FERPA Compliant PE Software and Student Fitness Data Privacy
eFit stores activity minutes, fitness assessment scores, and course grades for students at 50+ institutions. This page is written for the technology director or IT security reviewer who has to sign off before faculty can use it.
What Student Data eFit Holds
Scope your review around three categories. Everything eFit stores about a student falls into one of them, and each one carries a different level of sensitivity for your district or campus.
- Roster data: student name, institution email address, course section, plus age and gender, which the fitness assessment scoring norms require
- Graded performance data: weekly activity minutes, pushup and crunch test counts, 1-mile walk test times, calculated VO2MAX and BMI results
- Optional student-entered content: nutrition logs, weight training logs, PocketAI Journal entries, and weight, which instructors can leave out of the assessment
Activity minutes arrive from a wearable such as a Fitbit, Apple Watch, or Garmin, or from a smartphone app for students who own no device. See activity tracking and fitness assessments for the exact measures faculty grade.
Who owns the records
Under FERPA, a grade earned in a physical education course is an education record of the institution that offers the course. eFit stores and processes those records so faculty can grade the activity component and push results to the campus gradebook.
The written agreement your institution signs is the document that controls permitted use, return of data, and deletion. Request a copy from sales@efit.software and read it next to your own board or system policy before you approve the vendor.
Because grades export as CSV into D2L, Canvas, Blackboard, Moodle, or Schoology, your institution keeps an authoritative copy of every graded result inside systems you already control.
How eFit Aligns With FERPA
The three questions a FERPA review normally turns on, answered in the order a reviewer asks them.
Disclosure to a service provider
FERPA lets an institution share education records with an outside party that performs an institutional service, stays under the direct control of the institution for use and maintenance of those records, and uses them only for the authorized purpose. Your agreement with eFit is where that designation is recorded.
Purpose limitation
eFit exists to grade the activity component of a course and report those grades back to faculty and the LMS. Ask for the permitted-use clause in writing, keep it in your vendor file, and confirm that it matches the annual FERPA notification your institution already publishes to families.
Access by parents and students
FERPA gives eligible students and the parents of minors the right to inspect education records and ask for correction. Faculty can produce a student's full activity and assessment history as a CSV or PDF export, so your registrar can answer an inspection request from the course record itself.
Encryption, Hosting, and Subprocessors
What eFit publishes about the infrastructure layer, and what to request in writing.
Encryption in transit and at rest
Student data is encrypted in transit and at rest using 256-bit SSL. Faculty and student sessions run over HTTPS, and the graded records held between sessions are stored encrypted.
Physical hosting
Servers sit in SSAE-16 certified facilities with 24/7 monitoring and biometric access controls at the door. The faculty and student application runs on efit.health. Ask for the current hosting regions and infrastructure detail in writing if your questionnaire requires them.
What eFit does and does not claim
eFit publishes four compliance claims: FERPA, 256-bit SSL, ADA, and SSAE-16 certified hosting. Accessibility is designed to meet WCAG 2.2 AAA.
If your questionnaire asks about SOC 2, ISO 27001, GDPR, COPPA, HECVAT, a VPAT, penetration test cadence, breach notification timelines, or the current subprocessor and hosting-region list, request the status directly from sales@efit.software.
Treat anything absent from this page as unconfirmed until you have it in writing. A vendor that lets you do that is easier to audit later.
Access Control and Faculty Versus Student Roles
eFit separates the two roles that use the platform. Faculty accounts are created around courses: an instructor sets up a course in about 15 minutes, and the students who enroll appear inside that course.
Faculty work with grading and analytics views: weekly activity totals, pre and post assessment comparisons with absolute and percentage improvement, class-wide analytics, and cross-term comparison. Students work with their own record: device sync, personalized workouts and meal plans, the PocketAI Journal, and their own progress charts.
For a formal review, ask for the current role matrix in writing: which fields each role can read, which fields each role can edit, how instructor accounts are provisioned and removed at the end of a term, and what an administrator can see across sections.
Retention, graduation, and transfers
A PE record has a short useful life. Once the grade lands in your LMS gradebook, the copy inside eFit is working data. Put four questions to us in writing and record the answers in your vendor file:
- How long records are retained after a course section closes
- How a deletion request for a graduated or transferred student is submitted and confirmed
- Whether backups are purged on the same schedule as live records
- What the final export contains and how long you have to pull it
Grades export as CSV and assessment data exports as CSV or PDF, so a section can be archived into your own systems before any deletion runs.
