Security and Student Data Protection Statement

Last Updated: July 10, 2026

Learning.com is committed to protecting the information entrusted to us by schools, districts, educators, and students. Schools and districts control the student data they provide or authorize for use in our platform, and Learning.com uses that data only to support the educational services we provide. Our security program is designed to support the confidentiality, integrity, and availability of the Learning.com platform and the data used to deliver our educational services.

Our Approach to Student Data

Learning.com collects and uses student data only for educational purposes related to providing products and services to our users. We gather the minimum subscriber data needed to support those educational purposes.

Student data is not used for unrelated commercial purposes. Learning.com does not repurpose student data for sale to third parties for their commercial use, does not create student profiles for non-educational purposes, and does not provide behaviorally targeted advertising to students.

School and District Ownership

Learning.com recognizes schools and districts control the student data they provide or authorize for use in our platform and are the primary authorities over that data. Learning.com serves as a steward of that data, collecting, using, and disclosing student personal information only for the educational purposes authorized by the school or district.

Learning.com acts as a service provider supporting those educational purposes. Schools and districts determine what student data is shared with Learning.com, ensure that the data is accurate and authorized for use, and manage appropriate access for their users. Learning.com supports schools and districts by working to protect the data in our custody and honoring authorized requests to review, delete, return, de-identify, or destroy data in accordance with our documented practices.

Data Accuracy and Customer Responsibility

Learning.com relies on schools and districts to provide accurate, complete, and current data when configuring accounts, rostering users, and using Learning.com services. Customers are responsible for ensuring that student, teacher, class, enrollment, and related roster data provided to Learning.com is accurate and authorized for use.

Accurate data helps ensure proper account matching, access, reporting, and student progress continuity. Student IDs, teacher email addresses, grade levels, enrollments, and SSO-related email addresses should be reviewed before data is shared or synced. If data is incomplete, outdated, or incorrect, the customer is responsible for correcting the data in the applicable source system or providing updated information to Learning.com.

Customers are also responsible for ensuring that student data entered into or accessed through Learning.com is used only for authorized educational purposes and is not disclosed or used for purposes that are not expressly authorized.

Security Safeguards

Learning.com uses administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, misuse, loss, disclosure, alteration, and destruction. These safeguards include encryption of sensitive data in transit and at rest, access controls, monitoring and auditing, incident response processes, vulnerability scanning, security patching, penetration testing, data minimization and retention practices, annual security training for personnel, background checks during the recruiting and hiring process, and role-based user access within the Learning.com platform.

Hosting and Encryption

Learning.com production systems are hosted using AWS cloud services located within the United States. Data transmitted between user devices and Learning.com servers uses industry-standard SSL encryption. Data in Learning.com’s custody is stored using FIPS-compliant encryption.

Independent Validation and Security Framework

Learning.com maintains independent validation of its security controls, including annual SOC 2 Type II attestation. Learning.com’s internal policies and procedures are aligned with NIST SP 800-53, and Learning.com uses qualified third parties to conduct penetration testing of its systems.

Access, Permissions, and Account Responsibility

Only authorized Learning.com personnel with a legitimate need to support Learning.com’s educational services may access personal information. Learning.com conducts background checks during the recruiting and hiring process and requires personnel to complete annual security training that includes guidance on safe handling of data and responsibilities under applicable laws and contracts.

Within the platform, student information is made available based on the user’s role and authorized educational need. Teachers can view information needed to manage their classes, assignments, grading, student progress, and student-generated work. District administrators and other authorized administrative users may access information needed for dashboards, reports, rostering, account management, and district-level administration.

Customers are responsible for ensuring that only authorized users are granted access to data through the application and for periodically reviewing access to confirm it remains appropriate for each user’s role. Users are responsible for maintaining the confidentiality of their login credentials and must not share passwords or allow unauthorized access to their accounts.

Retention and Disposal

Learning.com retains data only as long as required to fulfill its educational purpose. Personal information is automatically de-identified 60 days after expiration of a customer agreement. The de-identification process anonymizes account-level personal information, including name, district ID, and username, and associated student-generated work is deleted.

Upon contract expiration, an educational institution may request immediate de-identification by submitting a written request from an authorized representative to Learning.com’s data protection officer at privacy@learning.com with “Request for Deidentification of Data” in the subject line. The request should include the name of the educational institution or agency and contact information for verification.

If de-identification is not acceptable, Learning.com will also honor a request for complete destruction of data. Upon verification of the request, Learning.com will process the request within 30 calendar days and send acknowledgement when complete.

For customers that maintain subscriptions across multiple years, any user account with no activity for more than two years is automatically de-identified during Learning.com’s annual archival process, which takes place in July.

Ongoing Commitment

By using Learning.com services, customers agree to follow applicable Learning.com terms and privacy practices and to uphold their responsibilities for authorized access, accurate data, credential security, and appropriate educational use of student data.

While no system or method of transmission over the Internet can be guaranteed to be completely secure, Learning.com is committed to protecting customer and student information and maintaining security at or above industry standards.

How to Contact Us

If you have any questions or comments about this Policy, our privacy practices, or if you would like to exercise your rights with respect to your personal information, please contact us by email or contact us at:

Learning.com
9450 SW Gemini Dr. PMB 148343
Beaverton, OR 97008
Email: privacy@learning.com
Phone: 1-800-580-4640