Somewhere in the pile of papers you signed at back-to-school night — between the emergency contact form and the photo permission slip — was a device acceptance form. You more than likely signed, without reading it (like most do), because the alternative was your kid carrying an inordinate load of textbooks like it's 1995.

But that form didn't just hand your kid a laptop. It authorized software that reads what your child searches, writes, emails, and uploads 24/7, even at home. It also flags what it finds and communicates that data to adults your kid has never met—sometimes for the police.

Consent was almost compulsory or at least felt that way. The uncomfortable part is the uncomfortable question is whether you know what you signed your kid up for.

You're not paranoid for not knowing, either — it's statistically normal. Per the Center for Democracy & Technology, 88% of teachers say their school uses student activity monitoring software. Only 45% of parents know it's happening at their child's school. The form worked exactly as designed: it got your signature, not your understanding.

The Form You Signed

Districts hand out Chromebooks with a form. Buried in the acceptable use policy — the one with the dense legal prose nobody parses — is authorization for monitoring software that watches nearly everything your kid types on a school account. Not just during class or on school grounds — I'll get to that.

If you're picturing antivirus software, recalibrate. This is surveillance infrastructure and the scale is enormous. A U.S. Senate investigation found over 7,000 schools or districts used GoGuardian's surveillance products in 2021 alone. Roughly 1,500 districts use Gaggle alone, tracking the online activity of around 6 million students. By one recent report, nearly half of K-12 students nationwide are subject to systems that can monitor everything they type (a keystroke logger) on school-issued devices. If your kid has a school laptop, assume this is your district.

What the Software Actually Does

The market is dominated by four companies: GoGuardian, Gaggle, Securly, and Bark — the same four that Senators Elizabeth Warren and Ed Markey singled out in their inquiry into digital school surveillance. Their products differ in features but share a core mechanism: software scans everything a student types, searches, writes, and views. And an algorithm flags anything matching categories like self-harm, violence, sex, or drugs, and a flag routes to school staff — or beyond.

What that looks like in practice:

GoGuardian's teacher dashboard shows a live thumbnail of every student screen, the way a Zoom call shows faces. A teacher can watch every student's screen simultaneously, close tabs, lock screens. During class, that's classroom management. But that same tool also runs when nobody's teaching.

Gaggle goes further. Its machine-learning classification model scans students' emails, documents, chat messages, and search queries — including assignments and journal entries — for thousands of flagged keywords and patterns. When the algorithm flags something, it goes to human moderators at Gaggle, who decide whether to alert school administrators. In cases flagged as imminent danger, Gaggle calls school officials directly. In rare cases where nobody answers, the company calls law enforcement for a welfare check.

Sit with that one a moment. A private company's moderation team is reading your kid's journal entry at 9 p.m. and can decide, from Dallas, to report that journal entry to the local police.

It Follows Them Home

This is the part worth understanding precisely. The surveillance attaches to the account, not the building. The monitoring follows the login: on a school-issued laptop at home, or whenever a student logs into their school account on a personal device. A 2025 report found that while 50% of schools monitor only during school hours on school days, 39% monitor outside school hours — evenings, weekends, breaks. The rest of the time, the question of who's watching your kid's screen depends on which district you live in and what your contract says — which means it's not your call.

In some districts, after-hours alerts don't go to teachers — they go straight to police. Baltimore City school officials route GoGuardian alerts to school police automatically, and officers have shown up at students' homes for wellness checks on nights and weekends. That's behavior of a Police state.

Here's the part I'd underline: this surveillance is effectively financially means-tested. CDT's research found that students who rely on school-provided devices — because they have no personal device at home — get disciplined more frequently, because every keystroke they make runs through the filter. All of their computer use is monitored by strangers. Roughly two-thirds of parents and teachers surveyed flagged exactly this worry. Families with means can buy their kid a personal laptop, skip the school account, and largely step outside the panopticon. Families without that option can't. The ability to maintain sovereignty is, functionally, a purchase.

The Safety Pitch vs. the Evidence

To be fair, the pitch isn't cynical marketing. After the pandemic, districts were staring down a youth mental health crisis and a chain of school shootings, and someone offered them a tool that promised to catch the kid in crisis before the worst day. Voting against that would be politically intolerable.

But the efficacy evidence, when you go looking for it, isn't there. The Brennan Center reviewed these tools and found no proof they prevent the violence they're marketed against — just the anecdotes the companies themselves promote. There's still no independent evaluation showing this surveillance reduces school shootings or self-harm. Districts are buying it on faith and marketing materials.

And the interventions do happen. A counselor in Vancouver, Washington receives three or four Gaggle alerts a month, and sometimes reaches a kid who was struggling in silence — that's real. A student in Washington's Highline School District who was potentially being trafficked used the alert channel to reach staff. Those are real outcomes and real people, and any honest accounting includes them.

So the honest summary is narrower than either the safety pitch or the civil-liberties alarm suggests: the tools sometimes help, they have never been independently proven to work at scale, and the school districts buying them generally aren't tracking whether they work at all. Nobody's measuring. They're just buying.

