Features

Playground IEP Privacy Policy

Updated: July 21, 2026

Introduction

This privacy notice for Playground IEP LLC ("Company," "we," "us," or "our") describes how and why we collect, store, use, and share ("process") your information when you use our services ("Services"), such as when you visit our website at https://www.playgroundiep.com, sign in to the Playground IEP application, or otherwise interact with our Services.

Questions or concerns? Reading this privacy notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have questions or concerns, please contact us at privacy@playgroundiep.com.

Playground IEP is a special education caseload management platform designed to organize information, facilitate teacher collaboration, and automate caseload management processes. Our goal is to provide special education teachers, administrators, and related service providers with the technology tools necessary to deliver a transformative educational experience for students with IEPs. We believe that privacy and confidentiality are fundamental rights, and we are actively committed to upholding them. This Privacy Policy outlines how we collect, protect, use, and share information on Playground IEP.

Core Data Privacy Principles

  • Minimal Data Collection: Only the minimum data needed for our services is collected.
  • Specific Use of Data: Your data is used solely to provide access to and support of our Services.
  • No Data Sales: We do not sell your data under any circumstances.
  • No Advertising to Students: We strictly avoid advertising to students.
  • Robust Data Protection: All data is safeguarded with strong administrative, technical, and physical security measures.
  • Compliance with FERPA & COPPA

This Privacy Policy governs the use of our web-based application that school staff and authorized individual users access to manage information about students receiving specialized educational support. By using Playground IEP, you confirm that you are an authorized user and agree to the terms of this Privacy Policy. If we update this Privacy Policy, you will be notified the next time you log into the Playground IEP portal.

Information We Collect and How We Use It

We collect only the information needed to provide our Services. This includes:

Account and authentication data

  • Email address
  • Display name
  • Authentication provider (Google, Microsoft, or email magic-link verification)
  • Multi-factor authentication settings, where enabled
  • Role and district/school affiliation

Caseload and student data (provided by your educational institution or authorized individual user)

  • Student names, identification numbers, grade level, and enrollment information
  • Special education and IEP information, including goals, accommodations, services, and progress monitoring data
  • Parent/guardian names and contact information, where provided for IEP scheduling and communication purposes
  • Teacher, related service provider, and school staff names and contact information

Service usage data

  • Voice note transcripts (audio recordings are processed for transcription only and are not retained on our platform — see Sub-processors below)
  • AI tool inputs and outputs generated within the application (drafts, edits, and prompts you supply)
  • Support communications and tickets you initiate
  • Operational telemetry such as IP address, device type, browser type, and session timestamps, used to maintain service security, reliability, and performance

Information We Do Not Collect

  • We do not collect personal information directly from students.
  • We do not use behavioral or advertising trackers.
  • We do not build profiles for marketing or advertising purposes.

In short, Playground IEP does not use student, teacher, or other user information for any purpose other than to enable access to and use of our Service.

How We Use AI in Playground IEP

Playground IEP includes AI-assisted features that help educators draft IEP content, generate supporting materials, and reduce repetitive paperwork. We design these features around three principles:

  • AI assists; humans decide. AI outputs are starting drafts only. All content produced by an AI feature must be reviewed, edited, and approved by an authorized educator before being saved to a student's record or used in an IEP. Playground IEP does not make autonomous educational, eligibility, or placement decisions about students.
  • No model training on Student Data. Under our agreements with our AI sub-processors (Anthropic and Google), data we transmit through AI features is not used to train AI models, and provider data-retention windows are limited to short periods sufficient to operate the service.
  • Minimum necessary input. AI features transmit only the minimum content required for a given task. Where possible, identifiers are minimized and full Student PII is excluded from AI prompts.

The specific AI sub-processors we use, and the data each one receives, are detailed in the Sub-processors section below.

Cookies and Tracking Technologies

Playground IEP uses a limited set of cookies and similar technologies that are strictly necessary for the operation of our platform. We do not use cookies for advertising, behavioral targeting, or any purpose unrelated to delivering and securing the Service.

What are cookies? Cookies are small text files placed on your device by a website or application. They help the site remember information about your visit and can make subsequent visits faster and more useful.

