1 How participation works
Each school receives submission links from us. Teachers and administrators share those links with students using the school’s own communication systems (school email, LMS, classroom display). We do not receive, request, or store student contact information; distribution stays entirely within the school.
There are two ways students participate:
1. Student word submissions
During a school event, students open the school’s link and submit two words describing the America they want, plus the four background questions. No name, no email, no account, no login. School-wide links are active only during a short window set by the school for the event.
2. Community interviews
Students interview adults in their community (never other minors) and record the adult’s two words plus the same four background questions about the adult being interviewed. We do not collect the interviewee’s name or contact information, and we do not collect the identity of the student conducting the interview. Interview links are issued per classroom section, so a teacher can see how many interviews the class has completed without any submission being tied to a particular student.
2 Exactly what is collected
Provided on the form
- Two words
- Birth year (required)
- Gender (required)
- Race / ethnicity (required)
- Home ZIP code (required)
Derived or generated by us
- Town/city, state, US region, and community type (urban, suburban, rural). These are looked up from the ZIP code, not typed by the respondent.
- The school, and for community interviews the classroom section, that the link belongs to
- Submission timestamp
- An internal submission identifier
- Moderation status, any spelling refinement made by school staff, and a possible-duplicate flag
- A platform-administrator-only moderation log containing the two words, their moderation result, school/section context, and timestamp. Rejected attempts are logged even when no survey response is stored.
- Whether a school administrator approved the school’s aggregate word cloud for public sharing, who approved it, and when
Technical data
- The request IP address is used in memory to rate-limit submissions and block spam. It is not written to the submission record.
- After a school-wide submission, a signed browser cookie records that this browser already submitted during that window, so the form is not filled in twice. It expires after 30 days and holds no identifier, only a marker that a submission happened.
We list these because persistent identifiers such as cookies and IP addresses can themselves be personal information. See the FTC’s COPPA guidance.
There is no form field for
- Names
- Email addresses
- Phone numbers
- Student ID numbers
- Street addresses
- Exact dates of birth
- Photos
- Audio or video
3 The exact student form
This is every field a student sees, rendered from the same source as the live form. It is shown here read-only and cannot be submitted.
Show the exact student form
Must be one word only (hyphens allowed). Do not enter a person's name.
Must be one word only (hyphens allowed). Do not enter a person's name.
Must be 5-digit US ZIP code
Auto-populated from ZIP code
Auto-populated from ZIP code
Auto-populated from ZIP code
Auto-populated from ZIP code
Preview only. Every field is disabled and there is no submit button.
4 Content review
Submitted words pass through moderation before they can be displayed. Known inappropriate words are rejected automatically; ordinary dictionary words are accepted automatically; anything else is held for a person at the school to review. Platform administrators can see a live moderation log of all submitted word pairs, including rejected attempts. That review means individual submitted words are read by school staff and by us.
The moderation log does not contain demographics, account identity, IP addresses, cookies, or browser fingerprints.
A school-specific word cloud remains private until its school administrator reviews the complete word inventory and explicitly approves it. Approval creates an unlisted public share link containing aggregate words and frequencies only, with no demographic filters. Any later change to the cloud automatically disables that link until the administrator reviews and approves the new version.
Students are told on the form not to enter anyone’s name. If a word identifies a person, it can be removed from every display. See section 6.
5 How background data is reported
Birth year, gender, race/ethnicity, and location are analysed and displayed as group totals, never as individual profiles. Two rules apply to every chart, dashboard, and map on the platform:
- A selection covering fewer than 10 responses displays no results at all.
- Within a chart, if any group has fewer than 5 responses, the whole chart is withheld rather than shown with a small group visible.
On top of that, the live displays that a school can open on a projector or share by link never show exact birth year, exact ZIP code, or town. Birth year is grouped into age ranges, and location stops at the state.
These thresholds substantially reduce the risk that a response can be traced to a person. They are a safeguard, not a guarantee, and we describe them so schools can judge them for themselves.
