FAQ: Student Data Protection

Answers for districts, state education agencies, and parents about how Pearl Education handles student data. Where an answer relies on our customer agreements, the relevant section is cited.

What Data Does Pearl Collect?

Pearl processes the student data a school configures for its program. Depending on setup, this may include identifiers (such as name, username/email, and a local or school-assigned ID), optional demographics the school elects to provide, enrollment and scheduling, session attendance and usage, messages between authorized users, uploaded instructional files, and — where the school enables it — online session recordings (DPA Schedule 1). Schools should not submit excluded data such as Social Security numbers, government IDs, financial account numbers, biometric records, or medical records beyond elected accommodations (MSA §3.2; DPA Schedule 1, Part C).

Note: Pearl’s mobile app is for adult users (instructors and administrators) only; students are not given mobile app accounts (DPA Schedule 1, Part D).

Does Pearl Sell Student Data?

No. Pearl does not sell student data (MSA §5.7; DPA §4.2).

Does Pearl Use Student Data for Advertising?

No. Pearl does not use student data for targeted or behavioral advertising directed at students, and does not build commercial student profiles except as needed to provide the Services (MSA §5.7; DPA §4.2).

How Does Pearl Use Data Beyond Running the Service?

Pearl uses student data to provide the Services at the school’s direction. Separately, Pearl may create and use de-identified and aggregated data for research, benchmarking, and service improvement, using a documented de-identification methodology; any third party receiving such data must agree in writing not to re-identify it (MSA §6; DPA Art. V). In short: Pearl does not sell student data, does not use it for targeted advertising, and does not train AI models on identifiable student data; Pearl may use de-identified and aggregated data consistent with its agreements.

Where Is Data Hosted?

All Pearl data is hosted in Amazon Web Services (AWS) US regions only. Customer Content is encrypted in transit and at rest (MSA §4.3).

How Does Consent Work?

The school is the consent authority, not Pearl. Pearl acts as a FERPA “school official” providing the service on the school’s behalf, and the school decides how consent is handled under FERPA, PPRA, COPPA, and state law (MSA §5.3–5.5). COPPA applies to children under 13; in a school context the school may provide consent for educational use. At a school’s request, Pearl can provide an in-product mechanism to capture verifiable parental consent (MSA §5.5). See Parental Rights and Consent.

How Do I Request Deletion?

Parents and eligible students make access, correction, and deletion requests through their school; if a parent contacts Pearl directly, Pearl refers them to the school (DPA §2.2). For schools: data can be exported during the term and for 30 days after termination, and Pearl deletes Customer Content no later than 60 days after that export period (or within 60 days of an earlier deletion request), certifying deletion in writing on request (MSA §4.6; DPA Art. VIII).

Is There AI in the Product?

The Platform Services may include AI-enabled features (for example, administrator insights and alerts, natural-language analytics over the school’s own data, and product help experiences). These features process Customer Content solely on the school’s behalf to provide the Services, and outputs are for the school’s use (MSA §7.1). For details, see Pearl’s AI documentation in the Trust Center.