Overview
FERPA and COPPA are federal laws that shape how schools and EdTech platforms handle student data. Understanding what these laws actually require, and what genuinely protective platform design looks like, helps district leaders make better procurement decisions. Typing Agent and Yeti Academy are built with privacy-by-design principles in mind, and we encourage every school to ask hard questions of every platform they deploy, including ours.
Schools and districts across the country trust Typing Agent and Yeti Academy with student data because privacy has been part of our platform architecture since the beginning. For more than a decade, we have built our products around the principle that schools, not vendors, should remain in control of student information.
Why We Wrote This
As a company that made student privacy a foundational design decision from day one, not a compliance response to regulation, we believe the entire EdTech industry benefits when schools ask harder questions. This article exists to help district leaders do exactly that, and to be transparent about how we answer those questions ourselves.
For more than a decade, Typing Agent has partnered with schools and districts nationwide, and privacy-by-design has remained a core product principle throughout the evolution of our platform. Our goal is not simply to comply with changing regulations, but to build technology that schools can confidently trust year after year.
We are not writing this to claim perfection or to tell schools to trust us without scrutiny. We are writing it because district administrators deserve a clear, honest explanation of what the legal framework actually requires, what genuine privacy-by-design looks like, and what questions they should be asking of every platform they deploy. Student data privacy is not a marketing message for us, it is a foundational commitment that we strive to earn every day through our products, our practices, and our partnership with schools.
The Privacy Landscape Has Shifted Significantly
The K-12 EdTech industry has experienced significant student data security incidents in recent years that have moved student data privacy from a procurement footnote to a school board agenda item. These incidents have shared a common thread: platforms that collected more student data than they needed, protected it less rigorously than they should have, and left schools and families with limited recourse when things went wrong. Few messages are more difficult for a school or district to send than one informing parents that their child’s identity has been exposed online.
The regulatory response has been substantial. State legislatures have passed nearly 150 student privacy laws since 2014. The FTC finalized significant updates to the COPPA Rule in 2025, taking full effect April 2026. School districts are increasingly requiring documented data privacy agreements as a condition of procurement. And parents, administrators, and state auditors are asking harder questions than they were even five years ago. For district leaders evaluating EdTech platforms, the question is no longer simply whether a platform is effective, it’s also whether it’s built in a way that supports the district’s own compliance obligations.
What FERPA & COPPA Actually Require
FERPA applies to schools, not vendors
FERPA is a federal law that governs how schools handle student education records, grades, attendance, disciplinary files, health records, and online learning data tied to a specific student’s identity. It applies to educational institutions, not to vendors. This means no edtech platform can be “FERPA certified”. That claim has no legal standing. What schools need is a Data Privacy Agreement (DPA) that contractually obligates the vendor to handle student data in ways that support the school’s own FERPA obligations. The school remains responsible.
The mechanism schools use to share student data with vendors without individual parental consent is FERPA’s school official exception. This exception requires that the vendor performs an educational function, operates under the school’s direct control, uses data only for the specified educational purpose, and does not re-disclose it to unauthorized third parties. Any commercial use of student data, including advertising, is inconsistent with this exception.
COPPA applies directly to vendors
The Children’s Online Privacy Protection Act governs how online services collect personal information from children under 13, and unlike FERPA, it applies directly to vendors. The 2025/2026 COPPA Rule updates, in effect April 2026, added mandatory data minimization, required deletion timelines, and separate parental consent for third-party data sharing. The FTC has made clear that FERPA compliance does not substitute for COPPA compliance. Both frameworks apply independently and both must be satisfied.
State laws have raised the bar further
Federal law sets the floor. Nearly 150 state student privacy laws now set the ceiling in many states. California SOPIPA, Illinois SOPPA, and New York Education Law 2-d are among the most comprehensive, prohibiting targeted advertising, commercial profile building, and the sale of student data, while requiring signed vendor DPAs, breach notification, and in some states mandatory public disclosure of all EdTech vendor agreements. The Student Data Privacy Consortium’s National Data Privacy Agreement (NDPA), adopted by 28 state alliances, has become an important procurement signal for districts navigating this landscape.
What We Do Not Do
Some commitments are not policies that change with business conditions. They are foundational decisions built into how our company operates and how our products generate revenue.
- We do not display advertising to students in any tier, in any configuration, at any price point.
- We do not sell student data to any third party for any purpose.
- We do not sell, license, or share student behavioral data with any third party for commercial purposes. Any usage data we use to improve our products or personalize the learning experience is aggregated and de-identified, does not identify individual students, stays within our platform, and is never sold or shared externally.
These are not compliance positions. They are built into the product.
This alignment of our business model with our customers’ interests allows product decisions to prioritize educational outcomes, customer trust, and long-term partnerships rather than advertising revenue or the commercial value of student data.
