Student data is not for sale
We do not sell student data or use identifiable uploaded records for targeted advertising or unrelated commercial profiling.
Your family's education records deserve more than a lock icon. See what we protect, how data moves, which providers help, what you control, and where our responsibility has limits.
Need a direct answer?
Privacy requests and vulnerability reports go to different, dedicated addresses.
We do not sell student data or use identifiable uploaded records for targeted advertising or unrelated commercial profiling.
Parents, advocates, and authorized educators decide which records to upload for a requested review.
AI output is informational. Important education and legal decisions still require human review and judgment.
Safeguards
A provider safeguard is not the same thing as an application control. These labels make that distinction visible.
Sensitive report views, exports, and deletion workflows are designed to require account authorization, with added verification where available.
Sensitive generated audit details are designed to be encrypted before storage and returned through authenticated application paths.
Firebase services use HTTPS in transit and provider-supported encryption at rest for the services that store customer content.
Firebase security documentationSMS, analytics, advertising, and routine logs are designed to exclude raw IEP text, student names, disability labels, findings, and raw upload links.
Raw uploads are normally removed after processing. Failed or abandoned uploads become eligible for automated stale-upload cleanup after 72 hours.
Support and administrative access is intended to be limited, logged, and tied to an approved support, security, or operational need.
Data flow
This is the practical lifecycle—not a promise that every record shares one retention schedule.
The browser creates an access-controlled upload for the review you requested. Upload only records you are authorized to submit.
Document content may be extracted and sent to an AI-processing provider for the requested analysis. The content is treated as untrusted input, not as instructions to the system.
Generated results are stored through the protected report path and shown only through an authorized account experience.
Raw uploads are normally removed after processing. Reports, account records, consent, billing, security logs, and backups can have different retention periods.
Account, billing, consent, support, security, backup, and institutional records may be retained for different periods when required for legal, accounting, dispute, security, continuity, or contractual reasons. Read the full Privacy Policy for the governing detail.
Service providers
The useful question is not just which logo appears in the stack. It is what role the provider performs and what information that role may require.
Service
Google Cloud & FirebaseRole
Hosting, authentication, database, private file storage, functions, and infrastructure.
Data boundary
Receives the account, upload, and service data needed to provide those platform features.
Service
AI processing providers
Role
Document extraction, review, and report generation requested by the user.
Data boundary
May receive uploaded content or minimized extracted text needed for that review. Provider settings and retention can differ by service.
Service
StripeRole
Checkout, card processing, invoices, subscriptions, billing records, and fraud prevention.
Data boundary
Receives payment and billing information. We design the payment flow not to send IEP text.
Service
Twilio & email providers
Role
Service-related SMS and email delivery.
Data boundary
Messages are designed to stay generic and direct you back to authenticated pages for sensitive details.
Service
Analytics & measurement
Role
Consent-based website and product measurement through tools such as PostHog, Google Analytics, Meta, and TikTok.
Data boundary
Events are designed to be minimized and to exclude raw student records, names, and report content.
Service
Calendly
Role
Optional scheduling for human-support appointments.
Data boundary
Receives the details you choose to enter on its scheduling page under its own privacy terms.
Providers and configurations can change. Institutional reviewers can request additional subprocessor and data-handling detail at privacy@theadvocateally.com.
AI boundaries
We do not intentionally use identifiable uploaded student records to train public AI models. Provider-specific settings and retention can differ, so institutional customers can ask for the applicable documentation before deployment.
Uploaded text is treated as untrusted content. It cannot authorize privileged actions or replace system safeguards.
Document content is processed to provide the review or report the user requested—not for unrelated commercial profiling.
Raw student content is designed to stay out of SMS, advertising, routine analytics, and payment processing.
Generated observations are informational and should be checked against the record, applicable sources, and qualified human advice.
Your controls
Some actions are self-service. Broader privacy requests go through an identity-verified process so one person cannot request another family's records.
Authenticated users can download available audit summaries from their account.
The dashboard can remove a selected review, its results, and uploaded files from the account workflow.
Ask for access, correction, deletion, restriction, or account closure. We may verify identity before acting.
Avoid sending student details in the first email. We will guide you through identity verification if needed.
Parents and guardians choose whether to share records they are authorized to use. The service helps organize review—not replace an advocate, attorney, educator, or the IEP team.
Read the Privacy PolicyProfessional access requires an authorized purpose. A district deployment may also require a written agreement, data protection addendum, security review, or procurement terms.
Read School & Educator TermsCoordinated disclosure
Include the affected URL or feature, steps to reproduce, likely impact, and helpful browser or device details. Please do not access, download, modify, destroy, or share another person's data.
We aim to acknowledge security reports within 3 business days and provide updates for validated issues as remediation progresses.
This Trust Center summarizes our current posture. The policies and signed institutional agreements govern where they apply.