IEPDesk
Sign in Try Free ›

Privacy Policy

Last updated: August 2026  ·  Versión en español

Plain-language summary: IEP Desk collects only the information necessary to provide the service. We do not sell your data, share it with advertisers, or use it to train AI models. Your child's information is encrypted, access-controlled, and under your control at all times.

1. Who We Are

IEP Desk ("we," "our," or "us") operates the website located at iepdesk.com and the web application located at app.iepdesk.com (collectively, the "Service"). IEP Desk is the data controller for the purposes of this Privacy Policy.

For any privacy-related questions or requests, please contact us at the email address provided in Section 13 of this policy.

2. Information We Collect

Information you provide directly

  • Account information: email address and password when you register for an account.
  • Child profile information: a name of your choice for your child (a first name, a nickname or a full name, as you prefer), disability category, school district, and grade level — only what you choose to enter. A first name or nickname is sufficient for the Service to work.
  • IEP data: IEP documents you upload (PDF), goals, progress notes, diary entries, meeting records, and communications you log within the application.
  • Communications: messages you send to us through support channels.

Information collected automatically

  • Usage data: pages visited, features used, session duration, and error logs, for the purpose of improving the Service.
  • Device and technical data: browser type, operating system, and IP address, used solely for security monitoring and technical support.
  • Cookies: session authentication cookies necessary for the Service to function, and optional analytics cookies. See our Cookie Policy for full details.

Information from third-party services

The Service is currently free during its beta period. If paid subscriptions are introduced in the future and you subscribe through a third-party platform, we would receive confirmation of your subscription status only. We do not and would not receive any payment card data — payments would be processed entirely by that platform.

3. How We Use Your Information

  • To create and manage your account and provide the Service.
  • To process IEP documents you upload using AI document analysis. Documents are sent to a third-party AI provider (currently Anthropic) solely for analysis. Under that provider's commercial terms, your data is never used to train AI models, and inputs and outputs are automatically deleted from the provider's systems within 30 days.
  • To generate legal letters and documents based on the information you provide.
  • To send transactional communications (account confirmation, security alerts). We do not send marketing emails without your explicit opt-in consent.
  • To monitor for and respond to security incidents.
  • To improve and maintain the Service using aggregated, anonymized usage data.

We never: sell your personal data to any third party; share your data with advertisers; use your child's data for any purpose other than providing the Service to you; or use personally identifiable information to train AI models.

4. Data Storage and Security

All user data is stored on Supabase infrastructure hosted in the United States (East US region). We implement the following technical and organizational security measures:

  • Encryption at rest: all data is encrypted at rest using AES-256 encryption.
  • Encryption in transit: all data is transmitted over TLS 1.3 encrypted connections.
  • Row-Level Security (RLS): our database enforces row-level security policies so that a user can only reach records they own or have been explicitly authorized to access — for example, an advocate a parent has invited — even in the event of an application-layer error.
  • Document storage: uploaded IEP documents are stored in a private, access-controlled storage bucket. Documents are not publicly accessible and cannot be retrieved without authenticated credentials.
  • Access controls: access to production systems is restricted to authorized personnel only and governed by least-privilege principles.

No security system is impenetrable. In the event of a data breach that creates a material risk to your rights, we will notify affected users within 72 hours of becoming aware of the incident.

5. Children's Privacy and COPPA

IEP Desk is a tool designed for parents and guardians of children with IEPs — not for direct use by minors. We do not knowingly collect personal information directly from children under the age of 13.

When you enter information about your child within the Service, you are doing so as the parent or legal guardian and in that capacity you authorize the processing of that information to provide the Service to you. Information about your child is used exclusively to help you manage their IEP process and is never shared with third parties except as described in Section 7.

Where a professional advocate enters or uploads information about a child on behalf of a family — including where that family does not have its own account — the advocate does so only on the basis of authorization obtained from the child's parent or legal guardian. Before creating such a record, the advocate must expressly confirm that they hold that authorization, and that confirmation is recorded with a timestamp. The advocate, not IEP Desk, is responsible for obtaining and holding that authorization. Section 6 describes advocate responsibilities in more detail.

If you believe a minor under 13 has independently created an account on the Service, please contact us immediately using the contact information in Section 13 and we will delete that account and associated data promptly.

6. Advocate Accounts

IEP Desk offers a separate account type for professional IEP advocates. Advocates use the Service both to collaborate with families who invite them and to manage their own practice.

