Trust & Privacy

We hold records about students, so your school needs to know how we handle them. This page covers what we do, what we do not do, what we keep, and every company that touches your data. If you need something that is not here, ask us.

What we do

  • Drafts, summarizes, and transcribes for staff.

    We write up a referral, condense a long thread, or turn a dictated note into text.

  • Builds tools on your own data.

    A workflow that lives in a spreadsheet or legacy tool today can move to us. Tools will never show a staff member data that they don't have access to.

  • Shows staff which words came from AI.

    Every answer we write in chat carries an AI label, so nobody guesses whether answers were written by AI.

What we do not do

  • We do not decide anything about a student.

    We draft, and a person decides. We do not score, rank, or predict, and we take no adverse action.

  • We do not show ads.

    No one advertises through us.

  • We do not sell or share personal information.

    Not student data, not staff data, not ever.

  • We do not train AI models on your data.

    What your school puts in stays your school's.

No data travels offshore

Everything we hold stays in the United States. The application and its database run here, your files are stored here, and all of our AI providers are here.

Your school sends us data by SFTP, API, or direct upload. It lands in storage we run, and we only work with trusted subprocessor partners to store and analyze it. We can tell you which subprocessor handled any request.

A school sends files to us, we hold them in our own storage, and only what a request needs is passed on to the companies that process it.

How we protect your data

  1. One school's data cannot reach another.

    The separation is enforced by the database itself rather than by our code remembering to ask for it. A check runs before every release and stops it shipping if the separation cannot be proven, and the account we serve requests with has no way around it.

  2. Nothing can be read in transit.

    Every connection is encrypted, and we tell browsers to refuse an unencrypted one. Anyone intercepting traffic between your staff and us gets nothing they can read.

  3. Your files are encrypted where they sit.

    Anything your staff upload, and anything we write for them, is encrypted on the storage that holds it.

  4. Unexpected requests are turned away.

    Every way in states exactly what it will accept and refuses the rest. An automated check makes sure a new one cannot skip that.

  • FERPA — Family Educational Rights and Privacy Act
  • COPPA — Children's Online Privacy Protection Act
  • SOPIPA — Student Online Personal Information Protection Act

We work within FERPA, COPPA and the state student-privacy laws that cover your school. We sign state data privacy agreements wherever one is available. We keep a written information security program, and we revisit it as the product changes.

What we keep

We keep the conversations your staff have and the documents they make in them, and the records your school puts in. Every AI answer stays tied to the staff member who asked for it. Your school sets who reaches which records, down to a single one. Two counselors can open the same tool and each see only the cases they are assigned to.

Your school decides every squareCounselorTeacherPrincipalCasesBehavior recordsAttendanceDocuments

What we discard

  • Dictation audio.

    We send the recording, get text back, and discard the audio. Nothing after that point knows the message was spoken.

  • The words of an AI turn in our diagnostics.

    Production traces carry only timings and token counts.

Questions schools ask

Getting data in

The AI

Who sees what

Your data

Agreements

What your network needs

That is the whole requirement. The first two are opened for a staff browser. The third is opened outbound, and only by a school that sends us files on a schedule. Nothing installs on school devices.

  • *.withmatilda.com

    Port 443

    Us. Everything your staff do happens here. One rule covers every subdomain we serve

  • accounts.google.com

    Port 443

    Sign in with Google. The browser redirect only. The token exchange happens on our servers

  • sftp.withmatilda.com

    Port 22

    Only if your school sends us files on a schedule. Outbound from the machine that runs the export, not from staff machines

Security and Privacy Review

This page plus the network settings your IT team needs, what deletion removes, and where the AI runs. Everything in it is generated from the same modules this page reads, so the two cannot disagree. Ask us and we will send a copy prepared for your school.

Where your state runs a standard agreement, that is the one we would rather sign. Many are filed through the Student Data Privacy Consortium. Otherwise send us your own and we will sign it, and if you would rather start from a template we have one. Our written information security program is available on request.

Our Privacy Notice, Terms of Use and Cookie Policy are published here.

What is inside

  • Who can see which records
  • Every company that touches your data
  • What your network has to allow
  • What deletion removes, and what it does not

Ask us something

Send privacy and security questions to privacy@withmatilda.com.