Evaluation Concerns

Each privacy concern category is organized by the most important and easy-to-understand privacy practices in order to quickly evaluate how an application or service compares to similar products. Each privacy evaluation concern is comprised of ten evaluation questions to provide a comprehensive analysis of the most important privacy practices of a product. Depending on the type of priavcy evaluation, either all of the ten evaluation questions below are used, or only the most critical basic evaluation questions, indicated below with ("BASIC"), are used to comprise a concern score. Learn more about each evaluation concern below with each of their possible answers for "does" engage in the practice, "does not" engage in the practice, is "transparent" or "non-transparent" about the practice, and "unanswered" because we did not evaluate that particular question.

Data Collection

What data does it collect?

Evaluating data collection takes into consideration best practices of limiting the type and amount of personal information collected from a user to only the information needed to provide the application or service.

  1. (BASIC) Collect PII: Do the policies clearly indicate whether or not the vendor collects personally identifiable information (PII)?

    • Does: Personally identifiable information (PII) is collected.
    • Does Not: Personally identifiable information (PII) is not collected.
    • "Rating icon for Unclear" non-Transparent: Unclear whether the product collects personally identifiable information.
    • Unanswered: Did not evaluate whether the product collects personally identifiable information (PII).
  2. PII Categories: Do the policies clearly indicate what categories of personally identifiable information are collected by the product?

    • Transparent: The categories of collected personally identifiable information are indicated.
    • "Rating icon for Unclear" non-Transparent: Unclear whether the categories of personally identifiable information collected are indicated.
    • Unanswered: Did not evaluate whether the categories of collected personally identifiable information are indicated.
  3. (BASIC) Collection Limitation: Do the policies clearly indicate whether or not the vendor limits the collection or use of information to only data that are specifically required for the product?

    • "Rating icon for Better" Does: Collection or use of data are limited to product requirements.
    • "Rating icon for Worse" Does Not: Collection or use of data are not limited to product requirements.
    • "Rating icon for Unclear" non-Transparent: Unclear whether the collection or use of data are limited to product requirements.
    • Unanswered: Did not evaluate whether the collection or use of data are limited to product requirements.
  4. Geolocation Data: Do the policies clearly indicate whether or not precise geolocation data are collected?

    • "Rating icon for Worse" Does: Geolocation data are collected.
    • "Rating icon for Better" Does Not: Geolocation data are not collected.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product collects geolocation data.
    • Unanswered: Did not evaluate whether this product collects geolocation data.
  5. Health Data: Do the policies clearly indicate whether or not any health or biometric data are collected?

    • "Rating icon for Worse" Does: Biometric or health data are collected.
    • "Rating icon for Better" Does Not: Biometric or health data are not collected.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product collects biometric or health data.
    • Unanswered: Did not evaluate whether this product collects biometric or health data.
  6. Behavioral Data: Do the policies clearly indicate whether or not any behavioral data are collected?

    • "Rating icon for Worse" Does: Behavioral data are collected.
    • "Rating icon for Better" Does Not: Behavioral data are not collected.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product collects behavioral data.
    • Unanswered: Did not evaluate whether this product collects behavioral data.
  7. Sensitive Data: Do the policies clearly indicate whether or not sensitive personal information is collected?

    • "Rating icon for Worse" Does: Sensitive data are collected.
    • "Rating icon for Better" Does Not: Sensitive data are not collected.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product collects sensitive data.
    • Unanswered: Did not evaluate whether this product collects sensitive data.
  8. Usage Data: Do the policies clearly indicate whether or not the product automatically collects any information?

    • "Rating icon for Worse" Does: Non-personally identifiable information is collected.
    • "Rating icon for Better" Does Not: Non-personally identifiable information is not collected.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product collects non-personally identifiable information.
    • Unanswered: Did not evaluate whether this product collects non-personally identifiable information.
  9. Combination Type: Do the policies clearly indicate whether or not the vendor would treat personally identifiable information (PII) combined with non-personally identifiable information as PII?

    • "Rating icon for Better" Does: Combined information is treated as personally identifiable information (PII).
    • "Rating icon for Worse" Does Not: Combined information is not treated as personally identifiable information (PII).
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product treats combined information as personally identifiable information (PII).
    • Unanswered: Did not evaluate whether this product treats combined information as personally identifiable information (PII).
  10. Child Data: Do the policies clearly indicate whether or not the vendor collects personal information online from children under 13 years of age?

    • "Rating icon for Worse" Does: Personal information from children under 13 years of age is collected online.
    • "Rating icon for Better" Does Not: Personal information from children under 13 years of age is not collected online.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product collects personal information online from children under 13 years of age.
    • Unanswered: Did not evaluate whether this product collects personal information online from children under 13 years of age.

Data Sharing

What data does it share?

Evaluating data sharing takes into consideration best practices that protect the disclosure of a user's personal information to third parties.

  1. (BASIC) Data Shared: Do the policies clearly indicate if collected information (this includes data collected via automated tracking or usage analytics) is shared with third parties?

    • Transparent: Collected information is shared with third parties.
    • "Rating icon for Unclear" non-Transparent: Unclear whether collected information is shared with third parties.
    • Unanswered: Did not evaluate whether collected information is shared with third parties.
  2. (BASIC) Data Categories: Do the policies clearly indicate what categories of information are shared with third parties?

