Privacy & Data Governance Policy

M-Powered Education Suite — Closed Beta

Effective Date: July 7, 2026  ·  Version 1.0
Section 1

Our Data Philosophy

M-Powered Education exists for one purpose: to give special education teachers better tools without compromising student privacy. Every design decision in this suite starts from a single principle — student data belongs to the student, the family, and the school district, never to us.

We don't collect student data to build a product. We don't sell it. We don't analyze it for our own purposes. Our system is engineered so that Personally Identifiable Information (PII) never has to leave the trust boundary of your district in order for you to benefit from our tools.

The M-Powered Commitment

We believe that the safest data is the data that never leaves. Our entire architecture is built around this conviction: local-first processing, boundary anonymization at the server edge, and zero retention of student-identifiable content on any external system.


Section 2

Scope & Definitions

This policy governs all modules in the M-Powered Education suite, including current and future tools deployed across the mpowerededucation.com domain and its subdomains. It applies to all authenticated users participating in the closed beta program.

The Suite

The IEP Goal Architect, SDI Scaffold Engine, Click-Track Data Utility, Caseload Management Portal, and any additional modules deployed under the mpowerededucation.com domain.

PII

Personally Identifiable Information — any data element that can directly or indirectly identify a student, including names, Database IDs, addresses, birth dates, and disability classifications.

Education Records

Records directly related to a student and maintained by the school or a party acting for the school, as defined by FERPA (34 CFR § 99.3).

Boundary Anonymization

Our server-side process that strips all PII from a data payload and replaces identifiable tokens with generic placeholders before any content reaches an external processing endpoint.


Section 3

How We Protect Your Data

Our protection model isn't an add-on; it's the architecture itself. The M-Powered suite operates on three interlocking safeguards that work together to keep student data under district control at every stage.

Three-Layer Protection Architecture
1
Local-First Processing PDF text extraction, IEP parsing, document drafting, and most UI interactions happen entirely in your browser. Student data for these operations never leaves your device. This is the first and strongest layer of protection — the data simply doesn't travel.
2
Encrypted Transmission to District-Controlled Endpoints When a feature requires server-side processing (such as AI-enhanced scaffolding), data is transmitted over TLS-encrypted connections exclusively to your district's controlled endpoint. No student content is routed through public or third-party servers.
3
Boundary Anonymization Layer Before any content reaches an AI processing endpoint, our server-side anonymization layer mechanically strips all PII — student names, Database IDs, and identifying context — and replaces them with de-identified placeholder tokens (e.g., {{student}}). The AI model never sees who the student is.

Section 4

The Anonymization Boundary

The Boundary Anonymization Layer is the critical architectural element that makes AI-assisted features possible without exposing student identity. Here is exactly how it works:

What is stripped: Student first and last names, Database ID numbers, home addresses, parent/guardian names, and any other identifying information present in the payload.

What passes through: Goal descriptions, curriculum content, instructional parameters, grade-level indicators, and accommodation strand selections — all of which are educational content, not student identity.

How re-identification works: When the AI-generated scaffold returns, the server re-inserts the student's display name into the final output before delivering it back to your browser. The AI model at no point has access to, processes, or stores any student-identifiable information.

Every Module, Every Workflow

The Boundary Anonymization Layer applies uniformly across all M-Powered modules. Whether you are generating an SDI scaffold, building a progress report, or using any AI-enhanced workflow, the same mechanical stripping process executes on the server before any external call is made. This is not configurable or optional — it is a structural guarantee.


Section 5

Zero-Training Commitment

We understand that even anonymized educational content carries sensitivity. A goal statement describes a child's challenges. A curriculum passage was selected for a specific learner. We treat this content with the gravity it deserves.

Our Contractual Guarantee

Our AI processing partners are contractually prohibited from using any content transmitted through M-Powered Education — including anonymized educational text — for the purpose of model training, fine-tuning, evaluation, or any form of machine learning improvement. This is not a default setting we rely on; it is a binding contractual obligation.

What this means in practice:

  • No training. Goal statements, curriculum passages, SDI scaffolds, and any other educational content are never used to train, retrain, or fine-tune any AI model.
  • No retention. AI processing endpoints do not store your input or output beyond the time required to generate and return a response within a single session.
  • No aggregation. Your content is not pooled, aggregated, or combined with data from other users or sources for any analytical or commercial purpose.
  • No secondary use. Content transmitted through the suite is used for exactly one purpose — generating the educational material you requested — and for nothing else.

Section 6

FERPA & Regulatory Alignment

The Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. § 1232g, is the federal framework governing access to and disclosure of student education records. M-Powered Education is designed to operate within this framework at every level.

Our FERPA alignment rests on three structural facts:

  • We are not a "School Official" by default. M-Powered Education does not require or request access to student education records beyond what a teacher chooses to input into the suite during their own session. We do not maintain standing access to any student information system.
  • PII never reaches external processors. Because the Boundary Anonymization Layer strips all identifying information server-side before any external call, the data that reaches AI endpoints does not constitute an "education record" under FERPA — it contains no information that could identify a specific student.
  • No centralized student database. M-Powered Education does not operate a database of student records. Caseload data entered by the teacher is stored in teacher-controlled Google Sheets infrastructure within the teacher's or district's own Google Workspace environment. We do not host, replicate, or have persistent access to this data.
District Partnership

If your district requires a formal Data Privacy Agreement (DPA), School Official designation, or FERPA addendum, we welcome and support that process. Please contact us at the address below, and we will work directly with your district's data governance office.

