Tepuy LMS
Privacy Policy
How Tepuy LMS handles student information.
In force since: 2026-08-24·Terms of Service
1. Who operates this service
Tepuy LMS is a learning management system operated by Juan Carlos Tovar for The School District of Osceola County, Florida. It is used only by students and staff of the District, on accounts the District controls.
Questions about this policy: —. Questions about a specific student's records should go to the school or the District, which holds those records.
2. Our role under FERPA
Tepuy LMS acts as a "school official" with a legitimate educational interest under the Family Educational Rights and Privacy Act, 34 CFR §99.31(a)(1)(i)(B). We perform a function the District would otherwise perform with its own employees, and we do so under the direct control of the District.
The education records in this system belong to the District. We do not own them. We use them only to run the service for the District, and for no purpose of our own.
We do not re-disclose personally identifiable information from education records to anyone else, except as the District authorizes in writing or as the law requires. This is the limit set by 34 CFR §99.33(a).
3. What we collect
Only what the service needs to teach a course and record how a student did in it:
- Identity: name and District email address. Role (student, teacher, counselor, administrator).
- Enrollment: which courses and sections the student is in, and their groups.
- Coursework: assignment submissions, quiz answers and attempts, files the student uploads to an assignment, and work saved inside an interactive lesson.
- Results: grades, rubric scores, standards mastery, self-assessments and teacher feedback.
- Activity needed to run the service: lesson progress, sign-in attempts, and a record of grade changes.
- Optional: date of birth, only if the District chooses to load it. The service works without it.
4. What we do not collect
We do not ask for, and the service has no field for, any of the following:
- Social Security numbers.
- Home address, home phone, or emergency contact details.
- Health, medical, disciplinary, immigration or free-and-reduced-lunch records.
- Biometric identifiers, location data, or device advertising identifiers.
- Payment or financial information. The service charges nothing.
5. What we never do
These are commitments, not preferences, and they match Florida's Student Online Personal Information Protection Act (§1006.1494, Fla. Stat.) and FERPA:
- We do not sell, rent or trade student information. Ever, and not in a bankruptcy or a change of ownership.
- We do not use student information for targeted advertising, on this service or anywhere else. The service shows no advertising of any kind.
- We do not build a profile of a student for any purpose other than the school work the District assigns.
- We do not use student information to train or improve any product, ours or anyone else's.
- We load no third-party analytics, advertising or social-media trackers. There are none in the code.
6. Cookies
The service sets three cookies and no others:
- tepuy_session — keeps the user signed in. Signed, HTTP-only, expires with the session.
- tepuy_lang — remembers English or Spanish. No personal data.
- tepuy_asset — a short-lived, signed permission to open the course files of one course from inside a lesson. Expires in 12 hours and grants nothing else.
No advertising cookies. No cross-site tracking.
7. Artificial intelligence
Tepuy LMS has two optional AI features. Both run on Azure OpenAI inside the Azure subscription that serves the District. No outside AI company receives any data.
- Instructor Assistant — drafts grading feedback for a teacher. The teacher approves, edits or discards it. A draft never reaches a student on its own, and the AI never sets a grade of record.
- Student Tutor — answers questions about the lesson the student is on. It is instructed to teach rather than to answer graded work, and it refuses to complete assignments.
What the model receives: the assignment text, the rubric, the lesson content and the student's own submitted work. What it does not receive: name, email address, student ID, or any other identifier. The work is sent unattached to a person.
Microsoft does not use this content to train its models or OpenAI's. Prompts stay within the Azure geography of the District's resource.
Either feature can be turned off entirely by the District, and both are subject to daily usage limits per user.
8. Who else touches the data
Microsoft Azure hosts the application, the database, the uploaded files and the AI service, in the United States. That is the only processor with access to stored student information.
When a teacher embeds a video or uses the in-browser Python editor, the student's browser also contacts the site that serves it — YouTube (in privacy-enhanced mode), Vimeo, or the code libraries jsDelivr and cdnjs. Those requests carry no student information from this service, and the District's own web filter applies to them.
9. How long we keep it, and how it gets deleted
Student information is kept for as long as the course runs, plus the current school year, so that grades and evidence remain available for review. After that it is deleted.
The District may ask for a student's records to be exported or deleted at any time, and we act on that request. The service has a built-in function that exports everything held about one student as a single file, and a second that deletes it: submissions, grades, quiz attempts, feedback, tutor conversations, progress and account.
Deletion is permanent. Backups roll off within 30 days.
10. Rights of parents and students
Under FERPA, a parent — or a student who is 18 or older — has the right to inspect and review education records, to ask that a record be corrected, and to control disclosure in most cases.
Those rights are exercised through the school or the District, because the records belong to the District. When the District asks us for a student's file or for a correction, we produce it. We do not respond to such requests directly, because we cannot verify who is entitled to the record — the District can.
11. Security
- All traffic runs over HTTPS. The application is not reachable over plain HTTP.
- Passwords are stored as bcrypt hashes, never in readable form.
- Single sign-on uses Microsoft Entra ID limited to the District's tenant. The service never creates an account by itself — a person must already be on the roster.
- Access is by role. A student sees their own work; a teacher sees their own courses.
- Repeated failed sign-ins are throttled by email address and by network address.
- Audit accounts are read-only at the network layer and see names and emails replaced by stable pseudonyms.
- Lesson content runs in an isolated frame with no access to the session or to any account.
- Course files are served through signed, expiring links scoped to a single course.
If student information is exposed, we notify the District without unreasonable delay and no later than 72 hours after we become aware, with what we know about what happened and what was affected.
12. Communication inside the service
Students can write in three places: feedback to their teacher on an assignment, peer review of a classmate's work when the teacher turns it on, and course discussions. All three are limited to people enrolled in that course, and the teacher can read all of it.
There is no private messaging with strangers, no public profile, no public posting, and nothing a student writes is visible outside their course.
13. Changes to this policy
We tell the District before any material change to how student information is handled, and this page shows the date of the version in force. Current version: 2026-08-24.