Privacy Policy
Last updated August 22, 2026
Who we are
SPEDMinutes is a product of The In App LLC, a California limited liability company. Contact: support@spedminutes.com.
The privacy commitment
SPEDMinutes is built for FERPA-aware special education professionals. Our core design principle is to minimize the student data that crosses our servers. No student name or ID field is saved to our servers; students are identified there only by sequential number, and we do not store student work product or student records. The one place a student’s name may appear is the optional nickname described in Section 03, which stays in your browser and never reaches us — and the goal-text fields are automatically screened for names before anything is sent to our AI provider.
When you use the quiz creator, the IEP goal text you enter is sent to our AI provider (Anthropic) so the application can generate aligned quiz items. To prevent student names from being transmitted, SPEDMinutes scans your goal text for common names before any request leaves your browser. If a name is detected, submission is blocked and you are prompted to replace the name with “the student” or initials. This check also runs on the server as a backstop. Goal text that passes the check is processed by Anthropic and not retained by SPEDMinutes after the request completes.
Two things are sent to our AI provider: bell schedule images you upload, and IEP goal text when you use the quiz features. Bell schedule images are sent as uploaded, so please don’t upload a schedule that has student names on it.
What we never store on our servers
SPEDMinutes has no fields for:
- Student names, dates of birth, addresses, or contact information
- Disability categories or eligibility records
- Parent or guardian information
- Student work product, written responses, photographs of student work, or any artifact produced by a student
- Any other student record covered by FERPA, IDEA, or California Education Code
IEP goal text is processed for the active request only and is not retained afterward.
Free-text fields such as schedule labels, class names, and service descriptions will store whatever you type, so please don’t type student names there.
Students are represented on our servers only as sequential placeholders (“Student 1,” “Student 2,” and so on). No name or other identifying field is stored against them.
You may optionally attach a nickname to a student on the Caseload or IEP Workflow Checklist tab. Nicknames are held in local storage in the browser profile on the device where you type them. They are not transmitted to us, are not stored on our servers, and are not included in any backup we hold. Moving them to another browser, browser profile, or computer is done by exporting them to a file from the Caseload tab; clearing your browser data removes them, and we cannot restore them.
What we collect and how it's used
- Account email, used for authentication via magic link.
- Stripe customer ID and subscription status, used for billing.
- IEP goal text you enter into the quiz creator, transmitted to Anthropic to generate aligned quiz items. Subject to the name-detection guardrail described in Section 02. Not retained by SPEDMinutes after the request completes.
- Bell schedule images you upload, transmitted to Anthropic to extract period times. Not retained after the request completes.
- Service-minute calculations and checklist progress, stored against placeholder student records only.
- Daily quiz generation counts, stored for usage-limit enforcement (user ID and timestamp only).
- Anonymous analytics on our marketing pages, captured by Microsoft Clarity — see Section 05.
Device-local nicknames are not in this list because we do not collect them. They are written by your browser to your own device and browser profile, are never sent to us, and are not visible to us. Section 03 describes them.
Analytics
Microsoft Clarity is enabled on our marketing pages (homepage, pricing, privacy policy, terms, and similar public pages) to help us understand how visitors discover and evaluate SPEDMinutes. Clarity records aggregate session behavior — pages viewed, clicks, scrolling, browser, device, and approximate location derived from IP address.
Clarity does not run on the application itself (/app), the settings page, or any page where you work with student data. Clarity is governed by Microsoft’s privacy policy.
Third-party processors
- Supabase — authentication and database hosting
- Stripe — payment processing
- Anthropic — AI processing of IEP goal text (quiz creator) and bell schedule images
- Vercel — web hosting
- Microsoft Clarity — analytics on marketing pages only
Each operates under its own privacy policy. Per Anthropic’s API terms, data submitted through their API is not used to train models.
FERPA, IDEA, and state student-data laws
SPEDMinutes is not a “school official” under FERPA and does not receive or maintain education records. Nothing that identifies a student reaches our servers: no name or ID field is saved to them, and we do not store work product or other identifying records. The optional nickname described in Section 03 stays on your device and browser profile and is never transmitted to us, so it does not become a record we hold. Because our goal-text guardrails screen for names before that text reaches our AI provider, SPEDMinutes operates with minimal exposure to FERPA, IDEA confidentiality requirements, California AB 1584, and SOPIPA.
You remain responsible for ensuring your use of SPEDMinutes complies with your district’s data policies. This includes not attempting to bypass the name-detection guardrail, not entering student PII into goal text or other fields, and consulting your district’s data governance team if you have any uncertainty about whether your use is appropriate.
Data retention and deletion
To delete your account, email us at support@spedminutes.comfrom the address you signed up with. We will confirm your request and remove your account and the data associated with it. Stripe billing records are retained per Stripe’s policies and applicable tax law.
Deleting your account does not remove device-local nicknames, because they are not held by us. You can clear them yourself at any time from the Caseload tab, or by clearing your browser’s data for this site.
Security
Data in transit is encrypted via TLS. Data at rest on our servers is encrypted by Supabase.
Device-local nicknames are not covered by either measure. They are stored as ordinary text in your browser’s local storage on your own device. Anyone with access to that device and browser profile may be able to read them, so consider whether a shared or unattended computer is the right place to use the feature.
Children's privacy
SPEDMinutes is intended for use by adult educators. The service is not directed to children under 13 and we do not knowingly collect information from children.
Changes
We may update this policy. Material changes will be communicated via email to active subscribers.
