Student Data Privacy
Last updated: 2 October 2026
For school leaders, IT directors, teachers and parents. This page explains, in plain words, what happens to a student's information when their school uses MegaExams.
The short version
- The school owns its student data. We look after it on the school's behalf.
- We use it only to run exams and courses for that school.
- We never sell it, never show ads, never build marketing profiles, and never use it to train AI.
- It is stored on a DigitalOcean server in Bangalore, India. US hosting is available on request.
- When the school asks, or its contract ends, we delete it within 30 days and confirm in writing.
Who is responsible
MegaExams is operated by Goodfit Software LLC, a Delaware limited liability company, 254 Chapman Road, Ste 208 #23129, Newark, Delaware 19702, USA. Contact: prasanth@megaexams.com.
FERPA
For US schools, we act as a "school official" with a legitimate educational interest under FERPA (34 CFR 99.31(a)(1)(i)(B)). That means we work under the school's direct control over how education records are used, we use them only for the purpose the school gave us, and we do not pass them on to anyone else except the service providers listed below who help us run MegaExams. Parents and eligible students exercise their FERPA rights through the school.
COPPA
Where students are under 13, the school gives consent on behalf of parents, as the FTC allows when a service is used only for the school's educational purpose and not for any commercial purpose. That is the only way we use it. A parent can ask the school, or us, to review or delete their child's information at any time.
What we collect from students, and why
| Data | Why |
|---|---|
| Name and email address | To identify the student to their teacher and send sign-in codes. Students sign in with a one-time code sent by email; setting a password is optional. |
| Class or grade, school, city, phone (all optional) | Only if the student or teacher fills them in. Used for class lists and the rankings a teacher chooses to show. |
| Answers, scores, time taken | To mark the exam and show results to the teacher and, once the teacher releases them, to the student. |
| Messages during an exam, and course doubts | So a student can ask their teacher a question and get an answer. |
| Photos of handwritten answers, rough work or course doubts | Only when the student uploads them, so the teacher can mark or answer them. |
| Proctoring events (only if the teacher turns proctoring on) | Counts of tab switches, fullscreen exits, copy and paste, and the browser type, so the teacher can review exam integrity. |
| Webcam photos (only if the teacher turns webcam on) | A small still photo about every 45 seconds, for the teacher to look at. No video, no audio. |
| Approximate country and city | Worked out from the IP address using a database on our own server. We keep the country and city, not the IP address. Schools can switch this off. |
What we never do
- Sell, rent or trade student data.
- Show advertising to students, or use student data for targeted advertising.
- Build profiles of students for any purpose other than the school's own use of MegaExams.
- Use student data to train AI models. OpenAI, which powers our AI features, does not train on data sent through its API.
- Use face recognition, or score emotion, attention or behaviour from webcam photos.
- Record audio or video.
About webcam proctoring
Webcam proctoring is off unless a teacher turns it on for a specific exam. When on, the student's browser takes a periodic still photo for the teacher to review. A simple brightness check marks a frame that is almost completely dark (for example, a covered camera); this is not face detection. Teachers can choose "Let them in and flag it", so a student without a camera, or who declines, can still take the exam. No student is forced to use a camera. Webcam photos are shown only to signed-in teachers of the student's school; anyone else gets a "not found" page.
AI features
Teachers can use AI to write questions or import them from a document. When an exam has typed written (essay) answers, the answer text, with the question and rubric, is sent to OpenAI after the student submits, to suggest a score for the teacher. The student's name and email are not sent. A school can turn AI processing off, and then no student answer is ever sent to OpenAI.
Controls the school has
- Proctoring and webcam are off by default, and are set per exam.
- Leaderboards are off by default. When on, the teacher picks anonymised or named, and whether scores and school details show.
- Teachers choose when results are released to students; until then, students do not see scores.
- Deleted items go to a 30-day Trash, then are permanently deleted.
- An "AI processing" switch for the whole school.
- A webcam photo retention setting (new schools start at 90 days; each school chooses).
- A one-click export of the school's data: a ZIP of CSV files with students, attempts, results, answers, proctoring events and the list of webcam photos.
- "Delete all our student data" for the school owner: scheduled 30 days ahead so it can be cancelled, then permanent deletion, including files.
- An access and export log the school owner and admins can view.
- Schools can switch shareable scorecard links off; students still see their own results when signed in.
- An IP location switch for the whole school.
Where data is stored
All application data and uploaded files are stored on one DigitalOcean server in Bangalore, India (BLR1). We say this plainly because many US districts ask. If your district's policy or board requires US hosting, tell us before you start and we will host your school's data in the US.
Service providers
DigitalOcean (hosting, India), OpenAI (AI features, USA), Resend (email, USA), Microsoft Clarity (analytics with all student and teacher page content masked, USA), Google (fonts, sign-up spam check, and Google Classroom or video lectures only if a teacher uses them, USA), and public CDNs for page code. Full details are on the subprocessors page.
How long we keep it
- Student accounts and results: while the school's account is active.
- Items a teacher deletes: 30 days in Trash, then permanently deleted.
- Webcam photos: as the school sets; new schools start at 90 days.
- Server logs: about 14 days. Database backups: 7 days.
- At contract end or on the school's request: deleted within 30 days, confirmed in writing.
Access, correction and deletion
Parents and students: ask your school first, because the school controls the records. You can also email prasanth@megaexams.com; we will confirm the request with the school and act on its instructions.
Schools: email us from the school account owner's address and we will provide a copy of the data, correct it, or delete it within 30 days, and confirm in writing.
If something goes wrong
If we confirm a security breach that affects a school's data, we will notify the school within 72 hours, with what happened, what data was involved, and what we are doing about it. See our security page.
A note for Idaho schools
Idaho Code 33-133 requires a written contract with security controls, data destruction timeframes, and a ban on secondary use, sale and targeted advertising. We will sign your Student Data Privacy Agreement (the SDPC National DPA through IDSPA, or your own) covering all of these. Idaho law also bans collecting biometric and affective computing data on students. MegaExams does no face recognition and no emotion or attention scoring, but webcam proctoring does take photos of students. Our advice: Idaho schools should leave webcam proctoring off, or confirm with their counsel before using it.
Signing a data privacy agreement
We sign the SDPC National Data Privacy Agreement, state DPAs, and district-specific agreements. Email prasanth@megaexams.com and we will send our addendum or sign yours.
Related
IP geolocation by DB-IP (https://db-ip.com).