The Companies Aren't Secure Either

If the pitch is "we watch everything to keep kids safe," the data should be guarded like national secrets. Here are three data points.

In February 2025, reporters at the Seattle Times and the Associated Press filed a public records request to Vancouver Public Schools about its surveillance software. The district responded by inadvertently releasing almost 3,500 sensitive, unredacted student documents — the flagged communications themselves, complete with the most private things kids had typed. The district apologized. The surveillance system designed to protect students' private moments had handed them to journalists, by accident.

Then there's the matter of the software itself. In 2021, McAfee researchers disclosed critical vulnerabilities in Netop Vision Pro — classroom monitoring software used by 3 million teachers and students across roughly 9,000 school systems — that allowed attackers to gain full control of student computers, webcams included. Teacher-student communications ran unencrypted.

And the surveillance architecture itself has a quiet trick: many filtering systems require installing a root certificate on the device. That's the cryptographic equivalent of giving the software a master key — it lets the school inspect encrypted traffic. Which means whoever controls that certificate controls the most sensitive channel on the machine. District IT teams are not security firms. The software watching your kid is often less secure than the apps you'd never let them install.

False Flags and Real Consequences

The cases where the machinery misfires aren't hypothetical, and the pattern is consistent: the algorithm doesn't understand context, and nobody downstream is positioned to restore it.

In Durham, North Carolina, a Gaggle alert about self-harm led to a student being outed to their family — who were not supportive. The Durham Board of Education voted to stop using Gaggle in 2023, ultimately deciding the risk of outing students and burning trust with kids wasn't worth it.

In Kansas, student journalists at Lawrence High School fought to get their files exempted from Gaggle's scanning, then sued the school system, alleging unconstitutional surveillance — after the district's monitoring swept up their journalism files in a district that had, notably, been the subject of their reporting. The Knight First Amendment Institute has backed litigation challenging these systems, and documented flagging of student research about Romeo and Juliet and civil rights history (this alone should give you pause.)

And the edge is sharp. In one case described in AP's investigation, a teenager flagged by monitoring software was taken to jail, interrogated, and strip-searched, and her parents couldn't reach her until the next day. The mother's recollection — her daughter asking, "I thought you hated me" — is what a false flag actually costs.

Context, in these systems, is a rounding error. A joke about a video game, a photography assignment, a song lyric quoted in an essay. The model doesn't know the difference, and increasingly, neither does the alert pipeline on the other end.

Where the Record Goes

Here's the part nobody can answer: what happens to all of this when your kid graduates?

A flagged search at 14 becomes an alert in a dashboard. Alerts aggregate into reports. Reports live wherever the vendor's retention policy says they live — and those terms are set in the same contract your district negotiated without your input. Gaggle says its data is school property and disappears when contracts end. Maybe. There's no independent verification, and no mechanism for your kid to check what was collected about them, correct it, or clear it — the same architecture we saw in Part I of our medical data series.

What we do know is that adolescent data never rots in isolation. Insurance companies already buy and use health data. Employers already screen social media. Data brokers already assemble dossiers from fragments nobody thought consequential. A 12 year-old's flagged searches about self-harm, or a fifteen-year-old's outed identity — sitting in some vendor's database, potentially for decades — is exactly the kind of material that has value to exactly the wrong future buyer. We can't say a flag will follow your kid into adulthood. We can say nobody has promised it won't, and nobody can make them prove it did or didn't.

What This Means for Your Family

This isn't necessarily a call to march on the school board, but understanding what's happening now means you're ready when the next wave hits your school district.

The software and its data trail are knowable. Districts publish or disclose which monitoring vendor they use, and public records laws mean contracts (which specify what's scanned, what's retained, and who receives alerts) are obtainable. Vancouver's current contract, for what it's worth, prices three years of surveillance at $328,036 — roughly one full-time counselor's annual loaded cost, per year, for three years. That's the trade your district made.

The boundary most families miss: the account, not the device, is what gets read. School-issued laptop on your home wifi, personal laptop logged into a school Google account — both put what's typed into the scanning pipeline. The personal notes written into a school-account Google Doc was never private, and neither was the search.

It's worth underscoring the economic asymmetry: families who provide their own devices and accounts sit largely outside the dragnet, which means opt-outs cluster among families who can afford them. And a federal lawsuit now before the courts (Knight First Amendment Institute v. Orange Unified School District) may reshape what districts can scan and what they must disclose. The legal terrain is moving, but the record generated in the meantime keeps rolling.

Some states now allow families to request and review what's collected, and a handful mandate deletion processes — the details vary enough that they're worth checking for your specific state rather than trusting a generalization here.

There's one more layer to this, and it deserves its own space: these systems are calibrated to a neurotypical baseline, and they flag deviation. For neurodivergent kids, being themselves is the alert condition. That piece is coming Monday — and for parents of Neurodivergent kids, it's the more urgent read.

Related reading: Metadata: The Invisible Envelope That Tells Your Child's Whole Story and Why Your Child's Safety Tool is Actually a Surveillance Device.