For schools · 3 min read

How do schools get student-data privacy with sayit?

sayit's public privacy page covers encryption, deletion, and joint-controller status for schools, but doesn't publish a named compliance certification.

What sayit's public privacy policy documents for school use is this: when sayit is used through a school, that school may be a joint or separate data controller for its students' data, and the school's own policies apply alongside sayit's own. Beyond that general framework, sayit's public-facing pages don't publish a named compliance certification (like a specific FERPA audit or an on-premise deployment option) — so the honest answer for a school evaluating this is to read what's documented below, and ask directly for anything a specific procurement or compliance review requires.

30-second version: Documented on sayit's own privacy page: encrypted uploads, recordings not kept long-term once scored, any recording deletable on request, account deletion removes personal data, and schools are named as potential joint controllers for their students. Not published on that page: a specific named compliance certification. If your institution needs that in writing, sayit's privacy page directs you to contact them.

What's actually on the record

ProtectionWhat's documented
EncryptionRecordings are uploaded over an encrypted connection
Data retentionRecordings aren't kept long-term once scores are saved; deleting a recording removes it from live systems
Account deletionRemoves personal data from live systems, ages out of routine backups except where the law requires retention (e.g. billing)
Model trainingOff by default for EU/UK/Swiss sign-ups (explicit opt-in); togglable anytime for any account
Children's privacysayit is built for teen/adult learners; doesn't knowingly collect under-13 data without consent; the school or teacher is responsible for classroom consent
Organisational roleA school using sayit may be a joint or separate controller for its members' data

What isn't published on sayit's public pages

  • A named, specific compliance certification (FERPA or otherwise) isn't stated on the privacy page itself.
  • Specific hosting vendors and regions are deliberately not published, for security reasons — the privacy page says to contact sayit directly if a compliance or procurement review needs that information.
  • No self-serve documentation for an on-premise or fully offline deployment is published alongside the standard privacy policy.

What to actually do if you're evaluating this for a school

  1. 1.Read the full privacy policy yourself — it's written in plain language and covers exactly what's collected and why.
  2. 2.If your institution has a specific compliance requirement (a named framework, a data-processing agreement, a specific region guarantee), contact sayit directly and ask for it in writing before committing — the privacy page itself invites this for "a legitimate need to know."
  3. 3.Confirm consent responsibilities before rostering students — sayit's own policy places classroom consent responsibility on the school or teacher, not on sayit.
  4. 4.Ask specifically about the model-training setting for any accounts your school creates — it's documented as togglable per account, and a school may reasonably want it off by default for student accounts regardless of region, rather than relying on whatever the default happens to be.

Why asking directly matters more here than for an individual user

An individual signing up for themselves can read the privacy policy and make their own call. A school signing students up is making that call on behalf of people who didn't choose the product themselves, which is exactly the situation sayit's own policy flags by naming the school as a potential joint controller — the responsibility genuinely is shared, not simply outsourced to whatever the vendor's default settings happen to be. Getting specifics in writing before rostering students isn't excessive caution; it's the honest consequence of that shared-responsibility framing.

Try it

Read the full privacy policy, or set up a class through pricing — and raise any specific compliance question directly at that point.

Free in your browser

Hear exactly which sounds to fix.

Say one sentence and get sound-by-sound feedback in seconds. No install, no card.