VoiceBridge Student Privacy Policy
Effective Date: August 25, 2026 • Last Reviewed: August 2026
At VoiceBridge, we believe student privacy, emotional safety, and data security are foundational human rights. This Student Data Privacy Policy details our strict adherence to federal, state, and international student privacy regulations and explains how VoiceBridge operates with a zero-developer-server, zero-data-collection footprint for K-12 students, educators, and school districts.
1. Compliance with Student Privacy Regulations
VoiceBridge is designed from the ground up to comply with all major federal, state, and international student data privacy laws:
- FERPA (Family Educational Rights and Privacy Act — 34 CFR Part 99): VoiceBridge treats student voice recordings and comments as protected educational records. VoiceBridge operates as a designated "School Official" with a legitimate educational interest pursuant to 34 CFR § 99.31(a)(1)(i)(B). VoiceBridge performs an institutional service for which the educational institution would otherwise use its own employees, remains under the direct control and custody of the school district regarding the maintenance of education records, and will never redisclose or monetize student records. Audio files reside exclusively inside the student’s and district’s Google Workspace tenant.
- COPPA (Children’s Online Privacy Protection Act — 16 CFR Part 312): VoiceBridge does not collect, solicit, or maintain personal information directly from children under 13 for commercial purposes. Pursuant to Federal Trade Commission (FTC) guidance, educational institutions and teachers are authorized to consent to student use of educational software on behalf of parents for educational and instructional purposes.
- Zero Biometric Identifiers (BIPA & State Biometric Law Compliance): VoiceBridge records standard acoustic audio files solely for human playback and grading between students and teachers. VoiceBridge does NOT extract, generate, scan, process, or store "voiceprints", vocal geometries, voice biometric templates, or any biometric identifiers or biometric information as defined under the Illinois Biometric Information Privacy Act (740 ILCS 14/1 et seq.), the Texas Capture or Use of Biometric Identifier Act (Tex. Bus. & Com. Code § 503.001), or any other state or federal biometric privacy statute.
- GDPR & International Frameworks: VoiceBridge adheres to strict data minimization, storage limitation, and purpose limitation. No user data leaves the user's controlled cloud environment.
- State Student Privacy Acts (e.g., California SOPIPA, New York Ed Law 2-d, Colorado Student Data Transparency and Security Act): VoiceBridge strictly prohibits student behavioral profiling, commercial targeted advertising, and the sale or licensing of student information.
2. Zero-Developer-Database Architecture ($0 Developer Server Footprint)
Client-Side Direct Upload Architecture
VoiceBridge operates on a decentralized, serverless client architecture:
- No External Audio Servers: Student voice recordings are never sent to, routed through, or stored on developer-owned servers or third-party cloud databases.
- Direct Student Ownership: When a student records audio, the file is uploaded directly from the student’s browser to their own district Google Drive account into a folder named
VoiceBridge Recordings. - No Account Creation: Students and teachers do not create a separate VoiceBridge account, username, or password. Authentication is handled natively via Google Workspace Single Sign-On (SSO).
3. Permissions, Local Storage & Least-Privilege Scopes
VoiceBridge requests the absolute minimum permissions required to function:
- Google Drive API Scope (
https://www.googleapis.com/auth/drive.file):
What this means: VoiceBridge is granted permission only to access and create files that VoiceBridge itself created.
What VoiceBridge CANNOT do: VoiceBridge cannot read, list, view, modify, or delete any other files, folders, or documents in the student’s Google Drive. - Chrome Identity API (
identity): Used exclusively to request an OAuth2 access token directly from Google on the local device. This token is used strictly within the local browser runtime to authenticate the direct upload into Google Drive. The token is never logged, transmitted to, or stored on any external server. - Local Extension Storage (
storage): VoiceBridge utilizes Chrome extension local storage (chrome.storage.local) exclusively to store user interface and accessibility preferences (such as selected Lexend or OpenDyslexic typography, high-contrast visual themes, and playback speed). No personal information, student credentials, or audio recordings are stored in extension storage. - Microphone Access: Used solely in real-time to capture audio input during active recording sessions. Audio streams are discarded immediately upon file generation.
- Chrome Offscreen API (
offscreen): Used solely to host a local audio recording worker in compliance with Manifest V3 background service worker standards.
4. Absolute Prohibitions: No AI Training, No Advertising
- Zero AI Training: Student voice recordings, transcripts, or audio samples are NEVER used to train, fine-tune, or benchmark commercial AI models or speech recognizers.
- Zero Behavioral Advertising: VoiceBridge contains no advertisements, no tracking cookies, and no third-party marketing pixels.
- Zero Data Selling: VoiceBridge does not sell, lease, or trade student data under any circumstance.
5. Classroom Audio Recording & Wiretapping Consent
In compliance with federal and state audio recording and wiretapping laws (including two-party or all-party consent states such as California, Florida, Illinois, Pennsylvania, and Massachusetts), the deploying school district, educator, and user are responsible for ensuring that appropriate notice is provided and any legally required consents are obtained prior to initiating audio recordings in educational settings.
6. Data Retention & Deletion
Because all recordings reside in the student's own Google Drive account:
- The school district, student, or parent may delete recordings at any time directly through Google Drive.
- Recordings are subject to the district’s native Google Workspace data retention and archival policies.
7. District Inquiries & Contact Information
For questions regarding student data privacy, district Data Protection Agreements (DPAs), or accessibility compliance:
Email: privacy@voicebridge.app
Website: https://voicebridge-ext.web.app
GitHub Repository: https://github.com/andrewgitnersolutions/voicebridge