Institution privacy and student data

Use worksheets and embeds without sending student personal information to the service.

Who this is for
Institution admins, educators, developers, and privacy reviewers
Before you begin
  • Review by the institution's responsible privacy or safeguarding contact

Keep learner data outside the service

  • Do not place student names, IDs, email addresses, scores, accommodations, or other identifying details in worksheet titles or API content.
  • Add names or scores by hand only after printing or downloading the worksheet, under your institution's own procedures.
  • Do not send student personal information in support messages or diagnostic attachments.
  • Learners do not need accounts and minors may not register for the service.

Understand the product data boundary

The app stores adult account and organization data needed for authentication, access, billing, recent history, and API operation. A worksheet creator's five most recent generated worksheets may be retained in their personal recent history. Review the Privacy Notice for the current categories, purposes, subprocessors, and request rights.

Review public embeds before use

  • Anyone with a direct embed URL may be able to view it; an allowed-domain list restricts framing, not necessarily direct access.
  • An embed can expose an answer key when its creator enabled one.
  • Do not encode student identity in the embed title or surrounding URL.
  • Revoke an embed that should no longer be available and allow for cache propagation before treating the change as complete.

Report a privacy concern

Email admin@overthemathwall.com with the institution name, affected product surface, approximate time, and a non-sensitive description. Do not attach raw API keys, payment-card data, passwords, or student personal information.

Success check

The institution has documented that learner identity stays outside the service, reviewed embed exposure, and knows the safe privacy escalation path.