How Typing Agent & Yeti Academy Are Built
The free tools discussion
Many schools first encounter EdTech platforms through free offerings. Understanding how those platforms fund ongoing development is an important part of evaluating long-term privacy practices.
Some free platforms rely on advertising, behavioral analytics, or other forms of data monetization to support their business model. Others do not. Schools should understand exactly how every platform they deploy generates revenue and how that business model aligns with their own student privacy expectations.
Typing Agent and Yeti Academy are licensed platforms. Schools pay for access. That straightforward business model removes any incentive to monetize student information. Our success depends on delivering educational value that schools choose to purchase and renew, not on commercializing student data.
What we actually collect
Typing Agent collects a student’s first name, last name, and app username which schools may configure to be as simple as a student ID number along with an app password, school-provided grade level, and lesson progress data: words per minute, accuracy, lesson completion, and time-on-task. That is the complete list. No email addresses. No dates of birth. No home addresses. No background information. No device fingerprints beyond session management. No behavioral profiles. No location data. Yeti Academy operates on the same principle.
Documentation before deployment
Typing Agent maintains student data privacy documentation posted publicly on our website for schools to review before deployment. For districts that require their own data privacy agreement, including those using the SDPC National Data Privacy Agreement or state-specific frameworks, we are prepared to review and sign your documentation as a standard part of onboarding. Either way, privacy documentation is in place before students access the platform.
Privacy governance
Technology is only one part of protecting student information. Strong privacy programs also require clear governance: defining who owns the data, who may access it, how access requests are documented, how schools exercise their deletion rights, and what happens when a relationship ends. We believe strong privacy depends as much on disciplined processes and accountability as it does on encryption and technical safeguards.
Security
Data in transit is protected by TLS encryption and data at rest is encrypted using AES-256, the same standard used by financial institutions and healthcare platforms. Role-based access controls ensure teachers see their students, school administrators see their school, and district administrators see their district. Typing Agent support staff may access student data only as needed to provide customer or technical support. No one has access to more data than their role requires. In the event of a security incident involving unencrypted student personally identifiable information, affected schools are notified in writing within 72 hours of detection, with specific information about what occurred and what remediation steps are being taken. Depending on the severity of the incident, we also notify law enforcement and affected school officials and families as required by law.
What District Leaders Should Ask Every EdTech Vendor
These questions apply to every platform, including ours. Use them in every technology evaluation:
- What specific data fields does the platform collect from students? Is that collection strictly necessary to deliver the educational service?
- Does the platform display advertising to students in any tier or configuration?
- Is student data used for any commercial purpose beyond instructional delivery, including algorithm training or product development?
- Is there data privacy documentation available before deployment? Will the vendor review and sign your district’s own agreement if required? Does the documentation include school-directed deletion rights, breach notification obligations, and a prohibition on data re-disclosure?
- What encryption standards are used for data in transit and at rest? Who within the vendor’s organization can access student data? Typing Agent uses TLS for data in transit and AES-256 for data at rest, with role-based access controls.
- What is the breach detection and notification process and timeline?
- How long is student data retained? What happens when a contract ends?
Signals worth paying attention to
- Any platform that cannot produce privacy documentation or refuses to sign your district’s data privacy agreement.
- Any platform claiming to be “FERPA certified” as a vendor-level certification. This has no legal meaning.
- Any platform that displays advertising to students in any configuration.
- Any platform whose privacy policy uses vague language like “data may be used to improve our services” without defining what that means.
- Any platform that cannot name a specific breach notification timeline.
Quick Answers to Common Questions
Is Typing Agent “FERPA compliant”?
No EdTech vendor can be “FERPA compliant” in a legally meaningful sense. FERPA applies to schools, not vendors. What we provide is a signed Data Privacy Agreement designed to support schools’ FERPA obligations: educational purpose limitation, no commercial data use, school-directed deletion rights, and breach notification commitments. We encourage schools to review the DPA and consult their own legal counsel.
Does Typing Agent sell student data?
No. Student data is used exclusively for instructional delivery and progress reporting. It is not sold, licensed, or shared with any third party for commercial purposes.
Does Typing Agent have Data Privacy documentation?
Yes. Typing Agent maintains student data privacy documentation posted publicly on our website for schools to review before deployment. For districts that use their own data privacy agreement, including the SDPC National Data Privacy Agreement or state-specific frameworks, we are prepared to review and sign your documentation as a standard part of onboarding. Privacy documentation is in place before students access the platform.
How long is student data retained, and what happens when a contract ends?
Should they opt not to purchase or renew, account administrators have the ability to immediately expunge all data from their accounts, or ask us to delete it immediately on their behalf. In addition, student data is deleted within 90 days following the separation or expiration of a school or district’s account.
Ready to Learn More?
Our student data privacy documentation is available on our website for review before deployment. If your district uses its own data privacy agreement or the SDPC NDPA framework, we are ready to work with you.



