privacy & trust

Student data is not a growth strategy

The paperwork should get easier and the protections should get stronger at the same time. SyncIEP is built FERPA-first: encrypted records, role-scoped access, and an activity trail on every case.

FERPA-first · Encrypted at rest · Role-scoped access

how protection works

Guardrails you can point to

This is the actual mechanics of who sees what and what the AI is allowed to touch, not a compliance page buried in a footer.

access

Every view is scoped by role

A co-teacher sees the snapshot, a provider sees the cases they’re bound to, a family sees their student, and a deny always beats an allow. Nobody gets “the whole database” because nobody needs it.

  • Role-scoped access for staff, providers, and families.
  • Providers see only the cases they’re assigned to.
  • District oversight is a defined capability, not a shared password.

the terms

The commitments are in writing

What we do with student data is spelled out in the terms of service and the privacy policy, both accepted explicitly at signup and readable on this site before you commit. No selling student data, no advertising use, no profiles beyond the IEP work itself.

  • Terms of service and privacy policy accepted explicitly at signup.
  • The commitments are spelled out in plain language on this site.
  • Export and deletion stay yours, on your timeline.

accountability

A memory of who did what

Every case keeps an activity trail: drafts accepted, documents shared, notices sent. When a question comes up months later, the answer is on the record, not in someone’s inbox.

  • Case activity trail across drafting, documents, and meetings.
  • AI proposals are attributed and flagged until a person acts on them.
  • What families see is explicit: shared on purpose, never by accident.

in writing, not in spirit

What we will, and will never, do

These aren’t marketing promises. They’re the terms every account accepts before a single student is added.

Read them yourself:

we will

  1. 1.Encrypt student records at rest.
  2. 2.Scope every view by role, so families and providers see exactly what they should.
  3. 3.Keep a case activity trail, so “who changed what” is never a mystery.
  4. 4.Put an educator’s review between every AI draft and the IEP.

and we will never

  • Sell student data.
  • Use student data for advertising or ad targeting.
  • Build profiles of students for anything but the IEP work itself.
  • Let AI finalize anything in an IEP on its own.
  • Keep student data hostage. Export and deletion are yours.

questions

Fair questions, straight answers

How is student data protected?

Records are encrypted at rest, access is scoped by role, and every case keeps an activity trail. The terms of service and privacy policy are accepted explicitly at signup, and you can read both right on this site.

Who can see a student’s record?

Only the people on that student’s team, each within their role: case managers work the full case, providers see the cases they’re bound to, co-teachers get the snapshot, families see their student in plain language. A deny always beats an allow.

What does the AI get to touch?

It reads the case file to draft and score, and that’s it. It can’t finalize an IEP, can’t invent evidence, and everything it proposes is flagged for an educator’s review with attribution in the activity trail.

Easier paperwork, stronger protections.

Read the terms, then set up a workspace that treats student data the way it deserves.