Parent and Student Opt-Out Handling
K-12 families raise three concerns most often. Each one has a practical answer you can give at a board meeting.
Buying a wearable
A device purchase is optional. Fitbit is recommended, and Apple Watch, Samsung Galaxy Watch, Garmin, Xiaomi Mi Band, and Fossil smartwatches all sync. A student with none of those can log activity through a smartphone app that connects to Google Health or Apple Health.
Sharing body measurements
Weight is an optional field in the assessment set. Instructors who teach in a district with a body-composition policy can run pushup, crunch, and walk-test scoring without it, and tell families exactly which measures the course grade uses.
Declining participation
Your own opt-out policy governs. When a family declines, contact eFit so the account is handled the way your policy requires, and get the removal steps confirmed in writing before the term starts so faculty know how to grade that student.
Accessibility Conformance
Accessibility usually rides along in the same procurement packet as security. eFit carries an ADA Compliant badge and is designed to meet WCAG 2.2 AAA. Every page on this site ships a skip-to-content link, keyboard-operable navigation, and an accessibility panel with text-size and contrast controls, so your reviewer can test the behavior directly on the page they are reading.
If your office requires a completed accessibility conformance report for the student application, ask sales@efit.software for the current status of that document.
Read the accessibility statementEvidence a reviewer can gather today
- Keyboard-only navigation across this site
- Text size and contrast controls in the accessibility widget
- Faculty references at institutions already running eFit, in case studies
- A working product walkthrough in the free demo, with no sign-up required
What to Ask Any PE Technology Vendor
Ten questions that separate a defensible student fitness data privacy review from a rushed one. Reuse this list with every vendor you evaluate, including us.
1. Which specific fields do you store about a student?
Ask for a field-level list, including anything derived such as VO2MAX or BMI. Vague category names hide the sensitive fields.
2. Does the agreement designate you a school official under FERPA?
The designation lives in the contract. Confirm the direct-control and purpose-limitation language is present before signing.
3. How is data encrypted in transit and at rest?
Get both answers separately. Many vendors answer for transit only and leave storage unaddressed.
4. Who can see a student's record, by role?
Request the role matrix. Pay attention to whether one instructor can view students in another instructor's section.
5. What is the retention schedule, and how are deletions confirmed?
Ask for the timeline in days, the request channel, and whether you receive written confirmation once a deletion completes.
6. Is student data used to train AI models?
Any platform generating personalized workouts or meal plans needs a written answer here. Put the answer in the contract itself, where it survives staff turnover.
7. Who are your subprocessors and where do they host?
Include analytics tools, email senders, and device-sync partners. Ask how you are notified when the list changes.
8. What happens to a student's data on graduation or transfer?
A wearable-linked account can outlive the course. Confirm how the account and the device connection are closed out.
9. What is your breach notification commitment?
Ask for the notification window in hours, the contact who receives it, and how it maps to your state reporting duty.
10. Can we export everything and leave?
Portability is the strongest protection you have. Confirm the export formats, the scope, and whether an administrator can run it without vendor help.
Request a Security Review or Procurement Documentation
Email sales@efit.software and include the five details below. That is usually enough for us to return the right paperwork on the first pass.
- Institution name, approximate student count, and whether you are K-12 or higher education
- The LMS your faculty use, so grade export questions are answered for your platform
- Your review deadline and the committee date it has to clear
- The exact forms your office requires, such as a vendor security questionnaire or a data privacy agreement template
- Whether you want a reference call with faculty at an institution already using eFit
Phone 346-222-3348 works for anything urgent, and the contact page reaches the same team. Learn who you are buying from on the about page.
Cost belongs in the same packet, and the answer is short. There is no institutional license fee, and faculty accounts are free. Student access is $59 per student, per semester, purchased by the student directly, through a campus bookstore that stocks access codes with your course materials, or in bulk by a department or district on a single invoice or purchase order. Higher education programs commonly combine bookstore adoption with a department bulk purchase for the sections the department covers. K-12 districts commonly use the district bulk purchase on its own, since school bookstores are uncommon. Bulk pricing is quoted per institution. Full details are on the pricing page, and sales@efit.software handles bulk quotes and bookstore setup.
Evaluate the product while the paperwork moves
The demo is an interactive walkthrough of the faculty dashboard. No credit card, no sign-up. Let a PE lead review the grading workflow while your office reviews the terms.
Start Your Free DemoFaculty accounts are free. Student access is $59 per student, per semester. 50+ institutions already use eFit.
Security and Privacy Questions
The questions technology directors and IT security reviewers send us most often.