Privacy Policy.

Last updated: June 25, 2026

CoPilot Data Solutions LLC ("CoPilot Data," "we," "us," or "our") provides a software-as-a-service platform that helps Texas public school districts manage and analyze state accountability data. This Privacy Policy explains how we handle information when you visit our marketing website at https://www.copilotdata.com, when our platform at https://connect.copilotdata.com is used by school districts and their staff, and when parents or guardians use our text-message (SMS) assistant.

This policy is intended to be read together with the agreements we sign with each school district, including any Data Privacy Agreement (DPA), and together with our separate Terms and Conditions at https://www.copilotdata.com/terms-and-conditions and our SMS Terms of Use at https://www.copilotdata.com/sms-terms, which govern the mobile messaging program. Where a school district has signed a DPA with us, that DPA controls over this Privacy Policy with respect to student and education data. See Section 17 (Order of Precedence).

1. Who We Are

CoPilot Data Solutions LLC is a Texas limited liability company, classified for federal tax purposes as an S corporation (effective January 1, 2026) and treated as a single-member LLC under Texas law.

  • Legal entity: CoPilot Data Solutions LLC, a Texas S corporation
  • Address: 608 E Hickory St, Ste 128, Denton, TX 76205
  • Contact email: info@copilotdata.com
  • Phone: (817) 752-4766
  • Marketing site: https://www.copilotdata.com
  • Application: https://connect.copilotdata.com
  • Privacy Policy: https://www.copilotdata.com/privacy-policy
  • Terms and Conditions: https://www.copilotdata.com/terms-and-conditions
  • SMS Terms of Use: https://www.copilotdata.com/sms-terms

Our customers are Texas public school districts. We sell our platform business-to-business; we do not sell a product directly to students, parents, or guardians.

2. Our Roles and the Two Categories of Data

We handle two distinct categories of data, and our role differs for each.

2.1 District and Student Data (we are a service provider / processor)

This is the data a school district provides to us, or that is generated through the district's use of our platform, including student education records and personally identifiable information (PII). For this category:

  • The school district owns and controls all of its student education records and is the data owner and controller. We do not own or control District and Student Data.
  • We act solely as a service provider, performing an institutional function that the district would otherwise perform using its own employees.
  • For purposes of the Family Educational Rights and Privacy Act (FERPA), we are a "school official" with a legitimate educational interest under the district's annual FERPA notification of rights (20 U.S.C. 1232g(b)(1)(A); 34 CFR 99.31(a)(1)(i)(B)).
  • Under the Texas Student Privacy Act (Texas Education Code Chapter 32, Subchapter D), we are an "operator."
  • Under the Texas Data Privacy and Security Act (TDPSA), we act as a "processor."

We process District and Student Data only on the district's behalf and under its documented instructions, and only for the authorized educational purpose described in Section 5.

2.2 Website, Account, and Parent Messaging Data (we are the controller)

This is the data we collect directly through our marketing website, through the administration of district staff accounts, and through our parent/guardian SMS assistant, such as contact details, login information, website usage data, parent/guardian mobile phone numbers, and the content of text messages exchanged with the assistant. For this limited category, CoPilot Data is the controller. This category does not include student education records, which remain District and Student Data under Section 2.1.

3. Direct Control by the District

We operate under the direct control of each school district with respect to the use and maintenance of education records (34 CFR 99.31(a)(1)(i)(B)). The district determines how its records are used, maintained, retained, and disclosed.

We will not unilaterally or silently change the way we handle District and Student Data in a way that conflicts with a district's instructions or its DPA. Material changes to our data-handling practices or to this Privacy Policy are communicated to districts and clearly flagged, not buried (see Section 16). This protects each district's ability to demonstrate the direct control that FERPA requires.

4. Information We Process

4.1 District and Student Data

Working on behalf of districts, we process:

  • Student education records and PII for K-12 students
  • STAAR and end-of-course (EOC) assessment results
  • A-F accountability ratings data
  • College, Career, and Military Readiness (CCMR) data
  • Student enrollment and roster data
  • Student photographs
  • District staff account information

Under Texas Education Code 32.151, "covered information" expressly includes test results, photographs, voice recordings, geolocation, text messages, and student identifiers. Accordingly, assessment data, student photographs, and SMS message content tied to a student are "covered information" and receive the full protections of Chapter 32.

