Privacy Policy

Last Updated: July 21, 2026

1. Introduction

This Privacy Policy describes how Orchestrate LLC ("we," "us," or "our") collects, uses, and protects information when you use Speddy ("Service"). This policy is designed for individual education professionals who use Speddy in their work with students in school settings.

2. Information We Collect

2.1 Provider Account Information

When you create an account, we collect:

  • Your name and professional contact information
  • School district email address
  • Professional role and credentials
  • School district and work location
  • Login credentials (encrypted)

2.2 Student Educational Data

As an authorized education professional, you may input student data including:

  • Student names (first and last) and other identifiers such as student IDs
  • Grade level and program information
  • Service schedules and appointments
  • IEP goals and progress data (when authorized)
  • Session notes and service documentation
  • Assessment data (when authorized)

Speddy stores each student's full name and protects it with database access controls (row-level security): a student's records are visible only to their assigned provider(s), any delegated staff, and authorized school or district administrators, and student data is encrypted at rest. To limit on-screen exposure, scheduling and planning views show only initials; the full name appears on the Students page — both in the caseload list and on each student's record.

Important: You are responsible for ensuring you are authorized to access and input all student data you enter into Speddy.

2.3 Usage Information

We automatically collect:

  • Log data (IP address, browser type, pages visited)
  • Device information
  • Usage patterns and feature utilization
  • Error reports and performance data

2.4 Google Calendar Data (Optional)

If you choose to connect your Google account, we access limited Google Calendar data (availability information, calendar event details, and the ability to create and update events on your calendar) solely to provide meeting scheduling features. See Section 5 for a complete description of how we handle Google user data.

3. How We Use Information

3.1 Provider Account Data

We use your professional information to:

  • Provide and maintain your Speddy account
  • Verify your authorization to access the Service
  • Provide customer support
  • Send important service updates and notifications
  • Ensure compliance with professional and legal requirements

3.2 Student Educational Data

Student data is used solely to:

  • Provide the scheduling and management tools you need
  • Generate reports and documentation for your professional use
  • Facilitate your authorized educational services
  • Maintain accurate records as required by law

We never use student data for marketing, advertising, or any commercial purposes beyond providing the Service.

4. Information Sharing and Disclosure

4.1 Student Data Sharing

We do not sell, rent, or share student educational data with third parties except:

  • With other authorized providers at the same school who need access for legitimate educational purposes
  • When required by law or court order
  • To protect the safety of students or others
  • With your explicit consent for specific purposes

4.2 Provider Data Sharing

We may share your professional information:

  • With other providers at your school for coordination purposes
  • When required by law or professional regulations
  • With service providers who assist in operating Speddy (under strict confidentiality agreements)

4.3 Service Providers

We work with trusted service providers:

  • Supabase: Database, authentication, and file storage (system of record for student and provider data)
  • Vercel: Application hosting and infrastructure
  • Sentry: Error monitoring (operational error data, configured to minimize personal information)
  • OpenAI and Anthropic: AI providers for optional AI-assisted features. These features are currently disabled platform-wide, and no student data is shared with either provider today. If enabled in the future, limited student data (such as initials and IEP goal text) may be shared with them to generate lesson and assessment content, and school districts will be notified in advance.
  • Help Scout: Help desk and chat support (we share provider account info such as name, email, role, and school; Help Scout's chat widget may also collect technical data such as IP address and browser type via standard web requests; users should avoid sharing student data in chat messages)

5. Google User Data (Google Calendar Integration)

Speddy offers an optional integration with Google Calendar that helps education teams schedule meetings (such as IEP meetings). This section explains how we access, use, store, and share Google user data when you choose to connect your Google account, and it applies in addition to the rest of this Privacy Policy.

5.1 What We Access

If you connect your Google account, Speddy requests only the minimum calendar permissions needed for scheduling:

  • Availability (free/busy) information — for your calendar and, through Google's existing sharing rules, for calendars already shared with you — so meeting organizers can find times that work without contacting each attendee individually
  • Calendar event information — to identify scheduling conflicts on your calendar that availability lookups can miss (for example, all-day events not marked "busy")
  • Event creation and updates on your calendar — so meetings scheduled in Speddy become ordinary Google Calendar invitations sent from the organizer's calendar, reschedules and cancellations stay in sync, and attendee RSVP responses for those meetings can be tracked

Speddy never requests access to Gmail, Google Drive, Google Contacts, or any other Google service. Connecting Google Calendar is always optional: scheduling features fall back to manual entry if you do not connect an account.

5.2 How We Use Google User Data

We use Google user data solely to provide the user-facing scheduling features you request: checking availability, proposing meeting times, creating and updating calendar events for meetings scheduled through Speddy, and tracking attendee responses to those meetings. We do not use Google user data for any other purpose.

