Privacy & data
What happens to a document when you upload it, who can read it, and which outside services see it.
Effective
The short version
To read your document, IEPdecode sends it to Anthropic's Claude API. Under Anthropic's published policy for its API, inputs and outputs are not used to train its models by default, and are automatically deleted from its systems within 30 days — longer only if its safety systems flag a violation of its usage policy. We don't control Anthropic's systems, so read its privacy center if you want the source.
Share only what you need to. A child's name, date of birth, or student ID that the check does not depend on is something you can black out before you upload — the findings come from the structure of the document, not from who it is about.
What a check actually does with your file
When you run a check, the file's bytes are posted to our server, forwarded to the model for extraction, and discarded. We do not write the original file to disk on the public checker path. What the model returns — a structured extraction of the document's sections — is what the deterministic rules engine reads.
If you are signed in, the finished analysis (not the original file) is saved to your check history so you can reopen it without re-running the model. If you are signed out, nothing is persisted at all.
What an account stores
An account exists for one reason: memory across years. When you file a document into a child's record, we store the uploaded file in a private storage bucket, the structured extraction, and vector embeddings of the goals used for the year-over-year comparison. The wording of each goal (never the file, and never your child's date of birth) is sent to Google's embedding API to produce those vectors, when that feature is switched on for this deployment; Google's terms for that API depend on the plan in use, and on a free plan Google may use that wording to improve its products. Voice notes, when enabled, use the same provider. Documents are immutable and versioned — filing a new one never overwrites the old one, because the old one is the evidence.
We also store your email address, a password hash held by our authentication provider, and the state code you selected. We do not store payment details, because there is nothing to pay for.
Who can read it
Every table and every storage object is protected by row-level security policies that trace back to your authenticated user ID. Another family querying with their own credentials gets zero rows — this is enforced by the database, not by application code that could be bypassed, and it is verified by an end-to-end test that signs in as a second real parent and confirms they can read none of the first parent's records.
We do not sell data, we do not run advertising, and we do not share records with any school district, state agency, or third party other than the outside services described in §01 and §03.
Cookies and local storage
We set a session cookie when you sign in — that is the only cookie, and it exists solely to keep you signed in. There is no analytics tracker and no advertising pixel on this site.
Your accessibility and appearance choices (text size, contrast, dyslexia-friendly type, reduced motion, language, light/dark) are kept in your browser's local storage. They never leave your device and are never sent to us.
Children's data
IEPdecode is built for parents and guardians, not for students. It is not directed to children under 13 and we do not knowingly collect information directly from them. Records about a child are entered by the adult who holds the educational rights for that child.
Deleting your record
Write to iepdecode@gmail.com and we will delete your account, every child record under it, and every stored file. We cannot delete copies held by the outside services in §01 and §03 beyond what their own retention policies provide.
This is information, not legal advice
Findings cite real provisions of the Individuals with Disabilities Education Act and its implementing regulations, and they come from unit-tested code rather than a language model's judgment. They are still not a substitute for an attorney or an advocate. See the terms of use.