Docs / COPPA / Student Data

COPPA / Student Data

A workspace pack on the same core masking engine — not a second SDK. When entitled, coppa_student is merged into enabled_packs and force-enables email, phone, and nationalId, plus pack-only studentId ([STUDENT_ID_n]) for Shield, SDK, and CLI --key scans. Policies dictionaries emit hard egress tokens [SCHOOL_TERM] and [PROGRAM_CODENAME] — never vaulted originals.

On this page+

What it does

  • Force-on via pack merge into enabled_packs — same resolution order as PCI / Financial, HIPAA / PHI, and Legal Privilege.
  • School / district and program-codename dictionaries from Dashboard → Policies sync through GET /v1/config (gated when the pack is not entitled).
  • Student / learner ID detector with education-file lexical context to limit false positives.
  • Telemetry can attribute pack-forced masks so Startup+ Audit Logs CSV/JSON evidence export shows industry pack provenance.

What it is not

  • Not a COPPA certification engine, parental consent manager, or age-gate product.
  • Not FERPA attestation or full student roster DLP.
  • Not network DLP — masking runs on-device / in-process before the model call.

Entitlement

  • Industry pack — $49/mo on Startup+ from Dashboard → Add-ons. Never plan-included (including Business+).
  • Developer must upgrade to Startup before Subscribe is available.
  • Ops can still grant via enterprise_grant for partners; when Active the pack appears in enabled_packs.
  • See also limitations and on-device architecture.