Privacy & data
Know what you share, where it goes and what you control.
Updated September 16, 2026Policy text is in English.
Do not enter student names, birth dates, IDs, addresses, school names, or combinations of details that identify a learner. Automated filtering is limited. Review what you enter, upload, save, and share.
What the service processes
When you generate a document, your form inputs and any reference text you select are sent to our application server and OpenAI’s API to create a response. The tool applies pattern-based redaction and gives the model privacy instructions. These measures cannot reliably detect all identifying information or guarantee that output is anonymous.
Generation requests use the Responses API with response storage disabled (store: false), without external tools or background processing. This setting does not establish Zero Data Retention. OpenAI may retain abuse-monitoring records, including content, under its applicable policies and agreements.
Generation does not save the response to document history unless you select the save option or choose Add to case. Adding a draft to a case creates a saved personal copy when needed, then copies a snapshot into the shared case. Later edits to either copy do not synchronize automatically. Form progress uses browser-tab session storage; browser session restoration can retain it. Clear draft inputs and sign out on shared devices. Saving a document, uploading a file, or adding content to a team workspace does store that content. Provider processing and retention are governed by the applicable service agreements; this is not a zero-retention service.
Private family organizer
The family organizer is for adults using de-identified information. We store your chosen aliases, record descriptions, service categories, dates, contact roles, plans, next steps and reviewed meeting-packet snapshots in Supabase. Original attachment filenames are not retained by this feature; files receive opaque storage paths. Removing names alone may not remove every identifying detail. We do not automatically de-identify attachments.
Your organizer is accessible through your own verified account. Joining a professional workspace or paying for another account does not grant access to it. This release has no family invitations, public share links, automatic messages or AI analysis of family records. The website assistant does not automatically retrieve organizer contents.
Attachments are private and downloaded through an account authorization check. File-size and format checks are not malware scanning. Upload only files you trust. This is server-managed storage, not a zero-knowledge or end-to-end encrypted vault. Do not upload identified health, therapy or education records.
A saved meeting packet retains the selected record descriptions and attachment-version references as they were when it was created. The text download contains the selected descriptions, not the original file bytes. Later record edits do not update older packets. Downloads saved to your device are outside our access controls. Archiving a record hides it from the active organizer but does not erase its files or earlier packet snapshots.
Account deletion removes the organizer and its attachments through the deletion workflow. Interrupted uploads reserve storage until retry or cleanup. Content-free deletion receipts may be retained for recovery and accountability. Contact support if deletion cannot finish. Provider backups and required retention follow the retention section below.
Workspace assistant
When AI conversation is active, each message sends a bounded recent conversation (up to 10 messages and 12,000 characters) and any proposed IEP fields to our server and OpenAI. Conversation does not automatically retrieve case records. Messages stay in page memory while the panel is open; closing, changing modes or starting a new chat clears them. Response storage is disabled in the API request; provider retention described above still applies.
IEP guided setup runs without AI. Choosing to review IEP fields transfers a temporary proposal in page memory to the generator, scoped to your account and selected case. It expires after five minutes if not opened and is lost on refresh. You review and edit fields before applying them. Applying fields updates the generator’s existing tab-based form autosave; it does not generate a document or save a case record.
Guide and manual discussion preparation run in your browser without AI or case retrieval. The assistant keeps these entries in memory while its panel is open; closing the panel or choosing Off clears that session. Using a draft in a discussion form does not post it. Posting through the case form stores an authored case entry.
For the separate selected-context mode, you must preview and approve the selected case context before sending a question. The preview includes the plan type, grade, stage and up to five open task titles and descriptions. Case labels, contacts, documents and discussion history are excluded. We send only that preview and your current question to OpenAI, using the same response-storage and spending controls described above. This is not a full-case analysis, and automatic filtering does not guarantee de-identification. AI access is subject to your own plan and current case permissions.
What is stored
- Account information: your email, authentication information, usage counters, subscription references, and account settings.
- Saved documents: document text, type, label, and creation time when you save a draft.
- Files: uploaded file content and metadata, including filenames. Remove identifying information before uploading.
- Team workspaces: case labels, notes, documents, contacts, meetings, tasks, messages, membership, and activity data entered by members.
- Case discussions, contribution requests, review comments, revisions and notification preferences are stored with the related account or workspace.
- Profile drafts stay private. Only the fields you publish are shared with your selected audience. You can unpublish or remove optional profile content while keeping your account and shared work.
- On your device: theme and language preferences may use local storage. Generator form drafts use session storage for the current browser tab.
- Operational information: authentication and rate-limit records, hosting logs, error diagnostics, and optional public-page analytics used to improve the service only after you allow it. No session replay is enabled.
We use input and output token counts to calculate AI spending. Budget records store pseudonymous user and organization counters, request reservation identifiers, dates, and reserved or calculated costs. These records and the generation gateway logs do not contain prompt or output text.
Who processes information
Supabase provides authentication, database, and file storage. OpenAI processes document-generation requests. Upstash stores rate-limit and AI budget counters. Stripe handles current subscription checkout and billing; legacy subscriptions may have been processed by Lemon Squeezy. Vercel hosts the application. Resend delivers service emails. Sentry provides error monitoring. These providers receive the information needed for their role. We do not store full payment-card details.
