Security and Student Data Privacy

This page explains how Fullmind handles information it processes as a service provider on behalf of schools, school districts, and other education customers (“Customers”). It does not apply to information collected from visitors to our public website, which is covered by our Website Privacy Policy.

1. Our Commitments Regarding Student Data

These commitments apply across our platform and every service we deliver. Where Fullmind processes student data for a Customer, our agreement with that Customer governs as well.

Fullmind does not:

  • Sell student data — not to anyone, at any price, for any purpose.
  • Pass student data to data brokers, advertisers, or anyone else for a purpose that is not educational.
  • Advertise against student data, whether targeted, behavioral, or otherwise, or use it to market anything to anyone.
  • Develop AI on student data. It is not used to train, fine-tune, or evaluate machine learning systems of any kind, including large language models, and our agreements with AI vendors bar them from doing the same.
  • Claim ownership of student data or district-created data.
  • Gather precise location, biometric, or comparable sensitive information from students, unless an educational purpose requires it and the law expressly allows it.
  • Design interfaces meant to draw more personal information out of a student than the service actually needs.

Fullmind does:

  • Restrict who can see student data to the people who need it to deliver the contracted service.
  • Encrypt student data in transit and at rest (see Section 7).
  • Keep all student data on servers located in the United States.
  • Screen employees who can access student data through a criminal background check.
  • Tell the Customer when an outside party asks for student education records, and refuse that request unless a court order, a lawful subpoena, or the Customer's own instruction requires us to comply.
  • Assess our products for the risk of physical, emotional, developmental, or privacy harm to the students who use them.

2. Student Data We Receive

Schools and districts provide Fullmind with the information our educators need in order to teach. Depending on the service, that can include:

  • First and last name
  • Grade level and course enrollment
  • Attendance records
  • Grades, assessments, and academic progress data
  • IEP status and accommodations, and other special education records, where Fullmind supports IEP fulfillment or related services
  • Teacher comments and feedback
  • Work students produce in our platform
  • Recordings of live Fullmind sessions

2.1 How we use it

Student data is used to deliver the services a Customer has contracted for, and for nothing else: live instruction and tutoring, IEP service minutes, credit recovery and attendance programs, customer support, and improving the quality of what we deliver to that Customer. Data that has been stripped of identifying information may be used internally to improve our products.

2.2 Session recordings

Fullmind records live sessions to support instruction and quality review. A recording is available to the educator who taught the session, to authorized district staff, and to the student who attended it. Fullmind does not make recordings available to anyone else, except where a legal obligation described in Section 3.6 requires it.

2.3 Disclosure

Beyond the Customer's own authorized users and the Fullmind educators assigned to its students, student data reaches only: service providers who help operate our platform and are contractually bound to protect it (Section 8); recipients entitled to it through legal process (Section 3.6); and, in the event of a merger or acquisition, the acquiring organization, which inherits every commitment on this page.

3. FERPA

3.1 Compliance

Fullmind provides contracted services to educational agencies and institutions (“EAs”). To deliver those services, an EA gives us access to personally identifiable information (“PII”) from student education records, limited to what our staff and contracted educators need for the work. The Family Educational Rights and Privacy Act (“FERPA”), 20 U.S.C. § 1232g(b)(1)(A), permits these disclosures without separate parental consent.

The mechanism is the school official exception at 34 CFR § 99.31(a)(1)(i)(B). An outside party may be treated the same as a school official employed by the EA when it performs a service the EA would otherwise staff itself, operates under the EA's direct control in how it uses and maintains education records, and accepts the redisclosure limits of 34 CFR § 99.33(a). Fullmind meets all three conditions.

Because we are an outside party rather than an EA employee, § 99.33(a) applies to us directly. We may not redisclose PII from education records except where the EA has authorized it under a FERPA exception and records that subsequent disclosure, or where a parent or eligible student has consented. Under 34 CFR § 99.3, an eligible student is one who has turned 18 or is attending a postsecondary institution. The routine case is a district asking us to help move its records out of our system and into a different platform.

Separately, 34 CFR § 99.31(a)(1)(ii) requires the EA to use reasonable methods to ensure a school official reaches only the records in which it has a legitimate educational interest. We support that obligation with the access controls described in Section 7, and will document them for any Customer that asks.

3.2 School Official Designation

An EA designates Fullmind as a school official with a legitimate educational interest by specifying the criteria for that designation in its annual FERPA notification to parents, as contemplated by 34 CFR § 99.7(a)(3)(iii) and § 99.31(a)(1)(i)(A). Where an EA has made that designation, Fullmind: (a) performs an institutional service or function the EA would otherwise use its own employees to perform; (b) remains under the EA's direct control in how it uses and maintains education records; and (c) uses those records only for the purpose they were disclosed for, and does not redisclose PII without authorization, consistent with 34 CFR § 99.33(a).

3.3 Directory Information

Whether any student data is designated “directory information” under FERPA is the EA's decision alone, governed by its own policy and FERPA obligations. Fullmind never makes that designation and never releases student data on that basis. We act on the EA's instructions and our agreement with it.

3.4 No Advertising Use

Education records are never sold, used, or redisclosed by Fullmind for advertising or marketing. Our products carry no advertising of any kind, so there is no behavioral or targeted advertising. Data inside the platform serves the contracted service and nothing else. Anonymized data that identifies no one may be used internally to make our services better for the EAs we work with.

3.5 Ownership of Student Data

Student data and district-created data in our products belong to the EA. Fullmind claims no ownership interest in either, at any point, and the EA retains control throughout.

