Student data privacy and security

class.locusmath.org is the school side of Locus, which is operated by Stel Studio Inc: classes, assignments, rosters, and the teacher workspace. Students sign in here and nowhere else. It is a separate site from the consumer product at locusmath.org, on its own origin, and it carries no analytics tag.

This page is written for a district privacy review. It states what we collect about students, who else receives it, how long we keep it, and how a school gets it exported or deleted. The platform privacy policy covers both products in full; the signed data privacy agreement is the binding document.

Our role: school official under FERPA

  • Locus acts as a school official with a legitimate educational interest, under the direct control of the school with respect to student education records.
  • Student data is used only to provide the service to the school. We make no commercial use of it and no secondary use of any kind.
  • We do not redisclose student data to anyone except the processors listed below, each limited to what is listed.
  • The school directs what happens to the data: review, correction, export, and deletion are all available on request at any time.
  • At the end of a contract we return or delete the district's student data on request.

COPPA and school authorization

  • Consumer accounts on locusmath.org are for users 13 and over, a condition of the Terms of Service.
  • Students of any age use Locus only through their school, under the district's signed agreement. That authorization stands in for parental consent under COPPA's school-authorization provision, for the educational use the agreement describes.
  • We collect no ages and no birthdates anywhere in the product. Consent attaches to the district relationship, not to a detected age, so there is no age gate for a student to answer.
  • A Clever sign-in always creates a student account, and a Google sign-in on the consumer site with a contracted district address is refused and pointed at the classroom site instead.

What we collect about a student

  • Account: the name and email address the school sign-in supplies (Google or Clever), the provider's identifier, and the student identifier if the school imported a roster. No password, no username, no age, no birthdate, no address, no phone number.
  • Class membership: which classes and groups the student is in, and when they joined.
  • Assignment work: problems served, answers submitted, correctness, score, hints used, time taken, corrections, and teacher grade overrides.
  • Self-study on this site: practice attempts, per-topic rating, review queue, bookmarks, and goals. Visible to the student, not to other students.
  • Crash reports: for a student these carry only the error text and the page path. The click trail and free-text context that a consumer account sends are dropped for students before anything is stored.
  • We do not store IP addresses, and email addresses in our own log lines are masked.

What students are kept out of

  • Public leaderboards and public profile pages: a student appears on neither.
  • The follow graph and activity feed, which exist between adult accounts only. A student session is refused on every one of those endpoints.
  • Billing: subscriptions are never offered to a student and a student session cannot reach a billing endpoint.
  • Free text: bug reports, the contact form, and problem reports are adult endpoints a student session cannot call.
  • Analytics: this site loads no measurement tag at all, so classroom work is never measured.
  • Third-party embeds: YouTube help videos stay off for students unless the district authorizes them in its contract. Otherwise every asset a student loads comes from a Locus domain.
  • Advertising: there is none anywhere in Locus, and no profiling, no behavioral targeting, and no sale of data.
  • AI: we do not use student data to train models, and no student is identifiable to our AI provider. The teacher assists send de-identified class statistics - accuracy, mistake counts, attempt counts - and, for one assignment question, up to ten wrong answers with nothing attached to say whose they are. Never a name, an email address, a roster, or an account identifier; the Anthropic row below lists everything that goes.
  • Behavioral monitoring: the ranked-play fairness signals the consumer product records (window focus, blocked copy and paste) are never stored for a student, and no anticheat flag is ever raised against one.

Subprocessors

These are the only third parties that receive data from the classroom product, and they receive only what is listed. Adding one, or widening what one already receives, means updating this page and giving districts notice under the agreement.

ServiceWhat it receives
CloudflareHosting, TLS termination, and delivery, so all traffic passes through it. It also delivers our service email (recipient address, subject, and body, which can contain a name, a class or assignment name, or a school name).
Google (sign-in)The sign-in exchange for a school Google account, from which we receive the name, email address, and Google account identifier.
CleverThe sign-in exchange and, if the district uses it, rostering: name, email address, school role, and district identifier.
Google ClassroomOnly if a teacher connects a course: we read that course's roster (student names and email addresses) to fill the Locus class.
YouTube (Google)Help videos, off for students unless the district authorizes embeds. When a tile renders the browser requests a thumbnail from YouTube; the player loads only on a click, through the youtube-nocookie domain. Teacher accounts are adult accounts and can see them.
StripeTeacher and school billing only: the payer's email address and the details entered on Stripe's form. Never a student, and card numbers never reach us.
AnthropicThe AI assists a teacher runs from their own workspace, the physics studio, and the paid authoring assistant. Each needs the paid Author plan on the teacher's account, bought or granted by us, and a server without a provider key runs none of them. The assists send de-identified class statistics: accuracy per skill, how many mistakes fell into each category, weekly attempt counts, mastery percentages against standards, and the text of the questions behind those numbers. Diagnosing a single assignment question also sends up to ten wrong answers to it, each a math expression cut to 80 characters. The authoring assistant sends a topic, a difficulty, and up to 2000 characters the teacher typed; the studio sends the teacher's own draft. No names, email addresses, rosters, account identifiers, class names, or teacher names: a draft written about one student carries the placeholder [Student], and the teacher's browser puts the name back on their own screen. Everything that comes back is a draft the teacher reads and edits before anyone else sees it.

