Privacy
Privacy Policy
This policy explains the information CompliantIEP handles, why it is needed, and the choices available to educators and schools.
Effective August 2, 2026
1. Scope and our role
This policy applies to CompliantIEP's website and educator workspace. CompliantIEP provides drafting, organization, and compliance-support tools for education professionals. When a school or educator submits student information, that organization or educator controls which records are provided and must have the authority to use the service for that purpose.
CompliantIEP is not a school, does not make eligibility or placement decisions, and does not claim that use of the service alone satisfies FERPA, IDEA, COPPA, or state student-privacy requirements. Educators should confirm that the service is approved under their school or district's policies before entering education records.
2. Information we collect
- Account data: name, email address, authentication identifiers, settings, and subscription status.
- Education data you provide: IEP text, student names or identifiers, grade level, disability information, goals, assessments, observations, progress data, notes, and generated drafts.
- Files: documents or images uploaded for text extraction or drafting.
- Billing data: customer, subscription, and transaction references. Payment-card details are collected directly by Stripe and are not stored by CompliantIEP.
- Technical data: request metadata, device and browser information, security events, feature usage, and privacy-filtered error diagnostics.
3. How we use information
We use information to authenticate users; extract documents; generate and save educator-requested drafts; organize students, IEPs, and progress records; process subscriptions; provide support; prevent fraud and abuse; diagnose failures; secure the service; and meet legal obligations. We do not sell personal information, use student data for targeted advertising, or build advertising profiles from education data.
4. AI processing
When an educator uses an AI-assisted feature, the relevant prompt, IEP content, and requested context are transmitted to OpenAI to generate the response. OpenAI states that API data is not used to train its models unless the customer opts in, and that default abuse-monitoring logs may be retained for up to 30 days. Do not submit information that is unnecessary for the requested task. Generated content must be reviewed by a qualified educator before use.
See OpenAI's current API data controls.
5. Service providers and disclosures
We disclose data only as needed to operate the service, at a user's direction, or when legally required. Current core providers include:
- Google Firebase and Google Cloud for authentication, databases, and cloud infrastructure.
- OpenAI for requested AI drafting and analysis.
- Vercel for application hosting and delivery.
- Stripe for checkout, subscriptions, invoicing, and payment processing.
- Sentry for privacy-filtered error and performance monitoring. Student content, request bodies, cookies, and authentication headers are excluded or redacted by our monitoring configuration.
Provider practices are governed by their own terms and privacy commitments. Firebase's privacy and security information is available here, and Stripe's privacy information is available here.
6. Student privacy and children
The service is intended for adults acting in a professional education role, not for use by students or for children to create their own accounts. Education data is used only to provide, secure, and support the requested service; it is not used for unrelated commercial advertising. If you believe a child created an account or information was submitted without proper authority, contact us so we can investigate and delete it as appropriate.
The U.S. Department of Education advises teachers to confirm that an online service is approved by their school or district. See its student privacy guidance.
7. Retention and deletion
Account and saved workspace content are retained while an account is active so the educator can return to their work. We may retain limited billing, security, and audit records when required for legitimate business or legal purposes. Deleted data may remain temporarily in encrypted backups before normal backup rotation removes it. To request access, correction, export, or deletion, email us from the account address.
8. Security
We use access controls, encrypted transport, provider encryption at rest, restricted server-side data access, rate limits, monitoring with sensitive-data filtering, and database recovery safeguards. No online system can guarantee absolute security. Notify us promptly if you suspect unauthorized access.
9. Cookies and similar technology
CompliantIEP uses necessary cookies for secure sign-in and local browser storage for interface preferences and email-link completion. We do not use third-party advertising cookies. Privacy-filtered diagnostics may measure reliability and performance.
10. Location and transfers
CompliantIEP and its providers may process information in the United States and other locations where they operate. Schools with specific residency or contractual requirements should contact us before use.
11. Changes and contact
We may update this policy as the service or law changes. We will post the revised effective date and provide additional notice when a material change requires it. Questions and privacy requests may be sent to support@compliantiep.com.