Privacy Policy
Last updated: 9/7/2026
Placeholder language. This document is a starting draft and is not legal advice. Because the Service handles personally identifiable information about minors and assessment data, you must have an attorney review this Privacy Policy in light of FERPA, COPPA, HIPAA (if applicable), and state student data privacy laws (e.g., California SOPIPA, NY Ed Law 2-d, CT, CO) before launch.
1. Who We Are
Reportly ("we", "us") provides software that helps credentialed school and licensed psychologists draft psychoeducational evaluation reports.
2. Information We Collect
- Account information — name, email, qualifications, and authentication credentials.
- Report content you enter — student demographics, referral information, assessment scores, observations, and narrative text. This may include personally identifiable information (PII) about minors.
- Uploaded files — screenshots or score images you upload for extraction.
- Usage and device data — log data, IP address, browser, and interaction events used to operate and secure the Service.
3. How We Use Information
- To provide and maintain the Service;
- To process the extraction tasks you trigger (score/screenshot extraction);
- To secure the Service and prevent abuse;
- To communicate with you about your account and the Service.
We do not sell student data. The Service is designed so that you enter de-identified information (district ID rather than student name). Confirm the current data-handling and model-training terms of our AI infrastructure provider before uploading anything you consider sensitive.
4. Role Under FERPA
The Service is intended to be used with de-identified information. Where a district determines that education records are involved, the district remains the controller of those records and should evaluate the Service under its own FERPA review, including where and by whom data is processed. We make no representation that use of the Service is, by itself, FERPA-compliant. Contact us to discuss a Data Processing Addendum (DPA).
5. HIPAA
The Service is not designed to be HIPAA-compliant by default. Healthcare providers who need to process Protected Health Information must execute a Business Associate Agreement (BAA) with us before such use. Without a BAA in place, do not upload PHI.
6. Subprocessors
We use vetted infrastructure providers to host the Service, store data, and run the score-extraction features. A current list of subprocessors is available on request.
7. Security
Access is restricted by authentication and row-level access controls, and traffic to the Service uses HTTPS. We maintain administrative and technical safeguards appropriate to the sensitivity of the data, but no system is perfectly secure.
8. Data Retention and Deletion
Reports are subject to an automatic retention limit. By default, a report is permanently deleted 30 days after it is created; each account holder may shorten or lengthen this window (7, 14, 30, 60, or 90 days) under Settings → Data retention. The deletion runs automatically on a schedule and applies to all reports on the account, including ones created before the setting was changed. Export any report you need to keep before it expires.
You may also delete individual reports or your entire account at any time from within the app. Deleting your account removes your reports, saved language, and settings, and cancels any active subscription. Limited billing records may be retained where required by law or by our payment processor. Backups are cycled out on a rolling basis.
9. Children's Privacy (COPPA)
The Service is not directed to children. Information about students is entered by authorized professional users on behalf of the school or supervising entity, which is responsible for any required parental notice or consent.
10. Your Rights
Depending on your jurisdiction (e.g., California, EU/UK), you may have rights to access, correct, delete, or port personal data, and to lodge a complaint with a supervisory authority. Contact us to exercise these rights.
11. Changes
We will post material changes to this Policy and update the "Last updated" date.
12. Contact
Privacy questions or DPA / BAA requests: [your privacy email].
