Privacy Policy

Last updated: August 5, 2026

1. Introduction

Ladderly Learning ("Ladderly", "we", "our", or "us") operates a web application that helps school districts manage Multi-Tiered System of Supports (MTSS) and Response to Intervention (RTI) programs. This Privacy Policy explains how we collect, use, disclose, and protect information about the students, educators, and other individuals whose data is processed through our service.

By accessing or using Ladderly, you agree to the practices described in this policy. If you do not agree, please do not use our service.

Districts with a signed agreement. Where a district has executed a Subscription Agreement, Order Form, or state-specific student privacy addendum with us, that agreement governs our handling of that district's data and controls over this policy in the event of any conflict. This page describes our general practices; your district's agreement describes what we owe your district.

2. Information We Collect

We collect the following categories of information:

  • Account information — name, email address, and school or district affiliation provided when you register or sign in via Google OAuth.
  • Student records — referral data, intervention plans, assessment results, and meeting notes entered by authorized school staff.
  • Usage data — pages visited, features used, and approximate access times, collected to improve reliability and performance.
  • Cookies and local storage — session tokens and preferences necessary to keep you signed in and remember your settings.

3. How We Use Information

We use the information we collect to:

  • Provide, maintain, support, and improve the Ladderly platform;
  • Authenticate users and enforce role-based access controls within each school district;
  • Store and retrieve student MTSS and RTI records on behalf of authorized school staff;
  • Respond to district requests for technical support or troubleshooting;
  • Send transactional emails (e.g., password resets, meeting notifications);
  • Perform data security and integrity functions; and
  • Comply with applicable legal obligations, including responding to lawful government orders or subpoenas. Where we receive such an order relating to a district's data, we will notify that district promptly and in advance to the extent the law permits.

4. What We Never Do

We commit that we do not:

  • Use student data to train artificial intelligence or machine learning models. We do not use student data to train, fine-tune, or improve any AI or ML model — whether operated by us or by any third party — without the district's prior written consent.
  • Sell, rent, lease, or trade student data;
  • Use student data for advertising or marketing, including targeted advertising directed at students or their families;
  • Build or augment a profile of a student beyond what is necessary to provide the service; or
  • Re-disclose student data to any third party except as described in this policy or as directed in writing by the district.

5. De-Identified and Aggregate Data

We may derive, retain, and use de-identified and aggregated data from district data for product research and development, platform improvement, benchmarking, and statistical or analytical reporting. De-identification is performed consistent with applicable law, including the standards under FERPA at 34 C.F.R. § 99.31(b), so that the data cannot reasonably be used to identify an individual student. We do not attempt to re-identify de-identified data.

Aggregate reports or findings derived from this data may be published or shared with third parties only where no individual student, district, or other individual is identifiable from those reports.

6. Sharing, Disclosure, and Subprocessors

We do not share personal information with third parties except in the following circumstances:

  • Service providers — infrastructure and email delivery partners who process data solely on our behalf and under appropriate data processing agreements;
  • Legal requirements — when disclosure is required by law, court order, or to protect the rights and safety of our users; and
  • School district — authorized administrators of your school district may access records entered by staff within their organization.

Our current subprocessors are:

  • Google Cloud Platform (Google LLC, United States) — primary cloud infrastructure. Hosts the application environment, databases, storage, and backups. All district data, including student data, resides in GCP infrastructure in the United States.
  • GitHub (GitHub, Inc., United States) — source code repository and deployment workflows. GitHub does not have access to district data or student data in the ordinary course.
  • PostHog (PostHog, Inc., United States) — product analytics and usage monitoring, configured to collect only the minimum data necessary. We do not transmit student data or personally identifiable information about students to PostHog.

7. Where Data Is Stored

District data, including student data, is hosted in data center facilities located within the United States. We provide districts with at least thirty (30) days advance written notice before any material change to the geographic location of the primary data centers used to host their data.