Types of cookies we use:

  • Strictly Necessary / Authentication Cookies. These cookies are essential for you to log in, navigate the platform, and use its features. Our authentication provider (Supabase) sets secure, HTTP-only cookies that maintain your authenticated session. These cookies are required for platform functionality and expire when your session ends.
  • Preference / Functionality Cookies. We may store small preference values to remember your display settings (for example, sidebar collapse state or recently used dashboard view) so your experience is consistent across sessions.

Cookies we do not use:

  • We do not use third-party advertising or remarketing cookies.
  • We do not use cross-site analytics cookies that track individual users across websites.
  • We do not allow any third party to place cookies on our platform for behavioral profiling or targeted advertising.

Because Playground IEP does not run advertising or cross-site tracking technologies, browser-level Do Not Track and Global Privacy Control signals do not change how we operate — there is no behavioral tracking to disable.

Our Data Privacy Commitments

We commit to and strictly adhere to the following:

  • We do not collect, maintain, use, or share Student PII beyond what is needed for authorized educational/school purposes, or as authorized by the parent/student.
  • We do not, and will not, sell any confidential Student PII data at any time, for any reason.
  • We do not, and will not, sell any user data at any time, for any reason.
  • We do not use or disclose student information collected for behavioral targeting of advertisements to students.
  • We do not knowingly retain Student PII beyond the time period required to support authorized educational/school purposes.
  • We maintain a comprehensive security program reasonably designed to protect the security, confidentiality, and integrity of Student PII against risks — such as unauthorized access or use, or unintended or inappropriate disclosure — through administrative, technological, and physical safeguards appropriate to the sensitivity of the information.
  • We provide resources to support educational institutions, teachers, and parents/students in protecting the security and privacy of Student PII while using our Service.
  • We require our sub-processors with whom Student PII is shared to follow these same commitments for the Student PII they process.
  • In the case of a merger or acquisition, a successor entity will maintain Student PII only if it is subject to these same commitments for the previously collected Student PII.
  • We incorporate privacy and security into the design and improvement of our products, tools, and services and comply with applicable laws.

Information Protection and Security

At Playground IEP, we are committed to safeguarding entrusted data with rigorous administrative, technical, and physical security measures.

  • Hosting: Our application is deployed on Vercel, and our database, authentication, and storage are operated by Supabase. Both run on United States–based AWS infrastructure, inheriting SOC 2 Type II and ISO 27001 controls from the underlying provider.
  • Encryption: Data in transit is protected by TLS 1.2+. Data at rest is encrypted with AES-256.
  • Access controls: Role-based access controls and Postgres Row-Level Security policies enforce that users only access data appropriate to their role and tenant. Multi-factor authentication is available for all users and is required for Playground IEP personnel with administrative access to the platform.
  • Authentication: We support passwordless sign-in via email magic link (one-time code), Google, and Microsoft. Playground IEP does not store user passwords. Authentication is handled by Supabase Auth, which manages session tokens issued after a successful sign-in.
  • Operational safeguards: All sub-processors handling Student PII operate under SOC 2 Type II, ISO 27001, or equivalent attestations.

Despite our diligent efforts, no system is infallible. If we become aware of a security incident that may affect student or school information, we will notify the affected school or district within 72 hours of confirmation of the incident, or within 24 hours where required by applicable law or contractual commitment (for example, districts subject to New York City Department of Education Chancellor's Regulations). We will work with the school or district to notify parents of all affected students.

How and When We Share Data

We share data only in the following circumstances:

  • When you or your educational institution gives us permission to share it.
  • With your authorized teachers, administrators, and other school staff, as necessary to provide the Service.
  • With our sub-processors (described below), as necessary to operate the Service, under contractual data-protection obligations.
  • If we are required to comply with the law, a court order, or direction from governmental authorities.
  • In a business transition (merger, acquisition, or sale), in which case data is transferred only to an entity that adheres to the same privacy and security standards set out in this Privacy Policy.

Third-Party Service Providers (Sub-processors)

To deliver, secure, and support the Playground IEP platform, we use a limited set of vetted third-party service providers ("sub-processors"). Each receives only the minimum data necessary to perform its specific function, and all are contractually required to protect data in accordance with standards equivalent to or exceeding our own. All Student Data is processed within United States–based facilities.

