Before publishing: replace the bracketed items and have an attorney familiar with FERPA, COPPA and your states' student-privacy laws review this page. Delete this notice once reviewed.

Trust Center

A plain-language summary for schools, districts and practices of how DecodeDesk protects the students you teach. For the full legal terms, see our Privacy Policy, Terms and Data Processing Agreement.

Our commitments

Security

AreaWhat we do
Encryption in transitAll traffic uses HTTPS (TLS). Plain HTTP is redirected.
Encryption at restEvery student-related record is encrypted with AES-256-GCM before it reaches the database. Backups are encrypted too.
Sign-inPasswords are stored only as salted one-way hashes. Accounts lock after repeated failed attempts. Two-step sign-in (authenticator app plus backup codes) is available to everyone, and account owners can require it for their whole team.
Access controlRoles limit what each person sees: owners, tutors (only their assigned students) and office staff (scheduling and billing, with no lesson data).
Activity logSign-ins, failed sign-ins, security changes and every create, change and delete are logged (never the record contents). Account owners can review and export the log.
Application securityStrict Content Security Policy, protection against cross-site request forgery, rate limiting on sign-in and sensitive actions, and security headers on every page.
BackupsEncrypted backups are made nightly and test-restored regularly. The newest [14] are kept, with an optional encrypted copy in separate storage.
MonitoringServer errors alert our team immediately, and site availability is monitored.

FERPA

When a school or district uses DecodeDesk, we act as a school official with a legitimate educational interest, under the school's direct control with respect to the use and maintenance of education records. We use education records only to provide the service, don't re-disclose them except to the subprocessors listed below (who are bound by equivalent obligations), and return or delete them at the school's direction.

COPPA and families

Students don't create accounts or give us information directly. Teachers enter lesson data. Schools provide consent on parents' behalf where COPPA allows it for educational use; independent practices get consent from the family. The optional family home portal uses a private link the teacher creates and can turn off at any time. It shows that family only their own child's practice, progress and schedule.

Subprocessors

We share data only with the providers needed to run the features you use:

ProviderPurposeData involvedWhen
[HOSTING PROVIDER]Hosting, database, email deliveryAll service data (encrypted at rest)Always
Stripe, Inc.Subscription billing; optional family card payments and autopayAccount billing contact; invoice number, amount and billing email for family payments; for autopay, the client's name and email. Card details go directly to Stripe.When paying, or when a practice turns on card payments
Anthropic, PBCOptional AI helpOnly the text of that request, with student names replaced by a placeholder. Never sent: names, notes or IDs.Only if the account owner turns AI help on
Twilio Inc. or Quo (OpenPhone Technologies)Optional text messagesA family's phone number and the text (reminder: practice name, student display name, lesson time, video link; or a teacher's short note)Only if a practice connects one, and only to families who agreed to texts
Google LLC, Microsoft Corporation, Clever Inc.Optional sign-inOnly what the provider returns when a user chooses to sign in with it: name, email, account number and organizationOnly for users who sign in with that provider
Intuit Inc. (QuickBooks Online)Optional accounting syncBilling clients' contact details, invoices (service lines with student display names) and paymentsOnly if a practice connects QuickBooks
Zoom Video CommunicationsOptional meeting creationA meeting title ("Reading lesson" plus a display name)Only if a practice connects Zoom
[VIDEO RELAY PROVIDER, e.g. Metered]Optional relay for video calls on restrictive networksEncrypted media it cannot viewOnly if enabled and needed
[OFF-SITE BACKUP PROVIDER]Optional encrypted backup copiesEncrypted backup filesIf configured

Data location, retention and deletion

Incident response

If we learn of unauthorized access to customer data, we will investigate right away, contain it, and notify affected customers without undue delay, and in any case within [72 hours] of confirmation, with what happened, what data was involved, and what we're doing about it. We will cooperate with schools on any notifications they must make.

Accessibility

We aim to meet WCAG 2.1 Level AA. See our Accessibility statement.

Contact

Security or privacy questions, or to request a signed Data Processing Agreement: [PRIVACY EMAIL]. To report a security issue: [SECURITY EMAIL].

[LEGAL BUSINESS NAME] · [MAILING ADDRESS] · Last updated [DATE]