4.2 SMS Assistant Data

For the parent/guardian SMS assistant (see Section 7), we process:

  • Parent/guardian mobile phone numbers
  • The content of text messages exchanged with the assistant
  • Mobile opt-in and consent records

4.3 Website Data

When you visit our marketing site, we may collect standard usage and device information (such as IP address, browser type, and pages viewed) and any information you submit through contact or demo-request forms.

5. How We Use Information — Purpose Limitation

We use PII from education records only for the purposes for which the district disclosed it to us — namely, to deliver and support the contracted accountability-analytics and SMS services for that district — and for no other purpose (34 CFR 99.31(a)(1)(i)(B)(1); 34 CFR 99.33(a)(2); Texas Education Code 32.154).

We make the following affirmative commitments regarding student data:

  • We do not sell or rent student PII or covered information.
  • We do not use student data for targeted advertising.
  • We do not build non-educational profiles of students.

These commitments are explained further in Section 6.

6. What We Do Not Do With Student Data

6.1 No sale or rental of covered information

We do not, and will not, sell or rent any student's covered information or PII (Texas Education Code 32.152(a)(3)).

The only exception is the narrow successor-in-interest exception permitted by Texas Education Code 32.152(c): the transfer of student covered information to a successor entity in connection with a merger, acquisition, bankruptcy, or other acquisition or sale of all or a portion of CoPilot Data Solutions LLC. Such a transfer is permitted only if the successor entity continues to be subject to the same commitments and obligations with respect to that covered information as those set out in this Privacy Policy and in the applicable district DPA. We will not use this provision as a route to a general data sale. Any such transfer involving a district's student data will be handled consistent with the district's DPA, including the TX-NDPA's successor-and-assignment provisions, and the district retains the right under that DPA to disapprove the successor and terminate if it does not consent to the assignment.

6.2 No targeted advertising

We do not use covered information or PII (including persistent identifiers) to engage in targeted advertising to students or their parents, and we do not allow any third party to do so using data acquired through the service for a school purpose. "Targeted advertising" means presenting advertisements selected based on information obtained or inferred over time from a student's online behavior, usage, or covered information (Texas Education Code 32.151, 32.152(a)(1)).

6.3 No non-educational profiling

We do not amass covered information to build a profile about a student except for a school purpose. We will not create profiles for advertising or for any commercial purpose unrelated to the contracted educational service (Texas Education Code 32.152(a)(2)). Adaptive, customized, and personalized academic recommendations made to support a student's education — including the academic-progress replies sent through the SMS assistant — are a permitted school purpose and are not "profiling."

6.4 No use of student data to train AI models

Student PII and SMS message content are not used to train or fine-tune any machine-learning or artificial-intelligence model. Our AI sub-processors are one or more third-party AI / large-language-model providers that process content transiently through their application programming interfaces (APIs) solely to generate a response, and they are contractually prohibited from retaining that content for, or using it in, model training. We identify our current AI providers to each school district in the Data Privacy Agreement and notify the district of material changes. This keeps the SMS feature within the "authorized educational purpose only" boundary required by FERPA, COPPA, and Texas Education Code Chapter 32.

6.5 No secondary monetization

Student data is never used to train advertising systems, sold or shared via data brokers, or combined with non-educational datasets — even in de-identified form — beyond the limited, disclosed product-improvement uses described in Section 12.

7. The Mobile Messaging (SMS) Assistant

The mobile messaging program is also governed by our separate SMS Terms of Use at https://www.copilotdata.com/sms-terms, which set out the program description, opt-in welcome message, message frequency, rate disclosures, and STOP/HELP instructions in full. This Section 7 summarizes the privacy-relevant terms.

7.1 How it works

Each district is assigned a dedicated sender phone number that parents and guardians can text to ask about their own student's academic progress and state assessment results. An automated AI assistant replies and can connect the texter to district staff. Parents and guardians opt in directly — they initiate contact or affirmatively sign up themselves — and we send messages only to people who have opted in or who text us first. CoPilot Data and our messaging carrier (Twilio) do not send unsolicited program messages. The district configures the program for its campuses and supplies the parent/guardian contact information used for the identity-verification gate described in Section 7.4.

