How to Secure Your Digital Life From Your Students

Have you ever had that moment when a student asks if you have a Facebook account? If you could befriend them on Instagram? Or a student liking a story you uploaded? Great, it’s not just me! In my first year of teaching (that was in 2018) I obviously had no previous experience and I was very happy to hear “Hey, I want to be your friend on socials”, but then reality hit me. Some students spammed me with messages, some made weird comments on my photos, some were asking personal questions. Thankfully, the school I was working at banned any kind of contact between a teacher and a student outside of school shortly after, and I could wash my hands from removing all students from my socials with the “Sorry, these are the new rules”. I learned the hard way that keeping your socials clean of students is the best thing you can do as a new teacher. Since then I’ve become an expert at securing my digital life, because even the ban didn’t work for a couple of nosy students. Also, I am almost a pro at cybersecurity, ha-ha, because my bachelor’s degree was in Computer Science, so yeah, I know a thing or two :)

In this blog post I will walk you through practical strategies and my own best practices that help me protect myself, my data, and my devices from the digital threats of students (and not only). Let’s dive in and take control of our online safety as teachers!

Real life example if you’re not convinced yet

In 2023 I used a shared account in Scratch for each grade I was teaching coding. If you don’t know what Scratch is – it’s a platform where students learn how to code through interactive and very fun tasks, it’s a whole thing! So, every student had the username and password for the account of their grade, this is how I bypassed the very painful process of acquiring e-mails for very young students (8-9 year olds)  and then teaching them how to log in (at least 3 week’s worth of work, ha-ha). When we started a lesson, they would all open that same account, open a brand new project and in the name of the project they would write their name and the name of the project we were doing (like “Christmas card with loops”). One late night, just before I went to bed, I received a notification on my phone. It was an e-mail that said something like “Is it really you that’s trying to change the account’s password? If yes, click this approval link”. It was a message about one of the whole-grade Scratch accounts. Some student was at home, trying to change the password to their grade’s account, so supposedly, when the lesson started the other day, nobody would be able to log in with the old password. Maybe that student thought that in this case I would just say “Fine, you can’t access Scratch, watch YouTube and talk to each other” or something like that. I like to think that there was no malicious intent, just a student poking around, but you get what I am saying. If it wasn’t for the e-mail verification that I turned on for the account, the student would have succeeded!

Here are my tips and advice:

Two accounts, two lives

This is the one thing I wish someone had told me in 2018. Keep your teacher self and your normal-human self completely separate. It’s the first thing I did.

That means a separate e-mail address for anything school-related. Not your personal Gmail from 2009 with your nickname in it. A clean, boring address like g.name.teacher@… that you use for school platforms, parent communication, Scratch, Canva, everything work-related. Your personal e-mail never touches the school world.

Why this matters so much: your e-mail is the key to every account you own. If a student knows your personal address, they can type it into the “forgot my password” box on any site and start poking. They can also search it on Facebook or Instagram and find you in two seconds, even if your profile is set to private.

Same logic for your phone number. If your school lets you use a platform for messaging parents (like a school app or e-mail), use that instead of giving out your personal number. If you absolutely have to be reachable, a free second number app works fine.

Lock down your socials (properly, not just “private”)

Setting your profile to private is step one, not the whole thing. Here’s the rest of the checklist I go through once a year, usually in August when I’m procrastinating on lesson planning, ha-ha:

  • Turn off “let people find me by my phone number / e-mail address” in the privacy settings of every app. It’s usually on by default. This is the single sneakiest one.
  • Check who can tag you in photos. Set it to “review before it appears on my profile”. Your friend tagging you at a party is not the problem – your friend tagging you at a party where the photo is public is.
  • Look at your profile photo and your cover photo. Those are public no matter how private your account is. Anyone who searches your name sees them. 
  • Check your old posts. Most platforms have a “limit past posts” button that makes everything you’ve ever posted friends-only in one click. Use it.
  • Turn off “suggest my account to others”. This is how you end up in the “people you may know” list of a student who happens to share a mutual contact with you.
  • Google yourself. Actually do it, in an incognito window so your own search history doesn’t skew the results. Whatever you see is what your students see. If something makes you uncomfortable, try to change it (hopefully it’s in a platform or website that you have easy access to).

And if a student does find you and sends a request – don’t accept and then quietly remove them later. Just don’t accept. Awkward for two days, peaceful for two years.

Passwords: the boring part that saves you

I know. Everybody says this. But my Scratch story only had a happy ending because of one setting I’d turned on, so let me say it anyway – use a password manager or have a note on your phone with your passwords and make them huge, no actual words, with numbers and symbols and everything. 

Turn on two-factor authentication (2FA) on your e-mail first, then everything else. That’s the “is this really you?” code or approval link and it’s an absolute necessity that has saved my dear a** so many times it’s hard to count them. That’s literally the thing that saved my grade’s Scratch account all of those years ago. A student can guess or shoulder-surf a password. They can’t grab the code from your phone though.

Funnily enough, the best way I’ve found to make 9-year-olds care about passwords is to let them make codes themselves. My Pigpen Cipher activity has them encrypting and decrypting messages in a special real-world cypher that was widely used in the past.

