Activity Bank
Two teachers audit the apps their students use, starting from a stack of sticky notes.

All activities Professional learning

What Do My Apps Know?

Teachers read a mock app privacy policy the way a 12-year-old would, then audit the real tools in their own classroom and decide what to keep, change, or replace.

Print handouts

Overview

Every app, extension, and AI tool we put in front of students collects something: names, voices, writing, clicks, sometimes location. Teachers are often the first, and last, person to decide whether a tool is used, yet few of us have read the policies. In this session, participants first experience a mock privacy policy for a fictional AI story app from a student's point of view, then use a 12-item audit to review two real tools they use, and leave with a plan to teach students the same habit of asking "What does this app know about me?"

Objectives

  • Participants will identify common privacy red flags in an education app's policy (unclear data sharing, indefinite retention, use of student input to train AI, advertising, missing parental consent for young children).
  • Participants will audit at least two tools they use with students against district approval status and a 12-item checklist, and decide on an action for each.
  • Participants will plan a short student lesson that teaches students to ask what an app collects and how to protect their own personal information.

Materials

On paper

  • Handout A: StoryBuddy AI Privacy Policy, mock (1 per person)
  • Handout B: Tool Privacy Audit (2 per person, one per tool)
  • Handout C: My Classroom Tool Inventory (1 per person)
  • Highlighters in two colors; sticky notes

On screen

  • One device per participant (laptop preferred) to open the real tools, their privacy policies, and their settings
  • Access to your district's approved-app list or data privacy agreement list, if one exists (share the link before the session)

Before you start

  1. Find out where your district publishes its approved-app list or signed data privacy agreements, and who to contact with questions (often the technology or instructional technology department). Have that information on a slide.
  2. Ask participants to bring a list of every app, site, extension, and AI tool students used in their class in the past two weeks.
  3. Read Handout A and mark the red flags yourself: the "improve our services" training clause, sharing with "partners," indefinite retention, voice recordings, and the age language. You'll model with it.

Step by step

  1. 10–5 min

    Hook

    Count the data trail

    Each person writes every tool students used in the last two weeks on sticky notes, one per note, and stacks them. Ask the room to call out their counts. Then say: "Each note is a place your students' information may live. Today we find out what those places know, and whether we'd be comfortable if our own child's name were in each one."

    Facilitator noteCounts vary widely. Don't shame anyone with a tall stack; the goal is awareness, not guilt.

  2. 25–17 min

    Explore

    Read it like a 12-year-old

    Participants read Handout A as a sixth grader who just wants to make a story. First pass (2 minutes): "Would you click 'I agree'?" Everyone would. Second pass, as teachers: highlight in one color what the app collects, in another where it goes (sharing, training, retention). In pairs, list the three things they'd most want a parent to know.

    Facilitator noteLook-for: pairs catch that stories and voice recordings may be used to train AI models (paragraph 4), that "partners" is undefined (paragraph 5), and that data is kept "as long as necessary" with no clear end (paragraph 6).

  3. 317–25 min

    Model

    Think aloud with the audit

    Project Handout B and walk through it for StoryBuddy AI, narrating each decision. "Item 1: is it on our district's approved list? I'd check that first, because the district may already have a data privacy agreement that changes what the vendor may do. Item 5: can I turn off using student content to train AI? The policy says 'you may contact us to opt out.' That's a No for an easy setting." Briefly name the relevant federal laws: FERPA protects the privacy of student education records, and COPPA governs how online services collect personal information from children under 13. Then say: "You don't need to be a lawyer. You need to know when to ask your tech department."

    Facilitator noteKeep the legal part short and accurate. Participants should leave knowing who in the district answers these questions, not trying to interpret law themselves.

  4. 425–45 min

    Apply

    Audit your own tools

    Each person chooses two tools from their sticky-note stack: one they use often and one AI tool or free app they're unsure about. On devices, they check the district list, open each tool's privacy policy (often linked at the bottom of the home page), and look in account or admin settings for data, sharing, and AI options. They complete Handout B for each tool, then log the result on Handout C with an action: keep, change settings, replace, or ask the tech department. Partners check each other's highest-risk tool together.

