The Family Educational Rights and Privacy Act (FERPA) protects the privacy of student education records. LifeLeveled is designed to support FERPA-aligned institutional use when deployed under an appropriate institutional agreement.
This page describes the controls currently implemented in the application, the controls that require institutional configuration, and the controls that are planned but not yet operational.
Important: Publishing this documentation does not itself establish FERPA compliance. Compliance depends on the platform's actual operation, institutional agreements, authorized use, data-handling practices, and continued verification. LifeLeveled is not "FERPA certified" — no such certification exists under the statute.
Currently Implemented Controls
The following controls are present in the application code and its hosting infrastructure today:
- Row-level security (RLS) on all user data entities. Every entity schema enforces that users can only read, create, update, or delete their own records. Cross-user data access is prevented at the database query level.
- Organization admin role management. Institutional administrators can manage members and roles within their organization through dedicated admin functions and dashboards.
- No advertising integrations. The application code does not include advertising SDKs, ad networks, or third-party advertising trackers.
- Data minimization. Entity schemas contain only fields necessary for the platform's educational features — budgets, bills, savings goals, simulator profiles, check-ins, resumes, and roleplay sessions.
- User-owned content. User-generated content (budgets, check-ins, simulator progress) is created by and linked to the user who generated it, with RLS rules enforcing ownership.
Institutional Configuration Required
The following controls require contractual agreement and institutional setup before they are operational:
- Data Processing Agreement (DPA). A signed DPA between LifeLeveled and the institution defining data processing scope, security obligations, and breach notification terms.
- Authorized use scope. The institutional contract must define which users are authorized to access the platform and under what terms.
- Data retention and deletion schedule. Per institutional policy, defining how long user data is retained and the deletion process.
- Role-based access configuration. Institutional administrators must be configured with appropriate roles for their organization.
- Breach notification timeline. Defined in the institutional contract, specifying notification procedures and timelines.
Planned Controls
The following controls are on the product roadmap but are not yet operational:
- Formal data deletion verification workflow with institutional confirmation
- Institutional admin audit logs for data access and modifications
- Enhanced data export capabilities for institutional review and portability
- Scheduled data retention reviews with automated notifications
Planned controls are presented as roadmap items, not operational claims. They should not be relied upon for current compliance determinations.