Education & Student Safety AI
Brisk Teaching
Medium riskChrome extension for teachers that layers AI onto Google Workspace and the sites they already use — generating feedback on student documents, creating materials, and replaying how a student's draft was written.
Is Brisk Teaching safe for confidential data?
Brisk's data posture is better than most extension-based tools and its documentation is unusually candid: it states user input is not used to train AI models, that it does not store the underlying student work it processes (the content of an essay it gives feedback on), and that it operates as a School Official under FERPA. The honest nuance in its own FAQ is that student names do get stored when teachers include them in prompts or when generated outputs contain them — a recommendation letter for a named student persists with the name in it. The structural risks are the extension model itself (a browser extension that can read student documents in Google Drive deserves a real permissions review, and typically arrives via individual teacher installs before any district agreement) and its Inspect writing-replay feature, which drops district workflows into the same false-accusation debate as AI detectors if replays are treated as proof.
Risk by plan
The same product often carries very different terms depending on the tier — consumer plans are where the exposure concentrates.
The dominant adoption path: an individual install with extension access to student documents, ahead of any district DPA or extension-allowlist decision.
District agreement with admin controls; the tier where the FERPA School Official designation is contractually anchored and the extension can be centrally allowlisted.
Data handling
Training on inputs
Brisk states plainly that user input is not used to train any AI models; generation runs on cloud-hosted LLMs under that restriction.
Retention
Underlying student work processed for feedback is not stored, per Brisk's security FAQ, but prompts and generated outputs are — including any student names they contain. Inactive accounts are deleted after 18 months; manual deletion is available on request.
Residency
Hosted on AWS in the U.S.; no Canadian residency option published. Because the extension reads documents inside school Google Workspace accounts, Canadian boards should cover it in a PIA (required in BC under FOIPPA) rather than treating a teacher's browser install as out of scope.
Compliance
- SOC 2Not verified
- GDPR / DPAConditional
- HIPAA BAANo
Certifications typically apply to specific tiers and contracts — confirm scope in writing before relying on them.
New to these frameworks? See our plain-language guides to SOC 2 and the other AI compliance standards.
Enterprise controls
- District agreements with School Official terms
- Central deployment via Google Admin extension policies
- No storage of underlying student work
- Account deletion and data request process
Frequently asked questions
Is Brisk Teaching FERPA compliant?
Brisk states it operates as a School Official under FERPA and limits collection to what the service needs, which is the right structure — under a school or district agreement. A teacher's individual free install has no such agreement behind it, so the School Official theory has nothing to attach to; districts that want Brisk's benefits should paper the relationship and manage the extension centrally.
Is Brisk safe for student data?
Its core design choice is reassuring: the student work it processes (essay content it reads to generate feedback) is not stored, and inputs are not used for model training. The stored residue is prompts and outputs — so a prompt or generated document naming a student persists with that name. The other review that matters is the extension permission itself: anything that can read documents in students' Drive should go through the district's extension vetting, not arrive one teacher at a time.
Does Brisk's Inspect feature prove whether a student used AI?
It replays the document's revision history, which is stronger context than a detector score — but it is still inference, not proof. Pasted text can be legitimately transcribed work, and fluent drafting is not evidence of AI. Given the documented false-accusation record around AI-detection tools, districts should treat Inspect replays as conversation starters governed by the same due-process rules as any integrity evidence, and remember that individual teachers running such checks through personal installs sit outside any policy the district has actually set.
Policy changelog
- Initial entry published from Brisk Teaching's published security documentation.
Sources
This profile summarizes the vendor's published policies as of the verification date. It is not legal advice.
Brisk Teaching is probably already in your organization.
Sanitized AI shows you who is using it and redacts sensitive data from prompts before it leaves your control.
More AI tool profiles
Consumer companion-chatbot platform where users chat with user-created AI personas; it has no education product, but is one of the most heavily used AI apps among teenagers.
District safety-monitoring service that uses AI plus human reviewers to scan student email, documents, and files in Google Workspace and Microsoft 365 for signs of self-harm, violence, and abuse.
Standalone AI-writing detector with a free web checker and paid tiers, widely used by individual teachers and professors to screen student work for AI generation.
Khan Academy's AI tutor and teaching assistant: a student-facing guide that coaches rather than answers, plus teacher tools, offered to families and through district partnerships.