5.3 Limited Use Disclosure

Speddy's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

  • We do not use Google user data for advertising of any kind
  • We do not sell Google user data, and we do not transfer it to third parties except as necessary to provide the scheduling features described here (specifically, encrypted storage and application hosting with Supabase and Vercel, described in Section 4.3), for security purposes, or to comply with applicable law. Our other service providers — including Sentry, Help Scout, OpenAI, and Anthropic — do not receive Google user data
  • Humans do not read Google user data unless we have your explicit permission, it is necessary for security or abuse investigation, it is required to comply with applicable law, or the data has been aggregated and anonymized for internal operations
  • We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models

5.4 Storage and Security

Google OAuth tokens are encrypted at rest, requested with the minimum necessary scopes, and never written to application logs. Availability (free/busy) data is processed transiently to compute open meeting times and is not retained as a copy of your calendar. What Speddy stores durably is the record of meetings scheduled through Speddy (such as the event identifier, meeting time, attendees, and their response status).

5.5 Retention, Disconnection, and Deletion

You may disconnect your Google account in Speddy at any time, which deletes your stored tokens and ends all calendar access. You can also revoke Speddy's access from your Google Account permissions page. Records of meetings scheduled through Speddy may be retained after disconnection as part of student educational records, under the retention terms in Section 7.

6. Data Security

We implement comprehensive security measures:

  • Encryption in transit (TLS) and at rest
  • Encrypted data storage with regular security audits
  • Role-based access controls
  • Regular security updates and monitoring
  • Incident response procedures

7. Data Retention

7.1 Student Data

Student educational data is retained:

  • While you maintain an active account and continue serving the student
  • According to your school district's data retention policies
  • As required by applicable education laws
  • Until you or your school district requests deletion

7.2 Provider Data

Your professional account data is retained:

  • While your account is active
  • For up to 90 days after account cancellation for reactivation purposes
  • As required by applicable laws and professional regulations

8. Your Rights and Controls

8.1 Access and Portability

You have the right to access, export, and port your professional data. For student data, access rights are governed by FERPA and your school district's policies.

8.2 Correction and Updates

You can update your professional information through your account settings. You are responsible for maintaining accurate student data according to your professional obligations.

8.3 Data Deletion

You may request deletion of your account and associated data. Student data deletion requests must comply with FERPA, school district policies, and applicable record retention requirements.

8.4 California Privacy Rights

California residents have additional rights under CCPA, including:

  • Right to know what personal information is collected
  • Right to delete personal information (subject to FERPA and retention requirements)
  • Right to opt-out of sale (we do not sell personal information)
  • Right to non-discrimination

9. Professional Responsibilities

As a provider using Speddy, you acknowledge:

  • You are bound by professional codes of ethics regarding confidentiality
  • You must comply with FERPA and other applicable privacy laws
  • You are responsible for ensuring authorized access to student data
  • You must follow your school district's data handling policies
  • You should not access student data outside your professional responsibilities

10. Children's Privacy

Speddy is designed for use by adult education professionals. We do not knowingly collect information directly from children under 18. Student data is provided by authorized education professionals, not directly from students. All student data handling complies with FERPA and applicable children's privacy laws.

11. International Data Transfers

If you access Speddy from outside the United States, your information may be transferred to and processed in the United States. By using Speddy, you consent to this transfer. We ensure appropriate safeguards are in place for international data transfers.

12. Cookies and Tracking

We currently use minimal tracking technologies for essential service functionality only. We do not use cookies for advertising or non-essential tracking. If this changes, we will update this policy and obtain appropriate consents.

13. Third-Party Links

Speddy may contain links to third-party websites or services. We are not responsible for the privacy practices of these external sites. We encourage you to review the privacy policies of any third-party services you access.

14. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. Material changes become effective 30 days after posting. We will notify you of significant changes via email or Service notification.

15. Contact Information

For privacy-related questions or to exercise your rights, contact:

Data Controller:
Orchestrate LLC
help@speddy.xyz

For privacy complaints, you may also contact your local data protection authority.

16. FERPA-Specific Provisions

16.1 Educational Records

When handling student educational records, we acknowledge our responsibilities under FERPA and will:

  • Use educational records only for authorized educational purposes
  • Not disclose records without appropriate consent or legal authority
  • Maintain appropriate security measures
  • Allow authorized school officials and parents to review records as required by law
  • Comply with record retention and destruction requirements

16.2 Provider as School Official

When using Speddy, you may be designated as a "school official" under FERPA with legitimate educational interests. As such, you agree to:

  • Use student data only for authorized educational purposes
  • Protect the confidentiality of educational records
  • Not re-disclose information except as permitted by FERPA
  • Comply with your school district's FERPA policies

16.3 Data Ownership

School districts retain ownership of all student educational records. We claim no ownership rights to educational records and acknowledge that districts have the right to control access, use, and disclosure of student data.