Privacy & Security
Teachers hold some of the most sensitive information in any profession. Here is exactly how IEP Studio treats it — in plain language, without legal fog.
Data minimization is the architecture, not a promise
IEP Studio is designed so that directly identifying student information never enters the system. Students are represented by initials (up to 4 characters) that you choose. There are no fields for student names, birthdates, ID numbers, addresses, or photos — the product works completely without them. The most effective way to protect data is to never collect it.
Encryption
All traffic between your browser and IEP Studio is encrypted with TLS. Data is stored on Supabase (built on PostgreSQL, hosted on AWS in the United States) and encrypted at rest. Access to production data is restricted and audited.
Row-level isolation
Your records are protected by database row-level security: every query is scoped to your authenticated account at the database layer, not just the application layer. No other user can read your caseload data.
No selling. No ads. No AI training
We do not sell or share your data, we do not run advertising, and your goals and progress data are never used to train AI models. Our only revenue is subscriptions — our incentives are aligned with yours.
You own your data
Export your goals and progress data at any time. Delete your account and all associated records permanently whenever you choose — deletion is immediate and irreversible.
FERPA, honestly stated
FERPA obligations formally attach to schools and districts, and 'FERPA certification' does not exist — any vendor claiming it is overstating. What we can honestly say: because IEP Studio collects no directly identifying student information, the records you keep here are engineered to fall outside the categories that create FERPA exposure. Schools or districts that want a signed data privacy agreement can reach us at hello@iepstudio.app.