The question gets asked in two very different ways. Sometimes it means “will the AI say something inappropriate to my students,” and sometimes it means “am I about to violate a policy nobody has explained to me.” The second is the one that actually gets teachers in trouble, and it is the one most vendor pages skip.
The three risks that are real
1. Student data entered into a tool that was never cleared for it
This is the big one, and it has nothing to do with lesson quality. Pasting a student's name, IEP text, behaviour log, or graded work into a general-purpose chatbot can put personally identifiable information from an education record into a system your district never reviewed. In the United States that is FERPA territory, and the obligation sits with the school, not with the teacher who was trying to save an hour.
The mitigation is simple and it is entirely under your control: lesson planning does not require student data. A learning target, a text, a grade band, and a description of what a group of students needs are enough to plan with. None of that is an education record.
2. Content that reaches students without a human read
A language model will produce a confident, well-formatted passage that is subtly wrong — a misattributed quotation, a date that is off by a decade, a science explanation that skips the step the misconception lives in. It will not flag any of it, because it does not know. Every credible guidance document on classroom AI lands in the same place: a teacher reviews the output before it is used.
3. A vendor whose posture nobody checked
Two questions separate the tools that are safe to adopt from the ones that merely look professional: what does the vendor send to the model, and what do they do with what you give them? Most marketing pages answer neither, because the honest answer is less impressive than a badge wall.
Questions to ask any AI lesson-planning vendor
- What exactly is sent to the AI model — everything I upload, or only what I explicitly confirm?
- Is my content used to train models, by you or by your model provider?
- If the tool connects to Google Drive or a school account, what scope does it request, and what can it see that it did not create?
- Do you hold a SOC 2 report, a signed data-privacy agreement, or a state privacy-alliance listing — and can I see it, rather than a logo?
- What happens to my content if I delete my account?
Ask us the same five. Here are our answers, including the ones that are not flattering.
Where TeacherHero actually stands
- Only confirmed excerpts are sent. An uploaded document is stored with its full extracted text and, separately, an excerpt you confirm. Only the confirmed excerpt is ever placed in front of the model, and only for sources you have switched on. The “Not sent to AI” badge is a description of the code path, not a reassurance.
- Your curriculum is not training data. Your courses, units, lessons and uploads are not used to train models and are not published anywhere by default.
- Drive export uses the narrowest scope available. Exporting to Google Drive requests `drive.file`, which grants access only to files the app itself creates. The rest of your Drive is not visible to it.
- We hold no SOC 2 report, and no FERPA, COPPA, or privacy-seal certification. We do not claim one. If your district requires a completed vendor review or a signed data-privacy agreement before staff may use a tool, treat that requirement as unmet today.
- No student data is required, and none should be entered. Differentiation is generated for a described group of learners, never for an identified child.
The short version
AI lesson planning is safe when it is used as planning support rather than as a content pipeline into a classroom: no student data in, a teacher's read before anything goes out, and a tool your district has actually cleared. A vendor who will tell you plainly what they do not have is a better signal than one with a wall of logos.