Privacy Policy
Aligned Practice
Last updated: 25 September 2026
Effective: 25 September 2026
The short version
We are a very small business making a documentation tool for speech-language pathologists. Here is the whole of our business model: clinicians pay us a subscription. That is it. There is no second revenue stream, and in particular there is no revenue stream that involves your data or the data of the children you work with.
We do not sell data. We do not run ads or work with ad networks. We do not use anything you enter to train artificial intelligence, ours or anybody else's, and we have contracted with our AI provider on terms that say they will not either. We do not build profiles of children.
There is one optional feature that sends text to an AI service, the rubric writing coach. You have to open it and type into it. It never receives your students, your scores or your reports, only the words you choose to type into that one screen. Section 9 sets out exactly what goes and what does not.
Children do not use Aligned Practice. Information about a child is in here only because a clinician typed it, and only as much as that clinician chose to type.
The rest of this document is the detail, because a district reviewer needs the detail.
1. Who we are and what this covers
Aligned Practice is operated by Nicole Poncia SLP LLC, a Pennsylvania limited liability company doing business as The Child-Led Therapy Center. Contact: hello@childled.org.
This policy covers alignedpractice.app and the Aligned Practice application. It does not cover other websites we operate, or any third-party site you reach from a link.
2. The three groups of people in here
Which parts of this policy apply to you depends on who you are.
Subscribers. Clinicians with accounts. We are the controller of your information. Sections 3, 5, 6, 8, 9, 10 and 11 are about you.
Students. The children a subscriber documents. We are a processor. We hold their information on behalf of the subscriber and, where the subscriber is acting for a school or district, on behalf of that school or district. We do not decide what happens to it. Section 4 is about them and Section 12 is the detail districts ask for.
Questionnaire respondents. Families and team members who fill in a questionnaire from a link a clinician sent them. They have no account and never see the student's code or name. Section 4 covers what they give us.
3. What we collect about subscribers
When you make an account: your email address, a password (stored only as a cryptographic hash, never in a form we can read), and a display name if you set one.
If you turn on two-factor authentication: the secret needed to verify your codes.
Payment: handled entirely by our payment processor. We receive a record that you paid and your subscription status. We never receive or store your full card number.
Automatically, when you use the app: ordinary server and network logs, which include IP address, browser type and timestamps, kept for a short period for security and troubleshooting.
Locally on your own device, not on our servers: your print branding preference, your build version, and a session-only setting for hiding names on screen. These live in your browser and never reach us.
We do not use third-party analytics, advertising trackers, or session recording. There is no tracking pixel on the app.
We do use one third-party error monitor. When something in the app breaks, a description of the fault is sent to Sentry so it can be found and fixed. It is sent only when something actually breaks, never while the app is working normally, and it carries the error and the screen it happened on rather than anything about a child. The text is scrubbed in your browser before it leaves the page. Section 6 sets out exactly what Sentry receives.
4. What you put in, itemised
This is what the database actually holds. It is written from the schema rather than from a template.
Students. A code you choose. Optionally: a display name, grade, setting, free-text notes, and a report due date. The name field is empty and switched off unless you deliberately turn names on in your settings.
Goals. Goal names, the communication skills selected, the four rubric levels for each, the scoring lens, accommodations, specially designed instruction, the frequency and criterion, baseline scores, and an opener sentence.
Scores. A date, a score for each skill, an optional note about the session, and an optional note about how the session went overall.
Saved reports. A frozen snapshot of a report at the moment you generated it, the period it covered, and whether the student's name was included.
Clinician notes. Free text you write in a student's record.
Schedule. Recurring weekly slots linking a student to a day, a time, and an optional location note.
Questionnaire links and replies. For each link: which student, whether it went to a family or a team member, a label you wrote so you know who it was for, and an expiry date sixty days out. For each reply: what the respondent typed as their name or role, and their answers with any notes. Respondents never see the student's code or name, and they are told before they start that their answers go to the clinician who sent the link.
