Privacy Policy

Last updated: July 20, 2026


Summary of Key Points

PaprFlow [PaprFlow, Inc. — confirm entity name upon formation] is a cloud application that helps K-12 special-education teachers draft IEP documents from uploaded evaluation records and typed student information. Here is what you need to know:

  • Who uses PaprFlow: Educational professionals (teachers, related service providers, administrators) who are 18 or older.
  • What information we collect from you: Your email address, password, and if you pay for a subscription, billing information managed by Stripe.
  • Student data: We receive student information only indirectly—inside documents you upload or typed into your roster. We do not collect directly from students or families. Uploaded files are redacted of personally identifiable information, sent to Google's Gemini model to generate your draft, and then deleted.
  • No sale or sharing: We do not sell, share, or use student data to train AI models. We do not use targeted advertising, collect geolocation data, or work with data brokers.
  • Your rights: You can export your data and delete your account using in-app tools. For state-specific privacy rights (California, Colorado, Connecticut, etc.), contact us at support@paprflow.com.
  • Encryption: Student roster fields are encrypted at the field level before storage.
  • Subprocessors: Supabase (database and authentication), Google (AI), Stripe (payment), Sentry (error monitoring—currently disabled), and a hosting provider.

For details, read the sections below.


Table of Contents

  1. Who We Are
  2. Our Users and Eligibility
  3. Information We Collect
  4. Student Data: Our FERPA and SOPIPA Role
  5. How We Use Information
  6. Subprocessors and Service Providers
  7. Cookies and Tracking
  8. Data Retention and Deletion
  9. Security
  10. Your Privacy Rights
  11. Changes to This Policy
  12. Contact Us

1. Who We Are

PaprFlow (operated by [PaprFlow, Inc. — confirm entity name upon formation]) provides a cloud application that helps K-12 special-education teachers draft IEP documents from uploaded evaluation records and typed student information. Our primary contact information is:

  • Website: https://paprflow.com
  • Support Email: support@paprflow.com
  • Mailing Address: 7440 Freeport Cir, Fontana, CA 92336, USA
  • Phone: (909) 581-5315 (not toll-free)

This policy applies to your use of PaprFlow. PaprFlow is an AI-assisted drafting aid that helps educators create IEP documents. The educator and IEP team review, edit, and own the final document. PaprFlow output is a draft only, not legal, medical, or educational advice.


2. Our Users and Eligibility

PaprFlow is designed for use by educational professionals 18 years of age or older, including classroom teachers, special-education teachers, related-service providers, and school administrators.

Students do not use PaprFlow. We do not collect personal information directly from students or their families. Student information arrives only indirectly—inside documents uploaded by authorized school personnel or typed into your student roster by you.

By accessing PaprFlow, you represent that you are 18 or older and have authority under your school or district's policies to upload and manage student records consistent with FERPA, your state's student privacy laws (including SOPIPA in California), and IDEA.


3. Information We Collect

Account Information

When you create a PaprFlow account, we collect:

  • Your email address
  • Your password (securely hashed by Supabase Auth; never stored in plaintext by PaprFlow)

We use email + password authentication only. We do not offer social login via Google, Microsoft, Facebook, X, or any other third-party provider.

If you contact our support team, we collect your support communications.

Billing Information

If you purchase a paid plan, billing is processed through Stripe. PaprFlow stores:

  • Your subscription status and plan tier
  • Your Stripe customer identifier and subscription identifier

Your credit card number is not stored by PaprFlow. Stripe handles payment card information directly. Full billing terms appear in our Terms of Service.

Operational Logs

We maintain security and audit logs that record:

  • Hashed identifiers of users (one-way hash; we cannot link them back to an individual)
  • The AI model name used (currently Google's Gemini model)
  • Timestamp of generation events
  • Event type (e.g., "IEP generation attempted")

Hashed identifiers mean raw user IDs are never written to logs.

Error Monitoring

We have integrated Sentry for error monitoring, but it is disabled by default. If we enable it, Sentry is configured to send:

  • Error text only (scrubbed of email addresses and UUIDs)
  • No IP addresses
  • No user identifiers
  • No request bodies

What We Do NOT Collect

We do not collect:

  • Information from data brokers, public databases, marketing partners, or social media platforms
  • Your geolocation
  • Biometric information (fingerprints, voiceprints, etc.)
  • Targeted advertising profiles

We do not engage in targeted advertising, cross-site tracking, or profiling for legal or significant effects. We do not sell, share, or license your personal information as defined under the California Consumer Privacy Act (CCPA) or other state privacy laws.


