Privacy Notice for LTI Users
How we handle data when Process Feedback LTI features are used through an institution's LMS
Effective date: August 2, 2026
Key Points (TL;DR;)
- Student work stays on the student's device until it is saved. Writing and process data are held in the browser and are not sent to our servers unless the student chooses to save.
- The instructor dashboard is view-only, scoped to the courses an instructor teaches, and shows nothing about a student's work that the student cannot see themselves.
- We have no accounts and no passwords. The institution's LMS confirms who each person is every time they open the tool.
- We act for the institution, not on our own account. Under FERPA we operate as a school official under institutional direction. The institution owns the records; we hold them on its behalf.
- We never sell student data or use it for advertising or profiling or to train any AI models.
1. Scope
This notice covers Process Feedback LTI (https://lti.processfeedback.org) when integrated into and accessed through an institution's learning management system (LMS) using the LTI standard.
The service has two sides. Students get a writing space where they draft and submit work. Instructors get a view-only dashboard for the courses they teach, where they read submitted work and the writing process behind it. Which one a person sees is determined by the role the LMS sends at launch. This notice covers both.
Our other tools (browser extensions, plugins, online document editor, online compiler, etc.) are covered by our general Privacy Policy. Those are separate systems with separate data storage. A person who uses both remains two unconnected records; we do not link accounts, match on email address, or combine data between them.
Process Feedback, LLC operates this service. Privacy questions: contact@processfeedback.org.
2. Our role
When an institution adopts Process Feedback, it remains the controller of its students' education records. We act as a service provider processing data on the institution's behalf and under its direction. Under FERPA, that makes us a school official with a legitimate educational interest.
Practically, this means:
- The institution decides what data reaches us and how long we retain it.
- We process data only to deliver the service the institution has contracted for.
- Students and instructors exercise their privacy rights through their institution, not through us. If a student or instructor contacts us directly about their records, we refer them to the institution and let the institution know they reached out.
Where a signed Data Privacy Agreement (DPA) exists with an institution, that agreement governs and prevails over this notice for the data it covers.
3. What we collect
Nothing is collected until a student or instructor opens the tool from the LMS, and content is not stored on our servers until it is saved.
| Data | Where it comes from | Why we have it |
|---|---|---|
| Identifier, name, email, role, course context Students and instructors |
Sent by the LMS at launch (the institution controls which of these are released) | To show each person the right view, apply the right permissions, and scope data to the correct course |
| Document content Students only |
Written by the student in the tool | To produce writing process reports and instructor dashboards |
| Writing-process data (revisions, edits, timing of activity, paste events, etc.) Students only |
Recorded as the student writes | To make the writing process visible to the student and, for submitted work, to their instructor |
| Audit log entries (source IP address, action, timestamp, etc.) | Recorded automatically when a document is submitted, saved online, or accessed | Security: detecting unauthorized access, investigating incidents, and answering institutional requests |
| Support correspondence | Sent by a user or the institution | To answer support requests |
How long we keep it. Everything above is kept for the duration of the institutional agreement and deleted within 60 days of its end (or based on institutional agreement terms).
What we do not collect: Biometric data (no facial recognition, fingerprints, or voice); geolocation; device fingerprints or hardware identifiers; browsing history outside the tool; advertising or cross-site tracking data; or any data from other courses, files, or accounts.
4. Work stored on the student's device
The student writing space is local-first. As a student writes, their text and process data are stored in the browser's local storage (IndexedDB) on the device in use. This data is not transmitted to us until the student saves.
Two things follow:
- On a shared or public computer, unsaved work stays in that browser until it is cleared. Students should save their work before leaving a shared device, or delete their documents from the device when finished.
- Local data has the security of the device it is on. We cannot protect data on a device we do not control.
The instructor dashboard works differently. It reads submitted work from our servers rather than from the browser, so nothing there is local-first.
5. AI features
There is currently no AI enabled in this service. Student work is not currently sent to any AI or machine learning system, by us or by anyone else. No part of a document, its writing process, or any other institutional data is used to train a model.
Any future AI feature will be disabled by default and available only when an institution elects to enable it under its agreement with Process Feedback. Before any such feature is enabled, we will update the applicable privacy notice and institutional agreement terms to describe its data handling and safeguards.
6. Sensitive information in student writing
Because Process Feedback is a writing tool, student work may contain information we never ask for. A student's document may contain health details, immigration or financial matters, disability disclosures, or information about other people.
We do not scan, classify, or analyze content to detect sensitive categories, and we do not profile users based on what they write. All content receives the same protections regardless of what it contains. Under FERPA, this material remains part of the education record; we are not a HIPAA business associate.
Student work becomes visible to the course instructor and to the institution once it is submitted through the LMS. Work that is only saved online, without being submitted, can still be viewed by the instructor and the institution.
7. Who else receives data
We rely on a small number of service providers to run this service. Each one is under contract that limits it to processing data on our instructions and prohibits any use for its own purposes.
