District Overview
What it is, how it protects student privacy, and what districts need to know
Operated by Blue Shed Studio LLC
Download PDFThis overview helps a school or district technology/privacy reviewer quickly evaluate Thinking Classroom Tracker ("TCT") for teacher use with a school-issued Google account.
What the App Does
TCT helps math teachers implement Building Thinking Classrooms (BTC), a widely-adopted instructional approach built on randomized student groups working at vertical whiteboards. The app generates random, constraint-aware groups; lets teachers give quick, formative feedback on collaboration and engagement (not academic grades); tracks that feedback per student over time; and lets teachers photograph and label student board work for later reference. It is a teacher productivity tool — students do not log in, and the app does not replace the district's gradebook or student information system.
How Student Data Actually Flows
TCT is architected so that no student name ever reaches our servers — not from Google Classroom import, and not from manual entry. When a teacher imports a class roster from Google Classroom, the request goes directly from the teacher's browser to Google's Classroom API — student names, emails, and course details are fetched and cached locally in the browser (IndexedDB) and are never routed through or stored on our servers. When a teacher types a student's name in manually instead, that name is used only to display the roster in the browser; the record sent to our server contains no name at all.
The only data that reaches our servers (hosted on Neon, a serverless Postgres provider) is: an opaque, sequential student number assigned per class period; Google's own opaque student identifier (present only for imported students, null otherwise); rubric scores; and group assignments. Our database schema has no column capable of storing a student's name — that capability was intentionally removed. The teacher's own browser maps student numbers back to names for display.
Student Privacy, At a Glance
- ✓ No student names on our servers, ever
Whether a student is imported from Google Classroom or typed in by hand, their name never crosses the wire to our servers. Our database has no column that can even hold a student name.
- ✓ Roster data stays in the browser
Full Google Classroom roster details, and any manually-typed names, are cached directly in the teacher's browser — never transmitted to or stored on our servers.
- ✓ No student accounts
Students never log in and never provide information directly — only the teacher's browser fetches and enters data, and only for their own class.
- ✓ Not graded, not shared with students
Feedback tracked in the app is formative (collaboration, persistence, engagement) and is teacher-only — it does not appear on a report card and is not currently visible to students.
- ✓ No ads, no data sale
Student information is never sold, never used for advertising, and never used to build behavioral profiles.
- ✓ District-controlled sign-in
Teachers authenticate with their school Google account (OAuth 2.0) — no separate password to manage or lose.
- ✓ Read-only Classroom access
The app requests only classroom.courses.readonly and classroom.rosters.readonly scopes — it cannot modify anything in Google Classroom.
- ✓ Teacher-scoped access
Each teacher only ever sees their own rosters and data; there is no cross-teacher visibility.
How This Fits FERPA
When a district authorizes a teacher's use, TCT operates as a "school official" with a legitimate educational interest under FERPA's school-official exception (34 CFR § 99.31(a)(1)) — the same basis districts already rely on for many classroom tools. TCT does not use student information for any purpose beyond providing the service to the teacher, and the district/school retains ownership of the underlying education records at all times.
Common Questions
Is this COPPA-regulated?
Students never interact with TCT directly or provide information themselves; all roster data is fetched by the teacher's own browser and scores are entered by the teacher acting on the school's behalf, consistent with FTC guidance for the education context.
Where is data stored?
An encrypted Neon Postgres database holds only an opaque per-period student number, Google's opaque student identifier (for imported students only), rubric scores, and group assignments — no names, in any form. Full roster details stay in the teacher's browser. Whiteboard photos are stored in the teacher's own Google Drive, not on our servers.
What Google permissions does the app request?
Basic sign-in (openid/email/profile); optional read-only Classroom roster access (classroom.courses.readonly, classroom.rosters.readonly); and optional Drive access for photo storage (drive.appdata, drive.file, documents). The app cannot modify anything in Google Classroom.
Can our district request data deletion?
Yes — a district may request deletion of any server-side data associated with a teacher's use of TCT by contacting thinking-classroom-tracker-8be333c0@ctomail.io. Teachers can also delete their account and data anytime from the Account page.
Does this replace our gradebook?
No. TCT tracks formative, non-graded feedback on collaboration and engagement. It is designed to complement, not replace, the district's official gradebook or SIS.
For a full Data Privacy Agreement, our Terms and Conditions, or our Privacy Policy, contact thinking-classroom-tracker-8be333c0@ctomail.io.
Blue Shed Studio LLC · thinking-classroom-tracker-8be333c0@ctomail.io · www.thinkingclassroomtracker.com