Student Work Samples Addendum
Version 2026-09-29.v1 · September 29, 2026
Student work samples are an optional Melaa feature, off for every district by default. A district turns it on only when its account owner accepts this addendum in Settings. It is published here so districts can review it first. See also our Data Sharing & Subprocessors page and Privacy Policy.
1. Purpose and scope
This addendum supplements the agreement under which the district (the "LEA") uses Melaa, including any signed Data Privacy Agreement ("DPA"), for one optional feature: storing examples of student work ("work samples") as evidence of English language development, for example for exit or reclassification decisions and post-exit monitoring.
The feature is off by default. It is turned on only when the LEA's account owner accepts this addendum in Melaa. Acceptance is recorded with the owner's name, title, the date, and this addendum's version.
For this feature, this addendum amends the list of student data elements in the LEA's DPA (for example Article III of the Melaa DPA template) to add the elements in section 2. Where the LEA's DPA or state law requires a written amendment to the data element list before new elements are collected, the LEA should complete that step before uploading any work sample.
2. What is collected
The file the LEA's staff choose to upload: a PDF, a JPEG, PNG, WEBP, or HEIC image (for example a phone photo of a worksheet), or a Word document, up to 15 MB each and up to 200 per student.
Details typed by staff about the sample: a title, the date of the work, the language domains it shows (listening, speaking, reading, writing), the class or assignment, a description, and an optional note on what it shows about the student's language use. Melaa also records the file name, type and size, who uploaded it and when, and whether it is attached to an exit decision or a monitoring check-in.
Melaa does not inspect, read, transcribe, or analyze the contents of a file. A file may contain anything the student wrote or drew, including the student's name and, if not covered, other students' names.
3. Who can see it
District administrators and the account owner see work samples for every student in the district. School administrators see work samples only for students in their assigned schools.
Teachers see and upload work samples only if the LEA also turns on teacher access, and then only for students on their own roster. Teachers can delete their own uploads for 30 days; after that, only administrators can.
Students and families have no Melaa accounts and never see work samples in Melaa. Requests from families to inspect records are handled by the LEA under FERPA, and the LEA can download any sample to respond.
Files are never public. Each view or download goes through an access check, is recorded in the LEA's student data access log and audit log, and uses a link that expires after 60 seconds.
During a Melaa support session (read-only, time-limited, recorded in the LEA's audit log) work sample files cannot be opened, and the typed details are hidden.
4. Never sent to AI
No work sample file and none of its typed details are ever sent to Melaa's AI provider or any other AI model. Melaa enforces this in code with an automated check that fails if any part of Melaa that prepares AI requests uses the work samples feature.
If a staff member separately downloads a work sample and attaches it to an AI chat message, that is a separate action covered by Melaa's Privacy Policy section 4, and the LEA's own guidance for staff applies.
5. Where it is stored
Files and details are stored by Supabase, Melaa's existing database and storage provider, in the United States (AWS us-east-1), encrypted at rest and in transit. No new subprocessor is added for this feature.
6. Retention and deletion
Each work sample is kept for the retention period the LEA chooses in Settings (1 to 5 years; 2 years unless changed), counted from the day it was uploaded, and is then deleted automatically, file and details, by Melaa's nightly retention job. Changing the period applies to new uploads; the owner may apply it to existing samples.
A work sample is also deleted when the student's record is deleted (the file within 24 hours), when a staff member with permission deletes it, and with all other LEA data under the canceled-account rule in the Privacy Policy.
Turning the feature off hides all work samples and stops uploads immediately. Stored files are kept until their retention date unless the owner uses "Delete all work samples now", which permanently deletes every work sample file and its details for the LEA and is recorded in the audit log.
7. The LEA's responsibilities
The LEA directs staff to upload only work that is needed for instruction, program decisions, or compliance records, and not to upload items outside that need (for example medical, disciplinary, or family documents).
The LEA directs staff to remove or cover other students' names and personal details before uploading. Melaa warns staff when the details they type appear to contain a name, but it cannot detect names inside a file.
The LEA remains responsible for its own obligations under FERPA and applicable state student privacy law, including any required notice to families and any required amendment to a signed DPA before this feature is used.
8. Order of precedence
If this addendum conflicts with a DPA the LEA has signed with IncluSend LLC, the DPA controls, except that this addendum adds the data elements in section 2 for this feature only.
Questions
Contact privacy@inclusend.com.