    • Transparent: The categories of information shared with third parties are indicated.
    • "Rating icon for Unclear" non-Transparent: Unclear whether the categories of information shared with third parties are indicated.
    • Unanswered: Did not evaluate whether the categories of information are shared with third parties are indicated.
  3. Sharing Purpose: Do the policies clearly indicate the vendor's intention or purpose for sharing a user's personal information with third parties?

    • Transparent: The purpose for sharing a user's personal information with third parties is indicated.
    • "Rating icon for Unclear" non-Transparent: Unclear whether the purpose for sharing a user's personal information with third parties is indicated.
    • Unanswered: Did not evaluate whether the purpose for sharing a user's personal information with third parties is indicated.
  4. Purpose Limitation: Do the policies clearly indicate whether or not the vendor limits the use of data collected by the product to the educational purpose for which it was collected?

    • "Rating icon for Better" Does: Use of information is limited to the purpose for which it was collected.
    • "Rating icon for Worse" Does Not: Use of information is not limited to the purpose for which it was collected.
    • "Rating icon for Unclear" non-Transparent: Unclear whether use of information is limited to the purpose for which it was collected.
    • Unanswered: Did not evaluate whether use of information is limited to the purpose for which it was collected.
  5. Third-Party Analytics: Do the policies clearly indicate whether or not collected information is shared with third parties for analytics and tracking purposes?

    • "Rating icon for Worse" Does: data are shared for analytics.
    • "Rating icon for Better" Does Not: data are not shared for analytics.
    • "Rating icon for Unclear" non-Transparent: Unclear whether data are shared for analytics.
    • Unanswered: Did not evaluate whether data are shared for analytics.
  6. Third-Party Research: Do the policies clearly indicate whether or not collected information is shared with third parties for research or product improvement purposes?

    • "Rating icon for Worse" Does: data are shared for research and/or product improvement.
    • "Rating icon for Better" Does Not: data are not shared for research and/or product improvement.
    • "Rating icon for Unclear" non-Transparent: Unclear whether data are shared for research and/or product improvement.
    • Unanswered: Did not evaluate whether data are shared for research and/or product improvement.
  7. Third-Party Providers: Do the policies clearly indicate whether or not third-party services are used to support the internal operations of the vendor's product?

    • Does: data are shared with third-party service providers.
    • Does Not: data are not shared with third-party service providers.
    • "Rating icon for Unclear" non-Transparent: Unclear whether data are shared with third-party service providers.
    • Unanswered: Did not evaluate whether data are shared with third-party service providers.
  8. Third-Party Roles: Do the policies clearly indicate the role of third-party service providers?

    • Transparent: The roles of third-party service providers are indicated.
    • "Rating icon for Unclear" non-Transparent: Unclear whether the roles of third-party service providers are indicated.
    • Unanswered: Did not evaluate whether the roles of third-party service providers are indicated.
  9. (BASIC) Social Login: Do the policies clearly indicate whether or not social or federated login is supported to use the product?

    • Does: Social or federated login is supported.
    • Does Not: Social or federated login is not supported.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product supports social or federated login.
    • Unanswered: Did not evaluate whether this product supports social or federated login.
  10. (BASIC) Third-Party Limits: Do the policies clearly indicate whether or not the vendor imposes contractual limits on how third parties can use personal information that the vendor shares or sells to them?

    • "Rating icon for Better" Does: Contractual limits are placed on third party data use.
    • "Rating icon for Worse" Does Not: Contractual limits are not placed on third party data use.
    • "Rating icon for Unclear" non-Transparent: Unclear whether contractual limits are placed on third party data use
    • Unanswered: Did not evaluate whether contractual limits are placed on third party data use.

Data Security

How does it secure data?

Evaluating data security takes into consideration best practices that protect the integrity and confidentiality of a user's data.

  1. Verify Identity: Do the policies clearly indicate whether or not the vendor or vendor-authorized third party verifies a user's identity with personal information?

    • "Rating icon for Worse" Does: A user's identity is verified with additional personal information.
    • "Rating icon for Better" Does Not: A user's identity is not verified with additional personal information.
    • "Rating icon for Unclear" non-Transparent: Unclear whether a user's identity is verified with additional personal information.
    • Unanswered: Did not evaluate whether a user's identity is verified with additional personal information.
  2. (BASIC) Account Required: Do the policies indicate whether or not the vendor requires a user to create an account with a username and password in order to use the product?

    • Does: Account creation is required.
    • Does Not: Account creation is not required.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product requires account creation.
    • Unanswered: Did not evaluate whether this product requires account creation.
  3. (BASIC) Managed Account: Do the policies clearly indicate whether or not the vendor provides user managed accounts for a parent, teacher, school or district?

    • Does: Parental controls or managed accounts are available.
    • Does Not: Parental controls or managed accounts are not available.
    • "Rating icon for Unclear" non-Transparent: Unclear whether parental controls or managed accounts are available.
    • Unanswered: Did not evaluate whether parental controls or managed accounts are available.
  4. Two-Factor Protection: Do the policies clearly indicate whether or not the security of a user's account is protected by two-factor authentication?

