Student data privacy

Last updated October 8, 2026

How iSoar handles student records for districts: the district stays in control, and we never sell student data or use it for advertising.

iSoar is used by school districts to run student information, learning and family communication. This page explains how iSoar Network ("iSoar", "we") handles student records on behalf of those districts. It applies to every school and district that uses iSoar, together with the district's agreement with us.

The short version: the district owns its data, we use it only to provide iSoar to that district, and we never sell it or use it for advertising.

1. The district is in control

Each district decides who has an iSoar account, what each role can see, and which modules are turned on. The district owns the student records it puts into iSoar and the records created while using it, such as attendance, grades and messages.

When we handle education records for a district, we act on the district's behalf as a service provider under its direct control. For districts in the United States, that means we act as a school official with a legitimate educational interest under the Family Educational Rights and Privacy Act (FERPA), and we follow the limits FERPA places on that role.

2. The student information we handle

We handle only what the district and its users put into iSoar or create while using it. Depending on the modules a district uses, this can include:

  • Identity and enrollment details, such as name, student number, grade, school, section and date of birth
  • Family contacts and the relationship between parents or guardians and students
  • Attendance, schedules, classes and teachers
  • Assignments, submissions, quizzes, exams, grades, report cards and transcripts
  • Behavior and recognition notes, forms and signatures
  • Messages and announcements between school staff, families and students
  • Files that users upload, such as assignment attachments and portfolio work
  • Account and activity records, such as sign-in times and the audit log of changes

3. Our commitments

  • We do not sell student personal information.
  • We do not use student information for targeted or behavioral advertising, and iSoar does not show advertising to students.
  • We do not build profiles of students except to provide features the district has asked for, such as an at-risk attendance list.
  • We use student information only to provide, secure, support and improve iSoar for the district, or as the district directs.
  • We collect only the information needed for those purposes.
  • We do not disclose student information to anyone except the district, the service providers listed on our Subprocessors page, or as required by law.
  • We will not make a material change to how we use student information without notifying districts first.

4. Who can see student information

Access in iSoar is based on role. Families see only their own children. Teachers see the classes and students assigned to them. School administrators see their school, and district administrators see the district. Community partners see only the students and fields that the district has released to them, and the partner screens say what has been shared.

District and school administrators can review the audit log to see who changed records and when.

Within iSoar Network, only staff who need access to support or operate the service can reach customer data, and that access is limited to what the task requires.

5. Students under 13

Student accounts are created by schools, not by students. Where the Children's Online Privacy Protection Act (COPPA) applies, the school provides consent on behalf of parents for the educational use of iSoar, as the law allows. Parents who have questions about their child's information should contact their school first.

6. Requests from parents and eligible students

Parents and eligible students can review student records and ask for corrections. Because the district controls the records, these requests go to the school or district, which can view, export and correct records in iSoar. If a request comes to us directly, we will send it to the district and help the district respond.

7. Keeping and deleting data

We keep student information for as long as the district uses iSoar. When a district asks us to delete its data, or when its agreement ends, we delete or return the data within 60 days, unless the district asks us to keep it longer or the law requires us to keep it.

Database backups are kept for 7 days and then deleted automatically, so deleted records also leave our backups within that time.

8. If something goes wrong

If we confirm that student information has been accessed or disclosed without authorization, we will notify the affected districts without unreasonable delay, and within 72 hours of confirming it. We will tell them what happened, what information was involved and what we are doing about it, and we will help them meet their own notification duties.

9. Agreements and state laws

Many states have their own student privacy laws and model data privacy agreements. We will sign the student data privacy agreement a district needs. The district's signed agreement controls if it differs from this page.

10. Contact

Questions about student data privacy? Email iSoar Network at theisoarnetwork@gmail.com.

Questions about this page?

Write to iSoar Network at theisoarnetwork@gmail.com.

Email us