the educator must use only synthetic or properly de-identified information. A signed district, school, or state-specific agreement controls where one exists and conflicts with this public addendum.
The school or authorized institution controls the education records and determines the permitted educational purpose, users, classes, retention instructions, and disclosures for its deployment. Instagrity uses supplied student data to provide, secure, support, and maintain requested classroom, assignment, assessment, grading, feedback, and related educational workflows, subject to the Terms, Privacy Policy, applicable written agreement, and the product’s access controls.
The parties should confirm the applicable FERPA school-official, service-provider, direct-school-authorized, or other legal conditions for each deployment; Instagrity does not declare automatic FERPA compliance. For children under 13, school authorization is limited to the school-approved educational purpose and does not replace any direct notice, consent, parental, state-law, or institutional requirement that may apply. Instagrity does not collect dates of birth or use this addendum to create an age-profiling system.
Depending on the feature and authorization, Instagrity may process teacher and student account details, school or class association, class and roster records, assignment titles and instructions, rubric and assessment data, submissions and attachments, grades, teacher feedback, inline annotations, writing-replay records, assessment attempts, operational metadata, security events, audit-oriented records, and integration metadata. The Privacy Policy explains why each category is used and the narrower categories involved in external-provider and AI workflows.
Instagrity does not sell student or classroom data, use it for behavioral or targeted advertising, provide it to data brokers, use it for unrelated profiling, or use it to train AI models unrelated to the Instagrity service. Access is limited by authenticated identity, role, class or collaboration relationship, resource authorization, product entitlement, confirmation, and security controls. Students and guardians do not receive teacher-only drafts, unreleased feedback, or teacher/admin-only state through student-safe surfaces.
The current implementation uses encrypted transport, managed infrastructure protections for data at rest, server-side integration routes, role and class authorization, applicable Supabase row-level security, rate limiting, challenge verification where configured, security-event logging, audit-oriented records, bounded outputs, and separation of preview from confirmed writes. This description is practical and evidence-based; it is not a security certification or audit report.
The current Privacy Policy identifies visible infrastructure and service providers and explains current purposes. That list is not represented as an exhaustive contractual subprocessor schedule until provider, purpose, data-category, notice, and contract-role evidence has been verified.
A school-selected ChatGPT, Claude, or other external AI workspace is not automatically an Instagrity subprocessor. It is an external recipient or processor only where the applicable relationship and agreement establish that role. The parties should confirm provider roles and change-notification requirements in a signed agreement.
Instagrity maintains security and operational controls intended to detect, investigate, contain, and remediate unauthorized access or disclosure. Instagrity will cooperate with an authorized school or institution on a suspected incident through the available contact path and applicable written agreement. This public addendum does not invent a breach deadline; the notice period, contacts, contents, and cooperation obligations should be set in the applicable contract.
Schools and authorized account holders can use available product workflows to review, correct, export, archive, or delete classroom data, subject to authorization and product availability. A parent, guardian, or eligible student should contact their school or authorized institution first and may also use the Instagrity contact path for privacy questions or assistance. Instagrity will assist to the extent available and permitted by the applicable account, role, class, legal, and contractual boundaries.
Deletion of live product content, account termination, or disconnecting an integration may not immediately remove backups, system logs, billing records, deleted-content recovery copies, audit records, security events, or legally required retention copies. The current Privacy Policy describes these limits and the narrower MCP log lifecycle. Schools should provide retention and deletion instructions through a signed agreement when their requirements are more specific than the product baseline.
Native Instagrity AI processing occurs when an available Instagrity feature is requested and is governed by the product’s role, premium, class, feature, and confirmation boundaries. MCP is optional, individually OAuth-authorized, account-bound, on demand, and limited to the selected request; the current connector does not perform background synchronization, indexing, bulk export, or prefetching. An external AI platform may receive prompts, selected classroom context, student work, or bounded attachments when the educator chooses a request, and that platform’s retention and workspace policies then apply.
Disconnecting or revoking an external OAuth connection stops future authorized calls until a new authorization occurs. It does not delete information already transmitted to the external platform and does not undo a confirmed change already saved in Instagrity. MCP consent separately requires an educator to affirm that the school permits the connected AI-platform use and understands this external-retention distinction.
Institutions that require a signed DPA, state-specific student privacy terms, security questionnaire, procurement schedule, retention schedule, incident notice, or verified subprocessor list should contact Instagrity before deployment. Do not treat this public page or a self-service acknowledgment as a substitute for those negotiations.
Review the Terms, Privacy Policy, Security Overview, and MCP information together with this addendum.