DRAFT prepared for legal review, not a policy.

# FERPA summary (draft)

Prepared 2026-09-19 for review by counsel. Nothing here is legal advice, and
nothing here binds Limud until counsel has approved it and it has replaced the
corresponding published page. The binding document today is the FERPA page at
https://limud.co/ferpa.

## 1. Role

Limud operates as a school official with a legitimate educational interest under
34 CFR 99.31(a)(1)(i)(B), acting under the direct control of the educational
agency or institution with respect to the use and maintenance of education
records. Limud does not use education records for any purpose other than
providing the service to the school.

## 2. What is held

- Roster identity: name, school email, role, classroom membership.
- Coursework: assignments, submissions, scores, teacher feedback.
- Teaching material a teacher uploads, and the per-student version of that
  material that Limud AI produces from it.
- AI tutor conversations, which are readable in full by the student, by that
  student's own teacher, and by a district administrator with the student-view
  permission. Every staff read is logged.
- Product telemetry: when a material was opened and for how long. No keystroke
  capture, no mouse tracking.

## 3. What is never produced

Assignments are not personalised. There is no code path that produces a
per-student version of an assignment, its questions, its points or its due date.
This is enforced by a test in the build rather than by policy.

## 4. Directory information

Limud does not designate or disclose directory information. Nothing is published
outside the district's own tenant.

## 5. Access, amendment and the audit trail

- A parent or eligible student exercises access and amendment rights through the
  school, which is the record holder. Limud provides the district with an export
  and with the audit log needed to answer such a request.
- Access to a personalised version or an AI tutor conversation by a member of
  staff writes an audit row naming who read what and when.

## 6. Retention and deletion

- Data is retained for the term of the district agreement.
- On termination, the district may request deletion; Limud's published
  commitment is deletion within 30 days of the request.
- Scheduled jobs already remove: accountless live-session data after 7 days,
  an individual learner's data 90 days after the subscription ends, and
  wellbeing check-in notes after 45 days or 14 days after resolution.

## 7. Subprocessors

Listed in the subprocessor draft in this packet and, in binding form, at
https://limud.co/subprocessors.

## 8. Open items for counsel

1. Confirm the school-official designation language the district's own policy
   requires, and whether a signed addendum is expected instead.
2. Confirm the 30-day deletion commitment against the district's contract
   template.
3. Confirm whether the audit log satisfies the district's record-of-disclosure
   expectations, or whether a separate disclosure register is required.
