Student privacy

Student privacy

Last updated August 7, 2026

A firearm detection system on a school's cameras will photograph students. That is the whole of the student privacy question here, and everything on this page follows from it.

The short answer: we hold no education records, build no profile of any student, run no biometrics, sell nothing, and advertise to nobody. The district decides what is kept and for how long, and can tell us to delete it.

Contents and other documents

1.The commitments, first

Everything below elaborates on these. If you read nothing else, read these.

No advertising, ever
We show no advertising to anyone, target none, and there is no advertising technology anywhere in this product or on this website. Nothing from a school ever informs an advertisement.
No student profiles
We build no profile of any student for any purpose other than the incident a frame belongs to. Nothing follows a student across incidents, across cameras on different days, or across school years.
No sale of student information
We do not sell, rent, trade, or otherwise disclose student information for consideration. There is no circumstance in which a school's data becomes a product.
No biometrics
No face recognition, no gait analysis, no template, no identifier generated from a student's body at any point.
The district stays in control
Student information is processed on the district's instruction, is deleted when the district says so, and does not survive the relationship except where the district's own records require it.

2.What this page covers

This page is for districts, schools, and the parents and students at them. It describes how a firearm detection system operating on a school's own cameras handles the one category of student information it can encounter.

For a school customer these commitments are contractual. They are incorporated into the data processing agreement through its schools addendum, which is what a school accepts at setup. The general handling of personal data is in the privacy policy, and this page adds to it rather than replacing it.

3.School-official status under FERPA

Where a school or district uses the service, we act as a school official with a legitimate educational interest under the Family Educational Rights and Privacy Act, on the criteria at 34 CFR 99.31(a)(1)(i)(B). Each of the four criteria, and how it is met:

An institutional service or function
Watching the school's own cameras for a visible firearm and telling the school's own staff. It is a safety function the district would otherwise perform with its own employees watching the same screens.
A function the school would otherwise use employees for
The alternative is a person watching a monitor wall. The service does not do anything a district could not do itself, more slowly.
Under the school's direct control
The district decides which cameras exist, where they point, who is notified, what escalates, how long frames are kept, and when data is deleted. We act on the district's configuration and its written instructions, and on nothing else.
Subject to the redisclosure limits
34 CFR 99.33(a) applies to us. What that means in practice is set out below.

The district is responsible for stating in its annual FERPA notification that it uses contractors as school officials, and for defining legitimate educational interest in its own policy. We will provide whatever description of the service that requires.

4.What we receive, and what we do not

We receive no education records. No student roster, no name list, no grade, no schedule, no attendance record, no discipline record, no individualized education program, no health record, no identification number. There is no integration with a student information system, and none is offered.

The roster we hold is of adults: the staff, administrators, and responders a district designates to receive alerts, with their names, work phone numbers, and email addresses.

The one category that can contain a student is a detection frame. A camera in a hallway will photograph whoever is in the hallway. That cropped still is attached to the detection, carries no name, is matched against nobody, and is used only for the incident it belongs to. Where such a frame is an education record because it is maintained by the district and directly relates to a student, it is handled as one.

5.Redisclosure

Under 34 CFR 99.33(a) we may not redisclose information from an education record except on the district's behalf and as the district directs. Every path by which a frame from a school camera can reach anyone outside the district is one the district switched on:

The district's own roster
The staff it designated. Not a redisclosure outside the school.
A dispatch provider
Only where the district enabled emergency dispatch, and only for a real incident. A drill never reaches an outside agency.
A law-enforcement agency the district linked
Established by us at the district's direction, visible in the district's audit log, and removed when the district says so.
A share link a district employee created
Scoped to one incident, expiring, revocable, watermarked, and every view recorded in the district's audit log.

We do not disclose to anyone else, and we do not use a frame for any purpose of our own. The district's audit log records each of these disclosures, which is also the record FERPA expects a district to be able to produce.

If we receive a subpoena or other legal demand for information in a district's account, we will notify the district before responding unless we are legally prohibited from doing so, so that the district can respond or object.

