Privacy Policy

Effective August 2026 · Last updated August 2026

This Privacy Policy explains what IEP Guide (“IEP Guide,” “we,” “us”) collects when you use iepguide.org and our mobile apps (together, the “Service”), how we use it, who we share it with, how long we keep it, and the choices and rights you have. It covers the free directory, free accounts, paid memberships, child profiles, the IEP meeting calendar, service and progress logs, saved school comparisons, the AI assistant, and agent (MCP) integrations.

Plain-language summary. You can use most of IEP Guide without an account. We never require your child’s real name, address, diagnosis, or IEP documents. We do not sell your personal information for money. We do not show ads anywhere on this site and we run no ad networks, ad cookies or third-party tracking scripts. Daily check-in logs stay on your device. You can export or delete everything at any time.

1. Who we are and what this policy covers

IEP Guide is an independent U.S. informational service. We are not a school, school district, local education agency, state education agency, healthcare provider, health plan, law firm, or government body. Because we are not a school and do not act as a school official, we do not receive or maintain student education records under the Family Educational Rights and Privacy Act (FERPA, 20 U.S.C. § 1232g). Information you personally choose to type into IEP Guide is your own record, not a school record.

This policy applies to iepguide.org, project subdomains, and our iOS and Android apps. It does not apply to third-party sites we link to, such as school district websites, state department of education portals, or public job boards.

2. Information we collect

a. Information you give us

  • Account information — email address and an authentication credential (password or a Google sign-in identifier). Optional display name.
  • Child profiles — only what you choose to enter: a nickname or initials, grade level, an optional program intensity tier (T1–T4), a color tag, and an icon avatar. There are no photo uploads and no free-text diagnosis field. You never need to enter a legal name.
  • IEP meeting calendar — meeting title, meeting type, date and time, optional location or video-conference link, computed annual/triennial deadlines, and checklist items you tick off.
  • Service schedules — the recurring services you record for a child (for example speech, OT, counseling, toileting or feeding support), with frequency and duration.
  • Saved school comparisons — the public schools you select to compare and any label you give the comparison.
  • Messages you send us — email, contact-form content, reviews, and data-correction reports.
  • AI assistant prompts — the questions you type into the chat widget.

b. Information that stays on your device

Daily check-in logs (mood, academics, behavior, accidents, medication notes, and similar entries) are written to your browser’s local IndexedDB storage on the device you use. They are not transmitted to our servers, are not backed up by us, and are not readable by us. Free-text meeting notes are never written to our database: they stay in your browser session (with a temporary local recovery draft) until you export or save them yourself. Clearing site data, uninstalling the app, or losing the device permanently deletes these entries — export a PDF if you need a copy.

c. Information collected automatically

  • Usage and device data — browser and device type, operating system, referring page, pages viewed (path only, without query strings), timestamps, and coarse region derived from IP.
  • A device identifier — a non-reversible visitor token derived from ordinary browser characteristics. We use it only to apply free-access limits fairly and to detect abuse. It is not a biometric identifier: we do not collect fingerprints, faceprints, voiceprints, retina or iris scans, or hand or face geometry, and we do not use facial recognition anywhere on the Service.
  • IP address — used transiently for security, fraud prevention, and abuse limits. Before any storage, IP addresses are hashed with a secret salt using SHA-256. We do not retain plain IP addresses.
  • Location — with your browser permission, we use your approximate coordinates to show nearby schools. If you type an address or ZIP code instead, it is used in memory for that session only. Addresses and precise coordinates are never written to our database, never placed in a URL, and never included in an analytics event.

d. Payment information

Paid memberships are processed by Stripe, Inc. Card numbers are entered directly with Stripe and never reach our servers. We receive only a customer identifier, subscription status, plan, renewal date, and the last four digits and brand of the card for receipts and support.

e. Public education data

School, district, staffing, and assessment figures come from public federal and state datasets. They are aggregated institution-level statistics. IEP Guide does not obtain, host, or publish individual student records, and no listing on this site identifies a student.

3. Sensitive and health-related information

IEP Guide is not a covered entity or business associate under HIPAA, and nothing you enter here is a medical record. Some optional entries — a program intensity tier, a therapy service on a schedule, a check-in note — could be inferred as health-related. We treat them as sensitive:

  • Check-in logs and free-text notes never leave your device in readable form.
  • Server-stored family data is never used for advertising, ad targeting, profiling, or automated decision-making producing legal or similarly significant effects, and it is never sold or shared for cross-context behavioral advertising.
  • We do not collect precise geolocation into storage, and we do not collect race, ethnicity, religion, immigration status, union membership, sexual orientation, genetic data, or biometric data.
  • Consistent with Washington’s My Health My Data Act, Nevada SB 370, and comparable state consumer-health-data laws, we do not sell consumer health data, do not use geofencing around healthcare, therapy, or school facilities, and collect health-adjacent entries only to provide the feature you asked for.