  • Vercel — Provides application hosting and deployment for the Playground IEP web application. Vercel processes incoming HTTP requests and serves static and server-rendered application content. Vercel does not have direct database access; application data is not stored within Vercel's systems.
  • Supabase — Operates our managed Postgres database, authentication service, and object storage. All application data — including student records, IEP content, staff accounts, and uploaded documents — is stored within Supabase. Supabase runs on United States–based AWS infrastructure with AES-256 encryption at rest and TLS 1.2+ in transit.
  • Anthropic (Claude API) — Powers AI-assisted writing features such as draft IEP goals, present levels, progress reports, and similar narrative content. Only the minimum contextual content needed for a given prompt is transmitted, and full Student PII is minimized wherever possible. Under our agreement with Anthropic, API inputs and outputs are not used to train AI models.
  • Google (Gemini API) — Provides AI-assisted image generation features within the application. Image-generation prompts and resulting images do not include Student PII.
  • AssemblyAI — Provides voice-to-text transcription used by Playground IEP's voice notes feature. Audio is processed by AssemblyAI for transcription and is not retained on Playground IEP's platform; only the resulting transcript is stored. AssemblyAI processes data under an enterprise data processing agreement that defines strict requirements for data handling, security, and confidentiality.
  • SendGrid — Sends transactional email such as account-verification messages, magic-link sign-in codes, support replies, and team-invitation emails. SendGrid receives recipient email addresses and message content necessary to deliver these emails.
  • Upstash (Redis) — Provides rate-limiting infrastructure to protect the application against abuse and ensure platform availability. Upstash stores short-lived rate-limit counters keyed by IP address or user identifier. No Student PII is transmitted to or stored by Upstash.
  • Customer.io — Sends product and lifecycle email communications to authorized account holders (such as feature announcements and onboarding messages). Customer.io receives recipient email addresses and account-level metadata. No Student PII is transmitted to Customer.io.
  • Google Workspace — Used by Playground IEP staff for business email, internal documents, and to support secure data-processing operations such as validating and reconciling roster information received from districts prior to import. Access is limited to authorized personnel; Google Workspace operates under SOC 2 Type II controls.

Sub-processor oversight. We choose sub-processors that maintain SOC 2 Type II, ISO 27001, or equivalent industry-standard security certifications, and we periodically verify those certifications remain in good standing through publicly available attestations. If a sub-processor's certifications lapse or its security posture materially changes, we will reassess our use of that provider. Under our contractual commitments to client districts, we will notify districts in writing in advance before enabling any new sub-processor that will process Student Data, providing a reasonable period during which districts may raise objections.

For a current list of sub-processors or to ask questions about our data-sharing practices, please contact us at privacy@playgroundiep.com.

Google User Data (Calendar and Drive Integrations)

Playground IEP offers optional integrations with Google Calendar and Google Drive. These integrations are off by default and are activated only when an individual user explicitly connects their own Google account from within the application. This section describes how we handle Google user data received through Google APIs, in accordance with the Google API Services User Data Policy.

What Google user data we access:

  • Google account email address — received when you connect an integration, used to display which Google account is connected.
  • Google Calendar (if connected): the names of your calendars (so you can choose which calendar to use), and the calendar events that Playground IEP itself creates for meetings you schedule in the application. We do not read, scan, or analyze your existing calendar events.
  • Google Drive (if connected): only the specific files you individually select through the Google file picker. Playground IEP uses Google's per-file authorization scope (drive.file), which means we cannot see, list, or access any other files in your Drive.

How we use it: Calendar access is used solely to create, update, and cancel calendar events for IEP meetings that you schedule in Playground IEP. Drive access is used solely to import the documents you select into your Playground IEP workspace, where they are treated as uploaded documents under this Privacy Policy.

