FREQUENTLY ASKED QUESTIONS
GENERAL POLICY QUESTIONS
State law now requires all public schools to prohibit the use of personal internet-enabled devices during the entire academic day. This "bell-to-bell" timeframe begins when the first bell rings to start the day and ends when the final dismissal bell rings.
Yes. Unlike previous policies, the ban is continuous and includes time between class periods, lunch, and recess.
Research indicates that unregulated device use in schools leads to lower academic performance, increased anxiety and depression, and a deterioration of the school climate. Adolescents spending significant time on social media are at double the risk of experiencing mental health issues.
The policy covers all personal "internet-enabled devices," including smartphones, tablets, smartwatches, and smart glasses. Non-internet-enabled devices, such as basic flip-style phones, are generally excluded from the specific software requirements but remain subject to general use restrictions
SAFETY AND COMMUNICATION
For all communication, parents should contact the school’s main office directly. This prevents interruptions to instructional time. If a student needs to call a parent, they may request permission from a staff member to use a school phone in the main office.
In the event of a school-wide emergency, district safety protocols and staff direction supersede this policy. The management application is also configured to preserve access to emergency services (911).
No. The school district assumes no responsibility for the damage, theft, or loss of any personal device brought to school. Students bring these devices at their own risk.
EXCEPTIONS AND DISCIPLINE
Yes. Exceptions are granted for requirements documented in an IEP or 504 Plan, as well as for monitoring documented health conditions (with prior permission from the Principal and school nurse). Exceptions also exist for translation services and emergency situations.
The district uses a progressive discipline model:
First Offense: Documented warning; no further discipline.
Second Offense: Administrative Detention and restriction from extracurricular activities until the detention is served.
Third Offense: Device confiscated for parent pick-up; 2 Administrative Detentions; extracurricular restrictions.
Fourth Offense: Device confiscated for parent pick-up; 1-day suspension.
Fifth Offense: Device confiscated for parent pick-up; 2-day suspension; the student is prohibited from bringing any personal device to school for the remainder of the year.
Attempts to circumvent the management application are violations that trigger discipline. This includes disabling the VPN, abusing the "emergency unlock" feature, deleting and reinstalling the app, or manually changing the device time to bypass schedules
APP MANAGEMENT (DOORMAN)
The district utilizes a district-managed device management application. This secure app allows students to keep physical possession of their phones while automatically restricting distracting features like social media and messaging during school hours.
Upon arrival at school or their first-period class, students must "tap" their phone to a designated district-issued NFC tag. This single action activates Restricted Mode for the remainder of the school day.
Yes. The application does not collect personal content, text messages, photos, or location history. It is designed solely to manage device functionality during the instructional day.
Parents may submit an opt-out attestation form confirming that no personal internet-enabled device will be brought to school grounds (See your school principal for more information). Students who choose to bring a device to school must have the application installed and functional; failure to comply will result in the device being prohibited from school grounds.
APP SECURITY AND COMPLIANCE INFORMATION
Doorman is built around the principle of data minimization. The complete list of what we collect is:
From the district's Student Information System: name, school email, school affiliation, and class schedule, for rostering.
From a student's device: tap-in events (classroom, timestamp) and policy-relevant events such as attempts to bypass restrictions while class is in session.
Anonymous app telemetry: standard mobile-app data (app version, OS version, crash diagnostics) that any responsibly built mobile app collects. Not tied to an individual student.
Doorman requires:
NFC access, to read the classroom DoorTag at the start of class (Apple granted entitlement on iOS, user controlled on Android)
VPN permissions, to enforce school-time restrictions.
[Optional] Push notifications for compliance alerts
[Optional] Camera, for unlocking via QR Code scanning (the app cannot save photos)
Doorman does not request, and has no way to access (including but not limited to):
Microphone, or photos, Contacts, Location services, Health data, calendar, or files, and any other app's data, including banking apps, Apple Cash, saved cards, messages, email content, photo libraries, or browsing history
iOS and Android both enforce app-level sandboxing at the OS layer. This means an app cannot reach into another app's data or the device's protected storage.
Doorman runs a VPN server (isolated environment per school) that a student's device tunnels into during school when a student activates restrictions, using a current, well-audited VPN protocol. Traffic does route through our infrastructure, but here’s what happens at the server and what doesn't.
TLS is end-to-end past our server. We do not perform TLS interception. There is no Doorman root certificate installed on the device. When a student connects to an HTTPS destination, the TLS session is between the student’s device and that destination. Our server forwards encrypted ciphertext and does not hold the keys to read it.
The VPN server necessarily handles DNS resolutions to do its job. What we retain from that is deliberately narrow: anonymized, aggregated counts at the school level (e.g., how many times a blocked category like TikTok or ad/tracking endpoints was attempted across all students at the school). We do not store per-student DNS requests, so we cannot reconstruct where a student attempted to go online.
Redirect and MITM risk. A compromised or misconfigured VPN cannot silently redirect HTTPS traffic to capture content. The destination's TLS certificate would not validate, and the student's device would refuse the connection. The public-key infrastructure that backs HTTPS provides a check on our server that exists independently of us.
Non-inspection is architectural, operational, and legal. SOPIPA legally prohibits the secondary use that theoretical more aggressive logging would enable.
What we claim is narrow and verifiable: HTTPS payload content is beyond our cryptographic reach because we don't intercept TLS, and per-student browsing patterns are not retained anywhere in our system.
Encryption in transit: industry-standard TLS between the app, our servers, and the dashboard.
Encryption at rest: stored data is encrypted on Google Cloud Platform.
Hosting: enterprise-grade cloud infrastructure, with application data on Google Cloud Platform.
Access controls: role-based permissions in the dashboard. Only authorized school personnel can view compliance data. Authentication is handled through the district's existing SSO provider (Google) rather than separate Doorman credentials.
Audit logging: every administrative action in the dashboard is logged. There is an auditable record of who accessed what, and when, and any user's access can be revoked at any time.
Doorman does not sell student personal information. Data is not used for advertising, profiling, or any commercial purpose.
Our privacy policy explicitly prohibits it.
SOPIPA and equivalent state laws make it illegal for any K-12 operator.
Our student data privacy agreement with your district through SDPC contains specific contractual data-handling obligations, and the district remains the data controller for all student information we process on its behalf.
The only third parties involved are infrastructure providers, such as Google Cloud for hosting, and Google for SSO authentication. These vendors are contractually bound to confidentiality and cannot use student data for their own purposes.
Doorman does not set its own retention period for student records. Retention follows the district's direction. Upon contract termination or district request, Doorman securely deletes or de-identifies student personal information.
It is true that privacy policy is a statement of practices, not a contract. The externally enforceable layers around our practices are:
Service agreement with the district.
FERPA: Doorman operates as a "school official" under FERPA, using student data only for the educational purposes the district has authorized.
SOPIPA: California state law prohibiting the advertising, profiling, and sale of student data. NJ has an equivalent law in P.L. 2019, c.494.
COPPA: for any student under 13, the district acts as the consent agent in the educational context.
Student Data Privacy Consortium (SDPC): Doorman is an approved SDPC vendor. New Jersey is a participating state.