3.1 Meeting notes, voice recordings, transcripts, and summaries

Meeting notes are never stored by IEP Guide. The Notes tab is a session-only workspace: what you type, record, transcribe, or summarize lives in your browser’s memory while you work, and it is written to our servers at no point. To protect you against a crash or an accidental tab close, a temporary recovery draft is kept in your own device storage during an active session; it is permanently wiped the moment you export, and any leftover draft is wiped after 24 hours.

  • Voice transcription uses a third-party AI processor. Your audio is transmitted for processing only, is not retained by us, and is discarded from memory immediately after the transcript is returned. Including the audio file in your export is optional and off by default.
  • Notes, transcripts, and summaries are never stored by iepguide.org. They exist only until you save them to your own device, Google Drive, Apple iCloud/Files, or Microsoft OneDrive. Uploads to those drives go directly from your browser to your account and never pass through our servers; our Google Drive access is limited to files our app creates.
  • Notes, transcripts, summaries, and audio are never used for advertising and are never used to train AI models.
  • Recording laws vary by state and district. You are responsible for obtaining the consent or giving the notice your state and school district require before recording an IEP meeting.

If our servers were ever breached or subpoenaed, your meeting schedule could be exposed — your notes could not. We don’t have them.

4. How we use information

  • To operate the directory, search, ratings, maps, and comparison features.
  • To create and secure your account and to authenticate you.
  • To store and display the child profiles, calendars, schedules, and comparisons you save.
  • To send transactional email you asked for: sign-in links, password resets, receipts, and IEP meeting reminders.
  • To deliver in-app and browser reminders you have enabled.
  • To process subscriptions, renewals, refunds, and billing support through Stripe.
  • To answer your AI-assistant questions and support requests.
  • To measure aggregate traffic, diagnose errors, and enforce free-tier limits.
  • To prevent fraud and abuse and to comply with law.

We do not use your personal information to train third-party generative AI models, and we do not sell personal information for money.

5. Advertising, cookies, and tracking technologies

iepguide.org does not display advertising anywhere on the site — public pages included. We do not load Google AdSense, Google Ads conversion tags, the Meta pixel, or any other advertising, retargeting or third-party tracking script, because families using this site are sharing information about children. We do not share identifiers or browsing activity with advertising partners, so there is no “sale” or “sharing” for cross-context behavioral advertising under the California Consumer Privacy Act as amended by the CPRA, and no “targeted advertising” under comparable state laws. We may promote IEP Guide on other websites, but that advertising happens off our site and never collects data about your visit here.

Cookies we use fall into two groups:

  • Strictly necessary — sign-in sessions, security, consent state, and your in-session search and filter preferences. These cannot be switched off.
  • Analytics — our own aggregate page-view and performance measurement. No third-party ad networks are involved.

There is no advertising cookie group, because we serve no ads. A consent banner lets you accept or decline non-essential cookies on your first visit, and we honor Global Privacy Control (GPC) browser signals. Disabling cookies in your browser may affect some site features.

No ads, anywhere. No advertising or third-party tracking scripts load on any page, and analytics events are additionally blocked on all signed-in account and family pages — including child profiles, calendars, service logs, check-ins, and saved comparisons. We may run ads for IEP Guide on other websites; those campaigns collect nothing from your visit here.

6. When we share information

We never sell your personal information. We disclose it only as follows:

  • Service providers acting on our instructions under contract: our hosting and database provider, Stripe (payments), our transactional email provider, and our AI model gateway for assistant replies. They may not use your information for their own purposes.
  • Advertising partners on public pages only, as described in Section 5.
  • Agent / MCP integrations — if you explicitly authorize an AI agent or third-party client through our OAuth consent screen, that client can read only the data your account is permitted to read, only for as long as the authorization lasts. You can revoke access from your account at any time.
  • Calendar feeds you create — a private iCal subscription link is a secret URL. Anyone you send it to can read those meeting entries. You can rotate or delete the link at any time.
  • Legal and safety — when required by valid legal process, or to protect rights, safety, or the integrity of the Service.
  • Business transfer — in a merger, acquisition, or asset sale, subject to this policy continuing to apply.

7. Security

We use HTTPS in transit, encryption at rest, hashed credentials, salted-hash storage of IP addresses, and database row-level security so that only your account can read or modify your own records. Access to production systems is limited and logged. No online service can guarantee absolute security. If a breach affecting your personal information occurs, we will notify affected users and applicable state authorities within the timeframes required by the breach-notification laws of all 50 states, the District of Columbia, and U.S. territories.

