For schools and districts
Last reviewed September 30, 2026
Bookroo Classrooms is a reading program for K-12 classes. The school owns and controls its students' data, and we use it only to provide Bookroo to the school. Under FERPA we act as a school official. Under COPPA, students under 13 use Bookroo only through a class their teacher creates, with the school's consent.
| Category | What |
|---|---|
| Name | First name and last name or initial, as the teacher or roster provides it |
| Sign-in | Class code, a short class passcode, a roster ID from Clever or Google, and a one-way hash of the school email (never the email itself) |
| Enrollment | Class, grade level, teacher and school |
| Reading | Books read, pages, minutes, dates, reading level and teacher notes |
| Quizzes | Answers, scores, points, badges and challenge progress |
| Student writing | Quiz questions and reviews a student chooses to write about a book |
| Technical | IP address, browser and device type, and error reports keyed to a numeric ID |
We don't collect a student's email address, home address, phone number, date of birth, photos, voice, location, or demographic, health, disability, discipline or attendance information.
A class's sign-in page lists its students by first name and last initial so they can pick themselves. It opens with the class link, the class code or the teacher's email, and each student then enters their own passcode.
Only these service providers, and only what they need to run Bookroo. We share student data with no one else unless the school directs us to or the law requires it.
| Provider | What it does | What it receives |
|---|---|---|
| DigitalOcean | Application servers and database | All student data, encrypted in transit and at rest |
| Amazon Web Services | Database backups | Encrypted copies of the database |
| Vercel | Website hosting | Page requests, including names shown on screen |
| Cloudflare | Network security and audio storage | Requests passing through, and audio of quiz questions |
| AppSignal | Server error monitoring | Numeric IDs and request details, with passwords, passcodes, tokens and emails filtered out |
| Sentry | Website error reporting | Numeric IDs and error details |
| OpenAI | Screens student-written quiz questions for inappropriate content | The question text only, never a name or ID |
| ElevenLabs | Reads quiz questions aloud | Quiz question text only, never a name or ID |
| Clever | Rostering and sign-in, when the school uses it | Sign-in requests; we receive the roster from Clever |
| Google Classroom rostering and sign-in, when the school uses it | Sign-in requests; we receive the roster from Google |
Stripe (payments), Loops (email) and Zendesk (support) receive teacher information only, never student data.
| A teacher removes a student | The seat is deleted at once; the student's remaining records go in our weekly cleanup, unless they're in another class |
| A teacher deletes a class | The teacher can restore it for 30 days. Then the class and its students' records are permanently deleted |
| A class goes unused for 12 months | We email the teacher. If it's still unused 30 days later, the class is deleted as above |
| A school asks us to delete its data | Deleted within 30 days of a written request to schools@bookroo.com |
Teachers can view, edit and delete their students' data at any time. Parents who want to review or delete a student's data should contact the school, and we'll help the school respond.
Questions, agreements and data requests: schools@bookroo.com. Our full privacy policy has the legal detail.
Bookroo (Vermilion Labs LLC), 971 S University Dr #1020, Provo, UT 84601