Skip to content

Trust & privacy

How we handle student and family data

IEP Advisor holds some of the most sensitive records a school keeps. This page states, plainly, what we store, who can see it, how long we keep it, which vendors touch it, and how our AI features are governed. Last updated 2026-09-16. Statements describe the product as configured; a signed data-processing agreement governs a pilot.

What we store and who sees it

Retention and deletion

AI governance

Sub-processors

VendorPurposeData
Microsoft AzureHosting, database, file storage, email delivery (Communication Services)All application data; email addresses and message content
AnthropicAI drafting, explanations, briefsThe document/draft and evidence in scope for the request; commercial API terms exclude training on content
StripeParent subscription billingParent name, email, payment details (held by Stripe)
SentryError monitoringTechnical error data with a numeric user id; no email, no request bodies

We notify districts before adding a sub-processor.

Accessibility

We build to WCAG 2.1 AA: keyboard-operable dialogs and forms, live regions for asynchronous results, visible focus, reduced-motion support, and phone-first reading views for families. Charts carry a text alternative. If something gets in your way, email support@iep-advisor.com — we reply within one business day and treat accessibility defects as blocking.

Agreements and contact

A data-processing agreement (including FERPA "school official" terms and a breach-notification commitment) is available on request and precedes any pilot with real student data. Questions: privacy@iep-advisor.com.