FERPA Information
Last Updated: March 2026
Effective Date: March 2026
What is FERPA?
The Family Educational Rights and Privacy Act (FERPA) is a United States federal law that protects the privacy of student educational records. FERPA applies to institutions that receive federal funding, and it requires that vendors and service providers handle student educational records according to FERPA guidelines.
Under FERPA, educational records include any records, files, documents, or other materials that contain information directly related to a student and are maintained by an educational institution or a party acting on its behalf.
FlowSpace is designed to support FERPA compliance and is built with FERPA guidelines in mind when handling educational records on behalf of students and institutions.
What Data FlowSpace Handles
FlowSpace stores and processes the following categories of student data that may constitute educational records under FERPA:
Academic Work Data
- What: Assignment titles, deadlines, task breakdowns, and completion status
- Storage: AWS DynamoDB (US-based, encrypted at rest, access-controlled)
AI Tutoring Data
- What: Problem or question text you submit to the AI tutor, and your tutor conversation history
- AI Processing: Problem text is sent to Google Gemini API for AI inference (cloud-based processing by Google LLC)
- Conversation Storage: Tutor conversation history is stored in AWS DynamoDB
Identity and Authentication
- What: University name (student-provided), Google account name and email address
- Storage: AWS DynamoDB (university name); AWS Cognito (authentication tokens stored in OS keychain)
Learning Progress Data
- What: Work sessions, concept mastery levels, and daily planning records
- Storage: AWS DynamoDB (US-based, encrypted at rest)
Session Analytics (Professor-Linked Courses)
- What: Anonymized session metadata collected only when you are enrolled in a professor's course inside FlowSpace
- Storage: Anonymized data stored in AWS S3
- Scope: Only collected when you actively connect to a professor's course
FERPA-Safe Design
FlowSpace is built with FERPA guidelines in mind across all data handling practices:
- Encrypted storage: Educational records stored in AWS DynamoDB (US-based, encrypted at rest, access-controlled via AWS IAM)
- Encrypted transit: All data transmitted between the app and our servers uses TLS/HTTPS
- Secure authentication: Auth tokens stored in your OS secure keychain (keytar), never in plaintext
- No evaluative sharing: FlowSpace does not share student educational records with institutions or professors without student consent, except as described under Institutional Data Sharing below
- Student control: Students can delete all data at any time from Settings > Account > Delete Account
- Minimal data collection: We collect only what is necessary to provide the service; anonymous usage analytics cannot be linked to individual students
Institutional Data Sharing
FlowSpace does not sell or share student educational records with institutions.
Session analytics (limited exception): If a student enrolls in a professor's course inside FlowSpace, anonymized session analytics may be shared with that professor's institutional dashboard. This data is anonymized before sharing and is used only for aggregate course-level insights — it cannot be used to identify individual students or evaluate their performance. Students are informed when connecting to a professor's course.
No other institutional sharing: Assignment content, task details, concept mastery records, AI tutor conversations, and personal tasks are never shared with institutions or professors.
If university integration features are added in the future that involve sharing identifiable educational records with institutions, explicit student consent will be required before any such sharing occurs.
Third-Party AI Processing Disclosure
When you use AI tutoring features, the problem or question text you submit is sent to Google Gemini API (provided by Google LLC) for cloud-based processing. This constitutes a disclosure to a third party under FERPA's "school official" exception, where the disclosure is necessary to fulfill an educational purpose (AI tutoring) that you have actively initiated.
FlowSpace's use of Google Gemini API is governed by Google's data processing terms. Google processes this data only to return a response to FlowSpace and is prohibited from using it for other purposes. See Google's privacy policy: https://policies.google.com/privacy
Student Rights Under FERPA
Under FERPA, students have the following rights with respect to their educational records:
Right to Inspect
You have the right to inspect and review your educational records maintained by FlowSpace. You can view all your data directly within the app, or request a full data export by contacting us.
Right to Request Corrections
You have the right to request that FlowSpace correct records you believe are inaccurate or misleading. Contact us with the specific information you believe should be corrected, and we will respond within 14 business days.
Right to Control Disclosure
You have the right to consent to disclosures of personally identifiable information from your educational records, except to the extent that FERPA authorizes disclosure without consent (such as the school official exception described above). FlowSpace will not share your identifiable educational records without your consent except as described in this page.
Right to Delete
You can delete all your data at any time from Settings > Account > Delete Account inside the app. This permanently removes all educational records FlowSpace holds about you.
How to Exercise Your FERPA Rights
To exercise any of these rights or to submit a FERPA-related request, email us at hello@myflowspace.app with "FERPA Request" in the subject line. We will respond within 14 business days.
Data Security and Storage
- Primary storage: AWS DynamoDB, US-based AWS regions, encrypted at rest
- Session analytics: AWS S3, US-based, anonymized before storage
- Authentication: AWS Cognito; tokens stored in OS keychain (never plaintext)
- Local storage: Workspace templates only (SQLite on your device)
- Access controls: AWS IAM restricts data access to authorized FlowSpace personnel only
- Audit trails: AWS CloudWatch logs access to sensitive data
Contact for FERPA Inquiries
For all FERPA-related requests, questions, or concerns:
Email: hello@myflowspace.app
Subject Line: FERPA Request
Response Time: Within 14 business days
For general privacy questions, see our Privacy Policy.
This FERPA information page is effective as of March 2026. FlowSpace is designed to support FERPA compliance and is built with FERPA guidelines in mind. This page does not constitute legal advice. Institutions with specific compliance requirements should contact us directly.