hypothesis / hypothesis/support-legacy

Article: Student privacy in LMS app + FERPA

Open
#32 0 comments 0 reactions 0 assignees View on GitHub
knowledge-base new-article team-requested
Dominant language
No language data
Stars
3
Forks
0
PR merge metrics
No merged PRs in 30d

Description

From this Zendesk ticket: https://hypothesis.zendesk.com/agent/tickets/2894

Q: What is the nature of the information that may be transmitted or stored by this tool (i.e. names, grades, assignments, etc.)?

Jeremy provided this answer:

> The answer to your questions will be changing soon. I'll explain the state of things as they are (I) and then tell you what's coming (II). In general, speaking as a former English professor (and rhetoric instructor!), Hypothesis is about as conscientious about these things as software companies come.
>
> I. Currently, students need to sign up for Hypothesis accounts manually. And then in most cases join a private course group. This is even in using LMS app (again, this will be changing soon). The LMS app only circumvents the need for a student to activate Hypothesis on a document (via browser extension for example).
>
> So Hypothesis stores the student's username and email address, and the content of the annotations they create. Their username can be anonymous. Their email needs to be real, but could be personal rather than institutional. Their annotations can be private or shared only to the class group and we have access and share with third parties only for the purposes of running the service and support. We're non-commercial so there's non of the crazy data harvesting that goes on elsewhere in ed-tech and tech generally. Some of this is explained more fully in our [Privacy Policy](https://web.hypothes.is/privacy/). We are GDPR compliant which is meaningful to explain to folks that are concerned about this stuff.
>
> Ib. Within the LMS app, there is an option for the instructor to use the Canvas Files repository to create Hypothesis-enabled readings. This requires a dev key at install which you'd likely need to ask an LMS admin to give you (or just use to install the app in your course for you). If you go this route, Hypothesis needs to be able to access the Canvas API in order to communicate with the Files repository. This is granted to us by the student during the workflow of accessing an Hypothesis enabled document. We don't store this token (though may in the future since this step is rather burdensome for the student-user) or use it for any other purpose except to access PDFs of readings in a course.
>
> II. We are currently working on major improvements to the LMS app that will change some of these things. These changes won't be released for another month or more, and won't be pushed to existing users unless desired, but just FYI. An attempt to explain how things will work below:
>
> Soon the LMS app will provision students with accounts based on data gathered from the LMS via LTI: using their email if available and creating a sensible username. We'll also gather the fact that they are in a particular course in order to create a private Hypothesis group for that course and associate their Hypothesis account with it.
>
> It's still TBD, but a future version of the LMS app will also sync with the gradebook. If Hypothesis is used as a Canvas "Assignment", there will be a way for a student to submit their annotations as a set. This will send the annotations to Speedgrader in Canvas for grading and feedback. In this case we will be sending that grade, I believe, but I don't think we'd store it in any permanent way (I'll check in this as things develop.)

I added:

> Jeremy covered everything pretty well! I just want to reiterate that the changes we're working on for the next version of the app will be "opt-in," so if you install the app now, it will behave as Jeremy describes in his first scenario, storing:
>
> - Usernames (which do not have to be related to students' real names)
> - Email addresses (can be personal or institutional; not used for purposes other than running the Hypothesis service)
> - Annotations, group memberships, and any optional profile information provided by the student (as detailed in the Information You Voluntarily Provide section of the Privacy Policy)
> - Log file information as described in the Automatically Collected Information section of our Privacy Policy.
> - If the Canvas File Picker is used, a Canvas API token generated when a student grants permission for Hypothesis to access their Canvas course site
>
> Finally, I assume your university is asking these questions in part because of FERPA compliance. While we obviously can't give legal advice, these steps can help ensure that instructors using Hypothesis are FERPA-compliant:
>
> 1. Inform students that Hypothesis is a 3rd party tool not owned by the university. Direct them to our Privacy Policy so they know what info we collect and store about them.
>
> 2. Have students annotate documents that are password-protected and not publicly accessible (i.e., within Canvas)
>
> 3. Make sure students annotate within the groups created by the instructor rather than in the Public layer
>
> 4. When using Hypothesis to comment on graded work, do not actually provide grading information in the text of your annotation (this will become more relevant when the Speed Grader functionality is added).

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.