The America I Want · Student Data Privacy

Student privacy is built into every submission.

We do not ask students for direct identifiers: no names, email addresses, student IDs, contact information, accounts, logins, or roster transfers.

A student submission is two words plus four required background questions: birth year, gender, race/ethnicity, and home ZIP code. It is associated with a school’s submission link, not with a student account. There is no student account to associate it with.

Effective September 9, 2026

01

No student accounts

Students never create an account or log in. The platform has no student login and stores no student names or email addresses.

02

No roster transfer

Schools share submission links through their own systems. We do not receive, request, or store student rosters, directory information, or contact details.

03

Background data reported in groups

The four background questions are used for group analysis. Displays withhold any group smaller than the thresholds in section 5.

A note on wording

We say direct identifiers rather than “personal information” because the two are not the same. Under the U.S. Department of Education’s definition of personally identifiable information, indirect identifiers also count, as do combinations of information that could allow someone to identify a student with reasonable certainty. Birth year, ZIP code, gender, and race/ethnicity are indirect identifiers. We collect them, we say so below, and section 5 describes what we do to keep them from being combined into an identification.

1 How participation works

Each school receives submission links from us. Teachers and administrators share those links with students using the school’s own communication systems (school email, LMS, classroom display). We do not receive, request, or store student contact information; distribution stays entirely within the school.

There are two ways students participate:

1. Student word submissions

During a school event, students open the school’s link and submit two words describing the America they want, plus the four background questions. No name, no email, no account, no login. School-wide links are active only during a short window set by the school for the event.

2. Community interviews

Students interview adults in their community (never other minors) and record the adult’s two words plus the same four background questions about the adult being interviewed. We do not collect the interviewee’s name or contact information, and we do not collect the identity of the student conducting the interview. Interview links are issued per classroom section, so a teacher can see how many interviews the class has completed without any submission being tied to a particular student.

2 Exactly what is collected

Provided on the form

  • Two words
  • Birth year (required)
  • Gender (required)
  • Race / ethnicity (required)
  • Home ZIP code (required)

Derived or generated by us

  • Town/city, state, US region, and community type (urban, suburban, rural). These are looked up from the ZIP code, not typed by the respondent.
  • The school, and for community interviews the classroom section, that the link belongs to
  • Submission timestamp
  • An internal submission identifier
  • Moderation status, any spelling refinement made by school staff, and a possible-duplicate flag
  • A platform-administrator-only moderation log containing the two words, their moderation result, school/section context, and timestamp. Rejected attempts are logged even when no survey response is stored.
  • Whether a school administrator approved the school’s aggregate word cloud for public sharing, who approved it, and when

Technical data

  • The request IP address is used in memory to rate-limit submissions and block spam. It is not written to the submission record.
  • After a school-wide submission, a signed browser cookie records that this browser already submitted during that window, so the form is not filled in twice. It expires after 30 days and holds no identifier, only a marker that a submission happened.

We list these because persistent identifiers such as cookies and IP addresses can themselves be personal information. See the FTC’s COPPA guidance.

There is no form field for

  • Names
  • Email addresses
  • Phone numbers
  • Student ID numbers
  • Street addresses
  • Exact dates of birth
  • Photos
  • Audio or video

3 The exact student form

This is every field a student sees, rendered from the same source as the live form. It is shown here read-only and cannot be submitted.

Show the exact student form

Must be one word only (hyphens allowed). Do not enter a person's name.

Must be one word only (hyphens allowed). Do not enter a person's name.

Must be 5-digit US ZIP code

Auto-populated from ZIP code

Auto-populated from ZIP code

Auto-populated from ZIP code

Auto-populated from ZIP code

Preview only. Every field is disabled and there is no submit button.

4 Content review

Submitted words pass through moderation before they can be displayed. Known inappropriate words are rejected automatically; ordinary dictionary words are accepted automatically; anything else is held for a person at the school to review. Platform administrators can see a live moderation log of all submitted word pairs, including rejected attempts. That review means individual submitted words are read by school staff and by us.

The moderation log does not contain demographics, account identity, IP addresses, cookies, or browser fingerprints.

A school-specific word cloud remains private until its school administrator reviews the complete word inventory and explicitly approves it. Approval creates an unlisted public share link containing aggregate words and frequencies only, with no demographic filters. Any later change to the cloud automatically disables that link until the administrator reviews and approves the new version.

Students are told on the form not to enter anyone’s name. If a word identifies a person, it can be removed from every display. See section 6.

5 How background data is reported

Birth year, gender, race/ethnicity, and location are analysed and displayed as group totals, never as individual profiles. Two rules apply to every chart, dashboard, and map on the platform:

  • A selection covering fewer than 10 responses displays no results at all.
  • Within a chart, if any group has fewer than 5 responses, the whole chart is withheld rather than shown with a small group visible.

