The school or district is the data controller: it holds the education records and decides how Umbrelly is used. Umbrelly is the service provider (processor), acting on the school's instructions under its agreement with the school. Where Umbrelly collects information about children under 13, it does so on the school's behalf under the school-consent model that COPPA permits for educational use.
Privacy Policy
Last updated September 2, 2026
Umbrelly is classroom monitoring and web filtering software that schools buy and operate. The school, not Umbrelly, decides who is monitored and when. This policy explains what the software records, who inside the school can see it, and what rights students, guardians and staff have. It is written to be read by a parent, not only by a lawyer.
Who is who
What Umbrelly collects
Accounts and roster information, for every user:
- Name, email address, role (teacher, student, school admin, IT admin, parent or guardian), school and organizational unit.
- For students who require parental consent: a guardian email address and whether consent has been recorded.
- Sign-in metadata, including the time of the last sign-in.
- A profile photo, if the person chooses to add one. This is optional, never required, and there is a Remove button beside it. Nobody is given a photo by the school and none is imported from a student information system — the only way one exists is that the account holder uploaded it. It is stored in Umbrelly's own database, not on a third-party image host, and it is visible to the same people who can already see that person's name on a class or school roster.
Umbrelly does not store a student's date of birth. Where a school's student information system supplies one, it is used once to work out whether that student needs parental consent, and then discarded — only the yes/no answer is kept.
Where a school connects a student information system (Google Classroom, Clever, ClassLink, OneRoster or PowerSchool), roster data arrives from that system and is kept in step with it.
During an active class monitoring session only, Umbrelly records:
- Screen images of the student's visible browser tab, with the time of capture. This is a picture of the web page on screen — not the whole desktop, not other applications, and never the camera, the microphone or what the student types.
- Browser tab activity: the page address, page title, site, and when the tab was opened and closed. This covers every tab open in the school browser during the session, not only tabs the class is using.
- Search terms, where a page address is a web search: the words searched for. They are part of the page address already recorded above; they are named separately because reports can list them on their own.
Screen images are the most sensitive thing Umbrelly holds. Whatever is on the page is in the picture, including anything the student has typed into it. Pages the student opens outside the school browser — and files on their own device — are not captured: the software only works on ordinary web pages.
Capture is bound to the session. When the session is not active, the software does not capture screens or tabs. Students can see for themselves whether monitoring is on: that indicator is a permanent part of the student view, and there is no hidden monitoring mode.
Independently of monitoring sessions, Umbrelly records:
- Blocked web requests: the address and site a student was prevented from reaching, the category and reason, and the time.
- Focused-browsing sessions, where a teacher restricts a class to a set of sites: which sites were allowed or blocked, and when.
- Administrative audit records of significant actions taken in the software — including every change to a student's consent, and every time monitoring was refused because consent was missing.
Reports and dashboards. From the tab activity above, Umbrelly reports which sites, videos, documents, web apps and search terms students used — by page title and address — to teachers for their own classes, and to school and district administrators for their schools. These are counts and lists of what was visited, not judgments about it.
Class messages, in two directions: a teacher or admin may message a class, a group, or one student at any time, and a student may reply — but only from inside an active, consented monitoring session, and only to the teachers on that class. A student cannot start a conversation on their own. A teacher's own per-class toggle turns off both their own sending and their own receiving of new messages for that class; it does not remove a class's message history from the class-wide oversight view described below, which any teacher or admin who oversees the class keeps regardless of their own toggle. Every message is written to the administrative audit record above.
Activity analysis a school can turn on
Until September 2026 this policy said Umbrelly performed no analysis of a student's activity. That is changing. The two capabilities below are approved and being built. Each is off until a school turns it on, each says here whether it is available yet, and this section is updated in the same release that makes one available.
- Off-Task, for teachers during a class. Not yet available. While a monitoring session is running, Umbrelly compares the site a student is on with the categories of sites expected for the class's subject, which the teacher sets, and once the student has been on an unrelated site for longer than a threshold the teacher chooses (30 seconds by default) shows that teacher the student's name, the time elapsed and the site. It works from the site's category, never from the page's text or the screen image; it is offered only for subjects whose site categories are reliable; it is shown only to the teachers running that session; and it keeps no record beyond the tab activity above.
- Safety alerts, for staff a district names. Not yet available. Where a district turns it on, Umbrelly checks text a student typed into a web search, into a school document or into a class message, and the text of pages the student reads, for signs of self-harm, violence, bullying or similar risk, and sends an alert to the staff the district has named for it — never to the student, to a teacher who is not named, or to a guardian. The check uses an AI service (see "Where the data lives"): the text is sent for classification and comes back as a category and a confidence. Nothing below the district's confidence threshold becomes an alert; every alert goes to a named person who decides what happens next; nothing acts on a student automatically. A staff member who opens the screen image attached to an alert sees a warning first, and that view is recorded. Alerts are kept for the periods under "How long it is kept".
What does not change: neither capability scores or ranks students for any other purpose, neither feeds advertising, and screen images are never sent to an AI service.
What Umbrelly does not do
These are statements about the current software, not promises about intent. The section above lists the two approved capabilities and whether each is available.
- No advertising, and no sale of personal information. Student data is never sold, rented, or used to target advertising.
- No third-party analytics or tracking. The application loads no analytics, advertising or session-replay services.
- No AI processing except the safety-alert check. Apart from that check, described above and only where a district has turned it on, no student data is sent to any AI service, and nothing in the software scores or profiles a student.
- No monitoring outside an active session. Screen and tab capture happen only while a session the student can see is running.
- No reading of what students write or read, except for safety alerts. Off-Task works from a site's category, not its content. Only the safety-alert check reads text, only for the risk signals named above, and only where a district has turned it on.