And about shared class accounts – if you use them like I did, treat that password as public information, because it is. Twenty-five 9-year-olds know it, which means their siblings and their friends know it too. So:

  • Never reuse it anywhere else, even slightly changed.
  • Make sure the recovery e-mail on it is your teacher e-mail with 2FA on.
  • Change it every term, and definitely at the end of the year.
  • Never, ever have a shared account own anything you’d be sad to lose.

Your classroom laptop is a public place

You’re projecting your screen onto a wall in front of thirty pairs of very observant eyes every day, a couple of times per day most of the time. They see everything – installed software, your browser tabs, the song on YouTube that you’ve been playing during the break between lessons, the titles of your e-mails if you were just checking your inbox, everything!

Things I do every single time to protect myself:

  • Turn off notification previews on my laptop before class. Nothing like a message from your teacher-friend saying “I’m going for a smoke” popping up mid-lesson in 40-point font. Windows has “Focus assist” / “Do not disturb”, Mac has the same.
  • Use a separate browser profile (or a whole separate browser) for teaching. Clean bookmarks, no saved passwords, no autofill, no history. When I start typing “sc” in the address bar it should say “scratch.mit.edu” and not something from my private life.
  • Never save passwords in the classroom browser. If a student sits at your desk for thirty seconds, saved passwords are visible in plain text in the settings. Thirty seconds is all it takes.
  • Lock the screen when I leave the room, even for one minute. Windows key + L. It’s muscle memory now.
  • Log out at the end of the day instead of just closing the lid.

Also, once a term, go into your Google/Microsoft account and look at “your devices” or “active sessions”. It shows you everywhere you’re logged in and if there’s a device you don’t recognize, sign it out.

Your phone counts too

Your phone lives in the classroom with you and your students can’t wait to get their hands on it! Especially if you have a nice colorful phone case you just got from Aliexpress :)

  • Screen lock on, with a PIN or fingerprint, not a swipe pattern. Patterns are extremely easy to read from across a room!
  • Hide notification content on the lock screen so messages don’t show a preview.
  • Turn on “find my device” and remote wipe, in case it ever goes missing.
  • Don’t hand your unlocked phone to a student to “just show them something”.

Keep communication where it belongs

Talk to students through school channels only – the school e-mail, the school platform, the principal or formal letters. Not WhatsApp, not Instagram DMs, not Discord, no matter how much easier it seems.

This isn’t only about hacking, it’s about protecting yourself. School channels are logged and visible to admin, which sounds scary but is actually the point: if a conversation is ever questioned, there’s a record of exactly what was said. A private DM has no such record, and it’s your word against theirs.

Quick rule I use for what to share: if I wouldn’t say it out loud in the staff room with the principal standing there, it doesn’t go in a message to a student.

… and If something does happen

It might, and it’s not a disaster if you move fast.

  1. Change the password on that account immediately, from a device you trust.
  2. Check the recovery e-mail and phone number on the account. Skilled attackers (and older students) change those first so they can lock you out again. This step gets skipped a lot.
  3. Sign out all other sessions. Every major platform has this button. I’ve done this multiple times on Facebook and Instagram.
  4. Turn on 2FA if it wasn’t on.
  5. Tell your school. Today, not next week. If any student data was involved, this isn’t optional and your school will have a procedure. It is always better to be the person who reported it than the person it was discovered about.
  6. Write down what happened and when, with screenshots. You’ll be grateful for this later.

If it’s harassment or bullying rather than an account issue – screenshot everything first, don’t reply, and take it to your admin. Don’t try to handle it yourself in DMs. That’s exactly the situation you set all these boundaries up to avoid.

Teach them this too

Here’s the nice part. Everything above is also a lesson.

My students are much less interested in poking at my accounts once they understand how accounts actually work – what a password does, why 2FA exists, what a digital footprint is. A lot of “hacking” at this age is just curiosity with nowhere useful to point it. Point it somewhere useful with a lesson about digital citizenship or cybersecurity.

I sneak this into coding lessons all the time: we talk about why we don’t put our real full name in a Scratch project, why we don’t share account passwords with a friend, what happens to a photo once you post it, and ten minutes here and there does more than one scary big lesson ever will.

If you want something ready-made, I use my Printable Digital Citizenship Discussion Prompts for exactly this – pull one out when you have ten spare minutes at the end of a lesson, no prep, no printing panic. And if you want the message living on your wall all year instead, the Digital Citizenship Bulletin Board kit does the quiet version of the same job.

The five-minute version

If you read all this and thought “I’ll do it later”, do these five things instead, immediately, right now, they take five minutes:

  1. Turn on 2FA for your main e-mail.
  2. Turn off “find me by phone number/e-mail” on Instagram and Facebook.
  3. Use the “limit past posts” button.
  4. Set a proper lock on your phone and hide notification previews.
  5. Google yourself in an incognito window.

That’s already 80% of it.

Your turn

I’d love to hear your stories – has a student ever found you online, or tried something clever with a class account? Tell me in the comments of this post or e-mail me, because I know mine isn’t the only Scratch-at-midnight story out there.

Stay safe out there, and go turn on 2FA. 💜

Leave a Reply