privacy & trust

Student data is not a growth strategy

The paperwork should get easier and the protections should get stronger at the same time. SyncIEP is built FERPA-first: encrypted records, role-scoped access, and a signed data privacy agreement before a single student is added.

FERPA-first · SDPC National DPA · Encrypted at rest

how protection works

Guardrails you can point to

This is the actual mechanics of who sees what and what the AI is allowed to touch, not a compliance page buried in a footer.

access

Every view is scoped by role

A co-teacher sees the snapshot, a provider sees the cases they’re bound to, a family sees their student, and a deny always beats an allow. Nobody gets “the whole database” because nobody needs it.

  • Role-scoped access for staff, providers, and families.
  • Providers see only the cases they’re assigned to.
  • District oversight is a defined capability, not a shared password.

the agreement

A real DPA, signed before day one

SyncIEP signs the SDPC National Data Privacy Agreement, the same standard agreement thousands of districts already use, and accepting it is a gate in signup, not an afterthought in a sales cycle.

  • SDPC National DPA with a General Offer your district can adopt.
  • The agreement is readable right on this site, before you commit.
  • Terms of service and privacy policy accepted explicitly at signup.

accountability

A memory of who did what

Every case keeps an activity trail: drafts accepted, documents shared, notices sent. When a question comes up months later, the answer is on the record, not in someone’s inbox.

  • Case activity trail across drafting, documents, and meetings.
  • AI proposals are attributed and flagged until a person acts on them.
  • What families see is explicit: shared on purpose, never by accident.

in writing, not in spirit

What we will, and will never, do

These aren’t marketing promises. They’re the terms of the data privacy agreement we sign before your first student is added.

We will

  • Encrypt student records at rest.
  • Sign a data privacy agreement (SDPC National DPA) before any student data is added.
  • Scope every view by role, so families and providers see exactly what they should.
  • Keep a case activity trail, so “who changed what” is never a mystery.
  • Put an educator’s review between every AI draft and the IEP.

We will never

  • Sell student data.
  • Use student data for advertising or ad targeting.
  • Build profiles of students for anything but the IEP work itself.
  • Let AI finalize anything in an IEP on its own.
  • Keep student data hostage. Export and deletion are yours.

Read the agreements yourself: terms of service · privacy policy

questions

Fair questions, straight answers

How is student data protected?

Records are encrypted at rest, access is scoped by role, and a signed data privacy agreement (SDPC National DPA) is in place before any student data is added. You can read the agreement itself right on this site.

Who can see a student’s record?

Only the people on that student’s team, each within their role: case managers work the full case, providers see the cases they’re bound to, co-teachers get the snapshot, families see their student in plain language. A deny always beats an allow.

What does the AI get to touch?

It reads the case file to draft and score, and that’s it. It can’t finalize an IEP, can’t invent evidence, and everything it proposes is flagged for an educator’s review with attribution in the activity trail.

Easier paperwork, stronger protections.

Read the DPA, then set up a workspace that treats student data the way it deserves.