6.No use of directory information

We receive no directory information and would have no use for it. Nothing from a school is used for marketing, for a case study, for a reference, or for any communication to students or families. We do not publish a district's name, logo, or incident unless the district asks us to.

7.No profile of a student is built

This is the commitment that most often turns out to be qualified elsewhere, so it is worth stating precisely. Within one incident, the system associates a moving figure across frames and cameras so that a trail can be reconstructed for the people responding. That association is geometric. It computes no identity, and it ends when the incident does.

Nothing links a person in one incident to a person in another. There is no field in the data model in which such a link could be recorded, which is a stronger statement than a policy: it is not that we choose not to, it is that there is nowhere to put it.

We produce no behavioural analytics, no risk scores, no discipline reporting, no attendance inference, and no dashboard that describes students rather than incidents.

8.Parents and eligible students

Rights of inspection, review, and correction under FERPA run against the school, not against us. A parent or eligible student who wants to see what is held should ask the district, which controls the data and can direct us.

When a district asks, we will help it locate and produce what it holds, in a form it can share. If a parent writes to us directly, we will tell them this and refer them to the district rather than acting on our own, because acting on a request from someone the district has not verified would itself be a disclosure.

9.Children under 13

The service is not directed to children and creates no student accounts. Accounts are held by adults acting for the district, and holding one requires being at least 18. There is no student-facing interface, no login for a student, and nothing a child interacts with.

A camera at an elementary school will see children under 13. Where that happens, we process on the school's behalf and under its direction as its service provider, and the school provides any notice or consent its own obligations require, as the Children's Online Privacy Protection Act contemplates for a school acting for parents in the educational context. We collect nothing directly from a child, use nothing for advertising, and retain nothing beyond what the district's retention setting and its instructions allow.

10.State student-privacy laws

A number of states impose obligations on school service providers that go beyond FERPA. The commitments those laws typically require are ones we make to every school customer regardless of state:

No targeted advertising
None to students, none to parents, none informed by anything a school camera saw.
No profile for a non-school purpose
No profile is built at all, for any purpose beyond the incident.
No sale of student information
Including in a merger or acquisition, where any successor is bound by these same commitments.
Deletion at the district's direction
On written instruction, and on termination, subject only to the audit-log limit described below.
Security appropriate to the data
The measures in the data processing agreement, which name what is actually in place rather than a category.
Notice of a breach
Without undue delay and within 72 hours, with assistance to the district in meeting its own notification duties.

Where a state requires registration on a vendor list, prescribed contract language, a signed state addendum, or annual reporting, that is the district's to identify and ours to sign. Tell us what your state requires and we will complete it.

11.Retention and deletion

A district administrator sets how long detection frames are kept, in days, between seven and 3650. Frames older than that are removed on a sweep that runs hourly. No schedule runs until the district sets one, and nothing in the service changes it afterwards.

On termination, or on written instruction at any time, we delete or return the district's data. Two carve-outs, both stated in advance rather than discovered later:

Frames that became evidence
A frame from an incident that escalated, reached an emergency provider, or was exported into an evidence package is retained past a retention period so the exported record stays reproducible. A district can still instruct us to delete it.
The audit log
It is append-only and hash-chained so an exported incident timeline can be shown to be intact, and no single entry can be removed without destroying that property for every entry after it. Deleting an account removes its log in whole. If your obligations require per-entry erasure, tell us before you deploy, because we cannot meet that.

12.Security

The measures are listed specifically in security measures in the data processing agreement. The three that matter most to a school: video is analysed inside the building and never transmitted, so there is no cloud recording of a hallway to breach; a camera password is sealed on entry and erased once the appliance has it, so we hold no credential that could open a school's stream; and a link to a frame is signed, scoped to one image, and expires in hours.

13.Contact

A district privacy officer, a technology director, or a parent referred by a district can write to privacy@optiarms.com. Security questions go to security@optiarms.com, and contract or addendum questions to legal@optiarms.com.