7.2 What we collect for SMS

We collect the parent/guardian mobile phone number, the content of the messages exchanged, and opt-in/consent records. We use this information only to operate the SMS service and to connect users to district staff.

7.3 Consent and authorization are separate things

Two different authorizations apply to the SMS feature, and they are not the same thing. Both must be satisfied before any student-specific text is sent, and one is never treated as standing in for the other:

  1. Consent to be texted (TCPA prior express consent). Sending automated texts to a mobile number requires the recipient's prior express consent under the Telephone Consumer Protection Act (TCPA). For our program, the parent or guardian provides that consent directly by opting in or by texting first. Consent is captured per program (per district) and is not shared across districts or other senders. We retain a record of the opt-in, including the date, method, and scope. We send messages only to numbers that have opted in or that initiate contact.
  2. Authorization to receive a given student's records (FERPA). Being opted in to receive texts is not the same as being authorized to receive a particular student's education records. The right to receive a specific student's records is a separate question, governed by FERPA and the district's school-official designation, and it is enforced by the identity-verification gate in Section 7.4. A parent's opt-in to messaging does not, by itself, authorize disclosure of any student's records; the texter must additionally pass identity verification for that specific student.

For students under 13, the district's school authorization additionally serves as the COPPA consent basis for our collection and use of the student's information through the service (see Section 13).

7.4 Identity verification and FERPA disclosure scope

Responding to a texter with a specific student's education records is itself a FERPA disclosure that occurs under the district's authority (34 CFR 99.31(a)(1); 34 CFR 99.33(a)). Before disclosing any student-specific information, the assistant verifies that the texter is an authorized parent, guardian, or eligible student for that specific student by matching the incoming mobile number against a parent/guardian contact number the school district has on file for that student and completing a one-time passcode (OTP) challenge sent to that number. If the number is not on file, or the OTP is not satisfied, the assistant discloses no student records and routes the texter to district staff. The assistant discusses only that student's own records and connects users to district staff for anything beyond the authorized scope. We do not ship or operate the SMS assistant for a district without this verification gate in place.

7.5 AI-generated responses

Replies from the SMS assistant are generated by a third-party AI / large-language-model provider for informational purposes. They may contain errors and are not a substitute for the district's official records or for advice from district staff. For authoritative answers, contact your district.

7.6 Mobile messaging consent and your choices

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing with subcontractors in support services, such as customer service, is permitted. All other use case categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third party.

Additional terms for the messaging program (see also the full SMS Terms of Use at https://www.copilotdata.com/sms-terms):

  • Program description: CoPilot Data Solutions, on behalf of your school district, sends text messages so that parents and guardians can ask about their own student's academic progress and state assessment results and be connected to district staff.
  • Brand and registration: Messages are sent under the single registered messaging brand of CoPilot Data Solutions LLC (EIN 90-2837534), operating one A2P 10DLC messaging campaign with a dedicated sender number assigned to each district from our number pool. CoPilot Data acts on behalf of, and provides the service to, each district. Consent you give is specific to your district's program and is not shared across districts or other senders, consistent with the 2025 FCC rule that opt-in consent is per-sender and may not be shared.
  • Opt-in and welcome message: You provide consent to receive texts directly, by opting in or by texting first; consent is never a condition of any school service. After you opt in, the first message you receive identifies the CoPilot Data / district program name and purpose, states that message frequency varies, states that "Msg & data rates may apply," and tells you that you can reply STOP to cancel and HELP for help.
  • Message frequency: Message frequency varies.
  • Cost: Message and data rates may apply for any messages sent to you from us and to us from you. Contact your wireless provider with questions about your text or data plan.
  • Quiet hours: Except for a message you yourself initiate (to which we may reply in real time), program messages are sent only between 8:00 a.m. and 9:00 p.m. in the recipient's local time zone, consistent with TCPA quiet-hours restrictions.
  • Opt out: You can cancel the SMS service at any time by replying STOP. After you send STOP, we will send a one-time message to confirm that you have been unsubscribed, and you will no longer receive messages from the program. We honor STOP requests as soon as practicable and no later than 10 business days after receipt, consistent with the 2025 FCC opt-out rule. STOP synonyms (such as CANCEL, END, QUIT, UNSUBSCRIBE, OPT-OUT, and REVOKE) are also honored.
  • Help: Reply HELP for help, or contact us at info@copilotdata.com or (817) 752-4766.
  • Carrier disclaimer: Carriers are not liable for delayed or undelivered messages.
  • Availability: The SMS service is provided on an as-is basis and may not be available in all areas, at all times, or on all carriers.