3.6 Third-Party Access Requests

If a third party seeks access to education records we hold, we inform the EA in writing immediately. We do not provide access or otherwise respond unless due process, a court order, or a subpoena lawfully issued by a court with jurisdiction compels us, or the EA instructs us to. Where such an order or subpoena arrives, the EA receives notice and a copy of it before anything is released, unless the law or the order itself forbids telling them.

3.7 Parent and Student Rights

Parents, legal guardians, and eligible students exercise FERPA rights through their school or district, using the procedures that EA has established. Those procedures generally include the right to inspect and review a student's education records, and the right to request an amendment to a record the parent or eligible student believes is inaccurate, misleading, or in violation of the student's privacy rights.

To request an amendment, write to an EA official, identify the specific part of the record at issue, and explain what is wrong with it. An EA that declines will say so and will explain the right to a hearing on the request.

Where an EA needs records that sit in our systems in order to answer such a request, Fullmind will retrieve them at the EA's direction and expense.

If you have a question about information Fullmind processes for a school or district, please contact that school or district directly.

4. HIPAA and Student Health Information

Fullmind supports special education service delivery and IEP fulfillment, so Customers often ask how HIPAA applies. In nearly every case, the governing law is FERPA, not HIPAA.

Records an EA discloses to Fullmind, and that we maintain to serve that EA, are education records under FERPA. HIPAA's definition of “protected health information” carves education records out explicitly — see paragraph (2)(i) of the definition at 45 CFR § 160.103, which excludes “education records covered by the Family Educational Rights and Privacy Act.” The reason is that FERPA already protects them. The U.S. Department of Education and the U.S. Department of Health and Human Services explain the boundary between the two statutes in their Joint Guidance on the Application of FERPA and HIPAA to Student Health Records (updated December 2019).

Where a Customer is not subject to FERPA, and the health information it shares with Fullmind therefore does constitute protected health information, Fullmind operates as a HIPAA-compliant Business Associate. In those engagements Fullmind and the Customer execute a Business Associate Agreement (“BAA”), and from that point HIPAA, the regulations implementing it, and the BAA itself set our obligations for that information.

Whichever framework applies, student health information — IEP records, evaluations, related service documentation — is protected by the safeguards described in Section 7, and the personnel who handle it are trained on the requirements of both laws.

5. COPPA

Fullmind's services are built to meet the Children's Online Privacy Protection Act. For students under 13, Fullmind relies on the school or district to provide consent on a parent's behalf, an approach FTC guidance permits where the information is collected solely for the use and benefit of the school and for no other commercial purpose. That condition describes exactly how we operate.

6. State Student Data Privacy Laws

A majority of states now regulate student data beyond what FERPA requires, tightening what may be gathered, how it may be used or shared, whether it may be sold, and how long it may be kept — and adding their own requirements for security, breach notification, and transparency. Fullmind complies with those obligations wherever they apply to us. Where a state conditions lawful processing on a specific contract term, data protection addendum, or written assurance, we work with the Customer in good faith to execute that documentation.

Requests from individuals under the California Consumer Privacy Act or comparable state laws should be directed to the school or district that controls the record. Where Fullmind holds personal information in its own right, write to us using the contact details in Section 12 and we will respond within the period the statute allows.

7. Data Security

Security is a core component of our technology and a cornerstone of our company culture. The technical and organizational measures we run are scaled to how sensitive student data is, and include:

  • Encryption in transit. Student data moves over TLS 1.2 or higher.
  • Encryption at rest. Stored data is protected with AES-256.
  • U.S. data residency. Student data resides on servers located in the United States.
  • Access controls. Systems holding student data are reachable only by authorized personnel who need them to deliver the contracted service.
  • Background checks. Employees who can access student data are screened through a criminal background check.
  • Training. Every employee completes security training when hired and repeats it on an ongoing basis, and phishing drills and security exercises run regularly across the company. Staff who work with student records also train on FERPA and the state student data privacy laws that apply to them.
  • Penetration testing and vulnerability scanning, with patching tracked and remediated through our engineering workflow.
  • Encrypted, point-in-time backups, with redundant infrastructure for continuous availability and DDoS mitigation at the network edge.
  • SOC 2 Type 2. Fullmind maintains a SOC 2 Type 2 attestation against the AICPA's Trust Services Criteria. The report is available to Customers on request.
  • Cloud Security Alliance STAR registration.

8. Subprocessors

Fullmind engages third-party service providers to help deliver its platform and services, and some of them process student data or other personally identifiable information on our behalf. We hold every subprocessor to protections at least as strong as our own, and we remain responsible to the Customer for a subprocessor's handling of student data to the same extent as if Fullmind had processed it directly.

A current list of Fullmind's subprocessors is available to Customers and prospective Customers on request using the contact details in Section 12.

9. Breach Notification

When Fullmind identifies a security incident affecting student PII, containment begins immediately. Within 72 hours of confirming the incident we notify the affected EA's superintendent, or whoever holds the equivalent chief executive role, with the facts as we know them at that point. Fullmind and the EA then determine a response together, including any notification of affected individuals required by law.

10. Data Retention and Destruction

How long Fullmind keeps student data, and the manner of its destruction, is set by whichever of these governs: the Customer agreement, a Data Processing Agreement, a Business Associate Agreement, or applicable law. Disposal is carried out so the contents stay confidential from start to finish, and a Customer may request written certification that destruction has occurred.

11. Policy Updates

Fullmind may update this page from time to time to reflect evolving state and federal law. We will not revise this page in a way that weakens the protections described here for an existing EA without that EA's written consent.

12. Contact

For questions about this page or Fullmind's student data practices:

Email: security@fullmindlearning.com
Mail: iTutor.com, Inc. d/b/a Fullmind, PO Box 25436, New York, NY 10087-5436

For questions about student records maintained by a specific school or district, please contact that educational agency directly.