Trust CenterLast reviewed August 13, 2026

Trust is earned in the details.

Your family's education records deserve more than a lock icon. See what we protect, how data moves, which providers help, what you control, and where our responsibility has limits.

Need a direct answer?

Privacy requests and vulnerability reports go to different, dedicated addresses.

Student data is not for sale

We do not sell student data or use identifiable uploaded records for targeted advertising or unrelated commercial profiling.

You choose what to submit

Parents, advocates, and authorized educators decide which records to upload for a requested review.

People remain the decision-makers

AI output is informational. Important education and legal decisions still require human review and judgment.

Safeguards

Specific controls, with their scope attached.

A provider safeguard is not the same thing as an application control. These labels make that distinction visible.

Product control

Account-bound access

Sensitive report views, exports, and deletion workflows are designed to require account authorization, with added verification where available.

Product control

Encrypted report storage

Sensitive generated audit details are designed to be encrypted before storage and returned through authenticated application paths.

Provider control

Protected in transit and at rest

Firebase services use HTTPS in transit and provider-supported encryption at rest for the services that store customer content.

Firebase security documentation
Data minimization

Sensitive content stays out of routine channels

SMS, analytics, advertising, and routine logs are designed to exclude raw IEP text, student names, disability labels, findings, and raw upload links.

Lifecycle control

Raw-upload cleanup

Raw uploads are normally removed after processing. Failed or abandoned uploads become eligible for automated stale-upload cleanup after 72 hours.

Operational control

Restricted support access

Support and administrative access is intended to be limited, logged, and tied to an approved support, security, or operational need.

Data flow

What happens after you choose a file.

This is the practical lifecycle—not a promise that every record shares one retention schedule.

  1. 01

    You upload a record

    The browser creates an access-controlled upload for the review you requested. Upload only records you are authorized to submit.

  2. 02

    The review is processed

    Document content may be extracted and sent to an AI-processing provider for the requested analysis. The content is treated as untrusted input, not as instructions to the system.

  3. 03

    A report is returned to your account

    Generated results are stored through the protected report path and shown only through an authorized account experience.

  4. 04

    Different records follow different clocks

    Raw uploads are normally removed after processing. Reports, account records, consent, billing, security logs, and backups can have different retention periods.

Retention has important exceptions.

Account, billing, consent, support, security, backup, and institutional records may be retained for different periods when required for legal, accounting, dispute, security, continuity, or contractual reasons. Read the full Privacy Policy for the governing detail.

Service providers

Who helps, why they are involved, and the boundary.

The useful question is not just which logo appears in the stack. It is what role the provider performs and what information that role may require.

Role

Hosting, authentication, database, private file storage, functions, and infrastructure.

Data boundary

Receives the account, upload, and service data needed to provide those platform features.

Service

AI processing providers

Role

Document extraction, review, and report generation requested by the user.

Data boundary

May receive uploaded content or minimized extracted text needed for that review. Provider settings and retention can differ by service.

Service

Stripe

Role

Checkout, card processing, invoices, subscriptions, billing records, and fraud prevention.

Data boundary

Receives payment and billing information. We design the payment flow not to send IEP text.

Service

Twilio & email providers

Role

Service-related SMS and email delivery.

Data boundary

Messages are designed to stay generic and direct you back to authenticated pages for sensitive details.

Service

Analytics & measurement

Role

Consent-based website and product measurement through tools such as PostHog, Google Analytics, Meta, and TikTok.

Data boundary

Events are designed to be minimized and to exclude raw student records, names, and report content.

Service

Calendly

Role

Optional scheduling for human-support appointments.

Data boundary

Receives the details you choose to enter on its scheduling page under its own privacy terms.

Providers and configurations can change. Institutional reviewers can request additional subprocessor and data-handling detail at privacy@theadvocateally.com.

AI boundaries

AI assists the review. It does not own the decision.

We do not intentionally use identifiable uploaded student records to train public AI models. Provider-specific settings and retention can differ, so institutional customers can ask for the applicable documentation before deployment.

Input boundary

Uploaded text is treated as untrusted content. It cannot authorize privileged actions or replace system safeguards.

Purpose boundary

Document content is processed to provide the review or report the user requested—not for unrelated commercial profiling.

Channel boundary

Raw student content is designed to stay out of SMS, advertising, routine analytics, and payment processing.

Judgment boundary

Generated observations are informational and should be checked against the record, applicable sources, and qualified human advice.

Your controls

Your choices should be easy to find.

Some actions are self-service. Broader privacy requests go through an identity-verified process so one person cannot request another family's records.

Download what is available

Authenticated users can download available audit summaries from their account.

Delete a review

The dashboard can remove a selected review, its results, and uploaded files from the account workflow.

Make a broader privacy request

Ask for access, correction, deletion, restriction, or account closure. We may verify identity before acting.

Start a privacy request

Avoid sending student details in the first email. We will guide you through identity verification if needed.

privacy@theadvocateally.com

For families

Parents and guardians choose whether to share records they are authorized to use. The service helps organize review—not replace an advocate, attorney, educator, or the IEP team.

Read the Privacy Policy

For schools and districts

Professional access requires an authorized purpose. A district deployment may also require a written agreement, data protection addendum, security review, or procurement terms.

Read School & Educator Terms

Coordinated disclosure

Found a security issue? Tell us safely.

Include the affected URL or feature, steps to reproduce, likely impact, and helpful browser or device details. Please do not access, download, modify, destroy, or share another person's data.

We aim to acknowledge security reports within 3 business days and provide updates for validated issues as remediation progresses.

security@theadvocateally.com

Read the documents behind this overview.

This Trust Center summarizes our current posture. The policies and signed institutional agreements govern where they apply.

Back to safeguards