Community content. Posts, replies, shared skills, your display name attached to each, and any reports you file about other people's content. This is the one area other subscribers can read. Nothing in these tables can be linked to a student, and there is no database column anywhere in the Community that could hold a student reference.
Your work in progress. An autosaved draft of whatever rubric you are currently building.
What we never ask for: dates of birth, addresses, phone numbers, identification numbers, medical records, diagnoses, disability categories, race, or ethnicity. There is no field for any of these. Please do not put them in a free-text box either.
5. Why we hold it, and what we will not do with it
We use it to run the software, to authenticate you, to keep the service secure, to bill you, to answer your emails, and to send you occasional messages about the service itself, such as an outage, a change to these policies, or a feature being removed.
Our staff do not read your student data. The exceptions are narrow and worth stating precisely: when you ask us for help with a specific problem and we need to look in order to fix it, when we are legally compelled, or when we reasonably believe someone is in danger. Ordinary maintenance does not involve reading it.
We will not sell your information or student information. We will not share it with advertisers or data brokers. We will not use it for targeted advertising. We will not use it to train machine learning models. We will not create profiles of students. We will not use it to make automated decisions about a child.
On artificial intelligence, precisely. There is exactly one feature in Aligned Practice that uses a language model: the rubric writing coach on the Goal writer screen. Everything else, including every progress report, every narrative summary and every printed document, is assembled from fixed templates and the numbers you entered, with no AI involved at any point.
What the coach sends. Only what you type into that screen. That is your description of how the child communicates, your wording for the four rubric levels, anything you add about partners or the environment, and which skills and scoring lens you selected. It is sent to Anthropic, which returns draft wording. Nothing is stored there by us.
What the coach cannot send, as a matter of how it is built. Student codes. Student names. Settings, schedules, dates. Scores, score histories, goals, reports, notes, questionnaires. None of it. The coach is not connected to your database at all: it is handed the text from one form and nothing else, so there is no route by which a record could travel even by mistake. A district reviewer can verify this claim from the request itself.
The one thing you control, and why we ask. The box where you describe the child is free text, and free text is the one place in this software where a name could end up, because you typed it. The screen asks you not to, and suggests a code or an initial instead. We cannot enforce that, so we are telling you here as well: do not type a child's name into the coach.
Training. Neither we nor our AI provider use anything you type into the coach to train models. Our use of Anthropic's API is under their commercial terms, which exclude customer inputs and outputs from model training. Anthropic retains inputs for a limited period for abuse monitoring under their own published policy, which is linked from Section 6 and is the authority on their side rather than this paragraph.
The ai_usage table. Our database contains a table by this name, and it is no longer empty. It records one row per coach request: which account made it, which kind of request it was, and how many tokens went in and out. It holds no content: not your text, not the model's reply, not any student information. It exists so a stuck loop cannot run up a bill unnoticed. We mention it because a district reviewing our schema will see it, and we would rather explain it than be asked.
Switching it off. The coach is optional at the person level, because you simply never open it. It can also be switched off for an entire deployment with a single configuration flag, which is how we would supply a district that does not permit AI tools. If that is a requirement for your district, email us and we will confirm it in writing.
A correction. Before 25 September 2026 this section said that no text ever left our database for a language model and that the ai_usage table was empty. Both were true when written and both stopped being true when the coach was switched on during the beta, which happened before this policy was updated. We should have updated this page first. The description above is accurate as of the date at the top, and we are telling beta members directly rather than relying on them to re-read this page.
