AccommodatED Academy — Privacy Policy
Policy version: v1.1 Effective date: September 1, 2026 Last updated: August 11, 2026
AccommodatED Academy ("AccommodatED Academy," "we," "us," or "our") is a product of AccommodatED Pathways LLC ("AccommodatED Pathways"). This Privacy Policy explains what information we collect, how we use and protect it, who we share it with, and the choices and rights you have. It applies to the AccommodatED Academy web application and to family and tutor accounts created on it.
We built this service for tutors, special-education professionals, and families who support students with learning differences. Because students — including children under 13 — use the platform, protecting their information is central to how it is designed. Please read this policy together with our Terms of Service.
Plain-language summary. We collect only what a tutor needs to deliver differentiated lessons and track a student's IEP/TEKS progress. A parent or guardian must give consent before a child's data is used. We do not sell data, run advertising, or use advertising or cross-site trackers. On our public marketing pages only, we use a cookieless, privacy-preserving analytics tool (Vercel Web Analytics) that never runs on signed-in or student pages. We do not send a student's name, date of birth, or any parent/tutor name to our AI provider. You can view, export, correct, or delete your information at any time. This summary is for convenience; the full policy below governs.
1. Who we are and how to reach us
AccommodatED Academy is operated by AccommodatED Pathways LLC, based in the Dallas–Fort Worth area, Texas, USA.
- Privacy and data requests: privacy@accommodatedpathways.com
- Compliance / security matters: compliance@accommodatedpathways.com
- General contact: contact@accommodatedpathways.com
- Mailing address: 5900 Balcones Dr, Suite 100, Austin, TX 78731
If you are a parent or guardian and want to review, correct, or delete your child's information, contact us or your child's tutor (see Section 9).
2. Who this policy covers
- Tutors and special-education professionals who create student records and deliver instruction.
- Parents and legal guardians ("families") who claim an access code to follow a student's progress.
- Students, including children under 13, whose educational progress data is recorded by their tutor. Students do not create their own accounts; a tutor creates the student record and a parent/guardian consents to its use.
3. Information we collect
We collect only information that maps to a working feature. Each category below is collected for the stated purpose and nothing more.
a. Account information (all users)
- Email address (used to sign in, deliver notifications, and recover your account).
- A securely hashed password (we never see or store your plaintext password).
- Your role (tutor, family, or administrator).
- Two-factor authentication enrollment status and secret (required for tutor and administrator accounts; stored encrypted).
- A display name you choose.
- Security and operational metadata: account creation time, last sign-in time, and failed-sign-in counters used to detect abuse.
b. Tutor profile information
- Professional credential type (used to attribute formal progress reports).
- Optional business name.
- Internal usage counters used to enforce per-tutor AI usage limits.
h. Billing information (tutors and administrators only)
When a tutor or administrator subscribes to a paid plan or starts a paid trial:
- Billing email and optional organization/business name.
- Your subscription and trial state (plan, status, trial end date) and the identifiers our payment processor (Stripe) assigns to your customer and subscription records.
- We never receive or store your full card number. Card details are entered directly with Stripe, our PCI-compliant payment processor (we rely on Stripe's SAQ-A scope). Families are never charged; only tutors/administrators pay.
c. Family (parent/guardian) information
- An optional family name.
- Your relationship to the student (parent, guardian, or other).
- A record of your consent: the date and time, the IP address from which you consented, the policy version you agreed to, and your browser's user-agent. We keep this as evidence of verifiable parental consent (see Section 6).
d. Student educational information
A student record is created by a tutor and may include:
- First name, last name, and an optional preferred name.
- Grade level.
- Documentation mode (general tutoring vs. IEP/504 support).
- The reason a student is receiving support and tutor planning notes.
- Documented learning-difference indicators and accommodations (e.g. SLD codes, accommodation codes, and their source — IEP, 504, or tutor observation).
- For students with an IEP: annual goal text, benchmarks, accuracy targets, and review dates. These are treated as education records.
- TEKS-aligned learning goals and mastery state.
- Date of birth. This is collected for one purpose only — to detect when a student turns 18 so that rights can transfer appropriately. It is read only by an automated age-check process and by an administrator through the audit trail. It is never sent to our AI provider and never appears on a report.
e. Learning activity information
- Tutoring sessions (start/end times, type, and tutor notes).
- AI-generated lesson content. Lesson text may include the student's first name for personalization; that name is inserted on our servers and is not sent to the AI provider (see Section 7).
