Your family's privacy, in plain language
IEP Amigo exists because a child's education records are sensitive. This policy says what we collect, what we deliberately don't, and what you can make us delete. The short version: when you upload on the web, names are removed on your device before anything uploads (the mobile app works differently — see below), everything lives on US servers, we never sell or share your data for advertising, and the delete button really deletes.
Who we are
IEP Amigo is operated by AIDUKAAN SOFTWARE (OPC) PRIVATE LIMITED ("we", "us"). We provide a web application at iepamigo.com that helps parents understand their child's IEP, 504 plan, or evaluation documents.
Questions about this policy or your data: support@iepamigo.com.
What we collect
Account: your email address and preferred language. That's the whole account.
Child context: a short nickname you choose for your child (like "my daughter" — never a legal name we ask for; if you leave it blank we use "My child"), plus the state, grade level, and report language you pick. We don't require or verify a legal name here — please avoid typing one in.
Documents: the file you upload — after on-device redaction when you upload on the web (see below) — and the analysis we generate from it (findings, letters, deadlines).
Payments: handled entirely by Paddle, our merchant of record. Your card number never reaches our servers; we receive only a transaction reference and what you purchased.
Basics: server logs (IP address, browser type, timestamps) kept briefly for security and debugging, and transactional email delivery status.
Cookies
Outside of checkout, we set two cookies, both strictly functional — never advertising, never cross-site tracking: ia_session, an HttpOnly cookie that keeps you signed in for up to 30 days, and ia_lang, which remembers whether you last read the site in English or Spanish so the next page loads in the right language.
Neither cookie is readable by other websites or used to build an advertising profile, so there's nothing here that needs a cookie-consent banner under the laws we're aware of — both are the kind every login-based site sets to function at all.
One exception, honestly stated: the checkout page. There, Paddle — our merchant of record — sets its own cookies and processes payment and subscription data for fraud prevention and subscription management, including its Retain service for returning subscribers. This happens only during checkout and is covered by Paddle's own privacy policy.
A second exception, also honestly stated: if you arrive from one of our Google ads, Google's measurement tag stores the ad-click identifier in a first-party cookie (names starting with _gcl) for about 90 days. It exists only so that, if you later sign up or purchase, we can tell Google Ads "that ad worked" — it does not track your browsing, here or anywhere else.
What we deliberately don't collect
We do not require your child's legal name anywhere in the product — the only child field is the optional nickname described above. Separately, when you upload through the website, our redaction step removes names and dates of birth it finds inside the document itself, on your device — in your browser — before anything uploads. The detected text is never sent to us; we only store which kinds of items were removed (for example: "one student name, one date of birth").
Honest limits: redaction depends on being able to read the document, and it can miss things. For text PDFs it is automatic; for photos we read the image on your device and remove what we confidently find. The preview always shows you exactly what will upload, and if nothing is detected (or you choose to keep something) you decide, explicitly, whether to upload anyway — we never upload silently. Our analysis is also instructed to never copy personal names into your report.
The mobile app works differently, and we want to be plain about it: photos and PDFs you upload from the mobile app travel over an encrypted connection to our private storage, but they are not redacted on your device first — they reach us exactly as they are. On-device black-out exists only in the website's upload flow, and it runs before a file is sent, so it cannot be applied to a document that is already uploaded. Two things hold either way: our analysis is built to leave personal names out of your reports, and you can delete any document — or everything — at any time.
We use no social media pixels and no analytics that profile you. Two measurement tools exist, both scoped tightly: our own traffic analytics (Vercel) are cookieless and see page paths, never people — we strip query strings before anything is sent. And Google's ad-conversion tag, described under Cookies, records only that one of our ads led to a signup or purchase, with ad personalization signals switched off — it measures our campaigns, not you.
Where your data lives
All user data is stored in United States regions only: our application and document storage run in a US data center (Washington, D.C. area), and our database runs in a US East region. Documents are stored in private storage that requires our server's credentials to access, and data is encrypted in transit and at rest.
This is a commitment, not a default: US-only residency is written into our engineering decisions.
