Student Data Privacy
Last updated: July 5, 2026
This page describes how Ember LMS handles student education records and children's privacy when used by schools and districts. It supplements our Privacy Policy and Terms of Service.
Ember is built FERPA-first for U.S. K–12 and higher education.
Our role
| Party | Role |
|---|---|
| School or district | Typically the owner and controller of student education records |
| Ember (Molar Labs) | Service provider / school official under contract — processes data only to deliver the Service |
When your school adopts Ember, we enter into a Data Processing Agreement (DPA) or equivalent terms that define permitted uses, subprocessors, security, and breach notification.
Request a DPA: security@ember.edu or visit Security & compliance.
What student data we process
Depending on how your school configures Ember, we may process:
- Name, email, and student ID
- Course enrollments and roster data from your SIS
- Assignments, submissions, grades, and teacher feedback
- Accommodation and IEP-related flags your school chooses to store
- Activity logs (e.g. last login, assignment completion)
- Parent/guardian observer links where enabled
We process only what the school authorizes for educational purposes.
What we commit to
- No sale of student data — ever
- No behavioral advertising targeted at students
- No training of general AI models on student education records
- Role-based access — teachers see their students; students see their own work; parents see only what the school permits
- Audit logging — access to sensitive student records is logged for administrator review
- Encryption — TLS in transit; encryption at rest in production environments
- Subprocessor transparency — a current list available to districts on request
AI & student records
When teachers use Ember's AI features on student work:
- Processing occurs to generate that teacher's draft feedback or suggestions
- Outputs require teacher review before reaching students (for grading workflows)
- Content safety filters apply in educational contexts
- Schools may disable or limit AI features by policy
FERPA
Under the Family Educational Rights and Privacy Act (FERPA), schools control disclosure of education records. Ember accesses records only as directed by the school to provide the platform — similar to other edtech tools operating under school contracts.
School officials with legitimate educational interest receive access through role permissions your administrators configure.
COPPA
For children under 13, schools typically provide consent under COPPA's school exception when Ember is used for educational purposes. Ember does not market directly to children or require students to create standalone consumer accounts outside a school relationship.
Parent rights
Parents should contact their child's school first for access, correction, or deletion of education records. Schools can fulfill requests through Ember's admin tools or by contacting us at privacy@ember.edu.
Data breach notification
If we discover a security incident affecting student education records, we will notify affected schools without undue delay and cooperate with their FERPA and contractual notification obligations.
See Incident Response for our process overview.
Retention & deletion
Retention follows your school's agreement and applicable law. When a school ends its contract or requests deletion, we delete or return student data according to the DPA — subject to limited backup retention for disaster recovery.
Subprocessors
We use infrastructure and service providers (cloud hosting, email, AI inference) under written agreements that require appropriate security and limit use to providing Ember. Districts may request the current subprocessor list during procurement.
Questions
| Topic | Contact |
|---|---|
| DPA / procurement | security@ember.edu |
| Privacy requests | privacy@ember.edu |
| General support | hello@ember.edu |
Related: Privacy Policy · SOC 2 Overview · Legal