Skip to content

Privacy Policy

Babbage Education LLC (“Babbage,” “we,” “us,” or “our”) provides special education compliance software for K-12 school districts. This Privacy Policy explains how we handle personal information collected through our website at babbageidea.com and through our software service (together, the “Service”). Our Service is intended for educators, school and district staff, and the administrators who manage them.

Last updated July 1, 2026Read the Terms of Service

Student data is handled separately

Please read this first

Babbage processes student records (including IEPs, 504 plans, behavior intervention plans, and evaluation records) only on behalf of the school districts we serve. When we handle that information we act as a School Official under FERPA, under the direct control of the district. That student data is governed by our Data Privacy Agreement (DPA) with each district and by the district’s own privacy policies, not by this Privacy Policy.

If you are a parent, guardian, or student and you want to review, correct, or delete student data, please contact your school district, which will direct any request to us as needed. This Privacy Policy covers the information we collect directly from educators, staff, and website visitors.

What this policy covers

This Privacy Policy applies to personal information we collect directly from and about the adults who use our Service and visit our website. It does not apply to student data or education records that we process for a district as a service provider. Where our handling of any information conflicts with the terms of a signed DPA, the DPA controls with respect to student data.

Personal information we collect

Information you provide to us

  • Contact and account data: your first and last name, work email address, professional title, and the school or district you are affiliated with, plus a phone number if you choose to share one.
  • Profile and credential data: the username and password you set to access the Service (passwords are stored in hashed form), your assigned role, and any details you add to your profile.
  • Communications data: the content of messages you send us, including support requests, feedback, and questions submitted through the Service, email, or other channels.
  • Marketing data: your preferences for receiving communications from us and information about how you engage with them.

Information from other sources

If you sign in through a third-party identity provider such as Google, Clever, or ClassLink, or through your district’s single sign-on, we may receive basic account information from that provider, such as your name and email, based on the settings your district or you have enabled.

Information collected automatically

  • Device and connection data: IP address, browser type and version, operating system, device type, and language settings.
  • Usage data: pages and screens you view, features you use, access times, and how you navigate the Service, along with whether you open our emails or click links in them.

Cookies and similar technologies

We use cookies and similar technologies to operate the Service, keep you signed in securely, remember your preferences, and understand how the Service is used so we can improve it. This includes session cookies that expire when you close your browser and persistent cookies that remain until they expire or you remove them. Most browsers let you block or delete cookies through their settings. If you disable cookies, some parts of the Service may not function properly.

How we use your personal information

Provide and operate the Service
Create and maintain your account, authenticate you, deliver the features you use, and provide customer support.
Secure the Service
Enable security features, monitor for unauthorized access, and protect the integrity of the Service.
Communicate with you
Send service announcements, updates, security alerts, and administrative messages, and respond to your requests.
Improve the Service
Analyze usage to understand what is working, fix problems, and develop new features.
Comply and protect
Meet legal obligations, respond to lawful requests, enforce our terms, and prevent fraud or misuse.

We do not sell your data, and we do not advertise to students

We do not sell personal information or student data to anyone. We do not use student data to build advertising profiles, and targeted advertising is strictly prohibited across our Service. We use the information we collect to run and improve Babbage, and for no unrelated commercial purpose.

How we share your personal information

  • Service providers and subprocessors: companies that help us operate the Service, such as cloud hosting, security, and email delivery. Each is bound by contract to protect the information they handle under terms no less strict than our own, and none may sell student data.
  • Authorities and legal process: government or law enforcement bodies where we believe in good faith that disclosure is required by law or lawful process. Where a request concerns student data held for a district, we notify the district as required by our DPA unless legally prohibited.
  • Professional advisors: lawyers, auditors, and insurers, where needed to provide their services to us.
  • Business transfers: in connection with a merger, acquisition, financing, or sale of assets. In any change of control, we remain bound by our DPA obligations and will provide the notice and successor assurances those agreements require.

We do not share personal information with advertisers or data brokers.

How we protect your information

We apply administrative, physical, and technical safeguards designed to protect the information we hold. These include:

  • Encryption: AES-256 for data at rest and TLS 1.2 or higher for data in transit.
  • Access control: role-based permissions with single sign-on and multi-factor authentication available. District administrators control user provisioning and can revoke access at any time.
  • Isolation: each district operates in its own database instance, and access controls prevent one district’s data from being reached by another.
  • Monitoring and testing: full audit logging of data access, threat and intrusion detection with alerting, and regular penetration testing and vulnerability scanning.
  • Independent assurance: we conduct regular internal reviews of our security controls and are evaluating third-party audit programs as we scale.

If a data breach affecting information we hold is confirmed, we notify affected districts within 72 hours of confirmation, in line with our DPA commitments, and follow a documented response plan covering detection, notification, remediation, and review. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

How long we keep your information

We keep account and contact information for as long as your account is active and as needed to provide the Service, then retain it only as required to meet legal, accounting, or reporting obligations or to resolve disputes. Student data held for a district is retained and disposed of according to that district’s DPA. On request or on termination, we dispose of or return a district’s student data within the timeframe set out in the DPA, which is 60 days unless the district directs otherwise or the law requires a different period.

Children and students

The Service is built for educators and school staff, and is not intended for direct use by children under 13. We do not knowingly collect personal information directly from children. Any student information in the Service is provided by or on behalf of a school district for a legitimate educational purpose. Where COPPA applies, the district provides consent on behalf of parents in its role as our customer. To the extent we access education records and personally identifiable information as defined under FERPA, we use that information only for the authorized purposes set out in our agreement with the district, and we do not redisclose it except as the district authorizes or as FERPA permits.

Student records we process for a district, including IEP, 504, and evaluation records, are also handled consistent with the confidentiality of information requirements of the Individuals with Disabilities Education Act (IDEA, 34 CFR Part 300, Subpart F), which build on the FERPA protections described above. These records are governed by our DPA with the district.

Your choices

  • Access and update: if you have an account, you can review and update your profile information by signing in.
  • Marketing communications: you can opt out of marketing emails using the unsubscribe link in any such message. You will still receive service and administrative messages related to your account.
  • Cookies: you can manage or remove cookies through your browser settings.
  • Student data requests: if your request concerns a student’s information, please contact your school district, which manages those rights and will direct requests to us as needed.

Other sites and services

The Service may link to websites and services operated by others, such as your district’s identity provider. We do not control those services and are not responsible for their practices. We encourage you to review the privacy policies of any third-party services you use.

Where your information is handled

Babbage is based in the United States, and the information we collect is processed and stored in the United States by us and by our service providers.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and post the revised policy through the Service or by other appropriate means. Your continued use of the Service after a change takes effect indicates your acknowledgment of the updated policy.

How to contact us

If you have questions about this Privacy Policy or how we handle your information, you can reach us at:

Babbage Education LLC
2317 Bonterra Blvd
Indian Trail, NC 28079

romanoff@babbageidea.com