Trust & Security

For school and district technology teams · Last updated August 6, 2026

What BehaviorSheets is

BehaviorSheets is a behavior data collection and reporting tool for special education teams. Teachers record interval behavior data on printed datasheets or by direct entry; a phone photo of a paper sheet is converted to digital data and reviewed by staff before being accepted. BCBAs and teachers then use the data for trend analysis and reporting — data collection the school is typically already doing on paper for students with IEPs and behavior intervention plans.

Only adults use BehaviorSheets. Accounts belong to school staff, behavior analysts, and (optionally) parents invited by the school. Students never sign in or interact with the service.

Data we handle

  • Staff/parent account data: name, email, hashed password, role.
  • Student records, entered by school staff: name, grade, behaviors tracked, interval behavior data, absences, staff notes, and photos of paper datasheets.
  • Audit log: who created, viewed, or changed records.

No advertising, no analytics profiles, no sale of data, and no use of student data to train AI models. Cookies are used only for sign-in sessions.

FERPA and COPPA

We operate as a school officialunder FERPA (34 CFR § 99.31(a)(1)): student records remain the property of the school or district, we use them only as the school directs, and we remain under the school’s direct control with respect to those records. COPPA does not apply to our collection because children never use the service; student information is entered by school staff and handled as FERPA education records.

We will sign a data privacy agreement with any school or district, including the SDPC National Data Privacy Agreement (NDPA) or your state’s standard version.

Security practices

  • All traffic encrypted in transit (TLS 1.2+); data encrypted at rest.
  • Role-based, tenant-scoped access control — every record is scoped to its school district, staff access is limited to students at their own district, and roles gate administrative actions.
  • Uploaded datasheet images are stored in private storage and are never publicly accessible; every image request is authenticated and authorization-checked against the requesting user’s student access.
  • Passwords stored as salted hashes; sessions expire automatically.
  • An audit log records creation, modification, and review of student records, including old and new values.
  • Scanned data is never auto-accepted — a staff member reviews and approves every scan before it becomes part of the record.

Subprocessors

We use three subprocessors, each solely to operate the service. All data is stored and processed in the United States.

ProviderPurposeLocation
VercelApplication hosting and private file storage for uploaded datasheet imagesUnited States
NeonManaged PostgreSQL database (encrypted at rest)United States
AnthropicAI-assisted reading of scanned datasheet images; API data is not used to train modelsUnited States

Retention, deletion, and export

School data is retained only while the school uses the service. On request, or within 30 days of the end of service, we export the school’s data (CSV/PDF) and permanently delete it, including database records and uploaded images. Individual student records can be deleted at any time at the school’s request.

Incident response

If we confirm a breach affecting student records, we notify affected schools without undue delay and no later than 72 hours after confirmation, including what happened, what data was involved, and what we are doing about it, and we cooperate with the school’s own notification obligations.

Requesting access for your school

If behaviorsheets.com is blocked on your network, the domains needed are behaviorsheets.com and *.behaviorsheets.com over HTTPS (port 443) — no other domains, trackers, or third-party scripts are loaded by the app.

For pilots, we’re glad to start with a bounded arrangement — a single classroom, named staff users, and deletion of all data at the end unless the school chooses to continue.

Contact

Security and privacy contact: privacy@behaviorsheets.com. Full details in our Privacy Policy and Terms of Service.