They fall into four categories:
- Hosting and storage for the service and the data described in Section 3
- LTI integration, which handles the launch and identity data the LMS sends
- Encrypted backup storage, which holds backups only
- Email, which carries support correspondence
Institutions receive the current list by name. Each provider is identified, with what it receives and where it operates, in the Data Privacy Agreement or in our completed HECVAT. We provide both to institutions evaluating or using the service, as part of procurement review. We notify institutions in advance of any change to that list, in accordance with the applicable institutional agreement.
We do not disclose data to anyone else except as directed by the institution, or where required by valid legal process (see Section 11).
8. Where data is stored
Institutional data is stored in the United States. Backups are held in a US region with a separate provider. As with any content delivery network, requests may transit our provider's global edge network under encryption when a user accesses the service from outside the US, but data at rest remains US-resident.
Backups age out within 30 days of deletion from production, and audit logs are kept for 12 months. We provide institutions with written certification once deletion is complete.
An institutional agreement may set different terms (storage location, data residency, cross-border transfer commitments, and the retention periods above), and where it does, that agreement governs.
9. Choices and rights
Students, directly in the tool:
- See all of their own work and its writing process at any time
- Edit and delete their own unsubmitted work
- Clear work stored on the device in use
Instructors hold the same rights over their own personal data. The identity information the LMS sends at launch is described in Section 3, and the dashboard itself is view-only, so there is no instructor-authored record to correct or delete.
Anyone, through their institution:
- Request a copy of their records
- Request correction of their records
- Request deletion of submitted work
- Ask questions about how the institution uses the tool
Institutions may request an extract of their data — scoped to the whole tenant, a course, an individual, or a date range — at any time, not only at the end of the agreement. We verify the requester before releasing anything, and we record each disclosure.
Submitted work cannot be deleted by students, because it forms part of the institution's course record. This is deliberate, and requests go through the institution.
10. Browser storage and tracking
At launch from the LMS, the service keeps the session in the browser's local storage — a short-lived access token plus the launch details the LMS sent (identifier, name, email, role, and course context, as described in Section 3). This is what keeps a student or instructor signed in while they work, and it expires on its own. Clearing browser storage signs the user out; relaunching from the LMS signs them back in.
The service sets no cookies of its own. Everything it needs is in the browser storage described above.
There are no analytics scripts, tracking pixels, advertising tags, or third-party trackers in the institutional tool. We do no cross-site or cross-session tracking. Our public informational website uses analytics; the LTI tools do not.
Local browser storage is also used to hold a student's in-progress work (IndexedDB), as described in Section 4. Neither store is used for tracking.
11. Legal requests
If we receive a subpoena, warrant, court order, or government request for institutional data, we:
- route it to our designated privacy owner — no one else responds;
- review it with counsel for validity and scope, and object to or narrow overbroad requests;
- notify the affected institution before disclosing anything, unless legally prohibited from doing so, and as soon as any such prohibition lapses;
- disclose only what falls within the request's scope;
- record the request and any disclosure.
The narrow exception is a genuine emergency involving imminent risk of death or serious physical harm, where we limit disclosure to what addresses the emergency and report it to the institution afterwards.
To date, we have received no such requests.
12. Security
Summarized:
- Data encryption in transit (TLS 1.2+) and at rest (AES-256)
- No accounts or passwords for institutional users — authentication is handled by the institution
- Each institution's data is separated by enforced access controls and alerts on any attempted cross-boundary access
- Automated security monitoring, with critical events alerting our team in real time
- Encrypted, immutable backups held with a separate provider
- Documented incident response, with breach notification to affected institutions
Our full security posture is documented in a completed HECVAT, available to institutions on request.
13. Children
This service is provided to institutions for use by their students. Institutions are responsible for obtaining any consents required by law before students use the tool. We do not knowingly collect data from children below the applicable age of digital consent without institutional authorization, and we do not use student data for marketing or promotional purposes.
14. Data breaches
If a security incident affects institutional data, we investigate and contain it, assess scope and impact, and notify affected institutions without undue delay and within the timeframe set by the applicable institutional agreement. Notification goes to the institution's designated contact, and we support their own notification obligations.
15. Accessibility
We maintain an Accessibility Conformance Report (VPAT) for this service, available on request. For accessibility questions and accommodation escalations, reach us at contact@processfeedback.org.
16. Changes to this notice
We review this notice at least annually and update it whenever our data handling, subprocessors, or features change materially. The effective date above reflects the most recent update.
For material changes, we notify institutional contacts in advance, in accordance with the applicable institutional agreement. We do not require students or instructors to accept an updated notice as a condition of continuing their coursework.
17. Contact
For privacy, security, accessibility, or general questions, reach us at contact@processfeedback.org. Students and instructors should contact their institution first, as the institution holds the records and coordinates with us directly.