On top of that, the live displays that a school can open on a projector or share by link never show exact birth year, exact ZIP code, or town. Birth year is grouped into age ranges, and location stops at the state.

These thresholds substantially reduce the risk that a response can be traced to a person. They are a safeguard, not a guarantee, and we describe them so schools can judge them for themselves.

6 Retention, deletion, and removal

Submissions belong to the school. We keep them for as long as the school uses the platform, so that a school can compare events over time, and we delete them:

  • On request, within 60 days. A school administrator or district officer emails us; we delete the school’s submissions, or a specific event window, and confirm in writing with the date the last backup containing them expires.
  • When the school’s agreement ends, within 60 days, unless the district asks us to transfer the data instead.

After deletion we may keep word counts only, with no demographic breakdown and no school name, for the national word cloud. That is de-identified data; it cannot be traced back to a school, let alone a student.

Removing a single submission. If a school believes a specific submission should be removed, for example a word that identifies a person, administrators can flag it and we will remove it from all displays. Because submissions carry no student identifier, a school will usually need to identify the submission by its words and approximate time.

Application logs are kept for 30 days and error reports for 90 days; neither contains survey responses. Database backups rotate within 30 days. Staff accounts are removed on request or within 12 months of the agreement ending.

7 Teacher and administrator accounts

Staff accounts are the only accounts on the platform. They store a name and a school email address, and are used to manage schools, sections, and word review.

The platform has no password sign-in. Our own team signs in with Google. Teachers and school administrators sign in with a single-use code sent to their school email address, which expires after a few minutes. There is no password to guess, reuse, or steal.

Adult account holders may request deletion of their account at any time.

8 Where data lives and who processes it

All data is stored in the United States. The services below receive some part of it in order to run the platform. Each is bound by a data processing agreement with us, is prohibited from selling the data, and receives only what is listed.

Service Purpose What it receives
Render Application hosting and database All submission records and staff accounts, encrypted at rest and in transit
Cloudflare File storage School logos only. No student data
Sentry Error monitoring Error reports with survey responses, email addresses, IP addresses, and cookies removed before sending
Zippopotam.us ZIP code to town lookup A ZIP code, and nothing else, when it is not already in our cache. Sent from our server, not the student’s browser
Resend Email Staff sign-in codes and invitations. Students receive no email
Google Sign-in for our own team; web fonts Our staff’s Google identity. Fonts are fetched by the browser and carry no application data

We add a row here, and notify schools under agreement, before any new service receives student data.

9 Security

  • All traffic is encrypted in transit (TLS) and the database is encrypted at rest.
  • Access to production data is limited to one named engineer. School staff see only their own school; teachers see only their own sections. Sign-in is described in section 7.
  • Survey responses are never written to request logs or error reports.
  • Submission links accept traffic only during the window a school opens, and are rate-limited to block spam.
  • Our security program follows the CIS Critical Security Controls. We complete a written security self-assessment annually and after any incident, and share it with schools on request.
  • We maintain a written breach response plan. If student data is ever accessed without authorization, we notify affected schools within 72 hours of confirming it, with what happened, what data was involved, and what we are doing about it.

10 Agreements and regulations

We have designed the platform to meet the requirements of the Student Data Privacy Consortium’s National Data Privacy Agreement (NDPA), the standard agreement most districts already use with their vendors, and we sign it with your state’s exhibit rather than asking districts to review custom paper. If we have already signed with a district in your state, the agreement is posted on the SDPC registry with a general offer of terms, and your district can adopt it with a one-page exhibit. If not, send your district’s version to privacy@theamericaiwantis.org and we will sign it.

What that means in practice, agreement or not: student data is and remains the district’s property; we act as a school official under the district’s direct control; we respond to access, correction, and copy requests within 30 days (parent requests go through the district); data is used only to run the program for your school, with no advertising, profiling, commercial use, sale, or disclosure beyond what the district allows; we never attempt to re-identify de-identified data, and do not name a school in anything we publish without its written approval; deletion within 60 days and breach notice within 72 hours as described above; and every service in section 8 is bound to terms at least as protective.

How this maps to the rules schools are held to

FERPA
We operate under the school-official exception: under the district’s direct control, for a legitimate educational purpose, using data only as the district directs. We treat the four background questions as indirect identifiers, as the Department of Education’s definition requires (see the note on wording above), rather than arguing they fall outside the law.
COPPA
Students under 13 may participate only through a school. We collect no more than the program needs, we use it for no other purpose, and the school’s authorization stands in for parental consent under the FTC’s guidance for educational use. Parents can ask the school to have a submission removed at any time.
State student privacy laws
Most states prohibit vendors from targeted advertising, profiling, and selling student data, and require reasonable security and deletion on request. Those are the commitments in the NDPA and on this page, and they apply to every school regardless of state.

Laws differ by state and we are not your district’s counsel. This section is meant to let your privacy officer check our practices against your obligations quickly; the signed agreement is what binds us.