Privacy Policy

Effective August 6, 2026

Who we are

BehaviorSheets is a behavior data collection and reporting tool for special education teams. Teachers and behavior analysts (BCBAs) use it to record interval behavior data — on paper datasheets that can be scanned with a phone photo, or by direct entry — and to generate trend reports.

This policy explains what data we handle, why, and the choices you have. We have tried to write it in plain language. If anything is unclear, contact us at privacy@behaviorsheets.com.

The short version

  • Students never create accounts or use BehaviorSheets directly.
  • Student records belong to the school. We use them only to provide the service, at the school’s direction.
  • We show no advertising, sell no data, and do not use student data to train AI models.
  • We delete school data on request.

Data we collect

Account data (from you): name, email address, a password (stored only as a salted hash), and your role (teacher, BCBA, administrator, or parent).

Student records (entered by school staff): student name, grade, optional notes, the behaviors being tracked, interval behavior data, absence records, and photographs of paper datasheets uploaded for scanning. These are education records under FERPA.

Operational data: an audit log of who created, viewed, or changed records, kept for accountability and security.

We do not collect data for advertising or analytics profiles, and we do not use third-party advertising or tracking cookies. Cookies are used only to keep you signed in.

How we use data

Solely to provide the service: recording behavior data, converting scanned datasheets into digital records, generating reports and exports, and securing the platform. We do not sell data, share it for marketing, or use student data for any purpose beyond providing BehaviorSheets to the school.

FERPA

When a school or district uses BehaviorSheets, student records remain the property of that school or district. We operate as a school officialwith a legitimate educational interest under FERPA (34 CFR § 99.31(a)(1)): we use education records only for the purposes the school authorizes, remain under the school’s direct control with respect to those records, and do not redisclose them except to the subprocessors listed below, who are bound to the same restrictions.

Parents and eligible students may review records through the school. We are glad to sign a data privacy agreement, including the SDPC National Data Privacy Agreement (NDPA), with any school or district.

COPPA

BehaviorSheets accounts are for adults only — school staff and parents. Children under 13 never create accounts, sign in, or interact with the service, so we do not collect personal information directly from children. Information about students is entered by school staff as part of the school’s educational program and is handled under FERPA as described above.

Where data lives and who processes it

Data is stored and processed in the United States by the following subprocessors, each used only to run the service:

  • Vercel — application hosting and encrypted file storage for uploaded datasheet images. Uploaded images are private: they are never publicly accessible and are served only to signed-in users authorized for that student.
  • Neon — managed PostgreSQL database, encrypted at rest.
  • Anthropic — AI-assisted reading of scanned datasheet images. Anthropic does not use data submitted through its API to train its models.

We will notify schools before adding or changing subprocessors.

Security

  • All traffic is encrypted in transit (TLS); data is encrypted at rest.
  • Role-based, tenant-scoped access control: access is limited to staff at the student’s own school district.
  • Uploaded datasheet images are stored privately, never at public URLs.
  • Passwords are stored as salted hashes, never in plain text.
  • An audit log records access to and changes of student records.

If we become aware of a breach affecting student records, we will notify affected schools without undue delay and no later than 72 hours after confirming it, and will cooperate with the school’s own notification obligations.

Retention and deletion

We keep data for as long as the school uses the service. When a school stops using BehaviorSheets, or on request at any time, we provide an export of the school’s data and permanently delete it — including database records and uploaded images — within 30 days. Individual student records can likewise be deleted on request.

Changes to this policy

If we change this policy, we will update the effective date above and notify schools of material changes before they take effect. We will never reduce protections for student data without the school’s agreement.

Contact

Privacy or security questions: privacy@behaviorsheets.com. See also our Trust & Security overview and Terms of Service.