Where a parent invites an advocate into their account, the parent chooses which modules to share. Within those modules, the advocate can view the shared information and can also upload documents on the family's behalf — for example, an IEP, an amendment or a specialist report the parent has sent them — which are labeled as uploaded by the advocate. The advocate can edit or delete only the documents they uploaded themselves; a parent's own documents cannot be modified or deleted by the advocate. The advocate has no access to modules the parent has not shared, and the parent may revoke that access at any time. Each grant of access is recorded with a timestamp.

Advocates may also manage children directly on behalf of families they work with, including families who do not have their own account. In these cases an advocate may create a child's record, upload the child's IEP and evaluations, and use the full case-management tools of the Service, alongside their own practice-management information such as case notes, contact details and prospective clients. Where an advocate does so, the advocate is responsible for that information and must confirm, when creating the record, that they hold the family's authorization to manage the child's data. By entering it, the advocate represents that they hold that authorization and that they will comply with any professional, contractual and legal obligations that apply to them. IEP Desk provides the tool; it does not determine the purposes for which an advocate processes the information of the families and children they serve.

Where a family an advocate has been managing later creates its own account, the advocate can transfer the child's record to the family. On transfer, ownership of the record and all associated data passes to the parent or legal guardian, and the advocate retains access only to the extent the family permits — on the same basis as any other invited advocate.

Case notes an advocate marks as private are visible only to that advocate and are never shown to the family. Notes an advocate chooses to share are visible to the family concerned.

7. Third-Party Service Providers

We share data with the following categories of third-party service providers, solely as necessary to provide the Service:

  • Supabase: database and file storage provider (United States). Supabase processes data on our behalf under a data processing agreement and does not use your data for its own purposes.
  • Anthropic: AI API provider used for IEP document analysis and AI Legal Assistant features. Data submitted to the Anthropic API is processed under Anthropic's API terms, which include a prohibition on using API data to train models. No personally identifiable data is included in prompts beyond what is necessary for the specific analysis requested.
  • Resend: transactional email provider. Used solely to deliver account emails such as sign-up confirmations, password resets and security notices. Resend receives your email address and the content of those messages, and does not use them for its own purposes.
  • Formspree: form-handling provider used to receive messages you send through our contact form. When you submit that form, Formspree receives the information you enter — such as your name, email address and message — and forwards it to us. Formspree processes this data on our behalf and does not use it for its own purposes.
  • Subscription platform: if and when paid subscriptions are introduced, payment will be managed by a third-party platform. We would receive only a subscription status signal and would have no access to payment card data. The Service is currently free during its beta period and no payment platform is in use.

We do not share your data with any analytics companies, advertising networks, data brokers, or other third parties beyond those listed above.

8. Data Retention

We retain your account data and associated child and IEP information for as long as your account remains active. If you delete your account, all personal data associated with your account — including child profile information, uploaded documents, and diary/progress entries — is permanently deleted from our systems within 30 days, with the exception of data that must be retained to comply with legal obligations or to resolve disputes.

Automated usage logs are retained for up to 90 days for security monitoring purposes before being permanently deleted.

9. Your Rights and Choices

You have the following rights with respect to your personal data:

  • Access: you can request a copy of all personal data we hold about you.
  • Correction: you can update or correct your account information at any time within the application settings.
  • Deletion: you can request deletion of your account and all associated data. An account deletion option is available in the application settings. Alternatively, contact us directly using the information in Section 13.
  • Data portability: you can request an export of your data in a machine-readable format.
  • Opt-out of marketing: if you have consented to marketing communications, you can withdraw that consent at any time using the unsubscribe mechanism in any marketing email.

To exercise any of these rights, contact us using the information in Section 13. We will respond to all requests within 30 days.

10. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including the right to know what personal information we collect, the right to delete personal information, the right to opt out of the sale or sharing of personal information (we do not sell or share personal information), and the right to non-discrimination for exercising your privacy rights. To exercise these rights, contact us using the information in Section 13.

11. Links to Third-Party Websites

The Service may contain links to external websites, including government resources (such as idea.ed.gov and parentcenterhub.org) and third-party information sources. This Privacy Policy applies only to the IEP Desk Service. We have no control over and accept no responsibility for the privacy practices of any third-party websites.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify active users by email or through a prominent notice within the application at least 14 days before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the Service after the effective date of changes constitutes acceptance of the updated policy.

13. Contact

For all privacy-related questions, requests to exercise your rights, or to report a privacy concern, please contact us at:

IEP Desk
Email:

We aim to respond to all privacy requests within 5 business days.

IEPDesk
Home Blog Privacy Terms Data Pledge Cookies

© 2026 IEP Desk. All rights reserved. Not affiliated with any school district or government agency.