6. Who else touches it
We use a small number of vendors to run the service. Each is contractually restricted to processing data on our instructions.
| Vendor | What they do | Where |
|---|---|---|
| Supabase | Database, authentication and file storage. This is where everything in Section 4 lives. | AWS, United States region |
| Cloudflare | Serves the website and provides network security | Global edge network, United States origin |
| jsDelivr | A public code network. Serves one optional library, used only if you generate a QR code for a questionnaire link. It receives an IP address at that moment and nothing else, and never touches the database. Everything the app needs to run is served from our own domain. | Global |
| Anthropic | Runs the language model behind the optional rubric writing coach. It receives only the text you type into that one screen, and never receives students, scores, goals, reports or anything else from the database. Under their commercial terms, customer inputs and outputs are not used to train models. See their commercial terms and their privacy centre for retention on their side. If you never open the coach, nothing of yours ever reaches this vendor. | United States |
| Stripe | Takes subscription payments and stores card details. We never see or hold a full card number. | United States |
| Resend | Sends account emails such as confirmations and password resets | United States |
| Sentry | Error monitoring. When something in the app breaks, Sentry receives the error message, the file and line it came from, and which screen you were on, so it can be fixed without waiting for somebody to write in about it. It never receives students, scores, goals, reports, session notes or anything else from the database. Error text is scrubbed in your browser before it is sent: quoted text, anything that looks like a name, dates, long numbers and email addresses are replaced before the message leaves the page. Session recording is not used and is not switched on. See their privacy policy. | United States |
Supabase is assessed annually against SOC 2 Type 2. Note that Supabase makes the report itself available only on its Team and Enterprise plans, so we can tell you the assessment exists but cannot currently hand you the report.
We publish changes to this list here. If we add a vendor that handles student information, we will update this table before the change takes effect.
Aside from these vendors, we disclose information only when you tell us to, when the law requires it, or when it is necessary to protect someone's safety. If we are ever legally compelled to hand over student information, we will tell the affected subscriber and their district before we do it, unless we are legally forbidden from telling them.
7. Where it lives
All data is stored in the United States.
8. How it is protected
Every table has row level security enabled. This is the important one. Access rules are enforced by the database itself, not by the application code, so a bug in the front end cannot expose another clinician's data. Every rule checks both that you are the owner of the row and that your account has active access.
Encryption in transit and at rest. Everything travels over TLS. The database is encrypted on disk.
Passwords are hashed, never stored in a readable form. Nobody at our end can see your password.
Two-factor authentication is available to every account, using an authenticator app, and we recommend turning it on.
Access is by allow-list. Every access rule checks your email against a list we control. Signing up creates a login, and until we have added that email to the list, the login can neither read nor write a single row. Access is granted by us, one person at a time.
Questionnaire links expire after sixty days and can be revoked at any time from the student's record. A link gives access to a blank form and nothing else. It cannot be used to read anything.
The secret database key is never in the browser. The key the app uses is the publishable one, which is safe to expose precisely because the row level security rules above are what actually enforce access.
No system is perfectly secure, and anybody who tells you otherwise is selling something. What we can tell you is what we have done and where the boundaries are.
9. How long we keep it
While your account is open, we keep what you entered until you delete it. We do not expire your data.
When you delete a student, every goal, score, note and saved report attached to that student is deleted immediately by the database itself.
When you close your account, we delete everything within 30 days and confirm it is done.
After a subscription lapses, your data remains available for you to export for 60 days, after which we may delete it.
Backups are retained on a rolling schedule and overwritten. Deleted data can persist in an encrypted backup for a short period after deletion.
Logs are kept for a short period for security and troubleshooting.
10. Your rights
Whoever you are and wherever you live, you can:
- See what we hold. Download everything from My library, at any time, without asking us.
- Correct it. Edit anything in the app.
- Delete it. Delete individual students yourself. Email us to delete your whole account.
- Take it with you. The export is a complete JSON file plus a CSV of scores, in formats other software can read.
- Object or complain. Email hello@childled.org.
Depending on where you live you may have additional rights, including the right to know what categories of information we hold and who we shared them with, the right to delete, the right to correct, the right to opt out of sale or targeted advertising, and the right not to be discriminated against for exercising any of them.
