Try the live demo

A data privacy agreement with every district.

Last updated: September 2, 2026

MorningCount never holds student data without a signed agreement. In New York, that’s the state model data privacy agreement under Education Law 2-d, with its exhibits. This page is what’s in ours.

This page is a plain-language summary. The agreement your district signs is the document that controls.

Signed before the first roster is uploaded.

Every district signs a data privacy agreement before any student data reaches MorningCount. New York districts use the New York State Model Data Privacy Agreement for Educational Agencies, or the district’s own Education Law 2-d agreement, with three exhibits attached: the Parents’ Bill of Rights for Data Privacy and Security, the supplemental information for the contract, and our Data Security and Privacy Plan. If your district is outside New York, we complete your state’s or district’s agreement.

The privacy obligations in the agreement outlive the contract. They end only when we certify that the district’s data has been destroyed.

What every district posts about us.

New York requires each district to post supplemental information about every contractor that receives student data. Here is MorningCount’s, so your district can link to it or copy it into its own posting.

Purpose

MorningCount receives student data for one purpose: running the district’s daily classroom lunch count and giving the cafeteria the totals it needs to plan production. It is never used for anything else.

Data received

Student first name, last initial, grade, classroom, and the local student ID from the district’s student information system, plus the teacher’s name and local teacher ID. The IDs exist to match roster updates to the right student and classroom and to prevent duplicates. Each day’s meal pick is held for that day and deleted overnight; only daily totals by school, classroom, and meal are kept. We keep no last names, no payment, eligibility, health, or contact information, and no per-student history.

Type of data

Student personally identifiable information only. No teacher or principal APPR data.

Contract term

Set in each agreement. Our standard term is one school year, ending June 30.

Subcontractors

One: Pressable, Inc., an Automattic company, which provides the managed hosting infrastructure. We never use a subcontractor without a written agreement that binds it to data protection obligations at least as protective as the district’s. Where a district buys MorningCount through a partner, the partner signs as the contractor and Juniper Creative LLC, the company that builds and runs MorningCount, is named as a subcontractor under the same terms.

When the agreement ends

At the district’s written direction, we transfer the data to the district or to a successor contractor in an agreed format. Then we securely delete everything that remains, including backup copies as they cycle out, and provide written certification.

Challenging accuracy

Parents, teachers, and principals who want to correct information contact the district. The district corrects its records and tells us, or the correction simply arrives with the next roster import. If a parent contacts us directly, we refer them to the district and let the district know.

Where data is stored and how it’s protected

On managed hosting in United States data centers, where site files, databases, and backups are encrypted at rest by default, a control covered in the host’s SOC 2 report. Every connection is encrypted in transit. The larger protection is how little we store: first names, last initials, grade, classroom, and a local ID, with each day’s picks deleted every night. No payment, eligibility, health, or contact data is ever collected. No third-party analytics or trackers run on any platform page, and student names are kept out of system logs.

Encryption

Student data is encrypted in transit and at rest.

Our security plan, in plain English.

The full Data Security and Privacy Plan is attached to every agreement. This is the shape of it.

  • Minimal by design. The platform is built to need as little student information as possible, and to delete each day’s picks automatically every night. We review our security practices whenever we update the platform, and at least once a year.
  • Safeguards. Access is limited to the few people who build and support the platform, each with their own login. Hosting includes a web application firewall, malware scanning, daily file backups, and hourly database backups, all encrypted. Classroom screens reach the platform only with a district-issued device code. No third-party scripts or trackers. Student names never appear in logs.
  • Training. Everyone with access reviews the confidentiality requirements of FERPA and New York Education Law 2-d before they get access to student data.
  • Written agreements. No one gets access to student data without a written agreement requiring the same protections as the district’s agreement.
  • Incidents. If we discover a breach or unauthorized disclosure, we notify the district in writing as quickly as possible, and never later than seven calendar days after discovery. We share what we know, cooperate fully with the district’s and law enforcement’s investigation, and, where the breach is ours, cover the cost of the district’s required notifications to families and staff.
  • Your data, any time. The district can request a full export of its data in a standard format such as CSV at any time, at no charge. When a district asks for a student’s data so a parent can review it, we respond within 30 calendar days.
  • Review and audit. On request, we provide the district with our policies and procedures for protecting student data, and the agreement gives the district audit rights.
  • Alignment. We follow the district’s data security and privacy policy and the Parents’ Bill of Rights. Our plan maps to the five functions of the NIST Cybersecurity Framework, the standard New York sets for district policies: we know exactly what data we hold and where it lives; we protect it with minimal collection, encryption, logins, and nightly deletion; we detect problems through the host’s firewall, malware scanning, and monitoring; we respond by notifying the district and fixing the issue; and we recover from encrypted daily file and hourly database backups.

Never sold, never marketed, never ours.

  • Student data belongs to the district. We have no ownership or licensing rights in it.
  • We never sell it, and never use or disclose it for advertising, marketing, or building profiles.
  • We disclose it to no one else, unless a statute, court order, or subpoena requires it, and then only after making every reasonable effort to notify the district first.
  • We never attempt to re-identify de-identified data, and never pass de-identified data to anyone.

A note for parents.

MorningCount is a tool your child’s school uses. The school district holds the agreement and your child’s records. To review or correct your child’s information, or to raise a concern, contact your district. New York’s Parents’ Bill of Rights for Data Privacy and Security explains your rights, and complaints about a breach can also go to the New York State Education Department’s Chief Privacy Officer at nysed.gov/data-privacy-security.

Districts are welcome to link to this page from their own Education Law 2-d postings. The address won’t change.

Request the agreement.

Ask us for the model agreement and our completed exhibits, or send us your district’s own agreement to complete. Either way, it’s signed before any roster is uploaded.