Parent/guardian phone numbers and message content are processed only to operate this service. They are never sold and are never used for marketing.

8. How We Disclose Information and Our Sub-Processors

We do not disclose or redisclose PII from education records to any other party without the prior written authorization of the district, except as otherwise permitted by FERPA or required by law (34 CFR 99.33(a)(1)). If we are compelled by law to disclose student data, we will notify the district before disclosure unless legally prohibited from doing so.

We use the following sub-processors and infrastructure providers to deliver the service:

Sub-processorFunctionNotes
Google Cloud Platform / FirebaseHosting, database, file storageData stored in the United States (us-central1 region)
TwilioSMS message deliveryProcesses phone numbers and message content to deliver texts at the district's direction
Third-party AI / large-language-model provider(s)AI natural-language processing of messagesProcesses content via API; contractually bound not to train on or retain the data; current providers identified to districts in the DPA

Each sub-processor is bound by a written agreement that flows down our obligations to it, requiring confidentiality, security, purpose limitation, no AI-model training on the data, and no onward redisclosure, and permitting the sub-processor to use the data only to provide services to us (Texas Education Code 32.153, 32.155). The AI providers process content via their APIs and do not train their models on the data. We maintain this list and will notify districts of material changes to it.

8.1 United States data residency

All District and Student Data, and all SMS phone numbers and message content, are stored and processed within the United States on Google Cloud / Firebase in the us-central1 region. We do not store student covered information or SMS data outside the United States, consistent with our DPA commitments (including TX-NDPA Article V). Where a sub-processor could route data outside the U.S., we configure the service to keep the data in U.S. regions, and we will not change that configuration in a way that conflicts with a district's DPA.

9. Data Security

We maintain a written information-security program with administrative, technical, and physical safeguards appropriate to the sensitivity of the data (Texas Education Code 32.155; 16 CFR 312.8 as amended, including the 2025 COPPA amendments). These include:

  • Encryption of data in transit and at rest
  • Access controls that limit access to authorized personnel with a legitimate need to know, using least-privilege principles and authentication controls
  • A written information-security program with regular risk assessment and monitoring of our systems, reviewed and updated on a periodic basis
  • A designated individual responsible for coordinating the information-security program
  • Identity verification safeguards for the SMS assistant, including mobile-number matching and a one-time passcode challenge before any student-specific disclosure (see Section 7.4)
  • Tenant isolation and access segregation so that each district's data is logically separated and accessible only to that district and to authorized CoPilot Data personnel

Our security program follows widely recognized information-security practices for handling sensitive student data. CoPilot Data does not currently hold a third-party security certification or attestation such as SOC 2 (Type I or Type II) or ISO/IEC 27001, and we do not represent that we hold any such certification. We will update this section if that status changes.

9.1 Audit and assessment cooperation

On a district's request, we will make summary results of any security assessment we have conducted available to that district. In addition, consistent with TX-NDPA Article V.2, a district (or its designated auditor) may, under a reasonable nondisclosure agreement and on reasonable advance notice, audit our compliance with the security and privacy obligations applicable to that district's data once per year, and additionally following a security incident affecting that district's data. We will cooperate reasonably with any such audit.

10. Data Breach Notification

If we discover or are notified of a security incident or breach involving student PII, we will notify the affected district within 72 hours of confirming the incident, consistent with the TX-NDPA, unless a law-enforcement agency directs a delay. Our notice will describe what was involved, the date or date range of the incident, the remediation taken, and the steps to protect affected individuals. Where the applicable DPA (including the TX-NDPA) specifies a shorter notification requirement, that shorter requirement controls (see Section 17).