    • "Rating icon for Better" Does: Two-factor account protection is available.
    • "Rating icon for Worse" Does Not: Two-factor account protection is not available.
    • "Rating icon for Unclear" non-Transparent: Unclear whether two-factor account protection is available.
    • Unanswered: Did not evaluate whether two-factor account protection is available.
  5. Security Agreement: Do the policies clearly indicate whether or not a third party with access to a user's information is contractually required to provide the same level of security protections as the vendor?

    • "Rating icon for Better" Does: Third-party contractual security protections are required.
    • "Rating icon for Worse" Does Not: Third-party contractual security protections are not required.
    • "Rating icon for Unclear" non-Transparent: Unclear whether third-party contractual security protections are required.
    • Unanswered: Did not evaluate whether third-party contractual security protections are required.
  6. (BASIC) Reasonable Security: Do the policies clearly indicate whether or not reasonable security standards are used to protect the confidentiality of a user's personal information?

    • "Rating icon for Better" Does: Industry best practices are used to protect data.
    • "Rating icon for Worse" Does Not: Industry best practices are not used to protect data.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product uses industry best practices to protect data.
    • Unanswered: Did not evaluate whether this product uses industry best practices to protect data.
  7. Employee Access: Do the policies clearly indicate whether or not the vendor implements physical access controls or limits employee access to user information?

    • "Rating icon for Better" Does: Employee or physical access to user information is limited.
    • "Rating icon for Worse" Does Not: Employee or physical access to user information is not limited.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product limits employee or physical access to user information.
    • Unanswered: Did not evaluate whether this product limits employee or physical access to user information.
  8. (BASIC) Transit Encryption: Do the policies clearly indicate whether or not all data in transit is encrypted?

    • "Rating icon for Better" Does: All data in transit are encrypted.
    • "Rating icon for Worse" Does Not: All data in transit are not encrypted.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product encrypts all data in transit.
    • Unanswered: Did not evaluate whether this product encrypts all data in transit.
  9. (BASIC) Storage Encryption: Do the policies clearly indicate whether or not all data at rest is encrypted?

    • "Rating icon for Better" Does: All data at rest are encrypted.
    • "Rating icon for Worse" Does Not: All data at rest are not encrypted.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product encrypts all data at rest.
    • Unanswered: Did not evaluate whether this product encrypts all data at rest.
  10. (BASIC) Breach Notice: Do the policies clearly indicate whether or not the vendor provides notice in the event of a data breach to affected individuals?

    • "Rating icon for Better" Does: Notice is provided in the event of a data breach.
    • "Rating icon for Worse" Does Not: Notice is not provided in the event of a data breach.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product provides notice in the event of a data breach.
    • Unanswered: Did not evaluate whether this product provides notice in the event of a data breach.

Data Rights

What rights do I have to the data?

Evaluating data rights takes into consideration best practices of providing users with the ability to review, access, modify, delete, and export their personal information and content.

  1. Collection Consent: Do the policies clearly indicate whether or not the vendor requests opt-in consent from a user at the time information is collected?

    • "Rating icon for Better" Does: Opt-in consent is requested from users at the time personal information is collected.
    • "Rating icon for Worse" Does Not: Opt-in consent is not requested from users at the time personal information is collected.
    • "Rating icon for Unclear" non-Transparent: Unclear whether opt-in consent is requested from users at the time personal information is collected.
    • Unanswered: Did not evaluate whether opt-in consent is requested from users at the time personal information is collected.
  2. User Control: Do the policies clearly indicate whether or not a user can control the vendor or third party's use of their information through privacy settings?

    • "Rating icon for Better" Does: Users can control their information through privacy settings.
    • "Rating icon for Worse" Does Not: Users cannot control their information through privacy settings.
    • "Rating icon for Unclear" non-Transparent: Unclear whether users can control their information through privacy settings.
    • Unanswered: Did not evaluate whether users can control their information through privacy settings.
  3. (BASIC) User Submission: Do the policies clearly indicate whether or not a user can create or upload content to the product?

    • "Rating icon for Worse" Does: Users can create or upload content.
    • "Rating icon for Better" Does Not: Users cannot create or upload content.
    • "Rating icon for Unclear" non-Transparent: Unclear whether users can create or upload content.
    • Unanswered: Did not evaluate whether users can create or upload content.
  4. Data Ownership: Do the policies clearly indicate whether or not a student, educator, parent, or the school retains ownership to the Intellectual Property rights of the data collected or uploaded to the product?

    • "Rating icon for Better" Does: Users retain ownership of their data.
    • "Rating icon for Worse" Does Not: Users do not retain ownership of their data.
    • "Rating icon for Unclear" non-Transparent: Unclear whether users retain ownership of their data.
    • Unanswered: Did not evaluate whether users retain ownership of their data.
  5. (BASIC) Access Data: Do the policies clearly indicate whether or not the vendor provides authorized individuals a method to access a user's personal information?

    • "Rating icon for Better" Does: Processes to access and review user data are available.
    • "Rating icon for Worse" Does Not: Processes to access and review user data are not available.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product provides processes to access and review user data.
    • Unanswered: Did not evaluate whether this product provides processes to access and review user data.
  6. (BASIC) Data Modification: Do the policies clearly indicate whether or not the vendor provides authorized individuals with the ability to modify a user's inaccurate data?