How we share it: We do not sell Google user data, and we do not transfer it to third parties, with these limited exceptions: files you import from Google Drive are stored by our hosting sub-processor (Supabase) like any other uploaded document, and — only when you choose to use an AI feature on an imported document — the document content is processed by our AI sub-processor (Anthropic) as described in the "How We Use AI" section above. Under our agreement with Anthropic, this data is not used to train AI models. Google Calendar data is never transmitted to any AI service. Google user data is never used for advertising, marketing profiles, or creditworthiness purposes, and is never transferred to data brokers.

Limited Use disclosure: Playground IEP's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we protect it: OAuth tokens for your Google account are stored encrypted at rest (AES-256) in our database and are transmitted only over TLS 1.2+. Playground IEP never sees or stores your Google password. Access tokens are short-lived and refreshed only when you actively use the integration.

Retention and deletion: You can disconnect Google Calendar or Google Drive at any time from Account Settings in the application. Disconnecting immediately and permanently deletes the stored OAuth tokens for that integration. Calendar events previously created on your calendar remain on your calendar (they belong to you), and documents previously imported from Drive remain in your workspace as ordinary uploaded documents unless you delete them. You can also revoke Playground IEP's access at any time from your Google Account security settings at https://myaccount.google.com/permissions.

Our Commitment to Data Integrity

We retain student and school data only for as long as necessary to fulfill the purposes for which it was collected, including providing our Services, complying with legal obligations, resolving disputes, and enforcing our agreements.

Retention Periods:

  • Student Information: Data related to student performance and special education needs, including IEPs, is retained for the duration of the student's enrollment with the school or district using our platform, or for the duration of the school or district's active subscription to our Service, whichever is shorter.
  • Teacher and School Staff Data: Information about educators and school administrators is retained for the duration of the school or district's active subscription to our Service.
  • Individual Account Holders: For free individual users, account and caseload data are retained for as long as the account remains active. Inactive accounts may be deleted after a period of dormancy, following written notice to the account holder.
  • Post-Contract Deletion: Upon expiration or termination of a school or district's contract, we securely delete or return all Student Data within 60 days, with written confirmation upon completion. Backups containing Student Data are purged according to our standard backup-retention schedule.

User-Requested Deletion: Users may request deletion of their personal information or their student's information by contacting us at privacy@playgroundiep.com. Upon verification of the requestor's identity, we will proceed with the deletion of the relevant data, subject to any legal or regulatory requirements that may require retention of certain information.

Privacy Law Compliance and Industry Standards

At Playground IEP, protecting your data is a top priority. We endorse the 1EdTech Trusted Apps privacy rules and apply their principles to our handling of user and student data.

We strictly follow FERPA and COPPA laws. Our goal is to be a dependable part of the education technology community, ensuring everyone's information is secure and respected. Below, we detail how we adhere to FERPA, COPPA, and applicable state privacy laws.

Compliance with FERPA

Playground IEP is committed to full compliance with the Family Educational Rights and Privacy Act (FERPA), a federal law that protects the privacy of student education records. FERPA gives parents certain rights with respect to their children's education records; these rights transfer to the student when he or she reaches the age of 18 or attends a school beyond the high school level.

Our Commitment to Protecting Education Records: Under FERPA, we are bound to protect the privacy of student education records and to provide parents and eligible students access to their records, as well as the opportunity to request correction of records they believe to be inaccurate or misleading.

How We Handle Student Education Records:

  • Access and Use: We access student education records only for legitimate educational interests and purposes as defined under FERPA, or as requested by the educational institution or the eligible student.
  • Disclosure: We do not disclose information from student education records without the written consent of the parent or eligible student, except in cases where FERPA authorizes disclosure without consent. This includes disclosures to school officials with legitimate educational interests, to other schools to which a student is transferring, and in connection with financial aid for which the student has applied or received.
  • Protection and Security: We implement rigorous administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of student education records. Our security measures are designed to prevent unauthorized access to or disclosure of student records.

Parental and Student Rights under FERPA:

  • Right to Inspect and Review: Parents and eligible students have the right to inspect and review the student's education records maintained by the school.
  • Right to Request Amendments: Parents and eligible students have the right to request that the school correct records they believe to be inaccurate or misleading.
  • Right to Control Disclosures: Parents and eligible students have the right to control disclosures of personally identifiable information contained in the student's education records, except to the extent that FERPA authorizes disclosure without consent.

