Privacy Policy
Last updated August 7, 2026
TherapyTrack is a workspace for school-based occupational therapy teams. This policy explains what we collect, why we need it, when service providers process it, and the choices available to clinicians, schools, and districts.
Student data is used to provide TherapyTrack—not for advertising, sale, or unrelated profiling. Authorized users control what enters a workspace, and AI features run only when a user requests them.
1. Scope and our role
This policy applies to the TherapyTrack website, application, and related support services. In this policy, “TherapyTrack,” “we,” and “us” mean THERAPYTRACK LLC. For student information entered under a school or district agreement, the school or district remains the data owner and TherapyTrack acts as its service provider or processor. A district Data Privacy Agreement (“DPA”) may add or replace terms in this policy for that deployment.
TherapyTrack is intended for use by adult clinicians and authorized staff. It is not a student-facing service, and students should not create accounts or submit information directly.
2. Information we collect
Account and workspace information
- Name, email address, professional role, state, authentication identifiers, and workspace membership.
- Subscription plan, billing status, and transaction identifiers. Payment card information is collected and processed by Stripe rather than stored by TherapyTrack.
- Invitations, collaborator roles, student assignments, permissions, and related activity metadata.
Student and service information
- Student name, grade, school, service information, goals, schedules, and team assignments.
- Session records, attendance, progress measurements, structured notes, attachments, summaries, and IEP-related drafts.
- Files and other content an authorized user chooses to upload or enter.
Technical and support information
- Authentication events, approximate device and browser information, security logs, and diagnostic information needed to operate and protect the service.
- Pseudonymous account identifiers and selected product events used to understand signup, onboarding, trial, and subscription completion. TherapyTrack disables automatic interaction capture, page URL collection, heatmaps, and session replay, and does not intentionally send student records or clinical content to product analytics.
- Support requests and communications.
- Referral and campaign parameters used to understand how account owners discover TherapyTrack. We do not use student data for marketing attribution.
3. How we use information
- Provide documentation, scheduling, progress tracking, collaboration, and export features.
- Authenticate users and enforce workspace, role, student, editing, and export permissions.
- Process subscriptions, provide support, prevent abuse, and maintain service reliability.
- Generate optional AI-assisted drafts when an authorized user affirmatively requests one.
- Meet legal obligations and enforce our agreements.
We do not sell student personal information, serve targeted advertising, or use student records to build advertising profiles. We do not use student data to train TherapyTrack advertising models.
4. IEP Assist and other AI features
TherapyTrack uses OpenAI’s API to provide IEP Assist, goal drafting, note rewriting, and summary features. When an authorized user selects an AI feature, TherapyTrack sends only the context needed for that request. Depending on the feature, this may include the student’s name, grade, school, goals, progress measurements, session notes, attendance, and the user’s instructions.
- AI processing is request-based; it does not continuously scan a workspace.
- Outputs are drafts and may be incomplete, inaccurate, or inappropriate.
- A qualified clinician must review, edit, and approve every output before relying on it or placing it in an official record.
- IEP Assist access is restricted to the student’s primary OT for final-documentation oversight.
OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer affirmatively opts in. TherapyTrack does not opt student data into model training and does not permit AI providers to use it for advertising. OpenAI may retain API prompts and responses in abuse-monitoring logs for up to 30 days under its standard API data controls unless a different approved retention control applies. Learn more in our AI Use Policy.
5. When information is disclosed
We disclose information only as needed to provide and protect the service, follow an authorized customer instruction, complete a business transaction, or comply with law. Categories of recipients may include:
- Cloud hosting, database, authentication, storage, monitoring, email, and security providers.
- OpenAI for user-requested AI processing.
- Stripe for subscription and payment processing.
- PostHog for limited product analytics configured without student content, automatic page capture, heatmaps, or session replay.
- Professional advisers, authorities, or transaction counterparties where legally necessary and subject to appropriate safeguards.
Service providers may process information only to perform services for TherapyTrack and are expected to protect it under contractual and legal obligations. We do not re-disclose education records for an unauthorized purpose.
6. Retention, export, and deletion
We keep account and student data while the workspace is active and as needed to provide the service. Workspace owners should use retention periods approved by their school or district and remove information that is no longer needed for its educational purpose.
Before closing a workspace, authorized users can export key student summaries, goal progress, and session records in supported PDF or CSV formats. Archiving a student only removes the student from the active caseload; it does not delete the record. A workspace owner can permanently delete an inactive student from that student's page, or permanently delete the owner's account and workspace from Account Settings. Permanent student deletion removes the student's IEPs, goals, sessions, progress data, schedule data, and uploaded files from active systems. Account deletion also cancels an active subscription, removes files uploaded by that user, removes or de-identifies the user's identity on records retained by another workspace owner, and deletes the sign-in identity.
A workspace owner, school, or district may also request return or deletion by emailing privacy@usetherapytrack.com. We verify authority before acting. Residual copies may remain temporarily in protected backups until the configured provider backup-retention period expires and are not restored except for recovery or security purposes. A deletion ledger retains only pseudonymous hashes, timestamps, scope, status, and operational counts needed to demonstrate and troubleshoot the request.
Some limited account, billing, security, and legal records may be retained where reasonably necessary for fraud prevention, dispute resolution, tax, accounting, or other legal obligations.
7. School and district controls
Schools and districts may request access, correction, export, or deletion of student information and may set additional rules through a DPA. We will reasonably assist with parent or eligible-student requests routed through the responsible educational agency. TherapyTrack does not independently decide who may inspect an education record.
FERPA compliance depends on both TherapyTrack’s safeguards and the customer’s authorization, configuration, access decisions, notices, and use. Educators should confirm district approval before entering student information. For a DPA, security questionnaire, or vendor review, contact privacy@usetherapytrack.com.
8. Security and incident response
We use administrative, technical, and organizational safeguards designed to protect information, including encrypted transport, encrypted managed storage, authenticated access, and role- and student-scoped permissions. No system can guarantee absolute security. If we confirm a breach affecting protected student information, we will notify affected customers as required by applicable law and any governing DPA. See our Security & Trust page.
9. Changes and contact
We may update this policy as the service or law changes. We will update the date above and provide additional notice when a change materially affects how student data is handled.
Questions or requests: privacy@usetherapytrack.com.