Privacy Policy
Effective July 6, 2026
This Privacy Policy describes how SyncIEP collects, uses, protects, and deletes information — with particular care for the student education records at the heart of the Service. Our standing commitments match the SDPC national standard: student data stays yours, is never sold or used for targeted advertising, and is protected and destroyed on a defined schedule.
1. What we collect
Account information
Your name, email, role/provider type, school or district, and state — collected at signup to provision your workspace.
Student records you bring into the Service
IEPs, evaluations, assessments, student work, progress data, meeting records, and related documents you or your team upload or create. These are education records under FERPA; we process them as a “school official” under your direction, with a legitimate educational purpose and under your school’s direct control with respect to their use and maintenance.
Usage information
Standard technical logs (device, browser, IP address, actions taken) used for security auditing, debugging, and improving the Service. We audit access to student records — reads of protected records are logged.
2. How we use information
- To provide, secure, and support the Service.
- To power the features you invoke — including AI-assisted drafting and grading, which process the evidence in your workspace solely to produce output for your review.
- To send service communications (invitations, notifications, receipts). Marketing email, if any, is only ever sent to educators — never to students or families — and is opt-out.
3. What we never do
- We never sell student data.
- We never use student data for targeted advertising or build advertising profiles.
- We never use student data to train generalized AI models. Model calls process your workspace’s evidence to draft for that student, and our AI vendors are contractually barred from retaining or training on it.
4. Sharing and subprocessors
We share data only with the service providers required to run the Service (cloud hosting, document storage, email delivery, AI model providers), each bound by agreements at least as protective as this policy. We do not share student data with third parties for their own purposes. We disclose records if required by law, and where lawful we will notify you before doing so.
5. Google user data
If you sign in with Google or connect your Google Calendar, SyncIEP accesses only your basic Google identity (name, email) and your calendar availability and events. Calendar access is used solely to place the meetings you schedule in SyncIEP onto your own calendar and to show you free/busy conflicts when scheduling; when checking availability we read only event times and status — never titles, descriptions, or attendees.
SyncIEP’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data — whether raw, aggregated, anonymized, or derived — is never transferred to third-party AI or machine-learning services, and is never used to create, train, or improve any AI or machine-learning model, whether ours or a third party’s.
6. Security
- Encryption in transit (TLS) and at rest.
- Tenant isolation: your workspace’s records are scoped so other accounts can never read them.
- Role-based access with deny-wins restrictions, and audit logging of access to student records.
- Breach notification: if a breach affects student data, we notify affected accounts without unreasonable delay and in accordance with applicable law.
7. Retention and deletion
Student data is retained while your account is active so your team can meet its educational and legal obligations. When you delete a record, close your account, or your subscription lapses past its grace period, we delete the associated student data within 90 days, except where law requires longer retention. You can export your records at any time before deletion.
8. Families and student rights
Rights of access, amendment, and deletion in student records belong to parents, guardians, and eligible students under FERPA and IDEA, exercised through the school. If a family contacts us directly, we will refer the request to you and assist you in fulfilling it. Where the Service offers a parent portal, families see only what your team publishes to them.
9. Children
The Service is used by educators; students do not create accounts. Student information enters the Service only through their school’s or teacher’s authorized use, consistent with FERPA’s school-official framework and, where applicable, COPPA’s school-consent provisions and state student-privacy laws (including California’s SOPIPA).
10. Your choices
- Access, correct, or export your account information from your settings.
- Control notification preferences in the app.
- Close your account at any time, which starts the deletion schedule above.
11. Changes to this policy
If we materially change this policy, we will notify you by email or in-app notice before the change takes effect. We will never weaken protections on student data already in the Service without your consent. The version you accepted is recorded with your account.