We will cooperate with the district's breach-response and notification obligations, including a Texas district's obligations to report to the Texas Education Agency and to affected parents (Texas SB 820; Texas Business & Commerce Code Chapter 521).

11. Data Retention and Deletion

We retain student PII only as long as necessary to provide the contracted service or as the district directs — not indefinitely.

  • On a district's request, or upon termination or expiration of the district's contract, we will delete or return the student covered information under the district's control, at the district's election.
  • Consistent with Texas Education Code 32.156, we will delete a student's covered information within 60 days of a district's deletion request, unless the contract specifies otherwise or the parent or eligible student consents to retention.
  • We can provide written certification of destruction on request.
  • Properly de-identified or aggregated data, and routine backup or archive copies subject to a rolling purge, may be retained as described in Section 12 and our backup-retention schedule.

For the SMS assistant, phone numbers and message content are retained only as long as needed to provide the service, and are deleted within 60 days after the district's contract ends or upon request (whichever comes first), on the same basis as other data under the district's control.

12. De-Identified and Aggregate Data

We may use de-identified or aggregate data to maintain, support, evaluate, and improve the service and to demonstrate its effectiveness, consistent with FERPA (34 CFR 99.31(b)) and Texas Education Code 32.154. When we do:

  • The data is de-identified using reasonable methods so that a student's identity is not personally identifiable.
  • We will not attempt to re-identify de-identified data, and any party to whom we transfer de-identified data is contractually barred from attempting to re-identify it.

13. Children's Privacy and COPPA

Because our platform processes the records of K-12 students, including students under the age of 13, the federal Children's Online Privacy Protection Act (COPPA) applies.

For students under 13, we rely on the school/district's authorization (with the district acting as agent for the parent) as the COPPA consent basis. This basis is valid only because the data is collected and used solely for the school-authorized educational purpose and for no other commercial purpose. Consistent with COPPA and the FTC's COPPA Rule (16 CFR Part 312, including the 2025 amendments effective June 23, 2025, with full compliance required by April 22, 2026):

  • We provide each district the COPPA-required notice of our data-collection and -use practices.
  • We give the district the ability to review the children's personal information we hold and to request its deletion.
  • We maintain a written data-retention policy for children's personal information, retain that information only as long as reasonably necessary for the educational purpose for which it was collected, and delete it when that purpose is fulfilled (16 CFR 312.10).
  • We maintain a written information-security program for children's personal information, including the safeguards described in Section 9 (16 CFR 312.8).
  • We do not disclose a child's personal information to a third party except to the sub-processors listed in Section 8, who act only to provide the service to us and are bound by written agreements that flow down our confidentiality, security, purpose-limitation, no-AI-training, and no-onward-disclosure obligations. We do not disclose children's personal information to any third party for that third party's own purposes; if we ever sought to do so, we would first obtain the district's separate, specific authorization for that disclosure, consistent with the 2025 amendments' separate-opt-in requirement for third-party disclosures.
  • We do not engage in targeted advertising or commercial profiling, and we do not condition the educational service on the collection of more information than is reasonably necessary.

We acknowledge that any targeted advertising, commercial profiling, undisclosed third-party disclosure, or failure to provide the required notice and review-and-delete ability would void our ability to rely on school consent.

14. Minimum Necessary Data Collection

We collect only the minimum student PII needed to perform the contracted function (data minimization), consistent with COPPA's collection-limitation principle and recognized education-privacy best practice (16 CFR 312.7, 312.10).

15. How Parents, Guardians, and Districts Exercise Their Rights

15.1 Parent and eligible-student rights run through the district

FERPA gives parents — and "eligible students" (students who are 18 or older, or who attend a postsecondary institution) — the right to inspect and review, and to seek amendment of, the student's education records (20 U.S.C. 1232g(a)(1)(A); 34 CFR 99.10–99.12, 99.20–99.22). These rights are exercised through the school district, not through CoPilot Data.

