Compliance & Privacy

FERPA & COPPA
compliant by design.

This is the page your procurement team will ask for. FERPA school official exception, COPPA school authorization, DPA, Security overview, subprocessor list, and parent rights — all in one place. Download what you need, then request the full Trust Package if your legal team requires it.

✓ FERPA Compliant ✓ COPPA-Aligned ✓ US Data Residency No Behavioral Advertising
FERPA

Family Educational Rights and Privacy Act

CyberHeroesHQ operates as a school official under the FERPA school official exception (34 C.F.R. § 99.31(a)(1)). We process student education records only as directed by the school or district — we are the processor, the school is the controller.

✓ What we do under FERPA

  • Collect only the minimum student data necessary to operate the educational platform
  • Process student data under the school official exception — no separate consent required from parents
  • Disclose no student data to third parties outside our defined subprocessors
  • Support district data export requests at any time
  • Honor district data deletion requests within 30 days of written request
  • Enter written agreements with each school or district

✕ What we never do

  • Never sell, rent, or broker student education records
  • Never use student data for advertising, profiling, or commercial purposes
  • Never disclose student records to third parties without written district consent (except as required by law)
  • Never publish student directory information — progress and XP visible only to the teacher and the individual student
FERPA Citation: 34 C.F.R. Part 99. The school official exception allows districts to designate vendors as having a "legitimate educational interest" without parental consent, provided the vendor: (a) performs an institutional service, (b) has direct control over records, and (c) does not disclose them further. CyberHeroesHQ meets all three conditions.

Children's Online Privacy Protection Act

CyberHeroesHQ is designed for children ages 8–18. For students under 13, we rely on the school authorization mechanism (16 C.F.R. § 312.5(b)(1)): schools act in loco parentis and provide consent on behalf of parents when they enroll students in a classroom. We do not independently collect data from children — all accounts are created and managed by teachers through the Teacher Portal.

✓ What we collect from children

  • Hero username (chosen by student or teacher — no legal name required)
  • Grade band (K-2, 3-5, 6-8, or 9-12)
  • Avatar selection (pre-approved, school-appropriate set — no photos)
  • Mission progress, quiz scores, XP earned, and badges
  • Daily challenge completions
  • AI mentor conversations with Cipher (7-day TTL, then deleted)

✕ We never collect from children

  • Legal name, date of birth, or government-issued ID
  • Precise geolocation or school address tied to student
  • Biometric or health data
  • Social media profiles or contact lists
  • Behavioral advertising profiles or cross-context tracking
📧

COPPA Rights Contact

All COPPA data rights requests — access, correction, deletion — are handled within 45 days per FTC guidance.

privacy@cyberheroeshq.com →
Data Processing Agreement

Download the DPA

Our Data Processing Agreement is suitable for district legal review. It covers: FERPA school official exception framing, COPPA school authorization mechanism, categories of data processed, retention schedule, deletion workflow, security commitments, subprocessor list, and signature blocks.

📋

Data Processing Agreement (DPA)

Covers: FERPA school official exception · COPPA authorization · Data categories · Retention & deletion workflow · Security commitments · Subprocessor list · Signature blocks

⬇ Download DPA (PDF)
Need a countersigned DPA? Email trust@cyberheroeshq.com with your district name and a contact email. We respond within 2 business days.

Security One-Pager (PDF)

Download our security overview — written for district IT administrators and CISOs. Covers: authentication model, encryption in transit and at rest, data residency, access controls, incident response procedure, backup & recovery objectives.

🔒

Security Overview

Covers: Auth model (teacher/student/parent/admin) · Encryption in transit + at rest · US data residency · Access controls · Incident response (72-hour notification) · Backup & recovery (RTO < 4h, RPO < 5 min)

⬇ Download Security Overview (PDF)
Need a custom security review or HECVAT completion? Email security@cyberheroeshq.com — we respond within 5 business days.
Subprocessors

Third-party vendors & what data they receive

We use a small, vetted set of subprocessors. We notify schools of any material changes to this list at least 30 days in advance. No student data is shared with ad networks or analytics services.

Vendor Purpose Data shared Region
Neon (PostgreSQL) Primary database hosting All platform data — encrypted at rest (AES-256 via AWS KMS) 🇺🇸 US-East (AWS)
Render Application hosting & deployment Application code; request metadata (IP, timestamp) — no student PII in logs 🇺🇸 US
Postmark Transactional email (teacher & parent notifications) Teacher/parent email address; student hero username appears only in notification subject lines 🇺🇸 US
Stripe Payment processing (family & district subscriptions) Billing email + card data (held by Stripe — never stored by us). No student data goes to Stripe. 🇺🇸 US
Anthropic (Claude) Cipher AI mentor — Socratic hints, chat, post-mission debriefs, AI-generated remediation challenges Session-scoped, anonymized only. Current mission context + student message. No real name, email, or student ID. Conversation history in our DB with 7-day TTL, not shared externally. Anthropic does not train on or retain this data. 🇺🇸 US

Parent rights & how to exercise them

Parents and guardians have the right to access, correct, and delete their child's data. We respond to all requests within 45 days.

