IEP Writing Companion Privacy Policy
Effective date: July 23, 2026
IEP Writing Companion is intended for authorized educators. Use with student information requires school or district approval. Educators must review every generated draft before using it in an IEP.
Information the extension processes
The extension may process information contained in the IEP Direct document that an educator chooses to scan, screenshots the educator chooses to attach, and notes the educator enters. This may include personally identifiable information, educational records, assessment results, disability or health-related information, parent concerns, and other sensitive student information. Firebase Authentication processes the teacher's email address, password, authentication tokens, and account identifiers.
How information is used
Information is used only to authenticate authorized teachers, read the open IEP Direct document after the teacher requests a scan, and generate editable draft IEP sections and annual goal candidates. The extension does not use the information for advertising, lending, credit decisions, sale, or unrelated purposes.
When information is transmitted
IEP content, screenshots, and teacher notes are transmitted only after the educator checks the district-approval confirmation and requests generation. The service uses Google Firebase for authentication, Google Cloud Run for the secured application service, and the OpenAI API to produce the requested drafts. These providers process information as service providers under their applicable terms and privacy commitments.
Storage and retention
The extension keeps the active teacher authentication session in Chrome session storage. Scanned IEP content, attached screenshots, teacher notes, and generated drafts are held in the side panel for the current working session and are cleared when the teacher clears or closes the session. The application does not create its own permanent database of IEP content. Infrastructure and service providers may retain limited data or security logs according to their applicable policies and configured services.
Sharing
Information is not sold. It is disclosed only to the service providers described above as needed to authenticate users, securely operate the service, and fulfill the educator's generation request, or when legally required.
Security
The service uses encrypted HTTPS connections, authenticated teacher accounts, and server-side secret management. No system can guarantee absolute security. Schools and educators are responsible for following applicable policies, contracts, consent requirements, and laws governing student records.
Educator and school responsibilities
The extension does not independently determine eligibility, classification, placement, services, or clinical treatment. It does not replace professional judgment or the IEP team. The publisher does not claim that installation alone establishes compliance with FERPA, state student-privacy laws, or district requirements.
Access, correction, and deletion
Teachers may clear session content using the extension's clear control and may sign out at any time. Requests concerning a teacher account or this policy may be sent to samirezzelarb@gmail.com. Requests concerning official student records should be directed to the responsible school or district.
Changes to this policy
This policy may be updated as the service changes. The effective date above will be revised when material changes are made.