Additional regulatory considerations: Where applicable, M-Powered Education is also designed to be consistent with COPPA (Children's Online Privacy Protection Act) protections and state-level student data privacy statutes. Our approach of not collecting, storing, or transmitting student PII to third parties is inherently aligned with the protective intent of these regulations.


Section 7

What We Collect & Why

Transparency matters. Here is a complete inventory of the information M-Powered Education collects, categorized by purpose.

Educator Authentication Data

  • Google account email address — used exclusively for session authentication and access control to the closed beta. Displayed in the UI as your session identifier.
  • OAuth2 access tokens — short-lived session credentials stored only in your browser's session storage. These are never persisted to any server and are revoked upon sign-out.

Educator-Entered Content (Session-Scoped)

  • IEP goal statements — entered or selected by the teacher within a session. Processed locally or through the anonymization boundary; never stored on M-Powered servers.
  • Curriculum source text — pasted by the teacher for SDI scaffold generation. Processed and discarded within the session.
  • Accommodation selections and instructional parameters — configuration choices made within the UI. These are functional inputs, not data collection.

What We Do Not Collect

  • Student names, addresses, birth dates, or government-issued identifiers
  • Disability classifications, medical records, or diagnostic information
  • Parent or guardian contact information
  • Behavioral records, disciplinary history, or attendance data
  • Analytics, telemetry, or usage-tracking data tied to student identity

Section 8

Data Storage & Retention

There is no M-Powered student data store. This is by design, not by limitation.

  • Browser session storage — OAuth tokens and session state are held in your browser and cleared on sign-out or tab close. We do not use persistent cookies or local storage for student data.
  • Teacher-controlled Google Sheets — Caseload rosters and goal data live in Google Sheets files within the educator's own Google Workspace account. M-Powered reads from these sheets during an active session at the teacher's request (via "Load Caseload") but does not copy, cache, or replicate this data.
  • AI processing endpoints — Content sent through the anonymization boundary is processed in real time and is not retained by the AI endpoint beyond the duration of the API call, per our contractual agreements.
  • Server logs — Our backend (Google Apps Script) may generate standard execution logs as part of normal Google Workspace operations. These logs do not contain student PII (which is stripped before processing) and are subject to Google Workspace's own retention and deletion policies.

Section 9

Your Data Stewardship Responsibilities

M-Powered Education provides the tools and the safeguards. As the educator, you remain the data steward — the person responsible for how student information is handled within your professional practice. This shared-responsibility model is core to how FERPA works.

We ask that you:

  • Follow your district's data governance policies when entering student information into any digital tool, including this suite. If your district requires pre-approval for software that handles student data, please work with your data governance office before using M-Powered Education.
  • Use the suite on secure, authorized devices. Because some student data is processed locally in your browser, the security of your endpoint device matters. Use your district-issued or district-approved device and a secure network connection.
  • Sign out when you're done. The "Sign Out" button in the suite header revokes your OAuth2 token and clears your session. Use it when you step away from a shared or classroom device.
  • Do not share your session. Your authenticated session is tied to your Google account. Do not allow others to use the suite under your credentials.
  • Report concerns promptly. If you believe student data has been exposed or that the suite is behaving unexpectedly with respect to privacy, contact us immediately at the address below.

Section 10

Your Rights

Because M-Powered Education does not maintain a centralized repository of student or educator data, many traditional "data subject rights" provisions (access, correction, deletion of stored data) are structurally satisfied — there is no stored data to access, correct, or delete.

You have the right to:

  • Know what is collected — this policy provides a complete and transparent inventory. If you have further questions, we will answer them.
  • Revoke access — you may sign out at any time, revoking your OAuth2 session. You may also revoke M-Powered Education's access to your Google account via your Google Account security settings.
  • Request information — you may contact us at any time to ask how a specific feature processes data, what is transmitted, and what safeguards apply.
  • Opt out — participation in the closed beta is voluntary. You may stop using the suite at any time, and no student data will persist as a result of your past usage.

Section 11

Breach Response Protocol

While our architecture is specifically designed to minimize the surface area for data exposure — primarily because we don't store student PII — we maintain a clear response protocol in the event of any suspected security incident.

  • Identification & containment — upon learning of a suspected breach, we will immediately investigate the scope and take all necessary steps to contain exposure.
  • Notification — affected educators and, where applicable, district data governance offices will be notified within 72 hours of confirmed incident identification, consistent with applicable state breach notification laws.
  • Remediation — we will provide a detailed account of what occurred, what data (if any) was involved, and what steps have been taken to prevent recurrence.
  • Regulatory cooperation — we will cooperate fully with any district, state, or federal investigation that may result from a data security incident.

Section 12

Policy Updates

We may update this policy as the suite evolves, as new modules are added, or as regulatory guidance changes. When we do, the "Effective Date" at the top of this document will be updated, and all authenticated beta participants will be notified of material changes via the email address associated with their Google authentication.

Non-material formatting or clarification changes may be made without individual notification but will always be reflected in the version number and effective date.


Section 13

Contact

For privacy-related questions, data governance partnership requests, or to report a concern:

M-Powered Education — Privacy & Data Governance

Email: privacy@mpowerededucation.com
Web: mpowerededucation.com

We commit to acknowledging all privacy inquiries within two (2) business days and providing a substantive response within ten (10) business days.