We do not sell personal information or use document content for advertising. Review the applicable providers’ privacy policies and your school’s requirements before using the service.
Saving, sharing, and team access
Individual saved documents are associated with your account. A share link grants access to anyone who has the link until it expires or you revoke it. Share links expire after seven days. Treat a link as confidential, and avoid sharing content that identifies a student.
Case access follows the case’s sharing mode and each member’s role. Case owners review access; being listed as a contact does not grant it.
Cases awaiting access review retain their existing organization-wide audience until the owner reviews it. Selected-document guests receive only the approved snapshots.
Account-linked contribution requests and notifications are distinct from staff-recorded contact tasks. Removing access preserves shared attribution and may require reassignment.
Create an optional professional profile, choose the fields to publish, and share them with current workspace colleagues or signed-in people with your link.
A profile does not verify credentials or grant case access. Profiles are not a public specialist directory.
Workspace people listings are optional and require a separate review of your published profile. Only selected shared professional details appear to current colleagues in active workspaces. Republishing, unpublishing or clearing your profile removes the listing until you opt in again. Listing choices and retry receipts are stored with your account.
Colleague requests start paused and require a separate opt-in. Requests and up to 20 professional-only messages are stored for their participants. No attachments or student information belong in this inbox. Blocking ends open requests across workspaces; closed conversations are not reopened by unblocking. A report explicitly shares the request and messages with site administrators. You can withdraw your report and its saved snapshot while keeping the block. Closing a request does not delete it; deleting a participating account removes its related requests and reports. Retry receipts contain identifiers and digests and are pruned during later successful writes.
Separately approved case access and assignments continue after a colleague inquiry closes. Case owners manage access and contribution follow-through in the case workspace.
Block lists retain a saved colleague name when available.
Team messaging is limited to organization members. School and District subscriptions do not include a separate student or family portal.
Inquiries, browser choices and international processing
A school inquiry needs your work email and school/team context so we can reply. Other requested details are optional. Sending it does not subscribe you to marketing. Optional public analytics is off until you allow it; your workspace, form contents and document text are excluded from analytics events. We honor Global Privacy Control and Do Not Track by keeping optional analytics off. Cookie policy explains storage, duration and withdrawal.
Providers may process information outside your country. We do not promise exclusive domestic processing or a particular data region. We do not embed advertising, social feeds, maps or third-party video players. External sites you open apply their own policies. Legally required disclosures, security investigations or a lawful business transfer may require additional disclosures with applicable protections.
Retention and deletion
Saved documents, files, and workspace content remain until deleted through the applicable feature or a support request. Removing a member does not automatically erase organization-owned work. Archive is not deletion, and revoked access cannot recall copies already exported by recipients. Provider backups and operational records may persist under the relevant provider’s retention practices.
You can cancel future renewals in Billing while keeping your account. Account deletion may require ownership transfer and review of assigned work first. It also attempts to cancel active Stripe subscriptions before removing your account; if it cannot finish, contact support. If you need help removing shared content, local browser data, or other account information, contact support. Billing, security and legal records may remain for their applicable purposes. We do not promise an immediate purge of all provider backups or a single retention deadline across suppliers.
School approval and educational records
SpecialEdAI is a drafting aid for adults working in education. It is not a certification of FERPA, IDEA, or other legal compliance. Your institution must determine whether the service and its agreements are appropriate for your intended use. Identifiable education records are not currently an approved use. A future arrangement requires separate institutional authorization, supplier agreements and verified safeguards before activation.
Your choices and requests
You can manage your account, delete personal saved work and revoke your share links. Workspace membership and deletion depend on your role. Depending on applicable law, you may also have rights to access, correction, deletion, portability, restriction or objection, withdrawal of consent, and a complaint to your privacy regulator. Contact privacy@specialeduai.com for access, correction, or deletion requests, or questions about this policy. Use support@specialeduai.com if you cannot reach the privacy address. We may need proportionate verification and institutional authorization for school-owned records. Do not include student records or identity documents in your initial email.
Children and changes to this policy
The service is intended for adults, not student accounts. Contact us if you believe a child has supplied personal information. We update this page when our practices change and display the revision date above.
Fictional handoff practice
The practice uses fixed, authored examples. Its steps stay in page memory. Reloading or starting again clears them. It does not save case records, send messages or call AI. The optional summary downloads to your device and contains only fixed practice steps and elapsed time, including pauses. We do not send these practice steps as analytics. Ordinary service request and security logs still apply.
Pro case collaboration
A personal Pro owner can invite up to two collaborators across their workspace. We store the invited email, selected case, a hash of the invitation token, acceptance or revocation status, and access events. Invitations expire after seven days. The recipient must accept with the invited verified email. Accepting shares the selected case context, document copies, contributions and discussions; it does not expose other cases or grant paid AI access. The owner can remove collaborators, and collaborators can leave. Saved contributions remain with the case after departure. Revocation cannot recall copies already exported.
If the owner loses Pro access, saved cases remain readable while editing and new invitations pause. Account deletion and shared-record requests may require support review. Pro collaboration does not change the restriction on identified student records.