    • "Rating icon for Better" Does: Processes to modify inaccurate information are available.
    • "Rating icon for Worse" Does Not: Processes to modify inaccurate information are not available.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product provides processes to modify inaccurate information.
    • Unanswered: Did not evaluate whether this product provides processes to modify inaccurate information.
  7. Retention Policy: Do the policies clearly indicate the vendor's data retention policy, including any data sunsets or any time-period after which a user's data will be automatically deleted if they are inactive on the product?

    • Transparent: A data-retention policy is available.
    • "Rating icon for Unclear" non-Transparent: Unclear whether the product provides a data-retention policy.
    • Unanswered: Did not evaluate whether the product provides a data-retention policy.
  8. (BASIC) Deletion Process: Do the policies clearly indicate whether or not the vendor provides a process for the school, parent, or eligible student to delete a student's personal information?

    • "Rating icon for Better" Does: Processes for the school, parents, or students to delete data are available.
    • "Rating icon for Worse" Does Not: Processes for the school, parents, or students to delete data are not available.
    • "Rating icon for Unclear" non-Transparent: Unclear whether the school, parents, or students can delete data.
    • Unanswered: Did not evaluate whether the school, parents, or students can delete data.
  9. User Deletion: Do the policies clearly indicate whether or not a user can delete all of their personal and non-personal information from the vendor?

    • "Rating icon for Better" Does: Processes to delete user data are available.
    • "Rating icon for Worse" Does Not: Processes to delete user data are not available.
    • "Rating icon for Unclear" non-Transparent: Unclear whether a user can delete all their data.
    • Unanswered: Did not evaluate whether a user can delete all their data.
  10. User Export: Do the policies clearly indicate whether or not a user can export or download their data, including any user created content on the product?

    • "Rating icon for Better" Does: Processes to download user data are available.
    • "Rating icon for Worse" Does Not: Processes to download user data are not available.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product provides users the ability to download their data.
    • Unanswered: Did not evaluate whether this product provides users the ability to download their data.

Data Sold

Is the data sold?

Evaluating data selling takes into consideration best practices of not sharing, renting, or selling a user’s personal information to third parties for financial gain.

  1. (BASIC) Data Sold: Do the policies clearly indicate whether or not a user's personal information is sold or rented to third parties?

    • "Rating icon for Worse" Does: data are sold or rented to third parties.
    • "Rating icon for Better" Does Not: data are not sold or rented to third parties.
    • "Rating icon for Unclear" non-Transparent: Unclear whether data are sold or rented to third parties.
    • Unanswered: Did not evaluate whether data are sold or rented to third parties.
  2. opt out Consent: Do the policies clearly indicate whether or not a user can opt out from the disclosure or sale of their data to a third party?

    • "Rating icon for Better" Does: Users can opt out from the disclosure or sale of their data to a third party.
    • "Rating icon for Worse" Does Not: Users cannot opt out from the disclosure or sale of their data to a third party.
    • "Rating icon for Unclear" non-Transparent: Unclear whether users can opt out from the disclosure or sale of their data to a third party.
    • Unanswered: Did not evaluate whether users can opt out from the disclosure or sale of their data to a third party.
  3. (BASIC) Transfer Data: Do the policies clearly indicate whether or not the vendor can transfer a user's data in the event of the vendor's merger, acquisition, or bankruptcy?

    • "Rating icon for Worse" Does: User information can be transferred to a third party.
    • "Rating icon for Better" Does Not: User information cannot be transferred to a third party.
    • "Rating icon for Unclear" non-Transparent: Unclear whether user information can be transferred to a third party.
    • Unanswered: Did not evaluate whether user information can be transferred to a third party.
  4. Transfer Notice: Do the policies clearly indicate whether or not the vendor will notify users of a data transfer to a third-party successor, in the event of a vendor's bankruptcy, merger, or acquisition?

    • "Rating icon for Better" Does: Users are notified if their information is transferred to a third party.
    • "Rating icon for Worse" Does Not: Users are not notified if their information is transferred to a third party.
    • "Rating icon for Unclear" non-Transparent: Unclear whether users are notified if their information is transferred to a third party.
    • Unanswered: Did not evaluate whether users are notified if their information is transferred to a third party.
  5. Delete Transfer: Do the policies clearly indicate whether or not a user can request to delete their data prior to its transfer to a third-party successor in the event of a vendor bankruptcy, merger, or acquisition?

    • "Rating icon for Better" Does: User information can be deleted prior to its transfer to a third party.
    • "Rating icon for Worse" Does Not: User information cannot be deleted prior to its transfer to a third party.
    • "Rating icon for Unclear" non-Transparent: Unclear whether user information can be deleted prior to its transfer to a third party.
    • Unanswered: Did not evaluate whether user information can be deleted prior to its transfer to a third party.
  6. Contractual Limits: Do the policies clearly indicate whether or not the third-party successor of a data transfer is contractually required to provide the same privacy compliance required of the vendor?

    • "Rating icon for Better" Does: Third-party transfer is contractually required to use the same privacy practices.
    • "Rating icon for Worse" Does Not: Third-party transfer is not contractually required to use the same privacy practices.
    • "Rating icon for Unclear" non-Transparent: Unclear whether third-party transfers are contractually required to use the same privacy practices.
    • Unanswered: Did not evaluate whether third-party transfers are contractually required to use the same privacy practices.
  7. Data Deidentified: Do the policies clearly indicate whether or not a user's information that is shared or sold to a third party is only done so in an anonymous or deidentified format?

