Annual audit

What school communication apps sell to the families your district enrolled

A district chooses a platform. The families have no choice at all — the roster put them there. So the question of what that platform then sells them is a district procurement question, not a consumer one. This audit records, from public and reproducible sources, what each family-facing property charges, advertises and loads, and whether the district's own contract permits any of it.

Last reviewed 2026-08-04 ยท Kastr is pre-launch; we publish dated status rather than logos.

The four monetisation vectors — how each is observed, what evidence is retained, and the contract term that closes it
VectorHow it is observedEvidence retainedContract term that closes it
Paid parent subscription or in-app purchaseApp-store in-app purchase tiers and prices exposed in public store metadataDated listing capture with the price tier as publishedNo family-facing subscription revenue derived from district rosters
Advertising or promoted content in family surfacesDirect observation of the family-facing web property; promoted units identified and datedDated capture plus the network request that served the unitNo advertising or promoted placement in any district-facing or family-facing surface
Third-party trackers on family propertiesNetwork requests logged loading the public family-facing property in a clean headless browser; third-party hosts classifiedFull request log, host classification and the scan dateNamed subprocessor list, change notice, no analytics vendor added without notice
Terms divergence between family and district paperFamily terms and privacy policy read against the district DPA, quoted side by sideBoth documents, both retrieval dates, the two passagesFamily terms subordinate to the district agreement where they conflict

Every scan is dated. Nothing is asserted about intent. A finding here says only that on a stated date a stated public property did a stated thing, and vendors receive their rows ten business days ahead of publication.

What is already public, and what the audit adds

Some of this is not in dispute and does not need a scan. ClassDojo is free to districts and takes its revenue from families instead: Dojo Sparks is published at $9.99 a month, and ClassDojo Plus is not priced publicly anywhere we can find. Bloomz publishes district tiers at $3, $5, $7 and $9. Those are the vendors' own published figures and any district can verify them today.

What the audit adds is the systematic version: the same four questions asked of every platform on the same date with the same method, the evidence retained, and the answer set against the district contract. A single vendor's pricing page is a fact. A dated grid of twelve vendors on one axis is a document a district can put in front of a board.

The other thing it adds is the year-over-year diff. Edition one is a snapshot. The story in edition two is who started charging families and who stopped, and that story cannot be told by anybody who did not take the snapshot first.

Method, and its deliberate limits

The scan is designed so that anyone can re-run it and get the same answer, and so that we never touch anything we have no business touching.

  • Public properties only. The family-facing marketing and login pages as any member of the public would load them. No account is created, no district's authenticated environment is accessed, no terms of service are circumvented and no rate limit is stressed.
  • Clean browser profile, no extensions, no prior cookies, from a stated network location, with the full request log retained.
  • Vendor-published labels are taken as the vendor's own statement. The App Store privacy labels and Google Play Data Safety declarations are what each company has itself declared, and we report them as such rather than as our findings.
  • Third-party hosts are classified, not interpreted. An analytics host is recorded as an analytics host. What data crossed it is not something a network log can establish and we will not claim it does.
  • Tooling and dates are published so a sceptical vendor can reproduce the run rather than argue about it.

The five questions to ask your own vendor

Free, and answerable only by contract. A policy answer to any of these is a non-answer, because a policy can be changed unilaterally by the company that wrote it.

  1. Does any part of your business derive revenue from our families? Not "do you sell data" — revenue, of any kind, from the people on our roster.
  2. Where in our agreement is that restricted, and what happens if you change your family-facing terms?
  3. Do any surfaces our families see carry advertising, sponsored placement or a paid upgrade prompt?
  4. Which third parties load on family-facing pages, and how are we notified when that list changes?
  5. If your family terms and our district agreement conflict, which governs? Get the answer in the contract, not in an email.

Our answer to all five, in one place. Clause 9.4 of the Kastr agreement bars us from marketing to, advertising to or selling anything to a district's families, and bars any family-facing subscription revenue, permanently. There is no free tier funded by parents because there is no parent-funded anything. Districts pay $3.50, $3.25 or $3.00 per student per year by enrolment band and that is the entire revenue model. If we ever wanted to change that, clause 11.2 lets you leave inside 90 days with export and a prorated refund, which is the only version of that promise worth anything.

Why this is a procurement question rather than a privacy one

Districts have become fluent in student data privacy. Signed NDPAs, state registries, SOPIPA and COPPA obligations, subprocessor disclosure — that machinery works reasonably well and it addresses the sale and misuse of student data.

It does not address a vendor charging a parent $9.99 a month for features inside the application their child's school required them to install. That is not a privacy violation, and a vendor doing it can be entirely compliant with every privacy instrument the district has signed. It is a conflict of interest, and the only place it can be resolved is the commercial section of the contract.

The reason it matters operationally, rather than only philosophically: a platform earning revenue from families has an incentive to optimise the family experience for conversion, and a platform earning revenue from districts has an incentive to optimise it for the district's message getting read. Those two designs diverge, and by the time a district notices, the families are already installed.

Questions people actually ask

Which school communication apps charge parents a subscription?

ClassDojo is the clearest published case: it is free to districts and monetises families instead, with Dojo Sparks published at $9.99 a month and ClassDojo Plus not priced publicly anywhere we can find. The audit checks every platform in scope against the same question on the same date using public store metadata, rather than relying on any one vendor's marketing page.

Can our district's vendor advertise to our families?

Unless your contract prohibits it, quite possibly. Most district agreements in this category restrict the sale of student data and say nothing whatever about advertising, promoted content or paid upgrades shown to parents. Those are separate permissions and they need a separate clause. The audit records what each family-facing property actually shows, dated.

Do school communication apps carry third-party trackers?

Some do, and the vendors themselves declare a good deal of it in App Store privacy labels and Google Play Data Safety sections. The audit logs third-party hosts observed loading each public family-facing property in a clean browser, publishes the method so the run is reproducible, and classifies hosts without claiming to know what data crossed them, which a network log cannot establish.

How did you scan these apps, and can I reproduce your results?

Yes, and reproducibility is the design constraint. Public family-facing properties only, loaded in a clean headless browser profile with no extensions and no prior cookies, full request log retained, tooling and scan date published. No accounts are created, no authenticated district environment is touched and no terms are circumvented.

What is the difference between what a vendor promises our district and what it tells families?

Frequently a great deal, and where those two documents disagree, the disagreement is the finding. The district DPA and the family-facing terms of use are separate instruments written for separate audiences, and the family terms are usually the ones that can be amended unilaterally. The audit quotes both side by side with retrieval dates rather than summarising either.

How do we contractually forbid family monetisation?

With a clause that names revenue rather than data: no marketing to, advertising to or charging of district families or students, and no family-facing subscription revenue derived from the district's roster, for the life of the agreement. Add a term stating that where family-facing terms conflict with the district agreement, the district agreement governs. The free rider published with the ownership scorecard contains both.

One price. Every feature. Locked for three years.

$3.50 per student per year under 5,000 students. No tiers, no add-on modules, no per-message fees. Published on the site because you should not have to book a call to learn a price.