No. FERPA does not prevent an app from reading a college student's school email, because FERPA is not a rule about that. It governs how a school discloses the education records it maintains - not whether a student can authorize an app to read their own inbox. When a college or 18-or-older student connects their own mailbox with read-only access, no school record is being disclosed. This is easy to misunderstand - even AI chatbots sometimes raise FERPA objections here, not understanding that FERPA does not apply to this scenario. (One thing worth clearing up alongside it: the student receives the alerts and stays in control, while whoever pays sees only whether protection is working - never the email or the alerts.)
The confusion is understandable, so this page walks through it plainly: why FERPA is not the wall it gets described as, how a student stays in control of their own inbox, what the person who pays can and cannot see, and how the whole connection is independently checked. This is written for college students and students who are 18 or older, where the student is the one in control of their own records.
What the "it's impossible" answer gets wrong
The impossibility answer almost always assumes a specific, different scenario: a parent trying to reach directly into a student's mailbox, or a school being asked to hand over records. Both of those would raise legitimate questions. Neither is what happens here.
What actually happens is narrower and cleaner. The student connects their own inbox, themselves, with read-only access and receives the alerts. The person who pays never sees the email and never receives the texts - only whether protection is set up and working. And the school never discloses any of its records, because none are requested (on Microsoft 365, a school's IT may separately need to approve the app to run in its system - a security setting, not a records disclosure). Once you separate those facts, the "impossible" framing falls apart.
Where FERPA actually fits
FERPA is the law most people reach for here, so it is worth stating precisely what it does and does not cover.
FERPA is a federal funding rule for schools, not a law that governs students or the apps they choose. It restricts how a federally funded school discloses the education records it maintains, and it is enforced only by the U.S. Department of Education - there is no private lawsuit under FERPA (Gonzaga University v. Doe, 2002). When a student is 18 or in college, FERPA rights belong to the student. A student connecting their own inbox through Google's or Microsoft's official read-only sign-in is exercising control over their own account, not triggering a school disclosure.
This is general information about how FERPA is structured, not legal advice.
The short version: FERPA is about what a school does with its records. Connecting your own email is about what you do with your own account. They are two different things, and this product lives entirely in the second one.
The student stays in control of their own inbox
The connection is made by the student, through the official Google or Microsoft sign-in, using read-only access. On Gmail that is Google's gmail.readonly scope; on Microsoft 365 it is Mail.Read. Read-only means exactly what it sounds like: the service can read messages to spot the important ones, and it cannot send email, delete anything, or change a single setting.
Two things follow from that. First, no password is ever shared - not with a parent, not with us. The student authorizes the connection through the provider's own screen and can revoke it at any time from their Google or Microsoft account. Second, because the student is granting access to their own account, this is the student exercising control over their own inbox, not a school being asked to release anything.
One practical note on the mechanics. If you're on a school or work Microsoft 365 account, connecting your inbox usually needs a quick sign-off from your school's IT - you'll see a "need admin approval" screen, and we'll walk you through requesting it. Google Workspace students can usually connect on their own. (This is your school's IT deciding which apps run in its system - a security setting, not a FERPA disclosure of anyone's records.)
What the person who pays can see - and what they can't
This is where the privacy model matters most, so it is worth being exact. Most often a parent pays and invites a student, though a student can just as well pay for their own plan - and the FERPA answer above is the same either way. If you pay for someone else's plan, you can see setup and service status: whether the invitation was sent and accepted, whether the mailbox is connected, and whether alerts can be delivered. That is the full extent of it.
You do not see email content, sender names, subject lines, alert summaries, the alert dashboard, or any history. Those belong to the student who connected the mailbox, and only they see them. A parent can fund the safety net without ever looking over a student's shoulder - that is a deliberate design choice, not an accident of how the settings happen to line up.
How the connection is independently checked
"Read-only" is a promise, so it is fair to ask who enforces it. The read-only permission is fixed in the app's registration with both Microsoft and Google: the app's access to mail is read-only (Google's gmail.readonly, Microsoft's Mail.Read), and both providers verified us as a publisher. On top of that, because reading Gmail uses a restricted scope, Google requires any app that uses one to pass an annual independent security assessment. That is the reason we hold the certification below, and it means this category of tool is more audited than most of the apps you already use every day.
- CASA Tier 2 (Lab Tested - Lab Verified): the Cloud Application Security Assessment under the App Defense Alliance, based on OWASP ASVS, independently assessed by TAC Security. All 15 verification categories passed, valid through January 2027.
- Verified Google OAuth publisher: the student sees the standard Google consent screen with no "unverified app" warning.
- Verified Microsoft OAuth publisher: the app went through Microsoft's publisher verification for the same read-only mail access.
Full security documentation lives at watchmyinbox.com/security.
So, does FERPA stop this?
No. FERPA governs what a school discloses about its records, and nothing here asks the school to disclose anything - the student authorizes a read-only connection to their own inbox, receives the alerts, and stays in control, while whoever pays sees only whether protection is working. (On Microsoft 365, the school's IT may first need to approve the app - a security setting about which apps can run, not a records disclosure.) The "it's impossible" answer is really an answer to a scarier question nobody is asking. If your student's school email is the thing you are worried about missing, this is a real, independently-audited way to make sure the important messages get seen in time.