Requests for Access or Amendments: If a parent or eligible student wishes to inspect, review, or request amendments to education records, they should submit a written request to the educational institution that maintains the records. Playground IEP will comply with requests from educational institutions to access or amend education records in accordance with FERPA regulations.

For More Information: For more information about our FERPA compliance practices, or if you have questions or concerns regarding the privacy of student education records, please contact us at privacy@playgroundiep.com.

Compliance with COPPA

Playground IEP is designed exclusively for use by educators, school teachers, and administrative staff as a tool for managing and supporting students' educational experiences. Our platform is not intended for use by students, including those under the age of 13, and we do not knowingly collect personal information from children.

Platform Usage:

  • Educator and Staff Use Only: Playground IEP is strictly intended for operational and educational management purposes by school staff and educators. As such, our platform does not engage directly with students nor collect personal information from children, including those under the age of 13.
  • No Student Access: Our services and features are developed with the explicit understanding that they will be accessed and utilized solely by educators and school personnel. We have measures in place to ensure our platform remains exclusive to this audience.

Data Collection and Privacy:

  • Data Handling: In providing our services, we may handle student data provided by the educational institutions we serve. However, this data is managed strictly within the context of delivering our services to schools and is not used for any other purpose.
  • Commitment to Privacy: We are committed to protecting the privacy of all data we handle and comply with all applicable laws and regulations, including COPPA, in the provision of our services to educational institutions.

California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act ("CPRA"), provides you with specific rights regarding your personal information. This section describes those rights and how to exercise them.

Personal information we collect. We collect the categories of personal information described in the "Information We Collect and How We Use It" section above.

Sources of personal information. We collect personal information directly from authorized users, from school districts that have authorized the use of our platform on behalf of their staff, and from operational sources such as authentication providers when you sign in.

Purposes for which we use personal information. We use personal information solely to provide, secure, support, and improve our Services, as described in this Privacy Policy.

Categories of personal information disclosed. We disclose personal information only to the categories of sub-processors listed above, and only as necessary to deliver the Service.

Your California rights. Subject to certain exceptions, California residents have the right to:

  • Know what categories and specific pieces of personal information we have collected about them
  • Request deletion of personal information we have collected
  • Request correction of inaccurate personal information
  • Opt out of the "sale" or "sharing" of personal information (Playground IEP does not sell or share personal information for cross-context behavioral advertising and has not done so in the preceding 12 months)
  • Limit the use of sensitive personal information (Playground IEP does not use sensitive personal information for purposes beyond providing the Service)
  • Be free from retaliation for exercising any of these rights

How to exercise your rights. California residents may exercise these rights by contacting us at privacy@playgroundiep.com. We may need to verify your identity before fulfilling your request, and we will respond within the timeframes required by law.

Authorized agents. California residents may use an authorized agent to submit a request, provided the agent has written authorization. We may require additional information to verify the agent's authority.

For students whose education records are held by Playground IEP under contract with a school or district, requests to access or delete student records should be directed to the educational institution that maintains the records, in accordance with FERPA.

New York State Education Law § 2-d

For school districts in the State of New York, our handling of personally identifiable information from student records is also governed by New York Education Law § 2-d and accompanying regulations.

In accordance with these requirements:

  • We provide each New York client district with a Parents' Bill of Rights for Data Privacy and Security, together with our supplemental information addendum, as part of the Data Privacy Agreement between Playground IEP and the district.
  • We commit to notifying affected New York client districts of any breach or unauthorized release of student data within the timelines required by Education Law § 2-d and its implementing regulations, and within 24 hours where applicable to districts subject to the New York City Department of Education Chancellor's Regulations.
  • A copy of our current Parents' Bill of Rights is available to New York client districts upon request at privacy@playgroundiep.com.

Inquiries and Concerns

Should you have any questions about our platform's use or our approach to privacy and data protection, please do not hesitate to contact us at privacy@playgroundiep.com. We are dedicated to maintaining open and transparent communication with the schools and districts we serve.

Changes to Privacy Policy

Material changes to this policy will be accompanied by a notification to users in the Playground IEP Portal.