Where state law imposes additional restrictions on transferring student data outside the state, we address those restrictions in a state-specific addendum executed with the district.

8. Data Retention, Return, and Deletion

We retain account and student data for as long as your district maintains an active subscription with Ladderly, and for a reasonable period thereafter to comply with legal obligations or resolve. You may request deletion of your individual account by contacting us at the address below.

9. Security

We maintain a written information security program (WISP) aligned to the NIST Cybersecurity Framework 2.0, reviewed and updated at least annually and following any confirmed security incident. It includes administrative, technical, and physical safeguards, among them:

  • Encryption of data in transit using TLS 1.2 or higher, and at rest using AES-256 or an equivalent industry-standard algorithm;
  • Role-based access controls limiting access to district data to personnel with a documented need, granted on a least-privilege basis and reviewed on role change or separation;
  • Centralized logging and monitoring of access to systems that store or process district data, with logs retained for a minimum of 90 days in hot storage and one year in archival storage;
  • A secure software development lifecycle with mandatory peer review of production code changes and environments logically separated from production;
  • Background screening, confidentiality agreements, and recurring security awareness training for personnel with access to district data;
  • Logical segregation of each district's data from that of other customers, with encrypted backups stored in geographically redundant United States locations and restoration tested at least annually.

No method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security. A summary of our current security practices is available to districts on written request.

10. Security Incident Notification

We maintain a written incident response plan, reviewed and tested at least annually, designed to detect, contain, investigate, and remediate unauthorized access to or loss of district data.

We notify affected districts of a confirmed or reasonably suspected security incident involving their data without unreasonable delay and no later than seventy-two (72) hours after we confirm the incident, or sooner where applicable state law or an executed state addendum requires it. Our notice describes the nature of the incident, the categories and approximate volume of data involved, the approximate date and time, the steps we have taken or propose to take, and a designated contact for ongoing communications. We provide a written summary of our investigation findings and corrective actions within thirty (30) days of confirming the incident.

Districts retain responsibility for determining whether an incident triggers notification obligations to students, parents, or government agencies, and we provide reasonable assistance with those notifications.

11. Student Privacy (FERPA, COPPA, and State Law)

Ladderly processes student education records on behalf of schools and districts. Districts designate us as a school official with a legitimate educational interest under the FERPA school official exception, 34 C.F.R. § 99.31(a)(1), and we are bound by the limits on use and re-disclosure in 34 C.F.R. § 99.33(a). We access and use student data only to provide the service and fulfill our obligations to the district, and for no other purpose.

Student data is processed solely at the direction of, and under the authority of, the school or district that controls the records, consistent with FERPA and the Children's Online Privacy Protection Act (COPPA).

State student privacy statutes may impose additional obligations beyond federal law. We comply with applicable state student privacy laws in our role as a third-party operator or service provider, and we execute state-specific addenda with districts where their state law requires it. Those addenda control over this policy with respect to the obligations they address.

12. Parent and Student Rights

School districts retain responsibility for responding to requests from parents and eligible students exercising their rights under FERPA and applicable state law, including rights to inspect, review, correct, or delete education records. We cooperate with districts in fulfilling those requests, including by making the relevant student data available to the district in a timely manner. We do not respond directly to parents or students regarding student data except as directed in writing by the district or as required by applicable law.

If you are a parent or guardian seeking access to your child's records, please contact your school district's data privacy officer.

13. Your Rights

Depending on your jurisdiction, you may have the right to access, correct, or delete personal information we hold about you. Requests relating to student records should be directed to your school district's data privacy officer in accordance with FERPA. Requests relating to your own account information may be sent directly to us.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the revised policy with an updated "Last updated" date. Continued use of the service after changes take effect constitutes acceptance of the revised policy. Changes to this policy do not modify a signed Subscription Agreement or addendum, which can be amended only in writing by both parties.

15. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at:

Ladderly Learning
343 E 4th N STE 217
Rexburg, ID 83440
Email: support@ladderlylearning.com