Hi again,
Day two of back-to-school PD. You've created three new logins before lunch. A QR code goes up on the screen, everybody scans it, and somewhere around slide four — in a font size that suggests total confidence — it says "FERPA-compliant!"
And here's the quiet truth about that room: nobody in it knows what happens to the words you type into that box. Not you. Probably not the presenter. Maybe not even the rep who made the slide.
I sat through that meeting too. And for a long time my options felt like the same two everyone has: trust the slide, or quietly never use the thing. Neither one felt right.
There's a third option. Ten minutes gets you three or four questions, quoted from the vendor's own document, that you can ask in one hallway conversation with your tech coordinator. And you already have the tool for it.
The fine print nobody reads
Every one of these products has a public privacy policy or terms of service, usually a link in tiny type at the bottom of their website. It's the document where the company puts in writing what they actually do with the text users type in. It's also four thousand words of legal prose, written by lawyers for lawyers, so nobody reads it.
But you have a robot that reads four thousand words in two seconds. So flip it: paste the tool's own fine print into the AI you already use, and make it answer three plain questions.
First, the safety beat — with a twist this time
You know the rule by now: never put student data into AI. Ever. Here's the nice part about this week's habit: a privacy policy is public text on a public website. It has zero student information in it. It is maybe the single safest thing you will ever paste.
The rule shows up somewhere else instead: while you're still deciding about a new tool, never test it with anything real. Not a real goal. Not a real parent email. If you want to poke at it, feed it something invented: a made-up 4th grader with a made-up fluency need. The tool earns real work only after you've read its fine print and your district has said yes.
Three questions, one prompt
You're asking the AI to do the reading, not the deciding. Three things you want out of any tool's policy:
1. What happens to what I type in? Where does it go, how long is it kept? 2. Do they train on it or share it? Does user text feed their models or go to third parties? 3. What should I ask my district before I trust it? The gaps and gray areas, turned into questions for the person whose actual job this is.
Here's the prompt. Grab the policy text off the tool's website first (select all, copy; it's public). One tip: if the site has a separate education, student-privacy, or DPA page, that's the one you want. The generic policy is often written for their marketing site.
You're helping me, a special education teacher, understand a tool's fine print. Here is the public privacy policy / terms of service from an ed-tech AI tool: [paste the policy text — nothing about your students, ever]. In plain language: (1) What does this tool say it does with the text users type in? (2) Does it say anything about training on user data, retention, or sharing with third parties? (3) List the questions I should ask my district's tech coordinator before using it for anything school-related. Quote the exact lines you're basing each answer on, and say "the policy doesn't address this" where it doesn't. Don't guess.
That last line matters. You want quoted lines so you can check them against the real document. The AI's read is a first draft, same as always, and you're the professional who verifies it. And you want "the policy doesn't address this" said out loud, because silence in a policy is information too.
What you do with the answers
Not a verdict. You don't get to declare a tool safe, and neither do I. I'm a special-education teacher, same as you, not anybody's lawyer. What you walk away with is better: a short list of informed questions for your district's tech coordinator, quoted straight from the vendor's own document.
Your district makes the call. That's the process working. They sign the contracts and they carry the responsibility. Your job is to show up asking better questions than the slide answered. Ten minutes gets you there.
A vendor slide says what they want you to hear. The privacy policy says what they were willing to put in writing. Read the second one.
The part nobody tells you
The most valuable line in the AI's whole answer is usually "the policy doesn't address this." The gaps are the goods. A policy that never mentions training on user data hands you the right question to ask — and "your policy doesn't say whether teacher input trains the model; do we know?" is exactly the kind of thing a tech coordinator can run down. Once you've read one policy this way, the "trust us" slide stops working on you. Ten minutes, and you walk into the next PD with the question instead of the knot in your stomach.
Try it this week
Pick one tool from this fall's PD lineup — whichever one you were already side-eyeing. Find its privacy policy (website footer, tiny link), run the prompt, and jot the three or four questions that come back. Next time you pass the tech coordinator, ask one.
Then hit reply and tell me what your district rolled out this fall, and the one question about it nobody in the room could answer. I'm building future issues from what you send.
Talk soon,
Shaun
P.S. — Somebody sat next to you in that PD session wondering the same thing. Forward them this one.
A quick but important note: this newsletter is for general educational and informational purposes only. I'm a special education teacher sharing time-saving ideas. The views here are my own and don't represent any school district or employer. I'm not a lawyer, and nothing here is legal, compliance, or professional advice. Always follow your district's and state's policies, especially on AI use and student privacy, and check with the right person in your district before acting on anything significant. You are the professional: review and finalize everything yourself. And never put student names or identifying details into any AI tool.