Last Updated: June 11, 2026
The Advocate Ally handles sensitive education records. This page explains how to report a security issue, what data we treat as restricted, and the guardrails we use for uploads, reports, AI processing, vendors, and account access.
Send suspected vulnerabilities to security@theadvocateally.com. Include the affected URL or feature, steps to reproduce, likely impact, browser/device details, and screenshots or logs that help us investigate. Please do not access, download, modify, destroy, or share another person's data.
We aim to acknowledge security reports within 3 business days and provide status updates for validated issues as remediation progresses. For privacy requests that are not security vulnerabilities, contact privacy@theadvocateally.com.
Uploaded documents and extracted text are untrusted input. Our prompts and processing paths are designed so document text cannot override system instructions or trigger privileged backend actions. We also aim to minimize what is sent to AI providers and to avoid putting raw student content into telemetry, SMS, marketing, or support tooling.
We do not intentionally use identifiable uploaded student records to train public AI models. Institutional customers may request more detail about AI subprocessors, data handling settings, and any applicable written agreement before a school or district deployment.
Raw uploaded documents are designed to be used for document review and then removed after processing or cleanup where available. Stale, failed, or orphaned upload objects may be subject to scheduled cleanup. Generated reports, action plans, account records, access logs, billing records, consent records, support records, privacy/security logs, backups, and institutional records may follow different retention periods based on legal, security, accounting, operational, or contractual needs.
Authenticated users can download available audit summaries or submit privacy requests in account settings. Broader access, deletion, correction, restriction, school, or district requests can be sent to privacy@theadvocateally.com. We may verify identity and may retain limited records where required or permitted.
The service may use Google Firebase/Google Cloud for hosting, authentication, storage, database, functions, task processing, and infrastructure; AI processing providers for document review; Stripe for payments; Twilio for SMS; SendGrid or SMTP providers for email; PostHog and analytics tooling for operational analytics, subject to privacy review and configuration; security/error-monitoring tools; and support tooling for privacy, security, and customer requests.
We do not sell student data. Contact privacy@theadvocateally.com for subprocessor information needed for a school, district, or institutional review.
We also design SMS, email, analytics, and conversion tracking so student names, disability labels, report findings, raw IEP text, raw upload links, and report content are not intended to be included in those channels.
No online service can promise perfect security. Users should protect account credentials, sign out on shared devices, upload only records they are authorized to submit, avoid pasting student details into support/privacy notes, and report suspected account or data exposure quickly.