We do not respond to parent or eligible-student record-access or correction requests directly. If we receive such a request, we route it to the district. We support the district by making the records we hold available to it so the district can verify the requester's identity and respond (generally within 45 days, as FERPA requires; sooner where a Texas district's DPA or state law sets a shorter window).

15.2 Transfer of rights to eligible students

When a student turns 18 or enrolls in a postsecondary institution, FERPA rights transfer from the parent to the student. Access and amendment requests for those students are still routed through the district.

15.3 Directory information

We treat data as "directory information" only as each district has designated and publicly noticed it, and we honor any parent or eligible-student opt-out from directory-information disclosure that the district conveys to us (34 CFR 99.3, 99.37). We do not treat any student data as directory information on our own initiative, and we do not disclose it as directory information without the district's instruction. This includes any display of student names or photographs and any element used in the SMS feature.

15.4 How districts exercise control

Districts direct our handling of their data through their contract and DPA, including issuing data-deletion or data-return requests, configuring the SMS program, and submitting or relaying data-subject requests.

15.5 Parent control over the messaging relationship

Because parents and guardians opt in to the SMS assistant directly, they can also end that messaging relationship directly at any time by replying STOP (see Section 7.6). This is separate from, and in addition to, the record-access rights they exercise through the district.

15.6 PPRA

If any survey or assessment data we process ever touches one of the protected categories under the Protected Pupil Rights Amendment (PPRA), it is administered under district control, with the district handling any required parental notice or consent.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We maintain version history and a change log, and the "Last updated" date at the top of this policy reflects the most recent revision. For material changes affecting District and Student Data, we provide advance notice to affected districts and clearly flag the change, rather than changing terms silently.

17. Order of Precedence

For student and education data, where a school district has executed a Data Privacy Agreement (DPA) with us, that DPA controls over this Privacy Policy and over our general Terms and Conditions in the event of any conflict regarding privacy, security, breach, data ownership, audit rights, data residency, and data return or deletion.

CoPilot Data signs each district's Texas Student Data Privacy Agreement — the SDPC / Texas Student Privacy Alliance instrument commonly called the TX-NDPA — and that signed district agreement is the controlling DPA. The order of precedence is: (1) the executed TX-NDPA (or other district-provided DPA) and its exhibits; (2) the signed order form or master subscription agreement; (3) our Terms and Conditions and SMS Terms of Use; and (4) this Privacy Policy and other policies incorporated by reference.

18. Texas Data Privacy and Security Act Disclosure

Two independent reasons may place CoPilot Data outside the substantive scope of the Texas Data Privacy and Security Act (TDPSA):

  1. Data-level FERPA exemption. Personal data regulated by FERPA is exempt from the TDPSA, so the student education records that are the core of our platform fall outside the TDPSA's substantive requirements.
  2. Entity-level small-business exclusion. The TDPSA does not apply to a small business as defined by reference to the United States Small Business Administration, and CoPilot Data may qualify for that entity-level exclusion.

Regardless of whether either exclusion applies, we follow TDPSA processor norms for the data we handle. The non-education-record data the SMS feature introduces — a parent's or guardian's own phone number and message content — is the parent's consumer data rather than a student education record, and we handle it consistent with the TDPSA's processor obligations. Consistent with the TDPSA, we do not sell sensitive personal data.

19. Governing Law, Venue, and Contact

This Privacy Policy and our relationship with you are governed by the laws of the State of Texas, without regard to conflict-of-laws principles.

  • For district customers: a signed DPA's governing-law and venue terms control as provided in Section 17. Where the TX-NDPA applies, venue and forum for disputes concerning student data lie in the county of the local educational agency (the district), and that provision overrides any contrary venue term in our general Terms and Conditions.
  • For parents, guardians, and website visitors (non-district relationships): the exclusive venue for any dispute is the state and federal courts located in Denton County, Texas.

Questions about this policy, or requests relating to data security and privacy, may be directed to:

CoPilot Data Solutions LLC
608 E Hickory St, Ste 128
Denton, TX 76205
info@copilotdata.com
(817) 752-4766

This Privacy Policy is subject to ongoing legal review and may be updated to reflect changes in applicable law or our practices.