Full privacy evaluation | See all
Thumbnail
Updated August 3, 2018

Schoolzilla

  • Privacy policies do indicate a version or effective date.
  • Data are not sold or rented to third parties.
  • Data are not shared for advertising or marketing.
  • Behavioral or contextual advertising is not displayed.
  • Unclear whether this product allows data collection by third-party advertising or tracking services.
  • Unclear whether this product uses data to track and target advertisements on other third-party websites or services.
  • Third parties cannot use data to create ad profiles, data enhancement, and/or targeted advertisements.
The criteria for "Use with Caution" are narrowly focused around data uses related to creating profiles that aren't related to any educational purpose, and using data to target ads. We include both first party (ie, the vendor that builds the service) and third party (any company given access by the vendor) data use. It's worth highlighting that using data to profile students violates multiple state laws, and in some cases also violates federal law.

A service can be designated "Use with Caution" for either a lack of transparency around data use -- which creates the potential for profiling and behavioral targeting -- or for clearly stating that they use data to target advertisements and/or create profiles. As with any application being considered for use within schools, school and/or district staff should review the privacy policies and terms of service to ensure that they meet the legal and practical requirements of their state laws and school policies.

As with the "Not Recommended" criteria, a "Use with Caution" designation is NOT a sign that a vendor is necessarily doing anything unethical or illegal. It is a sign that, based on publicly available policies,  we do not have adequate guarantees that data will not be used by first or third parties to create non-educational profiles or to target behavioral ads.
Use with Caution
Full evaluation
41
Overall Scoreinfo-bubble

This overall score represents how the service addressed all our evaluation questions. A higher score (up to 100) means the service provides more transparent and comprehensive policies.

Overview

Schoolzilla integrates a school's data with their online platform of tools to help visualize students' information and provide data analytics. Schoolzilla specifies in their terms that they are a Public Benefit Corporation. The terms of Schoolzilla state they provide Services to schools and educators to better evaluate and visualize student data. Schoolzilla's terms state they collect personal information and performance data about a student, school, and district they are affiliated with for the purposes of data analytics. Schoolzilla's terms state they take security seriously and provide security methods such as two-factor authentication, data encryption, management of strong passwords and encourages developers to peer-review its code to ensure best practices for security as used. Lastly, the terms state a school user designates Schoolzilla (including its employees, contractors, and agents) as a “school official” under FERPA and parental consent for users should be obtained by the School.

Schoolzilla can be accessed through its website. The Privacy Policy and Terms of Use accessed for this evaluation can be found on Schoolzilla’s website. This evaluation only considers policies that have been made publicly available prior to an individual using the application or service.

Read the Common Sense standard privacy report (SPR)arrow
The standard privacy report (SPR) displays the most important privacy practices from a product’s polices in a single easy-to-read outline. The report displays an alert when a particular privacy practice is risky, unclear, or not evaluated. This alert indicates more time should be focused on these particular details prior to use.
SafetyPromoting responsible use
arrow
Evaluating safety takes into consideration best practices that protect a user's physical and emotional health. A higher score (up to 100) means the service provides more transparent and comprehensive responses related to safety.
0

The terms of Schoolzilla state they provide services to schools and educators to better evaluate and visualize student data. The policies specify that students do not currently have logins into the service, but the policies do not disclose any information about whether users's information can be made publicly visible or whether they can interact with other users, or students can interact with other students in the same classroom, or school?

PrivacyProtecting collected information
arrow
Evaluating privacy takes into consideration best practices that protect the disclosure of a user's personal information. A higher score (up to 100) means the service provides more transparent and comprehensive responses related to privacy.
39

The terms of Schoolzilla state they collect personal information and performance data about a student, school, and district they are affiliated with for the purposes of data analytics. Schoolzilla's terms state they will only share data with third parties that has been de-identified and includes aggregated data that does not identify a user, school, students, or other staff. In addition, Schoolzilla's terms state they do not use any data collected from a user for targeted advertisements. The terms further specify that Schoolzilla has developed and follows an incident response plan that includes notification in the event of security issues.

SecurityProtecting against unauthorized access
arrow
Evaluating security takes into consideration best practices that protect the integrity and confidentiality of a user's data. A higher score (up to 100) means the service provides more transparent and comprehensive responses related to security.
84

Schoolzilla's terms state they take security seriously and provide security methods such as two-factor authentication, data encryption, management of strong passwords and encourages developers to peer-review its code to ensure best practices for security as used. In addition, Schoolzilla's terms state they use security administrators who are knowledgeable about security practices and continually monitor security resources for advisories and vulnerabilities to ensure student information remains secure.

ComplianceFollowing statutory laws and regulations
arrow
Evaluating compliance takes into consideration best practices of companies that collect personal information from children or students and the legal obligations for the privacy and security of that information. A higher score (up to 100) means the service provides more transparent and comprehensive responses related to compliance.
34

The terms state a school user designates Schoolzilla (including its employees, contractors, and agents) as a "school official" under FERPA and parental consent for users should be obtained by the School. Schoolzilla's terms state it has a "legitimate educational interest" in using and accessing a user’s Educational Records and provides training to its employees on the importance of methods to protect pupil records and remaining in compliance with FERPA. In addition, any request sent to Schoolzilla by a student or parent to modify or delete a user’s information will be directed back to the school or educator.

About Privacy Evaluations

The privacy evaluations have been designed with the help and support of a consortium of schools and districts across the United States. These evaluations are designed to streamline making an informed decision about the potential privacy implications of educational technology used to support teaching and learning.

Our core evaluation criteria are freely available and will remain freely available. People are encouraged to read the questions we use and the information security primer we released. Vendors are encouraged to use our questions and the information security primer to self-evaluate. You can also learn more about our evaluation process.

Please be in touch with any questions or feedback.