4. Student Data: Our FERPA and SOPIPA Role

This section is critical. Student data is protected education records under FERPA and, in California, under SOPIPA. Please read carefully.

How Student Data Reaches PaprFlow

You provide student information in two ways:

  1. Uploaded Documents: You upload evaluation documents (psychoeducational reports, progress monitoring data, teacher observations, etc.) to PaprFlow to help generate a draft IEP.
  2. Typed Roster Entries: You type student information directly into PaprFlow (name, grade, disability category, optional next-IEP-review date).

We never collect student information directly from students, families, or anyone but authorized school personnel. Students never access PaprFlow.

How We Store Student Data

Student roster fields (name, grade, disability category, review date) are encrypted at the field level using application-layer encryption on top of database-level encryption at rest. Only non-identifying metadata (e.g., domain, status flags) is stored in plaintext.

How We Process Uploaded Documents

When you run a generation:

  1. Your uploaded file is converted to text
  2. Personally identifiable information (names, birthdates, student IDs, family information, etc.) is automatically redacted
  3. The redacted text is capped in length
  4. The redacted text is sent to Google's Gemini model to generate your IEP draft
  5. The original uploaded file is deleted from storage immediately after generation, whether it succeeds or fails

Uploaded files are never retained.

Prior-Year IEPs

Prior-year IEPs (used for annual updates) are never stored. They are processed through the same extract → redact → delete pipeline. Only the encrypted change-summary (delta) that you approve is saved.

AI and Student Data

Student data is sent to Google's Gemini API (currently Gemini 2.5 Flash) for text generation. Here is what you need to know:

  • The redacted text is what goes to the model, not original student names or identifiers
  • System prompts refer to "the student" generically, not by name
  • Student data is never used by PaprFlow to train or improve AI models
  • PaprFlow's use of the Gemini API is under terms that prohibit Google from using the data to train its models [Founder: confirm paid-tier Gemini API terms are in effect]

Your Role Under FERPA and SOPIPA

For Individual Teacher Accounts: You are responsible for using PaprFlow consistent with your school and district policies, FERPA (34 CFR 99.31(a)(1), school-official exception), and COPPA (if applicable). You must have authority to upload and manage the student records you use with PaprFlow.

For Future District Contracts: PaprFlow will act as a "school official" or data processor under your district's direct control. We will use student records solely to provide the contracted service and will not re-disclose them without authorization.

SOPIPA Compliance: PaprFlow complies with California Business & Professions Code Section 22584 (SOPIPA):

  • We do not use student data for targeted advertising based on student information
  • We do not engage in student profiling for non-educational purposes
  • We do not sell student data, ever

COPPA: PaprFlow is not directed to children under 13. We do not collect information directly from any child. Student records about children are provided only by school personnel in their official capacity.


5. How We Use Information

We use your personal information to:

  • Operate the service: Create your account, authenticate you, process subscription billing, and maintain your access
  • Generate IEP drafts: Process redacted student data via the Gemini API to produce your draft documents
  • Communicate with you: Send administrative notices, respond to support inquiries, and notify you of policy changes
  • Improve the service: Analyze aggregated, non-identifiable usage data to identify trends and improve features. Student data is never used to improve AI models or services.
  • Security and compliance: Maintain audit logs, monitor for abuse, comply with legal obligations, and respond to lawful requests

We do not use your information for direct marketing, advertising, or profiling with legal effects.


6. Subprocessors and Service Providers

We share personal information with the following vendors only to the extent needed for them to operate services on our behalf. Each vendor is contractually required to protect your data and may not use it for their own purposes.

VendorPurposeData Shared
SupabaseDatabase, authentication, encrypted storage of app data and student rosterEmail, password hash, account data, encrypted student fields
Google (Gemini API)AI text generation for IEP draftingRedacted student data (with PII removed)
StripePayment processing and subscription billingStripe customer/subscription identifiers, subscription status
SentryError monitoring (currently disabled)Error messages (with PII scrubbed); no IP addresses, user IDs, or request bodies
[Hosting provider — confirm: Vercel or Hostinger]Application hosting and deploymentApplication runtime and log data

All subprocessors receive only the minimum data necessary and may not use it for their own business purposes.