    Facilitator noteMany people find a tool they love has a setting they never knew about, such as whether student work is visible publicly. That discovery is the win. If a policy is impossible to understand, that's a finding: record it as a question for the tech department.

  5. 545–53 min

    Debrief

    What we found, what we'll change

    Go around quickly: each person names one tool and one action. Chart the actions in four columns. Ask: "What surprised you? What would students need to know to protect themselves in these same tools?" Close by connecting to students: "Our students will spend their lives clicking 'I agree.' The habit we want them to have is the one you just practiced: ask what it collects, where it goes, and whether you can say no."

    Facilitator noteIf a tool turns out to be unapproved and collecting student data, remind people to follow district procedures rather than posting about it publicly.

  6. 653–60 min

    Transfer

    Plan the student version

    Each person sketches a 15-minute student lesson on the back of Handout C: students look at one tool the class uses and answer three questions in their own words: "What does this app know about me? Who else might see it? What can I choose not to share?" Younger students do it with the teacher reading the policy aloud; older students read it themselves.

    Facilitator noteFor students, center actions they control: using a nickname where allowed, not typing personal details into AI tools, checking what is public, and asking a trusted adult before signing up for anything.

Paper or screen

Unplugged

Run Hook, Explore, and Model entirely on paper with Handout A. For the audit, participants complete Handout B from memory and mark every item they can't answer as "Don't know." Those unknowns become a written question list to send to the district technology department, which is itself a useful product. The student lesson can also run unplugged with a printed, read-aloud policy excerpt.

Digital

Participants audit live: the district approved-app list, each tool's actual privacy policy, and its account and AI settings. Handout C can be a shared spreadsheet so a campus sees its whole tool inventory in one place, which helps the technology department prioritize. In a virtual session, use breakout pairs and share screens during the audit.

Does it need a screen? Reading the real policy and clicking through real settings is the only way to find what your own tools actually do. The mock policy teaches the questions, but the live audit is where teachers find the setting they didn't know existed. That discovery produces changed practice.

Evidence of learning

What you should be able to see or collect if it worked.

  • Handout A annotations distinguish what is collected from where it goes, and flag the AI-training clause.
  • Each completed Handout B leads to a specific action on Handout C, with "ask the tech department" used for real unknowns rather than guesses.
  • At least one participant changes a setting or replaces a tool during or right after the session.
  • Student lesson sketches focus on actions students control (what they type, what's public, when to ask an adult).

Adaptations

K–2 teachers
Focus the audit on tools young children use through class accounts and on what appears publicly (names, photos, voices). The student version becomes a picture sort: "OK to share with the app" vs. "Ask a grown-up first."
Librarians
Audit the library's databases, e-book platforms, and makerspace apps, and offer to be the campus point person who collects teachers' questions for the technology department.
Higher Ed faculty
Audit tools required in a course, including AI tools, and draft a syllabus statement explaining what each collects and what alternatives students have if they decline.
Short on time
Do the Explore and Model steps (20 minutes) in a PLC meeting and assign the two-tool audit as homework with a partner.

Standards connections

Teachers audit the privacy policies of tools they use and plan a student lesson on asking what an app knows, the privacy-and-security substrand.

TEKS
privacy, safety, and security (c)(10)TEKS sections: Technology Applications §126.5–§126.7, §126.8–§126.10, §126.17–§126.19, high school Technology Applications courses (19 TAC Chapter 126)
UDL 3.0
2.17.23.4

See how all activities align

Reflect

  • How do I guide students in safe and responsible internet use when I'm the one choosing their tools? (Teacher ELE 2.2)
  • Which tool in my classroom would I be least comfortable explaining to a parent? What will I do about it?
  • What would transparency from an AI tool look like, and how will I teach students to look for it?

Take it to your students

Complete audits for your remaining tools over the next month and share your inventory with your campus technology contact. Teach the three-question student lesson with one tool your class already uses, and collect students' answers as evidence of what they understand about their own data.

Pairs well with