    • "Rating icon for Worse" Does: User information is shared in an anonymous or deidentified format.
    • "Rating icon for Better" Does Not: User information is not shared in an anonymous or deidentified format.
    • "Rating icon for Unclear" non-Transparent: Unclear whether user information is shared in an anonymous or deidentified format.
    • Unanswered: Did not evaluate whether user information is shared in an anonymous or deidentified format.
  8. Deidentified Process: Do the policies clearly indicate whether or not the deidentification process is done with a reasonable level of justified confidence, or the vendor provides links to any information that describes their deidentification process?

    • "Rating icon for Better" Does: The vendor describes their deidentification process of user information.
    • "Rating icon for Worse" Does Not: The vendor does not describes their deidentification process of user information.
    • "Rating icon for Unclear" non-Transparent: Unclear whether the vendor describes their deidentification process of user information.
    • Unanswered: Did not evaluate whether the vendor describes their deidentification process of user information.
  9. Third-Party Research: Do the policies clearly indicate whether or not collected information is shared with third parties for research or product improvement purposes?

    • "Rating icon for Worse" Does: data are shared for research and/or product improvement.
    • "Rating icon for Better" Does Not: data are not shared for research and/or product improvement.
    • "Rating icon for Unclear" non-Transparent: Unclear whether data are shared for research and/or product improvement.
    • Unanswered: Did not evaluate whether data are shared for research and/or product improvement.
  10. Combination Limits: Do the policies clearly indicate whether or not the vendor imposes contractual limits that prohibit third parties from reidentifying or combining data with other data sources that the vendor shares or sells to them?

    • "Rating icon for Better" Does: Contractual limits prohibit third parties from reidentifying deidentified information.
    • "Rating icon for Worse" Does Not: Contractual limits do not prohibit third parties from reidentifying deidentified information.
    • "Rating icon for Unclear" non-Transparent: Unclear whether contractual limits prohibit third parties from reidentifying deidentified information.
    • Unanswered: Did not evaluate whether contractual limits prohibit third parties from reidentifying deidentified information.

Data Safety

How safe is this product?

Evaluating safety takes into consideration best practices that protect a user's physical and emotional health.

  1. (BASIC) Safe Interactions: Do the policies clearly indicate whether or not a user can interact with trusted users?

    • "Rating icon for Better" Does: Users can interact with trusted users and/or students.
    • "Rating icon for Worse" Does Not: Users cannot interact with trusted users and/or students.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product supports interactions between trusted users and/or students.
    • Unanswered: Did not evaluate whether this product supports interactions between trusted users and/or students.
  2. Unsafe Interactions: Do the policies clearly indicate whether or not a user can interact with untrusted users?

    • "Rating icon for Worse" Does: Users can interact with untrusted users, including strangers and/or adults.
    • "Rating icon for Better" Does Not: Users cannot interact with untrusted users, including strangers and/or adults.
    • "Rating icon for Unclear" non-Transparent: Unclear whether users can interact with untrusted users, including strangers and/or adults.
    • Unanswered: Did not evaluate whether users can interact with untrusted users, including strangers and/or adults.
  3. Share Profile: Do the policies clearly indicate whether or not information must be shared or revealed by a user in order to participate in social interactions?

    • "Rating icon for Worse" Does: Profile information is shared for social interactions.
    • "Rating icon for Better" Does Not: Profile information is not shared for social interactions.
    • "Rating icon for Unclear" non-Transparent: Unclear whether profile information is shared for social interactions.
    • Unanswered: Did not evaluate whether profile information is shared for social interactions.
  4. (BASIC) Visible Data: Do the policies clearly indicate whether or not a user's personal information can be displayed publicly in any way?

    • "Rating icon for Worse" Does: Personal information is displayed publicly.
    • "Rating icon for Better" Does Not: Personal information is not displayed publicly.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product displays personal information publicly.
    • Unanswered: Did not evaluate whether this product displays personal information publicly.
  5. Control Visibility: Do the policies clearly indicate whether or not a user has control over how their personal information is displayed to others?

    • "Rating icon for Better" Does: Users can control how their data are displayed.
    • "Rating icon for Worse" Does Not: Users cannot control how their data are displayed.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product allows users to control how their data are displayed.
    • Unanswered: Did not evaluate whether this product allows users to control how their data are displayed.
  6. Monitor Content: Do the policies clearly indicate whether or not the vendor reviews, screens, or monitors user-created content?

    • "Rating icon for Better" Does: User-created content is reviewed, screened, or monitored by the vendor.
    • "Rating icon for Worse" Does Not: User-created content is not reviewed, screened, or monitored by the vendor.
    • "Rating icon for Unclear" non-Transparent: Unclear whether user-created content is reviewed, screened, or monitored by the vendor.
    • Unanswered: Did not evaluate whether user-created content is reviewed, screened, or monitored by the vendor.
  7. (BASIC) Filter Content: Do the policies clearly indicate whether or not the vendor takes reasonable measures to delete all personal information from a user's postings before they are made publicly visible?

    • "Rating icon for Better" Does: User-created content is filtered for personal information before being made publicly visible.
    • "Rating icon for Worse" Does Not: User-created content is not filtered for personal information before being made publicly visible.
    • "Rating icon for Unclear" non-Transparent: Unclear whether user-created content is filtered for personal information before being made publicly visible.
    • Unanswered: Did not evaluate whether user-created content is filtered for personal information before being made publicly visible.
  8. (BASIC) Moderating Interactions: Do the policies clearly indicate whether or not social interactions between users of the product are moderated?