6 Retention, deletion, and removal
Submissions belong to the school. We keep them for as long as the school uses the platform, so that a school can compare events over time, and we delete them:
- On request, within 60 days. A school administrator or district officer emails us; we delete the school’s submissions, or a specific event window, and confirm in writing with the date the last backup containing them expires.
- When the school’s agreement ends, within 60 days, unless the district asks us to transfer the data instead.
After deletion we may keep word counts only, with no demographic breakdown and no school name, for the national word cloud. That is de-identified data; it cannot be traced back to a school, let alone a student.
Removing a single submission. If a school believes a specific submission should be removed, for example a word that identifies a person, administrators can flag it and we will remove it from all displays. Because submissions carry no student identifier, a school will usually need to identify the submission by its words and approximate time.
Application logs are kept for 30 days and error reports for 90 days; neither contains survey responses. Database backups rotate within 30 days. Staff accounts are removed on request or within 12 months of the agreement ending.
7 Teacher and administrator accounts
Staff accounts are the only accounts on the platform. They store a name and a school email address, and are used to manage schools, sections, and word review.
The platform has no password sign-in. Our own team signs in with Google. Teachers and school administrators sign in with a single-use code sent to their school email address, which expires after a few minutes. There is no password to guess, reuse, or steal.
Adult account holders may request deletion of their account at any time.
8 Where data lives and who processes it
All data is stored in the United States. The services below receive some part of it in order to run the platform. Each is bound by a data processing agreement with us, is prohibited from selling the data, and receives only what is listed.
| Service | Purpose | What it receives |
|---|---|---|
| Render | Application hosting and database | All submission records and staff accounts, encrypted at rest and in transit |
| Cloudflare | File storage | School logos only. No student data |
| Sentry | Error monitoring | Error reports with survey responses, email addresses, IP addresses, and cookies removed before sending |
| Zippopotam.us | ZIP code to town lookup | A ZIP code, and nothing else, when it is not already in our cache. Sent from our server, not the student’s browser |
| Resend | Staff sign-in codes and invitations. Students receive no email | |
| Sign-in for our own team; web fonts | Our staff’s Google identity. Fonts are fetched by the browser and carry no application data |
We add a row here, and notify schools under agreement, before any new service receives student data.
9 Security
- All traffic is encrypted in transit (TLS) and the database is encrypted at rest.
- Access to production data is limited to one named engineer. School staff see only their own school; teachers see only their own sections. Sign-in is described in section 7.
- Survey responses are never written to request logs or error reports.
- Submission links accept traffic only during the window a school opens, and are rate-limited to block spam.
- Our security program follows the CIS Critical Security Controls. We complete a written security self-assessment annually and after any incident, and share it with schools on request.
- We maintain a written breach response plan. If student data is ever accessed without authorization, we notify affected schools within 72 hours of confirming it, with what happened, what data was involved, and what we are doing about it.
10 Agreements and regulations
We have designed the platform to meet the requirements of the Student Data Privacy Consortium’s National Data Privacy Agreement (NDPA), the standard agreement most districts already use with their vendors, and we sign it with your state’s exhibit rather than asking districts to review custom paper. If we have already signed with a district in your state, the agreement is posted on the SDPC registry with a general offer of terms, and your district can adopt it with a one-page exhibit. If not, send your district’s version to privacy@theamericaiwantis.org and we will sign it.
How this maps to the rules schools are held to
- FERPA
- We operate under the school-official exception: under the district’s direct control, for a legitimate educational purpose, using data only as the district directs. We treat the four background questions as indirect identifiers, as the Department of Education’s definition requires (see the note on wording above), rather than arguing they fall outside the law.
- COPPA
- Students under 13 may participate only through a school. We collect no more than the program needs, we use it for no other purpose, and the school’s authorization stands in for parental consent under the FTC’s guidance for educational use. Parents can ask the school to have a submission removed at any time.
- State student privacy laws
- Most states prohibit vendors from targeted advertising, profiling, and selling student data, and require reasonable security and deletion on request. Those are the commitments in the NDPA and on this page, and they apply to every school regardless of state.
Laws differ by state and we are not your district’s counsel. This section is meant to let your privacy officer check our practices against your obligations quickly; the signed agreement is what binds us.