Last Updated: June 11, 2026
The Advocate Ally reviews sensitive education documents, including IEPs, 504 plans, evaluations, and related notes. This policy explains what we collect, why we use it, who helps us process it, and how parents, guardians, advocates, educators, and schools can ask questions or make privacy requests.
This policy covers use of The Advocate Ally website, account tools, document upload flows, audit reports, school and educator workflows, support channels, SMS notices, payments, and related services. If a school, district, agency, or other institution signs a written agreement with us, that agreement may add or replace terms for that institutional use.
We collect the information needed to provide and protect the Services. That may include:
We use information for limited service, safety, and compliance purposes:
We use AI and document-processing tools to help review uploaded education records and generate requested reports. Uploaded documents and extracted text are treated as user-provided records, not as instructions that override our safety, privacy, or security rules.
We share information only as needed to run, secure, support, or legally protect the Services. We may use service providers for cloud hosting, authentication, database and storage services, document processing, AI processing, payment processing, email, SMS, analytics, security monitoring, error tracking, customer support, and professional advice.
Service providers are expected to use information only for the services they provide to us, subject to their role, contract terms, confidentiality obligations, and applicable law. We may also disclose information if required by law, subpoena, court order, regulator request, merger, acquisition, financing, sale of assets, bankruptcy, or to protect rights, safety, security, or service integrity.
We use layered administrative, technical, and operational safeguards, including access controls, authorization checks, encryption in transit, provider-supported encryption at rest, private storage paths for uploaded records, security logging, and restricted support/admin workflows. Our infrastructure uses Google Firebase and Google Cloud services.
No internet service can guarantee perfect security. You are responsible for using a strong password, protecting your account, uploading only records you are authorized to submit, and telling us quickly if you believe your account or student data may be at risk.
Raw uploaded documents are designed to be used for document review and then removed after processing or cleanup where available. Generated reports, action plans, account records, access logs, billing records, consent records, support records, privacy/security logs, backups, and institutional records may have different retention periods depending on the workflow, legal requirements, tax/accounting obligations, security needs, backup limits, and any written school or district agreement.
Authenticated users may download available audit summaries or submit privacy requests in account settings. You can also contact privacy@theadvocateally.com to request access, export, correction, deletion, restriction, or account closure. We may need to verify your identity before fulfilling a request, and some records may be retained where required or permitted for security, legal, accounting, dispute, or continuity reasons.
The Services are intended for adults, including parents, guardians, advocates, educators, and authorized institutional users. Children under 13 and students should not create accounts, upload records, or provide personal information directly. If you believe a child submitted information directly, contact privacy@theadvocateally.com.
Teachers, school staff, and institutional users may use the Services only for authorized professional purposes and only with records they are permitted to use. Access to a student record does not automatically mean permission to upload it to every tool.
If a school, district, or educational agency uses the Services, the applicable written agreement, district policy, parent/student notice requirements, and legal obligations govern that use in addition to this policy. Institutional users should not direct students to create accounts or submit records unless we have expressly approved that workflow and the required notices, permissions, and agreements are in place.
If you provide a phone number and opt in to SMS, we may send service-related texts such as audit status, booking reminders, or account updates. We design SMS messages to stay generic and direct you back to authenticated pages for sensitive details.
Message Frequency: Message frequency varies. You may receive 1 to 5 messages per month depending on your activity.
Message and Data Rates: Message and data rates may apply.
Opt-Out: You can opt out at any time by replying STOP. For help, reply HELP or contact support@theadvocateally.com.
No SMS marketing sale: We do not sell, rent, or share your phone number with third parties for their marketing purposes. Phone numbers are used for service-related messaging through our SMS provider.
We may update this policy from time to time by posting a new version and changing the "Last Updated" date. Contact privacy@theadvocateally.com for privacy questions, security@theadvocateally.com for security reports, and support@theadvocateally.com for general support.