- Practice ("climb") activity: questions presented, answers chosen, whether each was correct, and response timing used to measure mastery.
f. Technical, security, and audit information
- IP address and user-agent, used for security, abuse prevention, and to record consent and disclosures.
- An append-only audit log of sensitive actions (who accessed or changed a student record, and when), kept so we can honor disclosure-recordkeeping obligations.
- Transient operational data (rate-limit counters, idempotency keys) that contain no personal information.
g. Communications between tutors and families
- If your tutor and you exchange messages in the app about a student, we store the message text, who sent it (tutor or family), and the time it was sent, associated with that student. Messaging is between adults (tutors and family members) only; students do not send or receive messages.
- Message content is included in the student's data export, and administrators may review messages for safety, support, and compliance oversight.
- Because messages are free text, please do not include information you would not want stored. We keep messages while the account is active and remove them when a student's record is deleted (see Section 10).
4. Information we do not collect
To minimize risk, we deliberately do not collect:
- Phone numbers or mailing addresses.
- Photos or biometric data.
- Advertising or cross-site tracking. We run no advertising trackers, no cookies, and no cross-site or behavioral advertising profiles. The one analytics tool we use (Vercel Web Analytics) is cookieless, collects no persistent visitor identifier, and runs only on our public marketing pages — never on signed-in, tutor, family, or student pages (see Section 8).
- Marketing tags or advertising identifiers.
- Precise geolocation (we use IP address only, for security and audit).
- Protected categories such as race, ethnicity, religion, political views, or other categories restricted by the Protection of Pupil Rights Amendment.
- Full payment card numbers. Paid plans are billed through Stripe, our payment processor; card details go directly to Stripe and are never stored on our servers (we keep only Stripe's customer/subscription identifiers and your billing/trial state — see Section 3h). Families are never charged.
- Health information beyond what a parent or tutor places in a student's IEP/504-derived record.
5. How we use information
We use information only to operate and improve the tutoring and progress- monitoring service:
- To generate differentiated lessons and practice based on a student's grade, documented learning differences, and accommodations.
- To track IEP and TEKS goal progress and to produce progress reports for ARD meetings or family review.
- To authenticate users, secure accounts, prevent abuse, and maintain an audit trail.
- To send transactional and notification emails (for example, when a goal is met or an account event occurs).
- To meet our legal and compliance obligations.
We do not sell personal information, we do not share it for advertising, and we do not use it to build advertising profiles. We do not use student data to train third-party AI models (see Section 7).
6. Children's privacy and verifiable parental consent (COPPA)
Students under 13 use this platform, so the Children's Online Privacy Protection Act (COPPA) applies and we follow it directly.
- No child self-registration. Children do not create accounts or provide information directly. A tutor creates the student record.
- Verifiable parental consent. Before a family account is linked to a student, the student's tutor verifies the parent's or guardian's identity out-of-band (in person or by phone). The parent then claims a one-time access code and provides consent in the app, which we record with a timestamp, IP address, and the policy version agreed to.
- No conditioning. We do not condition a child's participation on collecting more information than is reasonably necessary.
- Parental rights. A parent or guardian may review the information we hold about their child, refuse further collection or use, and request deletion (see Section 9). To exercise these rights, contact us or the student's tutor.
The consent a parent agrees to reads, in substance: "I am the parent or legal guardian of this student. I consent to AccommodatED Academy storing and processing my child's educational progress data as described in the Privacy Policy and Terms."
7. How we use artificial intelligence (algorithmic transparency)
AccommodatED Academy uses an AI service to (a) generate differentiated lesson content, (b) generate practice questions, and (c) draft narrative summaries for progress reports. We design these features for transparency and data protection:
- What the AI receives is sanitized. We never send the AI provider a student's name, date of birth, or any parent or tutor name or email. The AI receives only de-identified inputs: an opaque student token, grade level, documented learning-difference and accommodation codes, sanitized goal text, and anonymized performance summaries.
- No training on your data. Our AI provider does not use data submitted through the service to train its models. The provider retains API request logs for a limited period (currently up to 30 days) for operational and abuse-prevention purposes.
- Human review. AI-drafted progress narratives are reviewed and approved by a qualified tutor before they are finalized. AI output is a drafting aid, not a substitute for professional judgment.
