Backpack Education

Version 2026.1 · September 21, 2026

What we collect, what we never collect, and what happens when a pilot ends.

This page and the three documents below are generated from the same source, so they cannot say different things. Everything here is governed by the Illinois Student Data Privacy Agreement.

What we collect

Student identifiers
Roster identifier, first name, last initial, grade, school, and section enrollments — for sign-in on the classroom device and matching a student to their teacher's collection.
Guardian contact
Name and email address where the roster supplies one, and relationship — for the family notice, the optional weekly digest, and the guardian view of their own child.
Staff identity
Name, email, role, school, and section assignments — for single sign-on, console access, and approval routing.
Usage
Video identifier, section, start and end time, and device session identifier — for a teacher's view of what a student watched, and aggregate reporting to the school and district.

What we never collect

Commitments

No advertising
No targeted advertising to students, on any screen, ever — under the Illinois Student Data Privacy Agreement and as a matter of product design.
No profiling
No behavioral profile of a student built or used except in direct furtherance of the K–12 purposes in the schedule of data above.
No sale of data
Student data is never sold, rented, or traded. Not to anyone, not for any reason.
No model training
Student data is never used to train machine-learning models, ours or anyone else's.
Deletion on offboarding
Student data is disposed of at the earliest of the district's written direction, 60 days after a student's roster record becomes inactive, or 90 days after the end of the term (shorter on the district's election). Encrypted backups expire within 30 days after that. A signed certificate of deletion follows.
Retention the district controls
Usage records older than the district's configured retention period (default one school year) are purged nightly. The district sets this period in the district console.
Row-level tenant isolation
Every district-scoped table carries an organization identifier, enforced by PostgreSQL row-level security. An automated isolation suite runs on every deployment and attempts a cross-tenant read on each district-scoped route.
Breach notice
The district's Data Steward is notified of a breach of covered information no later than 30 calendar days after Backpack determines a breach occurred, with the information the district needs to meet its own notice obligations to families.

Subprocessors

The third parties that may receive or process covered information on our behalf. We give a district's Data Steward 30 days' written notice before adding one.

SubprocessorFunctionDataLocation
Vercel, Inc.Application hosting, edge network, scheduled jobsAll application data in transit; no persistent student data at rest beyond request logs (retained 7 days, identifiers redacted)United States
Neon, Inc.Managed PostgreSQL databaseAll data in the schedule of data, encrypted at rest (AES-256) and in transitUnited States (us-east)
Google LLC, YouTube Data APIVideo metadata lookup and privacy-enhanced playback embedVideo identifiers only. No student identity is sent. Playback uses youtube-nocookie.comUnited States
Google LLC, WorkspaceProvider's internal email and document storage for contract administrationContract documents and district contact details; no student dataUnited States
Stripe, Inc.Invoicing of district feesDistrict billing contact and purchase order; no student dataUnited States
Transactional email providerDelivery of notices, digests, and document room messagesRecipient email address and message content (guardian name, child's first name in a digest)United States

No analytics, advertising, session-recording, or AI-model training service receives covered information. Backpack's consumer product uses a separate subscription platform that is disabled at the code level for every district tenant.

Downloads

For your compliance review, dated and versioned the same as this page.