321school Trust Center

Privacy, safety and school control in one place

A practical overview for schools and school owners assessing 321school, Feide login, AI features, data processing and deletion routines.

Working version. Last updated: 9 August 2026.

Our basic principles

  • Students can join classroom Spaces anonymously with code or QR where account use has not been approved.
  • 321school supports Feide login when the school owner approves the service.
  • 321school does not sell personal data and does not use student data for third-party advertising.
  • AI features are documented and should be assessed by the school before systematic student use.

Find the right information

For teachers

Understand what students can do in Spaces, accounts, assignments and AI-supported workflows.

For school owners

Review data processing, sub-processors, Feide, deletion routines and the DPA draft.

For parents

See how anonymous participation, accounts and student work are handled.

Sub-processors

External services that may process data, including Firebase, Feide, Vercel, OpenAI and email/payment providers.

Terms and contact

General terms, sales terms and contact information for follow-up questions.

Data location and data sovereignty

Schools often need to know where personal data and student work are stored. The main Firestore database for the active 321school Firebase project is located in europe-west1, Belgium.

  • Core app data in Firestore is stored at rest in europe-west1, Belgium.
  • Firebase Authentication processes authentication data in the United States according to Firebase documentation. This is described in the sub-processor overview.
  • The active school Storage bucket 321skole-storage is located in the EU multi-region.
  • Hosting and server functions are delivered through Vercel.
  • AI requests are processed by OpenAI only when AI features are used.
  • The final school agreement should state all confirmed regions and any processing outside the EU/EEA for the current production setup.

Cookies and browser storage

321school uses necessary browser storage so login, anonymous participation and classroom activities can function. This is not used to sell data or run third-party advertising.

  • Firebase Auth may use cookies, IndexedDB and local browser storage to keep users signed in.
  • 321school uses localStorage/sessionStorage for functional state such as app mode, anonymous classroom participation, quiz/session aliases and unsaved drafts.
  • Google Analytics may be used for aggregate product analytics where configured; school-facing pages should describe any analytics in the general privacy policy.

DPA and municipal templates

321school can enter into a data processing agreement with the school or school owner. We maintain a DPA draft and structured information that can also be used with the municipality's own template or KS/SkoleSec/Digdir-based templates.

  • Available information includes purpose, data categories, sub-processors, processing locations, security, deletion/access routines and AI use.
  • If the municipality uses its own DPA template, 321school can use the same information as the basis for completing it.
  • The school owner remains responsible for its own assessment, risk review and final approval before systematic school use.

Feide login

Feide lowers the threshold for safe school login because access is controlled by the school owner. Feide approval opens login; paid school agreements and extended school administration are handled separately in 321school.

  • School owners can approve or deny Feide login for their users.
  • 321school receives only the identity data needed for login and account access, such as technical ID, name and email where available.
  • Feide is not required for anonymous classroom participation in Spaces.

For school assessment

This Trust Center is intended to make the assessment easier. It is not a substitute for the school owner's own privacy and security review.

Contact 321school