Data Processing Agreement

Last Updated: September 19, 2026

Who This Is For

Several states (including Illinois, California, New York, and others) require a signed DPA between a school or district and any vendor handling student data before that data can be lawfully shared. If you are an independent educator, homeschool user, or tutor rather than a school/district employee, you generally do not need a DPA; the protections in our Privacy Policy apply to your invited learners regardless. This page describes our actual practices in the categories a DPA typically covers; see Section 8 to request a signed one.

1. What Student Data PushPad Collects

A learner account is created only when an educator sends an invitation and it is accepted. PushPad does not support self-registration. For each learner account, PushPad collects and stores:

  • A username and display name chosen at invite acceptance
  • A hashed 6-digit PIN used for sign-in (no plaintext password or real email address)
  • A system-generated internal identifier used only for authentication, not a reachable email address
  • Assignment, attempt, score, and progress data tied to lesson pads the educator assigns

PushPad does not require or collect a learner's home address, phone number, government ID, Social Security number, or precise geolocation. Full detail is in our Privacy Policy.

2. Purpose Limitation: No Marketing, No Ad Profiles, No Model Training

Student data is used only to operate the assigned educational service: delivering lesson pads, computing scores and progress, and supporting the inviting educator's view of that progress. PushPad does not use student data to build advertising or marketing profiles, does not use student data for targeted advertising, and does not use student data to train PushPad's own AI models. Learner submissions sent to Anthropic for grading contain only the answer text and grading rubric, never a learner's name or account identifier.

3. Data Ownership And Educator Control

Every learner roster row, assignment, and attempt is scoped to the inviting educator's account at the database level: an educator can only read or modify learners and curriculum they created or were invited by them. PushPad does not share a learner's data with any other educator or with the public. A lesson pad an educator publishes to the marketplace uses a separate, frozen content snapshot and never includes learner data.

4. Data Deletion

When an educator removes a learner from their roster, PushPad disables the learner's ability to sign in immediately and begins a 30-day process before the account and its data are permanently deleted, during which the educator can reverse the removal. An educator can also request immediate permanent deletion instead of waiting out the 30-day period. Payment records (unrelated to learner data) are retained for 7 years for tax and legal compliance, consistent with standard requirements.

5. Data Security

  • Encryption in transit (HTTPS/TLS) and at rest
  • Learner PINs and educator passwords are hashed, never stored in plaintext
  • Database access is scoped per-educator through row-level security, not just application-layer checks
  • Payment processing is handled by Stripe under PCI DSS compliance; PushPad never stores full card numbers

6. Subprocessors

PushPad uses the following subprocessors, each under its own data processing terms. None of these services receive a learner's name or account identifier alongside their submitted work:

  • Supabase: database, authentication, and file storage
  • Anthropic: lesson pad generation and grading (answer text + rubric only)
  • OpenAI: course outline generation assistance for educators
  • Stripe: payment processing (subscription and marketplace transactions)
  • Vercel: application hosting

7. Breach Notification

In the event of a security incident involving student data, PushPad will notify affected school/district contacts without unreasonable delay. The exact notification timeline (commonly 48–72 hours in state student-privacy laws) is set in the executed DPA rather than this page, since it is a binding commitment that should be reviewed by both parties' counsel.

8. Requesting A Signed DPA

To request a Data Processing Agreement for your school or district, email support@pushpad.com with your district name and the name of the educator(s) using PushPad. We will provide a DPA reflecting the practices described on this page for review by your district's legal counsel before signature.