🔍

Right to Access

Download a complete JSON export of your child's data — hero username, progress, XP, badges, quiz scores — from the Family Dashboard.

✏️

Right to Correction

Request correction of inaccurate data by emailing privacy@cyberheroeshq.com. We update or annotate within 45 days of verified request.

🗑️

Right to Deletion

Permanently delete all your child's data from the Family Dashboard — deletion is immediate and irreversible. Or email privacy@cyberheroeshq.com.

Email request workflow: Send to privacy@cyberheroeshq.com with subject "Student Data Request" and include the student's hero username + school name. Response within 45 days.
District Responsibilities

What districts & schools are responsible for

CyberHeroesHQ is the processor — the school or district is the controller. Here's what the district is responsible for under our model.

1

Teacher-managed accounts (classroom code model)

All student accounts are created and managed by teachers through the Teacher Portal. Students never self-register. They join via classroom code (CYBER-XXXX format) issued by their teacher — no password, no PII required on the student side.

2

School as data controller

The school or district controls enrollment, classroom existence, and account termination. CyberHeroesHQ processes data only as directed — no independent data collection from students.

3

COPPA parental consent (school authorization)

Schools act in loco parentis under the COPPA school authorization mechanism (16 C.F.R. § 312.5(b)(1)). By enrolling students under 13, the school represents it has authority to provide consent for educational platform use.

4

Roster maintenance & account removal

Schools are responsible for removing students who transfer or withdraw. Submit deletion requests to privacy@cyberheroeshq.com or via the Teacher Portal. We respond within 30 days.

5

State student privacy laws

Schools are responsible for compliance with applicable state student privacy laws in their jurisdiction (SOPIPA, CA SOPPA, NY Education Law §2-d, TX SCOPE Act, etc.). Email trust@cyberheroeshq.com for state-specific documentation.

Questions procurement always asks

Answered directly — no weasel words.

Do you sell student data?
No. We do not sell, rent, or broker student data to any third party. Our revenue comes from school and family subscriptions — not data monetization.
Do you serve ads to students?
No. Zero advertising on the platform. No ad networks, no behavioral tracking, no cross-site data sharing for advertising purposes.
Can parents opt out or request deletion?
Yes. Email privacy@cyberheroeshq.com. We delete within 30 days and confirm in writing. District admins can also initiate deletion via the Teacher Portal.
Is AI mentor data used to train models?
No. We send only the current mission context + student message (anonymized — no name, no email, no student ID) to Anthropic's Claude. Anthropic does not train on or retain this data. Conversation history is in our own DB with a 7-day TTL. Per-student rate limit (20 messages/hour) and jailbreak filter run before every AI call.
Where is student data stored?
United States only. Neon PostgreSQL on AWS US-East; Render US region for app hosting. No data transferred outside the US.
Are you COPPA-compliant?
Yes. Via the school authorization mechanism (16 C.F.R. § 312.5(b)(1)). Schools act in loco parentis and provide consent when enrolling students under 13. We do not independently collect data from children.
Do you comply with state student privacy laws?
Our practices are designed to comply with FERPA, COPPA, and major state student privacy laws (SOPIPA, CA SOPPA, NY Education Law §2-d, TX SCOPE Act). For state-specific review, email trust@cyberheroeshq.com.
What happens when a pilot ends?
Data retained for 90 days post-pilot for data export, then purged. Districts can request immediate deletion at any time. Teachers can export classroom data via the Teacher Portal before the pilot ends.
Trust Package

Request our full Trust Package

Districts with additional procurement requirements get a complete trust package — countersigned DPA, compliance attestation letter, security questionnaire responses, subprocessor DPAs on request, and reference contacts.

  • Countersigned Data Processing Agreement
  • Security questionnaire responses (HECVAT, SIG, custom)
  • COPPA / FERPA compliance attestation letter
  • Subprocessor DPAs on request
  • Reference contacts from active district customers

Request Trust Package

Get in touch

📋

Privacy & FERPA/COPPA

Data access, correction, deletion requests, parental consent questions

privacy@cyberheroeshq.com
🔒

Security

Vulnerability reports, HECVAT, custom security reviews

security@cyberheroeshq.com
📦

Trust Package & DPA

Countersigned DPA, compliance attestation, procurement requirements

trust@cyberheroeshq.com