Thoughtlas.Our Story

Is My Child's Data Safe When Using AI Tools at School?

By Thoughtlas Team

Is My Child's Data Safe When Using AI Tools at School?

Not automatically — and the answer depends heavily on which AI tools your child's school is using and how those tools are configured. Some school-approved AI platforms have strong data privacy protections and are legally compliant with children's privacy laws. Others are consumer-grade tools not designed for minors and may collect, store, or use your child's data in ways you'd find alarming. This guide breaks down what you need to know, what questions to ask, and what your rights are as a parent.


The Privacy Landscape for EdTech AI in 2025

The use of AI in schools has outpaced the development of clear privacy standards. In 2025, students are using AI tools that range from:

  • Fully vetted, school-procured platforms with FERPA-compliant data agreements
  • Free consumer tools (like the public version of ChatGPT) that were never designed for educational use and have no special privacy protections for minors
  • Hybrid tools adopted informally by individual teachers without district approval or data review

The risk profile is completely different across these categories — and most parents have no idea which category their child's tools fall into.


The Laws That Should Protect Your Child

COPPA (Children's Online Privacy Protection Act)

Applies to websites and online services directed at children under 13. Requires:

  • Parental consent before collecting personal data from children
  • Disclosure of what data is collected and how it's used
  • Ability for parents to review and delete data

The problem: Many AI tools used in schools aren't "directed at children" in their design and claim COPPA doesn't apply to them — even when children are the primary users.

FERPA (Family Educational Rights and Privacy Act)

Applies to educational institutions that receive federal funding. Gives parents the right to:

  • Access their child's educational records
  • Request correction of inaccurate records
  • Consent to the disclosure of personally identifiable information

The problem: FERPA governs what schools can share — not what third-party AI vendors do with data once they have it. If a school shares student work with an AI platform and that platform's privacy policy allows data use for model training, FERPA alone doesn't stop that.

SOPIPA (Student Online Personal Information Protection Act) and State Equivalents

Several states have enacted stronger protections specifically for student data. California's AB 1584, New York's Education Law 2-d, and similar laws in other states explicitly prohibit edtech companies from using student data for advertising or selling it to third parties.

Check your state: Student data protection laws vary significantly by location. Your state's Department of Education website should have current information.


The Real Risks Parents Should Understand

1. Training Data Harvesting

Some AI platforms use user inputs (including student essays, questions, and conversations) to improve their models. If your child is typing their personal views, creative writing, or academic work into these tools, that content may become training data. Review each platform's privacy policy specifically for language about how user inputs are used.

2. Data Persistence and Breach Risk

Any data a platform stores is subject to potential breach. Platforms with weaker security practices represent a risk that your child's personal information — or more sensitively, records of their academic struggles and personal essays — could be exposed.

3. Behavioral Profiling

Consumer AI tools may build profiles based on usage patterns. While the immediate harm from a student's ChatGPT conversation log may seem minimal, the principle of children having commercial profiles built on their intellectual and academic behavior is ethically significant.

4. Uninformed Consent

Many schools deploy AI tools without specifically notifying parents or requesting consent beyond general technology use agreements signed at the start of the year. Your child may be using tools you've never heard of.


💡 Practical Tip: The 5 Questions to Ask Your Child's School

Email or call your school's principal or IT administrator and ask:

  1. What AI tools are approved and in use at our school this year?
  2. Do these tools have a signed Data Processing Agreement (DPA) with the district?
  3. Are student inputs or work samples used to train the AI model?
  4. Where is student data stored, and for how long?
  5. How can I opt my child out of specific AI tools if I choose?

A school that cannot answer these questions confidently should be prompted to find out. You have a legitimate right to this information as a parent.


How to Evaluate Any AI Tool Your Child Uses

When a teacher assigns or suggests an AI tool — or when your child starts using one independently — run through this checklist:

QuestionWhat to Look For
Does it have a Privacy Policy?Must have one; no policy = red flag
Does it mention COPPA compliance?Should, for any tool used by under-13s
Does it use student data for AI training?Look for "we may use your inputs to improve our models" — this is a concern
Is it a school-procured tool?School procurement implies vetting; consumer tools have fewer protections
Does it require account creation?Accounts create persistent data records
Is there a "Student Data Privacy Consortium" (SDPC) agreement?This is a strong positive signal for US schools

What Parents Can Do Right Now

1. Request the list of approved tools from your school. Most districts have an approved technology list. Request it in writing. Any AI tool your child uses that isn't on this list is being used without district vetting.

2. Review privacy policies of tools your child uses at home. Look specifically for: data retention policies, whether user inputs are used for model training, and whether data is sold or shared with third parties.

3. Establish a household rule about personal information in AI prompts. Your child should never include their full name, school name, grade, or any personally identifying information in AI prompts — particularly on consumer platforms.

4. Opt for AI tools with student-specific privacy protections. Platforms explicitly designed for educational use (with FERPA compliance and signed DPAs) are meaningfully safer than consumer tools.

5. Stay current. The regulatory landscape is changing rapidly. Sign up for updates from your district's technology department and your state's education department.


FAQ

Q: Is ChatGPT safe for my child to use? The consumer version of ChatGPT (at ChatGPT.com) collects user data and, depending on settings, may use conversations for model improvement. It is not COPPA-compliant for users under 13 — OpenAI's terms of service require users to be at least 13 (or have parental consent). ChatGPT Edu and API-based implementations used by schools under enterprise agreements have significantly stronger privacy protections.

Q: Can I ask the school to delete my child's data from an AI platform? Under FERPA and many state laws, yes. Submit a written request to the school. The school should be able to work with their vendor to facilitate data deletion for your child.

Q: What if I find out the school has been using a tool without proper vetting? Raise the concern formally with school administration and, if unresolved, with the district's technology director. Parent Teacher Organizations (PTOs/PTAs) can be effective advocacy channels for school-wide policy changes on technology.

Q: Are AI tools from well-known companies automatically safer? Brand recognition is not the same as privacy protection. Even major AI platforms have faced regulatory scrutiny over data practices. Always review the privacy policy regardless of the company's reputation.


The Balance: Protection Without Paranoia

The goal isn't to keep your child away from AI tools entirely — many of them offer genuine educational value when used appropriately. The goal is to ensure that value comes without hidden costs to your child's privacy.

Children who learn to be thoughtful consumers of technology — asking "what happens to my data?" before signing up for new tools — develop digital literacy skills that will protect them throughout their lives.

You can model this by asking those same questions out loud when evaluating tools together.


See your child's reasoning come alive with Thoughtlas — the platform built to make thinking visible, not just answers.