Google Analytics is not on this list: it runs on locusmath.org only, only after a personal learner account signs in, and never on this site.

How long we keep data

DataKept for
Student record, class membership, assignment work, and self-study historyUntil the school or district asks for deletion, or the contract ends. There is no automatic expiry, so grades and progress stay intact for as long as the school needs them.
Crash reports90 days, then deleted by a nightly job.
Email verification and password-reset tokens (teachers)Deleted when they expire. The send records behind our rate limits are deleted after 30 days.
Class invitationsAn invitation expires 7 days after it is sent, and unused invitations are deleted then. The moment one is accepted, the name, email address, and student identifier it carried are erased; what remains is the record that this class invited someone, when, and from which roster. Deleting a student also deletes any invitation still open to their address, and a nightly job re-checks that no accepted invitation is still carrying a name or address.
Administrative audit logKept as the record of who read, exported, or deleted student data. It keeps the identifier of the account an action was taken against even after that account is deleted, so the disclosure trail stays meaningful.

Export, deletion, and end of contract

  • Export: on request we send a JSON copy of everything we hold - profile, classes, assignment work, corrections, physics quiz scores, practice attempts, topic ratings, physics attempts, bookmarks, review schedule, and goals. Ask from the contact on the contract; there is no student self-serve export.
  • Deletion: we delete a named student on request. It is immediate and permanent, and it removes the student record together with class memberships, assignment work, corrections, grade overrides, and the student's own practice history, and clears the roster invitation trail that named them.
  • End of contract: on request we purge, in a single operation, every student the contract accounts for - linked to it directly, matched by the district's Clever identifier, or on one of its email domains - and report the count back.
  • Every export, search, and deletion of student data is written to our audit log with the person who did it, the action, and the target.
  • We confirm the request came from the contact on file, then act within 30 days and usually sooner. Students cannot delete or export their own records; the school controls them.
  • Send requests to [email protected].

Parents and eligible students

Parents and eligible students exercise their rights of access, correction, and deletion through the school, which can obtain any of them from us. We do not act on a request from a parent directly, because we cannot verify the relationship and the records belong to the school; we forward such a request to the district contact instead.

Security

  • Every connection is encrypted in transit with TLS.
  • Teacher passwords are hashed with Argon2 and never stored in a readable form. Students have no password: they sign in through the school's identity provider.
  • Session cookies are httpOnly, SameSite=Lax, Secure in production, scoped to the API path, and expire after 24 hours. Students and adults carry different cookies and different token types, and each is rejected by the other's endpoints.
  • Our API sends HSTS, a strict content security policy, X-Frame-Options DENY, nosniff, and a strict referrer policy.
  • Sign-in, password reset, class joining, and report submission are rate limited.
  • Administrative access is behind a role check, and reads, exports, and deletions of student data are written to an audit log. A teacher exporting a gradebook is logged the same way.
  • A teacher sees only their own classes; a student sees only their own work.

If there is a breach

We contain the incident, determine exactly which students and records are affected, and notify within 72 hours of confirming it. Districts are notified through the contact on their contract, with what happened, what data was involved, what we have done, and what we recommend. We notify regulators where state law requires it.

Where data is stored

Student data is stored and processed in the United States. Our hosting provider delivers pages and static files from its global network, so a page asset may be served from a location near the school, but student records live in the United States.

Rostering and sign-in

Students sign in with school Google or Clever accounts; there are no Locus passwords for students. Classes fill through a join code, an email invitation, a pasted roster, or a Google Classroom or Clever roster sync.

Roster import and roster sync are restricted to teachers we have verified, and a row that matches a student who already belongs to a district is refused unless the importing teacher is on that same district's contract. An emailed invitation does nothing until the student accepts it.

Get the data privacy agreement

Stel Studio Inc, the company that operates Locus, signs NDPA-style data privacy agreements. There is no download link: ask and we will send the current template, along with anything else your review needs.