    • "Rating icon for Better" Does: Social interactions between users are moderated.
    • "Rating icon for Worse" Does Not: Social interactions between users are not moderated.
    • "Rating icon for Unclear" non-Transparent: Unclear whether social interactions between users are moderated.
    • Unanswered: Did not evaluate whether social interactions between users are moderated.
  9. Log Interactions: Do the policies clearly indicate whether or not social interactions are logged by the vendor are available for review or audit?

    • "Rating icon for Better" Does: Social interactions of users are logged.
    • "Rating icon for Worse" Does Not: Social interactions of users are not logged.
    • "Rating icon for Unclear" non-Transparent: Unclear whether social interactions of users are logged.
    • Unanswered: Did not evaluate whether social interactions of users are logged.
  10. Report Abuse: Do the policies clearly indicate whether or not a user can report abusive behavior, or cyberbullying?

    • "Rating icon for Better" Does: Users can report abuse or cyberbullying.
    • "Rating icon for Worse" Does Not: Users cannot report abuse or cyberbullying.
    • "Rating icon for Unclear" non-Transparent: Unclear whether users can report abuse or cyberbullying.
    • Unanswered: Did not evaluate whether users can report abuse or cyberbullying.

Ads & Tracking

Are there advertisements or tracking?

Evaluating ads and tracking takes into consideration best practices of not using a user’s personal information for any third-party marketing, behavioral advertising, tracking, or profile generation purposes.

  1. (BASIC) Third-Party Marketing: Do the policies clearly indicate whether or not personal information is shared with third parties for advertising or marketing purposes?

    • "Rating icon for Worse" Does: data are shared for third-party advertising and/or marketing.
    • "Rating icon for Better" Does Not: data are not shared for third-party advertising and/or marketing.
    • "Rating icon for Unclear" non-Transparent: Unclear whether data are shared for third-party advertising and/or marketing.
    • Unanswered: Did not evaluate whether data are shared for third-party advertising and/or marketing.
  2. (BASIC) Traditional Ads: Do the policies clearly indicate whether or not traditional advertisements are displayed to a user based on a webpage's content, and not that user's data?

    • "Rating icon for Worse" Does: Traditional or contextual advertisements are displayed.
    • "Rating icon for Better" Does Not: Traditional or contextual advertisements are not displayed.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product displays traditional or contextual advertisements.
    • Unanswered: Did not evaluate whether this product displays traditional or contextual advertisements.
  3. (BASIC) Behavioral Ads: Do the policies clearly indicate whether or not behavioral advertising based on a user's personal information are displayed?

    • "Rating icon for Worse" Does: Behavioral or targeted advertising is displayed.
    • "Rating icon for Better" Does Not: Behavioral or targeted advertising is not displayed.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product displays behavioral or targeted advertising.
    • Unanswered: Did not evaluate whether this product displays behavioral or targeted advertising.
  4. (BASIC) Third-Party Tracking: Do the policies clearly indicate whether or not third-party advertising services or tracking technologies collect any information from a user of the product?

    • "Rating icon for Worse" Does: data are collected by third-party advertising or tracking services.
    • "Rating icon for Better" Does Not: data are not collected by third-party advertising or tracking services.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product allows data collection by third-party advertising or tracking services.
    • Unanswered: Did not evaluate whether this product allows data collection by third-party advertising or tracking services.
  5. (BASIC) Track Users: Do the policies clearly indicate whether or not a user's information is used to track users and display target advertisements on other third-party websites or services?

    • "Rating icon for Worse" Does: data are used to track and target advertisements on other third-party websites or services.
    • "Rating icon for Better" Does Not: data are not used to track and target advertisements on other third-party websites or services.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product uses data to track and target advertisements on other third-party websites or services.
    • Unanswered: Did not evaluate whether this product uses data to track and target advertisements on other third-party websites or services.
  6. (BASIC) Data Profile: Do the policies clearly indicate whether or not the vendor allows third parties to use a student's data to create an automated profile, engage in data enhancement, conduct social advertising, or target advertising to students, parents, teachers, or the school?

    • "Rating icon for Worse" Does: Data profiles are created and used for data enhancement, and/or targeted advertisements.
    • "Rating icon for Better" Does Not: Data profiles are not created and used for data enhancement, and/or targeted advertisements.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product creates and uses data profiles for data enhancement, and/or targeted advertisements.
    • Unanswered: Did not evaluate whether this product creates and uses data profiles for data enhancement, and/or targeted advertisements.
  7. Marketing Messages: Do the policies clearly indicate whether or not the vendor may send marketing emails, text messages, or other related communications that may be of interest to a user?

    • "Rating icon for Worse" Does: The vendor can send marketing messages.
    • "Rating icon for Better" Does Not: The vendor cannot send marketing messages.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this vendor can send marketing messages.
    • Unanswered: Did not evaluate whether this vendor can send marketing messages.
  8. Third-Party Promotions: Do the policies clearly indicate whether or not the vendor may ask a user to participate in any sweepstakes, contests, surveys, or other similar promotions?