7. Cookies and Tracking

We use cookies and similar technologies only for the following purposes:

First-Party Cookies (Set by PaprFlow)

  • Supabase Auth Session Cookie: Keeps you signed in. Strictly necessary. Deleted when you sign out or your session expires.
  • Sidebar State Cookie: Remembers whether your sidebar is open or closed. Functional. Expires in 7 days.

Browser Storage (Not Cookies)

  • Language Preference (stored in localStorage): Remembers your language choice (English or Spanish)
  • Greeting Dismissal Flag (stored in localStorage): Remembers that you dismissed an onboarding message

Third-Party Cookies

  • Stripe Cookies: Stripe sets its own cookies on Stripe-hosted checkout and billing pages. These are governed by Stripe's privacy policy and are necessary for fraud prevention and payment processing.

What We Do NOT Use

We do not use:

  • Analytics cookies (Plausible is under consideration; if adopted, it will be cookieless and privacy-first, and we will update this policy)
  • Advertising cookies or web beacons
  • Flash or Local Stored Objects (LSOs)
  • Cross-site tracking

No cookie banner or preference center is required because we do not set non-essential cookies. Blocking essential cookies via your browser will break sign-in. You can control cookies through your browser settings.


8. Data Retention and Deletion

While Your Account Is Active

Personal data (email, account settings, student rosters, IEP drafts) is kept while your account is active.

Account Deletion

You can delete your account anytime using Settings → Account → "Delete account". Typed-confirmation deletion removes:

  • Your account
  • All user-scoped data (students, drafts, and uploads)
  • Deleted immediately and permanently via database cascade

What Survives Deletion

The following are retained after account deletion:

  • Hashed audit log entries: Keyed by one-way hashed user IDs (cannot be linked back to you by PaprFlow). These are kept for security purposes.
  • Billing records: Stripe transaction records and related data required for legal and tax compliance

Data Export

You can export all your data as JSON using Settings → Account → "Export my data". The export is decrypted locally in your browser; plaintext never passes through PaprFlow servers.


9. Security

We implement organizational and technical security measures to protect your information, including encryption at rest and in transit, access controls, and audit logging. However, no electronic system is 100% secure. We cannot guarantee that unauthorized parties will not be able to access, steal, or modify information, despite our best efforts. You assume the risk of transmitting information over the internet and should access PaprFlow only from a secure environment.


10. Your Privacy Rights

In-App Privacy Controls

These tools are available in the PaprFlow interface:

  • Export My Data (Settings → Account): Download your data as JSON, decrypted locally in your browser
  • Delete Account (Settings → Account): Permanently delete your account and associated data

Do-Not-Track

We do not track users across websites or over time, so Do-Not-Track (DNT) and Global Privacy Control (GPC) signals have no practical effect on our service — there is no tracking to disable. Because we do not sell or share personal information, GPC opt-out signals are honored by default.

US State Privacy Rights

If you live in California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you have the following rights (subject to applicable law):

  • Access: Request access to personal information we hold about you
  • Correct: Request correction of inaccurate information
  • Delete: Request deletion of your personal information
  • Portability: Obtain a copy of your data in a portable format
  • No Discrimination: We will not discriminate against you for exercising these rights
  • Appeal: If we decline your request, you may appeal by replying to our decision email; if your appeal is denied, you may contact your state attorney general

What We Have NOT Done (No Opt-Outs Required)

  • We have not sold or shared personal information
  • We do not use targeted advertising
  • We do not use profiling for decisions with legal effects
  • No opt-out mechanism is required

How to Exercise Your Rights

Contact us at support@paprflow.com or by mail at the address below. We will verify your identity and respond to valid requests within the timeframes required by law. You may also designate an authorized agent to submit requests on your behalf (the agent must provide written proof of authorization).


11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email or in-app notification with an effective date. The "Last updated" date at the top of this policy will reflect the most recent revision. We encourage you to review this policy periodically to stay informed of how we protect your information.


12. Contact Us

If you have questions or concerns about this Privacy Policy or our privacy practices, please contact us:

Email: support@paprflow.com Mailing Address: [PaprFlow, Inc. — confirm entity name upon formation] 7440 Freeport Cir Fontana, CA 92336 USA Phone: (909) 581-5315

For California residents: You may also file a complaint with the California Attorney General if you believe your rights have been violated.