Template: not legal advice. Replace the bracketed items and have an attorney review this policy before you accept real customers. Delete this notice once reviewed.
Privacy Policy
Effective [DATE] · [LEGAL BUSINESS NAME] ("we", "us")
Summary
- DecodeDesk stores lesson and progress data that educators enter about their students. That data belongs to the educator or their organization, not to us.
- We never sell student data, never use it for advertising, and never build profiles of students for any purpose other than providing the service.
- Student records are encrypted at rest. The app loads no third-party analytics, advertising or tracking scripts.
- You can export or permanently delete your data at any time.
Who this policy covers
DecodeDesk is used by educators, tutors, therapists and schools ("Customers"). Students do not create accounts. When a school or district uses DecodeDesk, we act as a "school official" with a legitimate educational interest under FERPA and process student data only under the Customer's direction. For schools we sign a Data Processing Agreement on request.
Information we collect
| Category | Examples | Purpose |
|---|---|---|
| Account data | Educator name, email, practice name, hashed password | Sign-in, support, billing notices |
| Student data entered by the Customer | Display name or initials, grade, skill mastery, session responses, fluency scores, goals, notes | Providing lesson planning, progress monitoring and reports |
| Materials & custom content | Inventory items, custom activities, practice notes | Providing the service |
| Billing data | Handled by Stripe; we store only a customer and subscription ID | Payments |
| Security logs | Sign-in times, actions taken, a one-way hash of IP address | Security, audit trail, abuse prevention |
We ask educators to use initials or nicknames and not to enter birthdates, addresses, student ID numbers or diagnoses beyond what instruction needs.
Children's privacy (COPPA)
Students under 13 never provide information to us directly. Where a school uses DecodeDesk, the school may consent on behalf of parents for the educational use of the service, as COPPA allows. Private tutors confirm they have parental consent to record a child's progress. Parents may ask their educator or us to review or delete their child's data.
Sign-in security & activity log
Users can turn on two-step sign-in with an authenticator app. The secret for it is stored encrypted, and backup codes are stored only as one-way hashes. We keep a log of account activity (sign-ins, failed sign-ins, security changes and which records were created, changed or deleted, with an anonymized network fingerprint) for security. The account owner can view it. The log never includes the contents of records.
Online payments by families
If a practice turns on card payments, families pay on a checkout page hosted by Stripe, Inc. on behalf of that practice's own Stripe account. Card details go directly to Stripe and are never seen or stored by DecodeDesk. DecodeDesk sends Stripe the invoice number, amount, practice name and the billing email on the invoice, and receives back the payment status and payer email to record the payment. The practice's Stripe key is stored encrypted.
Staff profiles
Team members can add a profile: photo, title, education, certifications and licenses, experience, an "about" section and links. Their team sees it; families see the profile of their student's teachers in the home portal; and it appears on the practice's public team page only if the person chooses to show it and the owner publishes that page. Certification and license numbers are visible only to the team. Photos are resized and stripped of location data before upload.
Signing in with Google, Microsoft or Clever
If a user signs in with Google, Microsoft or Clever, that provider tells DecodeDesk the user's name, email address, a stable account number and, for school accounts, the organization (Google Workspace domain, Microsoft tenant or Clever district). DecodeDesk stores the account number, organization and email to recognize the user next time; it never receives their password. Student accounts can't sign in to DecodeDesk.
School rosters and districts
When a school imports a roster file from its student information system, Clever or ClassLink, the file is read in the teacher's browser. Only the students the school selects are saved, with a display name (first name and last initial, or initials), grade and assigned teachers. Student ID numbers, emails and birthdates in the file are not stored; a one-way fingerprint of the roster ID is kept so re-imports update the same student. District administrators see only aggregate numbers for each school (for example the number of students, sessions and average accuracy), never an individual student's name or records.
Automatic payments (autopay)
If a family chooses automatic payments, they save a card on a page hosted by Stripe for the practice's own Stripe account, after reading an authorization. DecodeDesk stores only Stripe's reference numbers and the card's brand, last four digits and expiry, never the card number. DecodeDesk then asks Stripe to charge each invoice's balance on its due date, emails the family a receipt, and retries a declined card twice before stopping. The family can stop automatic payments at any time by contacting the practice, which removes the saved card from its Stripe account.
Insurance superbills
A practice can print a superbill for a family to submit to their insurance. It uses the practice's provider details, the services and payments on the family's invoices, and diagnosis codes the provider enters for a student, which are stored encrypted on the billing client and visible only to the owner and office staff. A patient's full legal name, date of birth and insurance member ID are never stored: they are typed just before printing or written in by hand.