    • "Rating icon for Worse" Does: The vendor does provide promotional sweepstakes, contests, or surveys.
    • "Rating icon for Better" Does Not: The vendor does not provide promotional sweepstakes, contests, or surveys.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this vendor provides promotional sweepstakes, contests, or surveys.
    • Unanswered: Did not evaluate whether this vendor provides promotional sweepstakes, contests, or surveys.
  9. Unsubscribe Ads: Do the policies clearly indicate whether or not a user can opt out of traditional, contextual, or behavioral advertising?

    • "Rating icon for Better" Does: Users can opt out of traditional, contextual, or behavioral advertising.
    • "Rating icon for Worse" Does Not: Users cannot opt out of traditional, contextual, or behavioral advertising.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product provides users the ability to opt out of traditional, contextual, or behavioral advertising.
    • Unanswered: Did not evaluate whether this product provides users the ability to opt out of traditional, contextual, or behavioral advertising.
  10. Unsubscribe Marketing: Do the policies clearly indicate whether or not a user can opt out or unsubscribe from a vendor or third party marketing communication?

    • "Rating icon for Better" Does: Users can opt out or unsubscribe from marketing communications.
    • "Rating icon for Worse" Does Not: Users cannot opt out or unsubscribe from marketing communications.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product provides users the ability to opt out or unsubscribe from marketing communications.
    • Unanswered: Did not evaluate whether this product provides users the ability to opt out or unsubscribe from marketing communications.

Can I provide parental consent?

Evaluating parental consent takes into consideration best practices of protecting children under 13 years of age by requiring a parent’s or guardian's verifiable consent before the collection, use, or disclosure of a child's personal information to an application or service.

  1. (BASIC) Children Intended: Do the policies clearly indicate whether or not the product is intended to be used by children under the age of 13?

    • Does: Intended for children under 13.
    • Does Not: Not intended for children under 13.
    • "Rating icon for Unclear" non-Transparent: Unclear whether intended for children under 13.
    • Unanswered: Did not evaluate whether intended for children under 13.
  2. Parents Intended: Do the policies clearly indicate whether or not the product is intended to be used by parents or guardians?

    • Does: Intended for parents or guardians.
    • Does Not: Not intended for parents or guardians.
    • "Rating icon for Unclear" non-Transparent: Unclear whether intended for parents or guardians.
    • "Rating icon for Unclear" Unanswered: Did not evaluate whether intended for parents or guardians.
  3. Actual Knowledge: Do the policies clearly indicate whether or not the vendor has actual knowledge that personal information from children under 13 years of age is collected by the product?

    • Does: Vendor does have actual knowledge that personal information from users under 13 years of age is collected.
    • Does Not: Vendor does not have actual knowledge that personal information from users under 13 years of age is collected.
    • "Rating icon for Unclear" non-Transparent: Unclear whether vendor has actual knowledge that personal information from users under 13 years of age is collected.
    • Unanswered: Did not evaluate whether vendor has actual knowledge that personal information from users under 13 years of age is collected.
  4. COPPA Notice: Do the policies clearly indicate whether or not the vendor describes: (1) what information is collected from children under 13 years of age, (2) how that information is used, and (3) its disclosure practices for that information?

    • "Rating icon for Better" Does: Children's privacy is applicable.
    • "Rating icon for Worse" Does Not: Children's privacy is not applicable.
    • "Rating icon for Unclear" non-Transparent: Unclear whether children's privacy is applicable.
    • Unanswered: Did not evaluate whether children's privacy is applicable.
  5. COPPA Exception: Do the policies clearly indicate whether or not the vendor collects personal information from children without verifiable parental consent for the sole purpose of trying to obtain consent under COPPA?

    • Does: COPPA parental consent exceptions are indicated.
    • Does Not: COPPA parental consent exceptions are not indicated.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product indicates COPPA parental consent exceptions.
    • Unanswered: Did not evaluate whether this product discloses COPPA parental consent exceptions.
  6. (BASIC) Parental Consent: Do the policies clearly indicate whether or not the vendor or third party obtains verifiable parental consent before they collect or disclose personal information?

    • "Rating icon for Better" Does: Parental consent is required.
    • "Rating icon for Worse" Does Not: Parental consent is not required.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product requires parental consent.
    • Unanswered: Did not evaluate whether this product requires parental consent.
  7. Limit Consent: Do the policies clearly indicate whether or not a parent can consent to the collection and use of their child's personal information without also consenting to the disclosure of the information to third parties?

    • "Rating icon for Better" Does: Parental consent is limited with respect to third parties.
    • "Rating icon for Worse" Does Not: Parental consent is not limited with respect to third parties.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product limits parental consent with respect to third parties.
    • Unanswered: Did not evaluate whether this product limits parental consent with respect to third parties.
  8. Withdraw Consent: Do the policies clearly indicate whether or not the vendor responds to a request from a parent or guardian to prevent further collection of their child's information?

    • "Rating icon for Better" Does: Parents can withdraw consent for the further collection of their child's information.
    • "Rating icon for Worse" Does Not: Parents cannot withdraw consent for the further collection of their child's information.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product allows parents to withdraw consent for the further collection of their child's information.
    • Unanswered: Did not evaluate whether this product allows parents to withdraw consent for the further collection of their child's information.
  9. Delete Child-PII: Do the policies clearly indicate whether or not the vendor deletes personal information from a student or child under 13 years of age if collected without parental consent?

