Skip to main content

FERPA Notice

Last updated: August 31, 2026

Draft prepared for review. This page describes the product as it works today, to the best of our records, but it has not been reviewed by a lawyer and is not legal advice. Do not rely on it as a finished policy until qualified counsel has reviewed it.

This page explains how Limud Education Inc. ("Limud") handles education records under the Family Educational Rights and Privacy Act (FERPA) for schools and districts that use our platform.

1. What Counts as an Education Record on Limud

When a school or district enrolls its students, the records Limud creates and maintains about them - grades, assignment submissions, enrollment, AI tutor conversation logs, skill/mastery records, and the AI-generated learning note described in our AI Disclosure - are education records for FERPA purposes.

2. The School Official Exception

FERPA lets a school disclose education records, without separate consent, to a "school official" with a legitimate educational interest - including a contracted service provider - when the school retains direct control over the data and the provider uses it only for the purpose for which it was disclosed. Limud operates as a school official under this exception: our Terms of Service require that whoever registers a school or district account is authorized to act as a school official on the district's behalf, and we use student data only for the educational purposes described in our Privacy Policy.

3. How Access Is Enforced in the Product

Access to a student's records is checked in code on every request, not left to the UI alone:

  • A parent can see their own linked child's records.
  • A teacher can see records only for students enrolled in a course they teach.
  • An admin can see records only for students within their own district.
  • Cross-district access is denied outright, regardless of role.

Each API route enforces this itself, on the server, before returning any record. The scoping condition is written into the database query rather than applied to the results afterwards, so a request for a record outside the caller's scope returns nothing rather than returning data that is then filtered. Identity always comes from the server-side session, never from the request. Access to student data is written to an audit log retained for seven years.

4. Parental Inspection Rights

Parents (and eligible students, i.e. those 18 or older) can inspect the records described above through the product itself:

  • Grades, assignments, and coursework - from the parent dashboard, or exported as a PDF summary report (Reports → Export).
  • The AI-generated learning note, including whether it was written by the AI model or a deterministic fallback, its confidence level, and a history of how it has changed - from the parent Reports page.

A complete, portable export of the full underlying record is available in the product. A parent can export their own linked child at Settings, and a student can export themselves at Account → Download My Data. The file is JSON, covers the learning record across every table we hold it in, and states inside itself which tables are included and which are deliberately excluded. Every export is recorded in the audit log described above. If you would rather not use the in-app export, email privacy@limud.co and we will process the request manually.

5. Correcting an Education Record

Grades and scores can be corrected directly by the teacher of record at any time through the gradebook. For any other correction - an inaccurate enrollment, a factual error you believe is in the AI-generated note, or anything else in a student's record - contact your school administrator or email privacy@limud.co, and we will investigate and correct or annotate the record as warranted. We do not currently offer a self-service "request a correction" form inside the product for anything outside the gradebook.

6. Deletion

A parent, an eligible student, or a district admin can request deletion of a student's education records - by category or in full - in-app at Account → Delete Account, or by emailing privacy@limud.co. Requests are reviewed and completed by an administrator within 30 days, as required under FERPA and COPPA.

7. Directory Information and Disclosure to Third Parties

Limud does not disclose education records to third parties for their own use. Our sub-processors (see Subprocessors) act on our behalf only, under written data-processing terms, and never use student data for their own purposes such as advertising or model training on our data.

8. Complaints

If you believe Limud has violated FERPA in how it handles your or your child's education records, contact us first at privacy@limud.co so we can investigate. You also have the right to file a complaint with the U.S. Department of Education's Student Privacy Policy Office.

9. Contact Us

Limud Education Inc.
Email: privacy@limud.co