How we use your information
To provide the service: reading your uploaded document, generating your analysis and letters, tracking the deadlines you ask us to track, and emailing you the things you asked for (sign-in links, scan results, deadline reminders).
We do not sell your personal information. We do not share it for advertising. We do not use your documents to train AI models.
Aggregated, anonymized statistics (for example, how often a type of red flag appears statewide) may be used to improve the product; these never contain your document contents or identity.
Service providers (subprocessors)
We use a small set of providers to run the service, each bound by their own data protection terms: Vercel (application hosting and document storage, US region), Neon (database, US region), Anthropic (AI document reading — via API terms under which inputs are not used to train models), Resend (transactional email), Paddle (merchant of record for payments), and Sentry (error monitoring — receives technical error details and IP addresses when something breaks; email addresses and document content are scrubbed before anything is sent), and GoDaddy (email hosting for support@iepamigo.com — whatever you choose to write to us is stored in that mailbox), and Google (advertising conversion measurement — learns that an ad click led to a signup or purchase, with ad personalization disabled; never sees your documents or your child's information).
If this list changes, we will update this page.
Retention, and deletion that is real
We keep your documents and analyses for as long as you keep your account, so your school-year tracking works.
The "Delete everything" button in Settings permanently deletes your uploaded documents, extracted data, reviews, findings, letters, and tracked deadlines from our live systems immediately — no waiting period, no "deactivated" limbo. You'll see a manifest of exactly what was purged.
One honest nuance about backups: like any service that has to survive a disaster, we keep encrypted backups, and our database keeps a point-in-time-restore history. Deleted data can persist in those for up to 30 days, after which it is gone there too. We never use backups to bring back a deleted account — they exist only to recover the whole service after a verified disaster.
Two things survive a deletion, honestly stated: a purge audit record (the fact that a deletion happened — id, time, counts; none of your content) and payment records held by Paddle, which they must retain for tax and fraud purposes and which contain no information about your child.
Children's privacy
IEP Amigo is a tool for parents and guardians, and accounts may only be created by adults. The service is not directed at children, and we do not knowingly collect personal information from children — the web upload flow is engineered to strip a child's identifying details before documents reach us, and our analysis is built to leave names out of the reports we generate.
If you believe a child's personal information has reached us despite these measures, email support@iepamigo.com and we will delete it.
Your rights and choices
You can access everything we hold about you from your dashboard, correct your account details in Settings, export your letters and reports at any time, and delete everything yourself without contacting us.
Residents of California and other states with privacy laws have rights to access, delete, and know about personal information; the tools above satisfy these directly, and you can also email us to exercise any right.
Do Not Track: we don't track you across other sites, so there is nothing for a DNT signal to turn off.
Deadline reminder and non-essential emails include an unsubscribe link; sign-in and purchase emails are transactional and accompany your use of the service.
California, Texas & other state privacy rights
If you're a California resident, the CCPA/CPRA gives you the right to know what personal information we hold about you, delete it, correct it, and not be discriminated against for exercising those rights. We don't sell or share personal information for cross-context advertising, so there's no "opt out of sale" to flip — it's already off.
If you're a Texas resident, the Texas Data Privacy and Security Act (TDPSA) gives you the same core rights — know, correct, delete, and get a portable copy of your data — plus rules for what counts as "sensitive data," a category that includes information revealing a disability. We treat anything about your child's disability that appears in an uploaded document as sensitive for exactly this reason: it's why the web upload flow redacts on your device before upload and why we never use documents to train AI models.
Other states with similar consumer-privacy laws get the same practical answer: use the dashboard and Settings tools above to see, correct, export, or delete your data yourself, any time, or email support@iepamigo.com and we'll handle the request by hand within a reasonable time.
This section describes our current practice in plain language; it is not a substitute for the full statutory text of CCPA/CPRA, TDPSA, or any other state law, and we expect to refine it as our launch states expand.
Changes to this policy
If we make material changes, we will update the date at the top and, for significant changes, notify you by email before they take effect.