More than half the educational apps used in Utah public schools collected student data they weren't supposed to have, according to findings reported publicly Tuesday, Aug. 18. For Granite School District's roughly 58,000 students, including those at Millcreek-area schools, the results raise pointed questions about what information their children's classroom apps have been quietly harvesting.

The investigation, commissioned by the Utah State Board of Education and conducted by BYU professors Mark Keith and Justin Giboney alongside the nonprofit Internet Safety Labs, tested 100 of the most commonly used apps in Utah K-12 classrooms. Researchers set up accounts mimicking students under age 13 and captured all outgoing network traffic during 15 to 20 minutes of simulated use.

The numbers were stark. Of apps with Data Privacy Agreements, 52% collected at least one data element their contracts didn't allow. Worse, 36% transmitted student data directly to advertising platforms. Overall, 61% shared student information with third parties.

Some individual apps sent data to dozens of ad-tech companies. Three apps communicated with 32, 33 and 54 separate advertising entities.

"It's a massive market — data brokers and resellers market — and the technology is increasing faster than people are aware of, as companies tie together data in ways that make it more useful without anybody knowing," Keith said.

What was collected

Many apps routinely grabbed persistent unique user identifiers, which allow tracking and behavioral profiling to continue even after a student logs out. Keith told BYU News that once a person is associated with such an identifier, "the likelihood is high that nearly every website you visit afterward contributes to your overall profile."

The investigation evaluated data collection against 79 potential student data elements tracked in state privacy agreements. Commonly permitted elements included student names, IP addresses and usernames. The unapproved tracking identifiers went well beyond those boundaries.

Granite SD's exposure

Granite School District, Utah's third-largest with approximately 58,312 students as of the 2023 state enrollment count, is subject to the same state Data Privacy Agreements that the investigation found widely violated. The district lists "Student Data Privacy" as a resource on its public website, but has not publicly commented on the investigation's findings or disclosed which of its apps may have been flagged.

The investigation did not publicly name which specific apps violated agreements. Vendors that fixed problems had their names redacted. Apps commonly used in Utah schools include Canvas, Duolingo, Khan Academy, Quizlet, YouTube, coolmathgames.com and Loom, according to KSL.

New law already in effect

The investigation directly prompted H.B. 55, sponsored by Rep. Tiara Auxier, R-Morgan, which took effect July 1, 2026. The law establishes stricter privacy terms in EdTech contracts, gives school districts the right to audit vendors and requires contracts to be terminated if violations aren't fixed within 30 days.

After USBE contacted 50 vendors about data mismatches, 31 signed or committed to updated agreements, 13 provided satisfactory explanations and seven removed tracking pixels or changed analytics settings. Seven other vendors said their privacy agreements applied only to paid services, not free tiers students might also use.

Keith sorted the vendors into three groups: those fully compliant, those who didn't realize they were breaking the law, and those who "knew what they were doing and ignored our requests."

What parents can do

The state report recommended ongoing network traffic testing to monitor compliance. Under H.B. 55, Granite SD and other districts now have explicit authority to audit their own vendors. Parents seeking information about which apps their children use can check Granite's student data privacy page.