Privacy Policy

Last updated August 2026

caseload.cloud is a caseload-planning tool for special education teachers. This page explains what information the app collects, how it's used, and how you can control it.

The short version

We ask you to track students by initials, not full names — but the app does still store sensitive information you enter, like IEP dates, disability category, and parent/guardian contact details. Your caseload data is yours: we don't sell it, mine it, or share it with other users. We use a small number of well-known service providers (listed below) to actually run the app, and nothing else. See our Security page for how it's protected, and our Data Processing Agreement if your district requires a signed agreement.

Account information

When you sign in with Google, we receive your name, email address, and profile picture. If you create an account with a password instead, we store your name, email, and a securely hashed version of your password (we never store or can see your actual password). We use this only to identify your account and let you sign back in.

Caseload data you enter

Everything else in the app — student records, IEP dates, goals, service logs, parent contact notes, accommodations, and so on — is data you enter yourself. It's stored so the app can show it back to you; we don't use it for any other purpose, and it's never shared with other users of the app or sold to anyone.

Use student initials only — never full legal names. This app is an educator planning tool, not an official student record, and isn't a substitute for your district's official systems. That said, IEP dates, disability category, and parent/guardian contact information are still sensitive education-related data. If your district requires a signed data-sharing agreement before you use an outside tool with that kind of information, we offer one — see our Data Processing Agreement.

Payment information

If you subscribe, billing is handled entirely by Stripe, our payment processor. We never see or store your card number — Stripe handles that directly and shares back only your subscription status and renewal date.

Who we share data with

We don't sell your data or share it with third parties for their own purposes. We use these service providers to run the app, each only for the purpose listed:

  • Google Cloud — hosting and database storage
  • Google Sign-In — optional Google account authentication
  • Stripe — subscription billing and payment processing
  • Resend — sending account emails (welcome, password reset, notifications)

Cookies

We use a single session cookie to keep you signed in. It's not used for tracking or advertising, and we don't use third-party analytics or ad-tracking cookies.

Children's privacy

caseload.cloud is intended for use by adult educators, not by children, and we don't knowingly create accounts for or collect information directly from anyone under 13. Information about students is entered by their teacher for planning purposes, under the account-holder's own responsibility to follow their district's policies — see "Caseload data you enter" above.

Data retention & security

We keep your data for as long as your account is active, so the app can show it back to you — there's no separate retention time limit running in the background. Data is stored in a Google Cloud SQL database with encryption in transit and at rest, accessible only through the app's own authenticated access — we don't provide direct data access to anyone outside of what's needed to operate and support the service. Every time our support staff view or act on an account, it's recorded in an internal access log.

Deleting your data

You can delete any student record yourself at any time from that student's Edit page. You can also permanently delete your entire account and everything in it yourself, any time, from the Danger Zone on your Profile page — no need to contact us. Deletion removes the record from our production database immediately. We also keep encrypted, rolling database backups for disaster recovery, retained for 7 days — a very recent deletion could still exist in one of those backups for up to a week before it fully ages out, the same way it would with virtually any backed-up system.

Changes to this policy

If this policy changes, we'll update the date at the top of this page.

Contact

Questions about this policy or your data? Email hello@caseload.cloud.