COPPA School Notice
This notice describes the personal information Tolus collects from students, how we use and share it, and the rights schools and parents have. It is provided so that a school or district may, where it chooses, authorize the collection of students’ personal information on behalf of parents, relying on the school-consent pathway recognized in Federal Trade Commission guidance under the Children’s Online Privacy Protection Act (COPPA) and its Rule (16 CFR Part 312). This pathway rests on FTC guidance — including the FTC’s COPPA FAQs and its 2022 policy statement on ed tech — rather than an express provision of the Rule, which the FTC declined to codify in its 2025 amendments. Tolus collects and uses student personal information only for the school-authorized educational purpose of running oral-defense assessments, and for no other commercial purpose.
Where a school cannot or chooses not to authorize collection on parents’ behalf, Tolus must instead obtain verifiable parental consent before collecting personal information from a child under 13.
What we collect from students
From the teacher’s LMS roster — Google Classroom, or Canvas or Schoology where the school has connected one — under the teacher’s authorization:
- Student full name, email address, and LMS user ID.
- Profile photo — fetched live for display to the teacher only; not stored by Tolus.
Where a teacher connects a Gradescope (Turnitin) assignment instead of an LMS roster, the same identity fields reach Tolus from that assignment’s autograder as each student submits: the student’s Gradescope user ID, name, and email. There is no roster sync and no profile photo.
During an oral defense:
- Voice audio — streamed in real time to our speech-to-text provider for transcription; never stored by Tolus.
- The text transcript of the defense (the student’s spoken answers and the AI’s questions).
- The student’s submitted work, read to ground the defense questions.
- Where a teacher grants Tolus access to a student’s submitted file through the Google Picker, a record of that grant: the student’s LMS user ID, the file’s identifier and type, and whether it could be read. No file contents are stored in this record.
- Where a teacher connects a Gradescope assignment, the text of the files the student submitted to it (source code and text files, and the text layer of up to two PDFs), the Gradescope assignment, course, and submission identifiers, the time of the submission, and a list of the submitted file names and sizes. Tolus stores the extracted text only, never the submitted file itself.
- The mastery score and written feedback the AI produces, and any feedback the student chooses to submit.
For access and security:
- A class PIN, issued by the teacher, used by the student to start the defense.
- Limited authentication logs: a masked IP-address prefix and a device identifier.
How we use it
We use student personal information solely to operate the assessment for the school: to generate defense questions, score the spoken defense, return the score and transcript to the teacher, and post the grade back to the school’s LMS (Google Classroom, Canvas, or Schoology). Where a teacher connects a Gradescope assignment, we also show the student their defense link, and their PIN when they submitted the work alone and the teacher has left PINs on for that assignment, inside their own Gradescope results panel, and return the defense score there if the teacher turns on score release. We do not use it for any other purpose.
Who we share it with
Each subprocessor is contractually bound to handle data only to provide its service to us. Your school’s own systems are listed here too, for completeness: the LMS and, where a teacher connects a Gradescope assignment, Gradescope. Those are the school’s systems of record, which Tolus reads from and writes to on the teacher’s authorization, not vendors that process data on our behalf.
- OpenAI — generates defense questions and scores the defense; receives submission text, transcript, and rubric. Data is excluded from model training under OpenAI’s API terms.
- Deepgram — speech-to-text and text-to-speech; receives the student’s voice audio for transcription, and receives the text of the AI’s questions to synthesize the spoken voice the student hears. Audio is not stored.
- Supabase — encrypted database hosting in the United States.
- Your LMS — Google (Classroom/Drive), or Canvas (Instructure) or Schoology (PowerSchool) where the school has connected one: authentication and roster/assignment/grade data accessed and written on the teacher’s behalf. The LMS is the school’s own system of record.
- Gradescope (Turnitin) — where the teacher connects an assignment. Its autograder sends Tolus the student’s Gradescope user ID, name, email, and submitted file text; Tolus returns the defense link, the PIN when the student submitted alone, and the score if the teacher turns on score release, all written back by the teacher’s own autograder. Gradescope is the school’s own system of record, not a Tolus subprocessor, and Tolus never signs in to it.
- Vercel — application hosting. Product analytics is disabled on student defense pages.
- Resend — transactional email; receives a student’s name and any feedback the student submits, sent to the teacher’s administrator.
What we do not do
- We do not use student personal information for targeted advertising.
- We do not build profiles of students for any purpose unrelated to the assessment.
- We do not sell, rent, or trade student personal information.
- We do not use student personal information to train, create, or improve any machine-learning or AI model.
Review, deletion, and retention
- A school may review the student personal information we hold and request deletion at any time by contacting hao@tolus.dev.
- An authorized teacher may delete an individual defense. Closing a personal workspace account deletes its associated student records and removes institutional memberships; institutional records remain under the institution’s control and retention policy. Legacy accounts without separate workspaces delete their teacher-owned defenses on closure.
- We do not retain student data indefinitely: defense records are automatically deleted 18 months after creation (unless the school requests a different period), and authentication logs are deleted after 90 days.
Security
Data is encrypted in transit (TLS), and stored Google OAuth refresh tokens are encrypted at rest with AES-256-GCM. Database access is limited to a dedicated service role, with row-level security enabled on all tables containing personal data as defense-in-depth. We maintain a Written Information Security Program, available to schools on request. Our controls are designed to align with the SOC 2 Trust Services Criteria; Tolus is not yet SOC 2 audited, and a formal audit is on our roadmap.
Notice to parents
Schools relying on the school-consent pathway should make this notice available to parents. A parent may review the personal information we have collected from their child, refuse to permit further collection or use, and request deletion — by contacting their school or by emailing us at hao@tolus.dev.
Contact
Questions or requests: hao@tolus.dev.