IEP Desk is built on a foundation of trust. This page explains — in plain language — the specific commitments we make to every family who uses the Service, and the technical measures that back them up.
Last updated: August 2026
Every piece of information you enter — your child's name, their goals, their documents — belongs to you. You can export it or delete it at any time, no questions asked.
IEP Desk is funded by the people who use it, not by advertising. Your data is not a product. We have never sold user data and we never will.
Documents you upload are analyzed by AI and nothing more. Anthropic's commercial terms prohibit using API data to train models, and what we send is automatically deleted from their systems within 30 days. Your child's IEP is not training data.
IEP documents you upload are stored in a private, encrypted bucket and stay there until you delete them or close your account. Specialist reports shared with an advocate are stored temporarily (maximum 30 days) and deleted automatically once downloaded or expired.
If you invite an advocate, you choose exactly which modules they can see. Within those modules, an advocate can view your information and upload documents on your behalf — such as an IEP or a report you've sent them — clearly labeled as uploaded by the advocate. They can only edit or delete what they uploaded themselves; they can never modify or delete the documents and information you added. You can revoke access at any time, module by module.
Messages exchanged with your advocate are private, linked to your child's profile, and never shared with third parties. They are permanently deleted when you close your account.
Promises are only as good as the systems that enforce them. Here is what we have actually built to make these commitments technically enforceable — not just contractually stated.
Our database enforces security at the data layer — not just the application layer. Even if there is a bug in our application code, the database itself will refuse to return your data to anyone you have not authorized to see it.
All data stored in our database and document storage is encrypted at rest using AES-256 encryption — the same standard used by financial institutions and government agencies.
All data transmitted between your device and our servers uses TLS 1.3, the most current and secure version of the Transport Layer Security protocol. Nobody between your device and our servers can read it.
Uploaded IEP documents are stored in a private, access-controlled storage bucket on Supabase. There are no public URLs that can be guessed or discovered. Access requires authenticated credentials.
We use Anthropic's API under commercial terms that explicitly prohibit the use of API data for model training. When your document is analyzed, the AI provider deletes the data from its systems within 30 days. It is never added to a training set and never used for any purpose other than answering our request.
Production database access is restricted to authorized technical personnel only, governed by least-privilege principles. No employee has routine access to user data without a specific, logged reason.
IEP Desk allows parents to invite an IEP advocate and selectively share specific modules with them — such as their child's IEP plan, meeting preparation, diary, documents, progress tracking or specialist reports. This sharing is always explicit, controlled by the parent, and revocable at any time.
Advocates who manage a child directly. Some advocates work with families who do not have their own IEP Desk account. In that case the advocate can hold the child's records directly — creating the record, uploading the IEP and evaluations, and managing the case. Because there is no parent account behind it, we require the advocate to confirm, at the moment they create the record, that they have the family's authorization to manage the child's data. That confirmation is stored with a timestamp. The advocate is responsible for holding that authorization; IEP Desk provides the tool and keeps the record of the attestation.
Handing a case back to the family. If a family that an advocate has been managing later decides to create their own account, the advocate can transfer the child's record to them. Ownership then passes to the parent or guardian, together with everything in the record, and the advocate keeps access only on the same terms as any invited advocate — whatever the family chooses to share.
IEP Desk may in the future use anonymized, aggregated data — information that has been stripped of all personally identifiable information and cannot be linked to any individual user or child — to produce general research or insights about the IEP system. For example, we might publish a report on the most common types of IEP goals across disability categories, using data that cannot be traced to any individual.
We will never include personally identifiable information in any such research. Before initiating any aggregated data research program, we will update our Terms of Service and Privacy Policy to provide full transparency, and we will provide users with the ability to opt out.
IEP Desk uses the Anthropic API to power AI document analysis and the AI Legal Assistant. We have reviewed Anthropic's API usage policy and confirmed that data submitted through the API is not used to train Anthropic's models. You can review the terms that govern this at anthropic.com/legal/commercial-terms and Anthropic's data retention policy at privacy.claude.com.
We minimize the data sent to the API to only what is necessary for the specific analysis or question at hand. When we send text to the API — for example, to draft a letter or answer a question in the assistant — your child's name and your name are replaced with neutral placeholders before the request leaves our systems, and put back only in the reply you see. When you upload a document for analysis, though, it is sent as it is, so any name written inside it travels with it. This is why the child profile only ever needs a first name or a nickname, and why we recommend using one.
If you believe IEP Desk has violated any of the commitments on this page, or if you have concerns about how your data is being handled, contact us directly at the email address below. We will respond within 5 business days and investigate all concerns thoroughly.
Privacy concerns can also be raised with your state's Attorney General office or, for California residents, with the California Privacy Protection Agency (CPPA).
IEP Desk
Email:
This page is a statement of commitment, not a legally binding contract on its own. The legally binding provisions governing data handling are contained in our Privacy Policy and Terms of Service. In the event of any conflict between this page and those documents, the Privacy Policy and Terms of Service govern.