When a school adopts a new learning management system, the data question is straightforward: names, grades, attendance, maybe some assignment submissions. When a school adopts an AI-powered tool, the data question becomes much more complex. Voice recordings, conversation transcripts, writing samples, learning patterns, behavioral data, biometric information — the list of what AI tools can collect goes well beyond what traditional educational software touches. For administrators, the challenge is not whether to use AI — the benefits are clear — but whether the data practices of a particular tool align with legal requirements, school policies, and community expectations.
What makes AI data collection different
Traditional educational software stores structured data in predictable fields. An LMS knows that a student submitted an assignment on a certain date and received a certain grade. AI tools, by contrast, often work with unstructured data — the content of student writing, the patterns in how a learner approaches problems, the tone and content of voice conversations. This data is inherently richer, and it raises different questions about who can access it, how long it is stored, and what it might reveal about a student over time. A writing assistant that stores every draft a student produces is storing something fundamentally different from a gradebook that records final scores.
The richer the data an AI tool collects, the more important it is to ask what happens to that data — and who decides.
Key legal frameworks administrators should know
In the United States, FERPA (Family Educational Rights and Privacy Act) is the baseline federal law governing student educational records. It defines what constitutes an education record, who can access it, and under what conditions. Most AI tools that integrate with school systems will be considered service providers under FERPA, meaning they can access student data only for specific purposes and cannot disclose it without consent. However, the way AI tools process data — particularly when that processing involves cloud services, third-party model providers, or data used for model training — can create ambiguity that FERPA was not designed to address directly.
COPPA considerations for tools used by younger students
The Children's Online Privacy Protection Act applies to tools that collect personal information from children under 13. For AI educational tools used in elementary schools, COPPA creates specific obligations: verifiable parental consent before collecting data, clear privacy notices, and the right to have data deleted upon request. Many AI tutoring and learning tools fall squarely within COPPA's scope, and administrators should verify that vendors are compliant — not assume that because a tool is used in a school, the usual COPPA requirements do not apply. Schools that provide access to AI tools without verifying COPPA compliance may be exposing themselves to regulatory risk.
What to ask AI vendors before signing
Vendor contracts should address several specific data questions that often get overlooked in the excitement of deploying a new tool. First, what data does the tool actually collect, and where is it stored? Some vendors store all data in the United States, while others use global cloud infrastructure that may process data in jurisdictions with different privacy standards. Second, who can access the data — and this includes the vendor's own employees, any third-party AI model providers, and any subcontractors. Third, is any data used to train or improve AI models, and if so, can the school opt out? Fourth, what happens to the data if the contract ends? Schools should be able to export their data in a standard format, and the vendor should have a clear deletion policy.
Data minimization and purpose limitation
Two principles from modern privacy frameworks apply directly to AI in schools. Data minimization means collecting only the data needed for the stated purpose — not building a comprehensive learner profile because it might be useful someday. Purpose limitation means using collected data only for what was originally disclosed to families. When evaluating AI tools, administrators should look for vendors who can articulate what data they collect and why, and who can demonstrate that they do not repurpose data for unrelated goals. A vendor who cannot clearly explain their data practices is a vendor worth scrutinizing more carefully.
Parent communication and consent
Even when legal requirements are met, community expectations matter. Parents increasingly understand that AI tools collect different types of data than traditional software, and many have questions about how that data is used. Transparent communication before deployment — explaining what the tool does, what data it collects, and how it is protected — builds trust and reduces the likelihood of complaints later. Some districts treat AI tool deployment similarly to other technology deployments, with standard acceptable use policies. Others have adopted more specific AI use policies that require additional parent notification or opt-in consent for certain types of tools. The appropriate approach depends on community expectations and district policy, but silence is rarely the right strategy.
- Review the vendor's data processing agreement and look for specific clauses on data ownership, retention, and deletion
- Verify FERPA and COPPA compliance — do not assume a vendor is compliant because they say so
- Ask whether any student data is used to train or improve AI models, and whether the school can opt out
- Confirm where data is stored and processed, especially for tools using cloud infrastructure
- Establish a data export process before deployment so the school can retrieve its data if needed
- Communicate with parents about what AI tools are being used and what data they collect
What Nivorius builds
Nivorius builds AI-powered education tools with student data privacy as a foundational design principle. When building products like LearnCore, Toynitive, and VoiceHub, the approach is to collect only the data necessary for the educational purpose, store it securely, and give schools full control over their data — including the ability to export or delete it on request. Nivorius does not use student data to train or improve underlying AI models, and all data processing is designed to comply with FERPA and COPPA requirements. The goal is to deliver the benefits of AI in education without creating privacy risk that outweighs those benefits.
Part of the Nivorius research and consulting team, focused on practical applications of AI in education and enterprise contexts.

