Skip to main content
IW Classroom

Privacy

Privacy at IW Classroom

Effective August 7, 2026. Operated by InstructorWeb.

IW Classroom is built privacy-first, especially for students. This page explains, in plain language, what we collect, what we don't, and the choices teachers and schools have. It describes how the product actually works today.

Our promise about student data

  • Education use only. Student information is used solely to operate the classroom service for the school and teacher. We do not sell student data, and we do not use it for advertising, marketing, behavioral profiling, or any commercial purpose.
  • School-authorized. Teacher accounts create and manage student records on behalf of the school. We rely on the school's authority to enroll students, consistent with the school-consent approach recognized under the Children's Online Privacy Protection Act (COPPA) for educational tools. Where COPPA applies, we rely on school authorization only for the school-authorized educational purpose, and InstructorWeb remains responsible for its own obligations as the operator of the service.
  • A service provider to the school. To the extent student information is part of a student's education records, we act as a service provider under the school's direction (a “school official” under FERPA): we use it only to provide the service, do not use it for our own commercial purposes, and do not share it except with our service providers, as the school directs, or as required by law.

Students

  • No email or personal contact information. Students never provide an email address, phone number, home address, or date of birth. They sign in with a class code, a teacher-assigned username, and a PIN.
  • Minimal data. A student record holds only what the classroom needs — a teacher-supplied name or label (a first name, initials, or a nickname is enough; a full legal name is not required), the teacher-assigned username, an optional teacher-supplied student ID, a hashed PIN, and the activity created inside the classroom's learning activities (such as practice answers and completions). PINs are stored hashed; they are never kept in readable form and are never shown back to anyone.
  • No ads or tracking. The student portal carries no advertising, no retargeting pixels, and no third-party marketing or analytics trackers. Student pages are marked not to be indexed by search engines and not to be cached.
  • Practice, not real-world stakes. Classroom activities are educational practice — where an activity uses a simulation, it is pretend. Students are told not to enter real bank account numbers, card numbers, Social Security numbers, or other sensitive personal or financial information.

Teachers

  • Account basics. A teacher account stores a name and email address, used to identify the account, to link it to the teacher's InstructorWeb membership, and for support. Teachers sign in with their existing InstructorWeb account rather than a separate password here.
  • You control your classes' data. Teachers can export their class records (rosters and activity records) and can permanently delete a class or an individual student, including the associated activity data.

Parent and school rights

  • Review, export, and deletion. Because students are enrolled by their teacher and we hold no parent contact information, parents should direct requests to review, receive a copy of, correct, or delete a child's records to the child's teacher or school. Teachers can fulfill these requests directly from inside the class using the built-in export and delete tools, or contact us for help.
  • No direct student contact. We do not contact students and have no way to do so — there is no student email on file.

Data handling

  • Where data is stored. Data is hosted on cloud infrastructure located in the United States.
  • Service providers. We use one vendor to run the service: a US-based cloud host (Cloudways / DigitalOcean) for application and database hosting. It processes data only to provide that hosting to us and is not permitted to use student data for its own purposes. We use no analytics, advertising, or error-reporting services of any kind.
  • Cookies. We use only essential, first-party cookies needed to keep you signed in and to protect forms against cross-site request forgery. We set no advertising or third-party tracking cookies.
  • Email. The service sends no email. Teachers sign in through their InstructorWeb account, students have no email address on file, and we send no newsletters, marketing, or notifications of any kind.
  • Security logs. To keep accounts safe we keep a record of security-relevant events — for example, when a class is created or deleted, or when repeated wrong PIN attempts lock a student out. These records include the internet (IP) address and browser type of the device that made the request. They are used only to operate and protect the service, never to build a profile of a student or to track anyone across other websites.
  • Retention. Exported files are temporary and expire automatically after 14 days. In our security logs, the IP address and browser type are erased after 90 days, and the remaining record of what happened is deleted after 24 months. Archived classes and students become eligible for permanent deletion after a period of inactivity, and teachers can delete their data at any time.
  • Security. Connections are encrypted over HTTPS. Passwords and student PINs are stored hashed. Access to student data is scoped to the owning teacher.
  • Security incidents. If we become aware of a breach affecting student data, we will notify affected schools and teachers without undue delay so they can inform parents as required.

Contact

Questions about privacy, or a request to export or delete data? Email help@instructorweb.com.

This notice describes current practice and may be updated from time to time. See also our Terms of Use & Teacher Agreement.