It starts innocently. You have a student with a complex support plan, it's 9pm, and you're trying to write a report card comment that actually reflects who they are. You open ChatGPT, type the student's name, their designation, a few notes from their IEP — and ask for help. The comment comes back polished and usable. You feel relieved. You move on.

Most BC educators using AI tools this way aren't cutting corners. They're genuinely trying to do right by their students. But there's something important happening in that moment that most teachers haven't been told about — and it's worth understanding before back-to-school season is in full swing.


What actually happens when you type into a public AI tool

When you open a consumer AI tool — ChatGPT, Gemini, Copilot on a personal account, or similar — and type something, that conversation is stored on servers. In almost every case, those servers are located in the United States. The company retains that conversation. In many cases, depending on your account settings, that content may be used to improve the model's training.

That means a conversation that includes a student's name, their grade, their school, their designation code, and details from their IEP has left Canada. It's sitting on a server you have no control over. You can't delete it with certainty. You can't retrieve it. You can't audit it. And you almost certainly didn't get parental consent for it.

The conversation felt private because it felt like thinking out loud. But legally and technically, it wasn't private at all.

Recent legal cases — including proceedings right here in British Columbia — have established something significant: AI chat logs are real records. Courts can compel AI companies to produce them. Law enforcement has done exactly that. The idea that an AI conversation disappears after you close the tab is simply not true.


This isn't just a teacher problem

The teachers who are most careful about privacy are often not the ones who need this reminder. It's the people working in education who are exhausted, who are trying to help a specific child, and who reach for the most accessible tool available. That includes:

Scenario — The frustrated EA

"I have a student whose behaviour support plan isn't working and I need ideas. His name is Marcus, he's in Grade 4, he has an ASD designation and an EA support plan that says..." The EA types the whole thing into ChatGPT at lunch, gets some ideas, closes the tab. Marcus's name, school, grade, and diagnosis are now on a server in San Francisco.

Scenario — The caring counsellor

"A student disclosed something difficult today and I need to write a letter to the family. Her name is Priya, she's in Grade 6, and she told me that..." The counsellor is trying to get the words right. The AI helps. But Priya's name and the sensitive disclosure are now part of a chat log that belongs to a US tech company.

Scenario — The conscientious teacher

"Can you help me write differentiated instructions for my class? I have Jordan with an IEP for reading, Aisha who is ELL Level 2, and three students who are working well above grade level..." This feels like responsible differentiation planning. But a list of names paired with designations and learning needs is exactly what FOIPPA is designed to protect.

None of these people are being careless. They're being human. But the gap between their intention and what's happening with the data is significant.


What FOIPPA actually says

BC's Freedom of Information and Protection of Privacy Act applies to public bodies — and school districts are public bodies. Teachers, EAs, counsellors, and administrators acting in their professional capacity are subject to it.

FOIPPA requires that personal information about students — including names, designations, assessment data, and anything else that could identify a child — be collected, used, and disclosed only for specific purposes, with appropriate safeguards, and in ways that keep that information under the control of the public body.

When student information goes into a consumer AI tool on a US server, the public body — your district — loses control of it. It can't be retrieved, audited, or deleted on request. That's the problem. Not that you used AI. That the record now exists somewhere your district cannot reach.

It's worth noting that BC's AI landscape for schools is currently a patchwork. As of early 2026, only 26 of BC's 60 school districts had publicly accessible AI guidance on their websites. Your district may or may not have a clear policy yet. That gap doesn't change what FOIPPA requires — it just means you may be navigating it without much support.


Before you use any AI tool — a practical checklist

Ask yourself these questions first

What to leave out — always

Never include these in a public AI tool

The better way to use AI for teaching

None of this means you shouldn't use AI. It means the design of the tool matters enormously. The safest AI workflow for a teacher is one where student identifying information never has to enter the AI at all — because the system is built around your roster from the start, handles anonymization automatically, and keeps your classroom data on your own device.

Public AI tool (ChatGPT, Gemini, etc.) PedagogAI
You type student details manually into a chat Student data lives in your browser — never typed into a chat
Student names go to US servers Names never leave your device — AI only sees "the student"
IEP notes and SEL notes included in your prompt Narrative personal notes stay on device — only structured data used
Chat history stored and potentially reviewed No chat history — each AI call is independent and anonymous
No BC curriculum awareness — you explain everything Built around BC curriculum, proficiency scales, and CSL framework
Data on US servers indefinitely Roster data on your device only; usage tracked in Canadian Supabase database

We want to be honest: no AI tool that uses a third-party language model can claim perfect FOIPPA compliance, because AI processing involves infrastructure outside Canada and teachers remain responsible for what they choose to type. What PedagogAI does is make it structurally harder to accidentally share identifying student information — because the system is designed so you never need to.


One last thing

Share this with your EA. Share it with your counsellor. Share it with the teacher down the hall who you know has been using ChatGPT for report cards. Not to alarm anyone — the goal isn't fear, it's awareness. Most of the people doing this don't know there's a better way, and most of them would choose it immediately if they did.

The world of education is changing rapidly with AI, and teachers who understand these tools — including their risks — are better positioned to use them well, advocate for good district policy, and protect the children in their care.

Built for BC Teachers · Privacy by Design

AI that already knows your classroom — without knowing your students

PedagogAI was built by a BC teacher who understood from day one that student privacy isn't optional. Your roster stays on your device. Student names never reach the AI. Designation codes, ELL levels, and support strategies inform the output — without creating an identifiable record of any individual child. You get the time-saving benefits of AI with a design that reflects how BC educators are actually expected to handle student information.

Try free — 3 AI generations on us →