- No access to files on the student's own device. The extension does not run on local files, and local file paths are never sent to Umbrelly.
Children under 13, and parental consent
Umbrelly can be told that a particular student needs a parent's consent before being monitored. When a student is marked that way and no consent has been recorded, the software refuses to monitor them. That check is not a setting in a menu that someone can forget to switch on: it runs again on every single capture, and if it cannot confirm consent — including if it cannot identify the student at all — it refuses. Every refusal is written to the audit record, so a school can show that it worked.
Consent can be withdrawn at any time by a school administrator, and monitoring of that student stops within seconds.
One limitation parents should know about. Umbrelly does not work out by itself which students are under 13. A student is only marked as needing consent when the school marks them — either by syncing a student roster that includes ages, or by setting it by hand. Until a school does that, Umbrelly treats a student as not needing parental consent and will monitor them. So the protection above is real and strictly enforced, but it only covers the students a school has actually marked. If you want to know whether your child has been marked, ask your school — they can see it and change it, and Umbrelly cannot answer for them.
Where the data lives
Screen images are stored inline in Umbrelly's own database rather than on a third-party image host or object store. Practically, that means student imagery does not travel to an outside storage provider. The database and application are hosted on Umbrelly's infrastructure providers, who process data on Umbrelly's instructions and have no independent right to use it.
One exception, tied to the safety-alert check above. When a district turns it on, the text being checked is sent to Anthropic, the AI provider, under a data processing agreement that restricts the text to returning the classification and forbids any other use, including training. Screen images are never sent. Until a district turns the check on, nothing is sent to any AI service.
All traffic between the browser, the extension and Umbrelly is encrypted in transit.
Who can see what
Access follows the school's own structure, and the software enforces it server-side rather than merely hiding things in the interface:
- Teachers see students in their own classes, and screen captures only for a session they are running. For messages, a teacher sees every message on a class they teach, in either direction — not only messages addressed to them personally.
- School administrators see their own school. District administrators see the schools in their district. Both get the same class-wide view of messages as a teacher, for any class they oversee.
- Guardians see their own linked child's blocked-site history, and nothing about any other student. The parent portal does not show messages at all.
- Safety-alert staff named by the district see the alerts routed to them, and only those. Alerts are not shown to teachers who are not named, to students, or in the parent portal.
- Students see their own monitoring status and what is collected about them, and only the messages they personally sent or received — never a class's full message history.
Screen captures are delivered only to staff views for the running session; they are never broadcast to student views.
How long it is kept
Umbrelly deletes student monitoring data automatically, on a schedule, rather than keeping it until somebody remembers to remove it. Each kind of record has its own window, because a screen image and an audit record are not equally sensitive and should not live equally long:
| What | Kept for |
|---|---|
| Screen images | 14 days |
| Browser tab activity | 30 days |
| Blocked web requests | 90 days |
| Class messages | 90 days |
| Safety alerts, open | 365 days |
| Safety alerts, resolved | 90 days |
| Administrative audit records | 365 days |
Those are the defaults. A school can set its own windows in its agreement with Umbrelly, and a district that needs data held for a shorter or longer period can have that instead. The deletion runs on its own several times a day and is permanent — deleted records are not moved to an archive that somebody could read later.
One exception, and it is deliberate. If a school places a record on legal hold — because of a safeguarding investigation, a records request, or a legal matter — that student's data stops being deleted for as long as the hold lasts, and the account cannot be erased either. A hold has an end date, so it lapses on its own rather than quietly preserving data forever, and who placed it and why is recorded.
When a school deletes an account, there is a 30-day pause first. The account stops working immediately — the person is signed out and cannot sign back in, and nothing further is recorded about them. Their existing records are erased permanently 30 days later. In between, an administrator at the school can undo the deletion, which is there for the ordinary case of the wrong person being selected from a list. Nobody outside the school can undo it, and once the 30 days are up the records cannot be recovered by anyone.
A school can also deactivate an account instead of deleting it. That switches off access and destroys nothing, which is usually the right answer when a student transfers or a staff member is on leave, and it can be reversed at any time.
Separately, a school district can place a records hold on an account, usually because of a legal matter or an open records request. While a hold is in place the records cannot be deleted, by anyone, including by a scheduled deletion that has already been ordered. A hold does not change who can see the records or what is collected — it only prevents their destruction.
Rights, and how to use them
Under FERPA, guardians (and eligible students) may review the education records a school holds, and ask for corrections. Depending on where a family lives, other rights may apply, including access, correction, deletion and a copy of the data in a portable format.
Requests go to the school first. Because the school is the controller, guardians should contact their school or district; the school can act directly in Umbrelly, and Umbrelly assists the school on request. Umbrelly does not release student records directly to a requester without the school's instruction, because it cannot verify a family relationship that only the school can confirm.
The browser extension
Monitoring and filtering rely on a Chrome extension that a school deploys to managed devices. The extension observes navigation in order to apply the school's filtering policy and, during an active session, to send screen and tab information. It is installed and removed by the school through device management, not by the student.
The extension runs only on ordinary web pages. It does not run on local files or on the browser's own internal pages, and it does not read network requests. Chrome requires broad site access for the screen-capture feature specifically; that access is limited in practice by the consent check above and by the fact that capture only happens during a session the student can see.
Changes to this policy
Material changes will be communicated to the schools that use Umbrelly. The date at the top of this page always reflects the current version.
Contact
Guardians and students: contact your school or district administrator, who can act on your request directly.
Schools, districts and privacy officers: contact Umbrelly through the address on your agreement, or through your Umbrelly representative.
A dedicated privacy contact address will be published here once support routing is in place.