Student Privacy Pledge
The Student Privacy Pledge is a voluntary set of commitments that ed-tech companies sign publicly, covering the handling of student personal information. It was introduced in 2014 by the Future of Privacy Forum and the Software & Information Industry Association, and updated in 2020.
| Rung | Mechanism | Who verifies it | What it proves | Cost to fake |
|---|---|---|---|---|
| 1 | Self-certification — a pledge, a trust page, a badge | Nobody | The vendor was willing to say it | A form submission |
| 2 | Contractual commitment — a DPA clause | The district, if it litigates | You have a remedy if it turns out false | A negotiation you might lose |
| 3 | Third-party attestation — SOC 2 Type II | An audit firm, over an observation window | Controls existed and operated for that period | Tens of thousands of dollars and a year |
| 4 | Verifiable technical control | Anyone who can read the test | The system behaves that way, continuously | Cannot be faked; the test either passes or does not |
What the commitments cover
The substance is uncontroversial, which is part of the point — the Pledge codifies practices a responsible vendor should already follow:
- Not to sell student personal information.
- Not to use or disclose it for behaviourally targeted advertising.
- Not to build a personal profile of a student other than for authorised educational purposes or with parental consent.
- To collect and retain only what is needed for authorised educational purposes, and to support access and correction through the school.
- To maintain a comprehensive security programme.
- To be transparent about collection and use, and to give notice before material changes to the policy.
- To require successors to honour the same commitments.
Read that list against the business model of any vendor you are evaluating. Several are structurally incompatible with a product that earns revenue from families rather than from the district, and the incompatibility is not resolved by signing.
Why it has teeth, and why it does not have many
The Pledge is not a law and nobody audits it. There is no inspection, no evidence submission and no revocation process worth the name. Signing is free.
What gives it any force is the deception theory: a public commitment that a company then breaks is a representation to the market, and the Federal Trade Commission has authority over deceptive practices. State attorneys general have similar authority under state consumer-protection statutes. So the Pledge converts a marketing statement into an enforceable one — but only after the harm, only if a regulator takes an interest, and only for the commitments as written.
What signing does not prove. It does not prove FERPA compliance, does not prove a security programme exists, does not prove data is isolated between districts, and does not prove anything about deletion. Treat a signature as a statement of intent from the marketing department, which is what it is, and then ask for a contract clause or a test.
Where Kastr sits, precisely
We have not signed the Pledge. We are pre-launch with no customers, and adding a signature to a list would be the cheapest possible signal at exactly the moment we have nothing else to show.
What we can point at instead, in ascending order of how much it proves:
- Rung 2, contract. Clause 9.4 prohibits marketing or selling to district families and prohibits family-facing subscription revenue for the life of the agreement. Clause 11.2 gives you a 90-day exit with export and a prorated refund if we are acquired or materially change our data terms — which is the successor commitment made specific and terminable rather than promised.
- Rung 3, attestation. We do not have one. No SOC 2 Type I or Type II, no audit in progress. Anyone claiming otherwise on our behalf is wrong.
- Rung 4, technical control. Tenant isolation is enforced by Postgres row-level security under a non-owner, DML-only role, so a query with no organisation context returns zero rows instead of everything. A cross-tenant leakage suite runs in CI against real Postgres on every commit, including a regression check that table ownership cannot bypass the policies. Administrative actions are recorded in an append-only, SHA-256 hash-chained audit log where editing history breaks the chain.
The ladder matters more than our position on it. A vendor with a Pledge signature and no answer at rung 4 has given you less than one with no signature and a test you can read.
Questions people actually ask
Is the Student Privacy Pledge legally binding?
Not on its own. It is a voluntary public commitment. Its force comes indirectly: breaking a public promise can be treated as a deceptive practice by the Federal Trade Commission or by a state attorney general. That is enforcement after harm, not assurance before it.
Who audits Student Privacy Pledge signatories?
No one. There is no inspection, no evidence review and no meaningful revocation process. Signing costs nothing, which is exactly why it should not carry weight in an evaluation on its own.
Is signing the Pledge the same as being FERPA compliant?
No. FERPA obligations attach to the school district, and a vendor's position under FERPA depends on its contract and on the school official exception. A pledge signature has no bearing on either.
Should a district require the Pledge in an RFP?
Requiring it costs nothing and screens out nobody, since any vendor can sign in an afternoon. It is more useful as one line in a wider assurance question that also asks for the data privacy agreement terms, any third-party attestation, and how tenant isolation is enforced and tested.
One price. Every feature. Locked for three years.
$3.50 per student per year under 5,000 students. No tiers, no add-on modules, no per-message fees. Published on the site because you should not have to book a call to learn a price.