Two of those are easy for us to answer. We do not sell personal information and we do not process it for targeted advertising. We have never done either.
To exercise any right, email hello@childled.org from your account address. We will respond within 30 days, and if we need longer we will tell you why. We do not charge for this.
A note about student information. If you are a parent asking about your child's records, we are not the right people to ask, and this is not us avoiding you. Under FERPA those records belong to your child's school, and the right to see, correct and control them sits with you through the school rather than through us. Contact the school, and if it helps, tell them the software is Aligned Practice and they can reach us at hello@childled.org. We will assist the school promptly with any request they make.
11. Email we send you
We send account emails, such as password resets and security notices, and you cannot opt out of those while you have an account. Anything promotional has an unsubscribe link and unsubscribing does not affect your subscription.
12. Student information: the section districts ask about
FERPA. Where a subscriber acts on behalf of a school or district, we operate as a school official with a legitimate educational interest under 34 CFR 99.31(a)(1). That means we perform a function the district would otherwise do itself, we act under the district's direct control regarding the use and maintenance of education records, we use those records only for the purpose we were given them, and we do not redisclose them without authorisation. We have a Student Data Privacy Agreement ready to sign, and we will sign a district's own agreement or an NDPA on request.
Individual subscribers. Where a clinician subscribes personally rather than through a district, our Terms of Service require them to confirm they are authorised to enter student information and that doing so complies with their employer's rules. We are relying on that confirmation. We say so plainly because a district reviewing us deserves to know exactly where the chain of authority sits.
COPPA. The Children's Online Privacy Protection Act applies to operators of services directed to children under 13, or with actual knowledge that they are collecting personal information online from a child under 13. Aligned Practice is directed to adult professionals. Children do not use it, do not have accounts, and do not submit anything to it. Information about a child reaches us because a professional entered it, which is not collection from the child. The amended COPPA Rule, in force since 22 April 2026, did not change this analysis, and the FTC expressly declined to adopt ed-tech-specific amendments when it finalised those changes. We will keep watching it.
State student privacy laws. Twenty states now have comprehensive consumer privacy laws, and a larger number have laws specific to student data, several of which impose obligations directly on vendors regardless of what a contract says. Our commitments not to sell student data, not to use it for targeted advertising, not to profile students, and to delete on district request are made to satisfy those laws generally rather than one by one. Where a state law or a signed district agreement requires more, that requirement governs and this policy yields to it.
Data breach. If student information is involved in a breach, we will notify the affected subscribers and, where we know them, their districts, without unreasonable delay. The notice will say what happened, what was involved, what we have done, and what you should do.
As a Pennsylvania business we are also subject to the Breach of Personal Information Notification Act, amended by Act 33 of 2024. Where a breach affects more than 500 Pennsylvania residents we notify the Office of Attorney General at the same time as we notify the individuals. That Act additionally requires twelve months of free credit monitoring where a breach exposes a Social Security number, driver's license number, state identification number or bank account number. Aligned Practice holds none of those, and has no field in which to store one, so that requirement cannot be triggered by our systems.
Where a district's own agreement with us specifies a shorter notification period or additional steps, that agreement governs.
13. Children
Aligned Practice is not for anyone under 18 and we do not knowingly allow anyone under 18 to create an account. If we learn that we have an account holder under 18, we will close it.
14. Changes to this policy
We may update this policy. If a change materially affects how we handle your information or student information, we will email you at least 30 days before it takes effect. The date at the top tells you which version you are reading, and we keep prior versions available on request.
15. Getting in touch
Email hello@childled.org, and please put "Privacy" in the subject line so it gets to the right place quickly. We answer within two business days, and within 30 days for a formal rights request.
Our mailing address is available on request by emailing hello@childled.org. We are a small business and do not publish a street address.
Nicole Poncia SLP LLC, doing business as The Child-Led Therapy Center. Registered in the Commonwealth of Pennsylvania.