1. Overview
Talk & Comment is built for K–12 classrooms. We take student data privacy seriously and have structured our practices around the laws and agreements that schools rely on. This page summarizes our compliance posture, signed Data Privacy Agreements (DPAs), and how to request a DPA for your district or state.
2. Federal Compliance
FERPA — Family Educational Rights and Privacy Act
Talk & Comment acts as a "school official" under FERPA when processing student education records on behalf of a school or district. Specifically:
- Student data is used solely for the educational purpose directed by the teacher or institution.
- We do not re-disclose personally identifiable information (PII) from education records without authorization.
- Data is protected with encryption at rest (AES-256) and in transit (TLS 1.2+).
- Districts may request deletion of all associated data at any time.
COPPA — Children's Online Privacy Protection Act
For students under 13, Talk & Comment enforces strict read-only mode:
- Under-13 users cannot create accounts or submit personal information independently.
- Under-13 users are limited to playback-only mode — no recordings, no PII collection.
- Schools may serve as COPPA consent agents for district-managed deployments.
- This restriction is enforced at the API level — not just the UI layer.
SDPC — Student Data Privacy Consortium
Talk & Comment has executed the SDPC National Data Privacy Agreement (NDPA) v2.2 through the TEC Cooperative. This is the standardized agreement used by thousands of school districts nationwide and is recognized by 34 state alliances.
3. Signed DPA Coverage
Talk & Comment has executed Data Privacy Agreements through state alliances, regional cooperatives, statewide partners, and district-specific agreements.
TEC Cooperative — SDPC NDPA (15 States)
Executed February 27, 2026. Covers all districts participating in TEC's multi-state NDPA alliance:
Agreement: SDPC NDPA v2.2 via a national cooperative pathway. Fully executed; detailed counterparty information available on request.
Minnesota regional service cooperative (60+ districts)
Executed March 2, 2026. Covers districts participating through a Minnesota regional service cooperative data privacy program across 60+ districts.
Agreement: Regional service cooperative DPA. Detailed counterparty information available on request.
Statewide online learning partner — Idaho
Statewide DPA covering a large online learning partner across Idaho.
CITE Privacy Services — California
District-specific CA-NDPA Standard v1.5 agreement through CITE Privacy Services. Talk & Comment signed on May 8, 2026; the LEA countersigned on May 20, 2026.
State Summary
In total, Talk & Comment has active DPA coverage represented across 18 states:
CA · IA · ID · IL · MA · ME · MN · MO · NE · NH · NJ · NY · OH · RI · TN · VA · VT · WA
Coverage paths vary by state, cooperative, partner, and district-specific agreement. If your district is not already covered, contact us and we can help route a DPA request.
4. Data Infrastructure
All student and user data is stored and processed in the United States:
- Application hosting: DigitalOcean (US regions)
- Audio file storage: AWS S3 (US region) with CloudFront CDN
- AI transcription: Self-hosted on
ai.talkandcomment.com— no third-party AI API processes your recordings - Email delivery: Postmark (US)
- Payments: Stripe (no student data involved)
- Analytics: PostHog + GA4 (anonymized/pseudonymized; can be disabled for student contexts)
No student data is transferred outside the United States. Our full sub-processor list is available upon request.
For our complete security posture, see our Data Security Plan.
5. Incident Response & Retention
Talk & Comment maintains a public breach-notification and retention procedure for district reviews. For student PII or teacher/principal APPR data, affected educational agencies are notified no later than 72 hours after discovery of a breach or unauthorized release.
- Incident response follows contain, assess, notify, remediate, and document steps.
- Personal information and student data are retained only as needed to provide the Service, support active agreements, satisfy legal or security obligations, resolve disputes, and enforce agreements.
- Contract termination, data return, destruction, and certification timing are documented in the Data Security Plan.
See the short procurement reference: Breach Notification and Data Retention.
6. Request a DPA for Your State
Don't see your state listed? We're actively expanding our DPA coverage. We support the SDPC National DPA template, state-specific agreements, and custom district DPAs.
Reach out to our team — we typically turn around DPA requests within 2–5 business days.