QuickBooks
A practice can download files to import into QuickBooks, or connect its own QuickBooks Online company (Intuit Inc.). When connected, DecodeDesk sends billing clients' names, email, phone and billing address, invoice numbers, dates and line items (service descriptions include the student's display name) and payments. Session notes and assessment results are never sent. The practice can disconnect at any time.
Calendar feeds & video meeting links
A teacher can create a private calendar link so their lesson times appear in their own calendar app (for example Google Calendar). Anyone holding that link can see the lesson times, the student display names (unless the teacher hides them) and meeting links. Teachers can replace or turn off the link at any time. If an account owner connects Zoom, DecodeDesk sends Zoom only a meeting title ("Reading lesson" and the student's display name) to create a meeting; Zoom's own privacy terms apply to the video call itself.
Online booking
If a practice turns on online booking, a new family can request an appointment from the practice's public booking page. The page asks for the parent's name, email and (optionally) mobile number, the student's first name or initials, grade, and an optional note. These details are stored encrypted for that practice only, used to arrange the appointment, and emailed to the practice's owner and office staff. We don't ask for birthdates, school IDs or diagnoses. Families who already have a home-portal link can book lessons there; only the chosen time and an optional note are sent.
Text messages
Text messages are off unless the account owner connects the practice's own Twilio or Quo (formerly OpenPhone) account. A family is only texted after the practice records that the family agreed to receive texts. To send a text, DecodeDesk gives that provider the family's phone number and the message: a lesson reminder (the practice name, student display name, lesson date and time, and the video link if there is one) or a short note the teacher wrote. Anyone can reply STOP to stop all texts from that practice; DecodeDesk keeps the list of numbers that opted out so they are never texted again unless they reply START. Message and data rates may apply. The provider's own privacy terms also apply to messages it carries.
Optional AI help
AI help is off unless the account owner turns it on. When it is on and a teacher uses it, DecodeDesk sends only what that request needs to Anthropic, PBC (the maker of Claude): skill names and example words, heart words, the passage text being edited, the teacher's question, or, for a parent-letter note, a short list of facts with the student's name replaced by a placeholder. Student names, notes, grades and identifiers are never sent. Anthropic processes these requests as our service provider and does not use them to train its models. We log that a request was made (for usage limits), not its content. Teachers review and edit everything the AI drafts before it is used.
Remote student screen & video calls
When a teacher shares the lesson to a student's device, our server briefly holds only the lesson material shown (words, letter tiles, passages) and the student's answers on that screen, linked to a temporary code. No names are included, and the data is deleted when sharing ends or within 6 hours. Video and audio in lesson calls travel directly between the teacher's and student's devices, encrypted, and are never recorded or stored by DecodeDesk. To connect the call, devices may contact a public STUN server (Google) and, on networks that block direct connections, a relay provider ([RELAY PROVIDER, e.g. Metered]) that passes encrypted media it cannot view. Customers are responsible for obtaining any parent/guardian consent their policies require for video lessons.
How we protect data
- HTTPS for all traffic; AES-256-GCM encryption of all student and session records at rest.
- Passwords hashed with a modern algorithm, account lockout after repeated failures, rate limiting.
- Strict separation between Customer accounts; an audit log of reads, writes, exports and deletes.
- Daily backups retained for [30] days at [HOSTING PROVIDER] data centers in [REGION].
Sharing
We share data only with subprocessors needed to run the service: [HOSTING PROVIDER] (hosting), Stripe (payments), and [EMAIL PROVIDER] (transactional email). We disclose data if the law requires it and will notify the Customer unless prohibited. If the business is sold, this policy continues to protect existing data.
Retention & deletion
Data is kept while the account is active. Deleting a student or the account removes the records from our live database immediately and from backups within [30] days. If an account is inactive for [24] months, we delete it after emailing a notice.
Your rights
Educators can export all data (Settings → Export) and delete it at any time. For other requests, including parent requests, contact [PRIVACY EMAIL]. Residents of certain states may have more rights under state law; we honor them.
Breach notification
If a security incident affects student data, we will notify affected Customers without undue delay and within the time required by applicable law.
Changes
We will email Customers at least 30 days before any material change. We will never make a material change to how student data is used without the Customer's consent.
Contact
[LEGAL BUSINESS NAME] · [MAILING ADDRESS] · [PRIVACY EMAIL]