8. How long we keep information

  • Account and family data: until you delete it or close your account.
  • Deleted child profiles and comparisons: removed from live systems immediately and purged from backups within 30 days.
  • Closed accounts: deleted within 30 days, except records we must keep for tax, accounting, or fraud purposes.
  • Billing records: retained as long as required by tax and accounting law (generally 7 years).
  • Hashed visitor tokens and hashed IPs used for abuse limits: up to 13 months.
  • Aggregate, non-identifying analytics: retained indefinitely.
  • On-device check-ins and notes: kept until you delete them or clear site data.

9. Your privacy rights and choices

Regardless of where you live, every IEP Guide user can: access and export their data (“Export all data” on each child’s Overview tab, and PDF export throughout), correct profile details, delete any child profile or the whole account, decline non-essential cookies, revoke notification and location permissions, revoke agent authorizations, and unsubscribe from non-transactional email.

Depending on your state of residence, you may also have the rights below under laws including the California CCPA/CPRA, Virginia CDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Iowa, Indiana, Tennessee, Montana, Oregon, Texas, Florida, Delaware, New Hampshire, New Jersey, Nebraska, Minnesota, Maryland, Rhode Island, Kentucky, and comparable laws as they take effect:

  • Know what we collect, use, disclose, and share, and obtain a copy in a portable format.
  • Correct inaccurate personal information.
  • Delete personal information, subject to narrow legal exceptions.
  • Opt out of targeted advertising and of any “sale” or “sharing,” including via a GPC signal.
  • Limit the use of sensitive personal information.
  • Appeal a denied request (we respond to appeals within 45 days).
  • Not be discriminated against or receive a lesser service for exercising a right.

To exercise any right, email privacy@iepguide.org from the address on your account, or use contact@iepguide.org. We verify requests by confirming control of the account email and respond within 45 days (extendable once by 45 days with notice). An authorized agent may submit a request with written permission. California residents may also request the categories described in Civil Code § 1798.83 (“Shine the Light”); we do not disclose personal information to third parties for their own direct marketing.

Do Not Sell or Share My Personal Information / Opt out of targeted advertising: decline cookies in the consent banner, enable Global Privacy Control in your browser, or email privacy@iepguide.org. Nevada residents may submit a verified opt-out of the sale of covered information to the same address.

10. Children’s privacy

IEP Guide is designed for adults — parents, guardians, educators, and advocates. It is not directed to children, and we do not knowingly collect personal information online from a child under 13 as defined by the Children’s Online Privacy Protection Act (COPPA, 15 U.S.C. §§ 6501–6506) and its amended Rule. Accounts require users to be 18 or older, or 13+ with verifiable parent or guardian consent and supervision.

A parent who creates a child profile is entering their own family information about their own child, voluntarily and under their own control; the child is not a user of the Service. We do not serve personalized advertising on any page containing child profile data, and we do not build advertising profiles of children. Under state student-privacy laws such as California’s SOPIPA and the Student Online Personal Information Protection Act framework adopted in many states, we do not target ads based on student-derived data, do not create non-educational profiles of students, and do not sell student information — noting again that we operate independently of any school and do not receive school-provided student records.

If you believe a child under 13 has provided personal information to us, email privacy@iepguide.org and we will delete it promptly.

11. Email and notifications

Transactional messages (sign-in, password reset, receipts, meeting reminders you scheduled) are part of the Service. Any promotional email includes a working unsubscribe link honored within 10 business days, identifies IEP Guide, and includes a valid postal address, as required by the CAN-SPAM Act. We do not send marketing text messages or autodialed calls. Push and in-app reminders are opt-in and can be turned off in your device settings or on the notification status panel in your account.

12. Accessibility

We aim to conform to WCAG 2.1 Level AA and to make the Service usable with keyboards and screen readers, consistent with the Americans with Disabilities Act and Section 504 of the Rehabilitation Act. If you encounter a barrier, email contact@iepguide.org and we will work with you to provide the information in an accessible way.

13. U.S.-only service and external links

The Service is intended for users in the United States and is hosted in the United States. We do not offer it to individuals in the European Economic Area, United Kingdom, or Switzerland, and we do not knowingly target or monitor them. We may link to public agencies, districts, and data sources; we are not responsible for their content or privacy practices.

14. Changes to this policy

We may update this policy as features and laws change. We will update the “Last updated” date above and, for material changes affecting how we use information you already gave us, provide notice in the app or by email before the change takes effect.

15. Contact

Privacy requests: privacy@iepguide.org. General questions: contact@iepguide.org or the Contact page. See also our Terms of Use.

This policy describes our practices in plain language and is not legal advice. State privacy laws continue to change; if a provision conflicts with a mandatory right you hold under the law of your state, that law controls.