8. Who we share information with (service providers / subprocessors)
We share information only with the service providers we rely on to run the platform. Each has a published Data Processing Agreement and encrypts data in transit and at rest. We do not authorize them to use the data for any purpose other than providing their service to us, and none of them sell it.
| Provider | What it does for us | Data it processes | Region |
|---|---|---|---|
| Supabase | Database, authentication, and file storage | All application data (encrypted) | United States (US-East) |
| Anthropic (accessed via the Vercel AI Gateway) | AI lesson, question, and narrative generation | De-identified inputs only — no names, DOB, or contact details | United States |
| Brevo | Transactional and notification email | Recipient email and name, and message content | European Union |
| Upstash | Rate limiting and short-lived caching | Operational counters and keys — no personal information | United States |
| Vercel | Application hosting, serverless functions, and cookieless public-page analytics (Vercel Web Analytics) | Request logs (IP, user-agent, path); aggregate, cookieless pageview data from public marketing pages only (no persistent visitor ID, no student/account data) | United States |
| Stripe | Payment processing for tutor/administrator subscriptions | Billing email, organization name, and card data entered directly with Stripe (we store only Stripe customer/subscription IDs + billing state; we never store card numbers) | United States |
We may add, remove, or change providers. If we make a material change to this list, we will give affected tutor and family accounts at least 30 days' notice.
9. Your rights and choices
You can exercise these rights at any time by using the in-app controls or by contacting us or the student's tutor:
- Access and export. Families and tutors can view all information we hold about a student and export it (in machine-readable or printable form).
- Correct. You can request a correction or amendment to a student record. A tutor reviews the request, and the outcome is recorded.
- Delete. You can request deletion of a student's information. On a deletion request, we redact the personal information; we may retain de-identified, aggregated data that no longer identifies the student.
- Withdraw consent / stop further use. A parent or guardian may deactivate the family account, after which the child's record is archived.
We will respond to verified requests within a reasonable time and within any period required by applicable law.
10. How long we keep information
- Active student and account records are kept while the account is in use.
- Inactive records are automatically archived after a period of inactivity (currently three years).
- Information is hard-deleted on a verified deletion request, subject to the retention of de-identified aggregates and any records we must keep by law. A deletion request also removes the student's tutor-family message thread.
- Backups are retained for a limited period by our hosting/database provider and then rotated out.
- The audit log is append-only and retained for security and compliance.
11. How we protect information
We apply the HIPAA Security Rule technical safeguards as a best practice (we are not a HIPAA covered entity — see Section 14), including:
- Encryption in transit (TLS 1.2 or higher) and at rest (AES-256).
- Strict role-based access control with row-level security, so each user sees only the records they are authorized to see.
- Mandatory two-factor authentication for tutor and administrator accounts.
- Password-breach screening and brute-force protection at sign-in.
- An append-only audit log and a logged, time-limited emergency-access ("break-glass") procedure for administrators.
No system is perfectly secure, but we work to protect your information using these and other measures.
12. Where your information is processed (international transfer)
Our service is operated for users in the United States, and most processing occurs in the United States. Our email provider (Brevo) processes recipient email information in the European Union under Standard Contractual Clauses. By using the service you understand that transactional email may be processed by an EU-based provider on our behalf.
13. Data-breach notification
If we confirm a breach affecting your personal information, we will notify affected individuals as required by law, including the notification timelines under the Texas Identity Theft Enforcement and Protection Act (Texas Business & Commerce Code § 521) — generally within 60 days of discovery — and will notify the Texas Attorney General where the law requires it.
14. Our regulatory posture (what we are and are not)
To set accurate expectations:
- We are not a school or educational agency subject to FERPA. We nevertheless apply FERPA-equivalent controls (access, amendment, disclosure recordkeeping) so that we can support school customers in the future.
- We are not a HIPAA covered entity. We apply HIPAA Security Rule technical safeguards as a best practice. We do not currently have Business Associate Agreements in place with our service providers; we will pursue them before serving customers who require them.
- We follow COPPA directly (Section 6) and the data-minimization and minor-protection principles of the Texas SCOPE Act.
15. Annual notice of rights (FERPA-style)
Where a student record contains education records, the parent or guardian (or the student, once rights transfer at age 18) has the right to inspect and review those records, to request amendment of records they believe are inaccurate or misleading, and to have a say in disclosures. This policy, presented at signup and available at https://academy.accommodatedpathways.com/privacy, serves as our notice of these rights.
16. Changes to this policy
We may update this policy. If we make a material change, we will update the policy version, post the updated policy, and — where required — ask tutors and families to re-accept it. The "Effective date" above reflects the current version.
17. Contact us
Questions about this policy or your information? Contact privacy@accommodatedpathways.com or write to 5900 Balcones Dr, Suite 100, Austin, TX 78731.