Compliance, in plain terms
The frameworks that protect students, how Slate meets them, and where to get the paperwork. The full policies live in the legal center.
COPPA
Students under 13 need verifiable parental consent and get restricted features. Parents can review and request deletion.
FERPA
Schools keep ownership of student education records. Slate processes them only on the school instruction.
GDPR
For EU and UK students: access, correction, deletion, portability, and the right to complain to a supervisory authority.
CCPA
California residents can know, delete, and opt out. Slate does not sell personal information.
Security
How we protect it
Encryption
Data is encrypted in transit and at rest.
Access controls
Least-privilege access with audit logging on sensitive actions.
Data ownership
Schools and students own their data and can export or delete it.
Disclosure
A coordinated vulnerability disclosure process with a response window.
Transparency
Who helps us run Slate
We use a small set of vetted sub-processors, and we keep this list current with notice of changes.
- Supabase (hosting + database)
- Stripe (payments)
- Resend (email)
- AI provider (assistant + grading)
Need the signed Data Processing Agreement, or a security question answered? Write to schools@slateapp.co.
View the DPA