Education & Student Safety AI

Brisk Teaching

Medium risk

Chrome extension for teachers that layers AI onto Google Workspace and the sites they already use — generating feedback on student documents, creating materials, and replaying how a student's draft was written.

Verified 2026-08-31Brisk Teachingwww.briskteaching.com

Is Brisk Teaching safe for confidential data?

Brisk's data posture is better than most extension-based tools and its documentation is unusually candid: it states user input is not used to train AI models, that it does not store the underlying student work it processes (the content of an essay it gives feedback on), and that it operates as a School Official under FERPA. The honest nuance in its own FAQ is that student names do get stored when teachers include them in prompts or when generated outputs contain them — a recommendation letter for a named student persists with the name in it. The structural risks are the extension model itself (a browser extension that can read student documents in Google Drive deserves a real permissions review, and typically arrives via individual teacher installs before any district agreement) and its Inspect writing-replay feature, which drops district workflows into the same false-accusation debate as AI detectors if replays are treated as proof.

Risk by plan

The same product often carries very different terms depending on the tier — consumer plans are where the exposure concentrates.

Free (teacher install)
No training

The dominant adoption path: an individual install with extension access to student documents, ahead of any district DPA or extension-allowlist decision.

Brisk for Schools / Districts
No training

District agreement with admin controls; the tier where the FERPA School Official designation is contractually anchored and the extension can be centrally allowlisted.

Data handling

Training on inputs

Brisk states plainly that user input is not used to train any AI models; generation runs on cloud-hosted LLMs under that restriction.

Retention

Underlying student work processed for feedback is not stored, per Brisk's security FAQ, but prompts and generated outputs are — including any student names they contain. Inactive accounts are deleted after 18 months; manual deletion is available on request.

Residency

Hosted on AWS in the U.S.; no Canadian residency option published. Because the extension reads documents inside school Google Workspace accounts, Canadian boards should cover it in a PIA (required in BC under FOIPPA) rather than treating a teacher's browser install as out of scope.

Compliance

  • SOC 2Not verified
  • GDPR / DPAConditional
  • HIPAA BAANo

Certifications typically apply to specific tiers and contracts — confirm scope in writing before relying on them.

New to these frameworks? See our plain-language guides to SOC 2 and the other AI compliance standards.

Enterprise controls

  • District agreements with School Official terms
  • Central deployment via Google Admin extension policies
  • No storage of underlying student work
  • Account deletion and data request process

Frequently asked questions

Is Brisk Teaching FERPA compliant?

Brisk states it operates as a School Official under FERPA and limits collection to what the service needs, which is the right structure — under a school or district agreement. A teacher's individual free install has no such agreement behind it, so the School Official theory has nothing to attach to; districts that want Brisk's benefits should paper the relationship and manage the extension centrally.

Is Brisk safe for student data?

Its core design choice is reassuring: the student work it processes (essay content it reads to generate feedback) is not stored, and inputs are not used for model training. The stored residue is prompts and outputs — so a prompt or generated document naming a student persists with that name. The other review that matters is the extension permission itself: anything that can read documents in students' Drive should go through the district's extension vetting, not arrive one teacher at a time.

Does Brisk's Inspect feature prove whether a student used AI?

It replays the document's revision history, which is stronger context than a detector score — but it is still inference, not proof. Pasted text can be legitimately transcribed work, and fluent drafting is not evidence of AI. Given the documented false-accusation record around AI-detection tools, districts should treat Inspect replays as conversation starters governed by the same due-process rules as any integrity evidence, and remember that individual teachers running such checks through personal installs sit outside any policy the district has actually set.

Policy changelog

  • Initial entry published from Brisk Teaching's published security documentation.

Sources

This profile summarizes the vendor's published policies as of the verification date. It is not legal advice.

Brisk Teaching is probably already in your organization.

Sanitized AI shows you who is using it and redacts sensitive data from prompts before it leaves your control.

Get a demo

More AI tool profiles