For schools and districts

Student Privacy & Security

Last reviewed September 30, 2026

Bookroo Classrooms is a reading program for K-12 classes. The school owns and controls its students' data, and we use it only to provide Bookroo to the school. Under FERPA we act as a school official. Under COPPA, students under 13 use Bookroo only through a class their teacher creates, with the school's consent.

Our commitments

  • We never sell student data
    Not to anyone, for any price.
  • No third-party marketing
    Student data is never shared for marketing, and we never market to students or their families.
  • No ads for students
    Students never see ads on Bookroo, targeted or otherwise: ads never load on the pages students use for class, or on any page while a student is signed in.
  • No third-party tracking
    Analytics and advertising tags never load on the pages where students sign in or work, or on any page while a student is signed in.
  • No tracking across apps or sites
    We don't follow students to other websites or apps, and we don't let anyone else do it through Bookroo.
  • No commercial profiling
    Reading data is used only to run Bookroo for the class. Book recommendations are part of the reading program, not advertising.

Student data we collect

CategoryWhat
NameFirst name and last name or initial, as the teacher or roster provides it
Sign-inClass code, a short class passcode, a roster ID from Clever or Google, and a one-way hash of the school email (never the email itself)
EnrollmentClass, grade level, teacher and school
ReadingBooks read, pages, minutes, dates, reading level and teacher notes
QuizzesAnswers, scores, points, badges and challenge progress
Student writingQuiz questions and reviews a student chooses to write about a book
TechnicalIP address, browser and device type, and error reports keyed to a numeric ID

We don't collect a student's email address, home address, phone number, date of birth, photos, voice, location, or demographic, health, disability, discipline or attendance information.

A class's sign-in page lists its students by first name and last initial so they can pick themselves. It opens with the class link, the class code or the teacher's email, and each student then enters their own passcode.

Who receives student data

Only these service providers, and only what they need to run Bookroo. We share student data with no one else unless the school directs us to or the law requires it.

ProviderWhat it doesWhat it receives
DigitalOceanApplication servers and databaseAll student data, encrypted in transit and at rest
Amazon Web ServicesDatabase backupsEncrypted copies of the database
VercelWebsite hostingPage requests, including names shown on screen
CloudflareNetwork security and audio storageRequests passing through, and audio of quiz questions
AppSignalServer error monitoringNumeric IDs and request details, with passwords, passcodes, tokens and emails filtered out
SentryWebsite error reportingNumeric IDs and error details
OpenAIScreens student-written quiz questions for inappropriate contentThe question text only, never a name or ID
ElevenLabsReads quiz questions aloudQuiz question text only, never a name or ID
CleverRostering and sign-in, when the school uses itSign-in requests; we receive the roster from Clever
GoogleGoogle Classroom rostering and sign-in, when the school uses itSign-in requests; we receive the roster from Google

Stripe (payments), Loops (email) and Zendesk (support) receive teacher information only, never student data.

How long we keep it

A teacher removes a studentThe seat is deleted at once; the student's remaining records go in our weekly cleanup, unless they're in another class
A teacher deletes a classThe teacher can restore it for 30 days. Then the class and its students' records are permanently deleted
A class goes unused for 12 monthsWe email the teacher. If it's still unused 30 days later, the class is deleted as above
A school asks us to delete its dataDeleted within 30 days of a written request to schools@bookroo.com

Teachers can view, edit and delete their students' data at any time. Parents who want to review or delete a student's data should contact the school, and we'll help the school respond.

Security

  • Every connection is encrypted with TLS, including the one to our database.
  • Sign-in cookies are sent only over HTTPS and carry an ID, never a student's name.
  • Student sign-ins and passcode guesses are rate limited, per student and per class.
  • Teacher passwords are hashed with Argon2, and database backups are encrypted.
  • Staff access to student data is limited to those who need it, and every staff sign-in as another user is logged.
  • If student data is ever breached, we notify the affected schools within 72 hours.

Agreements and documents

  • Data privacy agreement (SDPC National Data Privacy Agreement or your state's standard DPA)
    We'll sign it. Send it to schools@bookroo.com.
  • Security questionnaire (CoSN K-12CVAT)
    Not published yet. We'll answer your district's questionnaire.
  • Accessibility conformance report (VPAT)
    Not published yet.

Contact

Questions, agreements and data requests: schools@bookroo.com. Our full privacy policy has the legal detail.

Bookroo (Vermilion Labs LLC), 971 S University Dr #1020, Provo, UT 84601