    • "Rating icon for Better" Does: Children's personal information is deleted if collected without parental consent.
    • "Rating icon for Worse" Does Not: Children's personal information is not deleted if collected without parental consent.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product deletes children's personal information if collected without parental consent.
    • Unanswered: Did not evaluate whether this product deletes children's personal information if collected without parental consent.
  10. (BASIC) Consent Method: Do the policies clearly indicate whether or not the vendor provides notice to parents or guardians of the methods to provide verifiable parental consent under COPPA?

    • "Rating icon for Better" Does: Parental consent notice and method for submission are provided.
    • "Rating icon for Worse" Does Not: Parental consent notice and method for submission are not provided.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product provides parental consent notice and method for submission.
    • Unanswered: Did not evaluate whether this product provides parental consent notice and method for submission.

School Purpose

Is the product intended for school?

Evaluating school purpose takes into consideration best practices of companies that collect personal information from students or teachers in K-12 and the legal obligations for the privacy and security of that information.

  1. (BASIC) Students Intended: Do the policies clearly indicate whether or not the product is intended to be used by students in preschool or preK-12?

    • Does: Intended for students.
    • Does Not: Not intended for students.
    • "Rating icon for Unclear" non-Transparent: Unclear whether intended for students.
    • Unanswered: Did not evaluate whether intended for students.
  2. Student Data: Do the policies clearly indicate whether or not the vendor collects personal information or education records from preK-12 students?

    • "Rating icon for Worse" Does: Personal information or education records are collected from preK-12 students.
    • "Rating icon for Better" Does Not: Personal information or education records are not collected from preK-12 students.
    • "Rating icon for Unclear" non-Transparent: Unclear whether personal information or education records are collected from preK-12 students.
    • Unanswered: Did not evaluate whether personal information or education records are collected from preK-12 students.
  3. Teachers Intended: Do the policies clearly indicate whether or not the product is intended to be used by teachers?

    • Does: Intended for teachers.
    • Does Not: Not intended for teachers.
    • "Rating icon for Unclear" non-Transparent: Unclear whether intended for teachers.
    • Unanswered: Did not evaluate whether intended for teachers.
  4. (BASIC) School Purpose: Do the policies clearly indicate whether or not the product is primarily used, designed, and marketed for preschool or K-12 school purposes?

    • Does: Product is primarily used by, designed for, and marketed toward students in grades pre-K–12.
    • Does Not: Product is not primarily used by, designed for, and marketed toward students in grades pre-K–12.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product is primarily used by, designed for, and marketed toward students in grades pre-K–12.
    • Unanswered: Did not evaluate whether this product is primarily used by, designed for, and marketed toward students in grades pre-K–12.
  5. Education Records: Do the policies clearly indicate the process by which education records are entered into the product? For example, are data entered by district staff, school employees, parents, teachers, students, or some other person?

    • Transparent: Product does create education records.
    • "Rating icon for Unclear" non-Transparent: Unclear whether the product creates education records.
    • Unanswered: Did not evaluate whether the product creates education records.
  6. School Contract: Do the policies clearly indicate whether or not the vendor provides a contract to a Local Educational Agency (LEA) or otherwise provides notice to users of additional rights?

    • "Rating icon for Better" Does: Notification of a contract or additional rights is provided.
    • "Rating icon for Worse" Does Not: Notification of a contract or additional rights is not provided.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product provides notification of a contract or additional rights.
    • Unanswered: Did not evaluate whether this product provides notification of a contract or additional rights.
  7. School Official: Do the policies clearly indicate whether or not the vendor is under the direct control of the educational institution and designates themselves a 'School Official' under FERPA?

    • "Rating icon for Better" Does: Vendor is designated as a school official.
    • "Rating icon for Worse" Does Not: Vendor is not designated as a school official.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product designates the vendor as a school official.
    • Unanswered: Did not evaluate whether this product designates the vendor as a school official.
  8. School Consent: Do the policies clearly indicate whether or not responsibility or liability for obtaining verified parental consent is transferred to the school or district?

    • "Rating icon for Worse" Does: Parental consent obligations are transferred to the school or district.
    • "Rating icon for Better" Does Not: Parental consent obligations are not transferred to the school or district.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product transfers parental consent obligations to the school or district.
    • Unanswered: Did not evaluate whether this product transfers parental consent obligations to the school or district.
  9. FERPA Exception: Do the policies clearly indicate whether or not the vendor may disclose personal information without verifiable parental consent under a FERPA exception?

    • Does: FERPA parental consent exceptions are indicated.
    • Does Not: FERPA parental consent exceptions are not indicated.
    • "Rating icon for Unclear" non-Transparent: Unclear whether the vendor indicates FERPA parental consent exceptions.
    • Unanswered: Did not evaluate whether the vendor indicates FERPA parental consent exceptions.
  10. Directory Information: Do the policies clearly indicate whether or not the vendor discloses student information as 'Directory Information' under a FERPA exception?

    • "Rating icon for Worse" Does: Directory information is disclosed.
    • "Rating icon for Better" Does Not: Directory information is not disclosed.
    • "Rating icon for Unclear" non-Transparent: Unclear whether this product discloses directory information.
    • Unanswered: Did not evaluate whether this product discloses directory information.