Privacy Policy
Last updated: July 31, 2026
1. Introduction
Vaccaro Ventures LLC ("we," "our," or "Casemate") operates IEP Casemate, special education case management software for educators, schools, and districts. This Privacy Policy explains how we collect, use, and protect information when you use our service.
When a school or district uses Casemate, we act as a school official with a legitimate educational interest under FERPA (34 CFR § 99.31(a)(1)). We process student data only to provide the service under the direction of the educational agency, we do not re-disclose it, and we do not use it for our own purposes.
2. Information We Collect
Account information: When you sign up, we collect your email address, display name, and authentication credentials (managed by Firebase Auth).
Student data (minimal, de-identified): Teachers enter student initials (e.g., J.M.), grade level, IEP goals, service requirements, accommodations, class schedules, and related caseload fields. We do not require or store student full names, home addresses, birth dates, or Social Security numbers as part of the standard caseload record.
Uploaded documents: If you upload an IEP, assessment, lesson, or work sample PDF, we extract structured information and strip personally identifiable information (PII) before persisting results. Full names are converted to initials; SSNs, dates of birth, phone numbers, emails, and addresses are removed. Source PDFs for some pipelines are deleted after processing.
Service logs & progress data: Session notes, completion status, progress-monitoring statements, and related notes you enter or that are generated from instructional features, linked to student initials and goal identifiers.
Student practice & AI tutor sessions: When a case manager launches interactive practice or an AI tutor session, we store session metadata (for example, selected goal, lesson plan steps, accommodations applied), practice items and answer keys (answer keys are not returned to the student interface), student attempts/responses, tutor conversation messages for that session, scores or summaries, and links to progress artifacts written back for the educator. Students access these experiences through a unique share link; they do not create a Casemate account.
Other educator-created share links:Depending on features you use (for example, family portal, collaboration calendar, or at-a-glance shares), we store the content and responses associated with those links under the educator's account.
Waitlist/leads & newsletter: If you submit your email on our website, we store it to send product or newsletter updates you requested.
3. How We Use Your Information
We use your data solely to provide and improve Casemate: to display caseloads, generate schedules, track compliance, draft IEP-related text for educator review, run practice and AI tutor sessions under educator direction, and produce progress artifacts. We do not sell your data. We do not use student data for advertising or marketing, and we do not use it to train our own models.
4. Artificial Intelligence & Automated Processing
Several features use generative AI, including: IEP/assessment extraction; present levels and progress statements; standards- or lesson-aligned practice generation; and AI tutor lesson planning and in-session coaching replies. By default, these requests are processed by Google Vertex AI on Google Cloud under the Google Cloud Data Processing Addendum. Content sent to Vertex AI is not used to train Google's models and is processed within a configured Google Cloud region.
We minimize the data sent to AI models: prompts are built from de-identified caseload data (initials, not full names) and pass an additional PII-scrubbing step before being sent. Tutor and practice prompts may include the selected IEP goal text, objectives, recent progress statements, relevant assessment summaries, prior tutor lesson history for that goal, grade level, and accommodation settings. A district or organization may optionally configure its own AI key (BYOK), in which case those requests use that customer's own provider relationship.
Educator-facing AI output (for example, progress statements or meeting drafts) is a draft for qualified professional review. AI tutor replies are constrained by prompt instructions and server validation to the selected goal and lesson, but generative systems can still make mistakes; educators remain responsible for the instructional use of the feature. See our Trust Center for details.
5. Share Links (No Student Account)
Practice, AI tutor, and certain other features use unguessable share links created by an authenticated educator. Access is granted to whoever possesses a valid, non-expired link. Links may expire automatically and may be closed by an authorized user. Public link endpoints are rate-limited. Answer keys for practice items remain server-side and are not included in the student-facing payload.
Educators and schools control how links are distributed. Treat active links like credentials for that session.
6. Data Storage and Security
Data is stored in Google Cloud (Firebase/Firestore). All data is encrypted in transit (TLS 1.2+) and at rest. Access is restricted by authentication and Firestore security rules for account-held data; share-link experiences are mediated by authenticated Cloud Functions. See our Security & Data Practices page for details.
7. Who Can Access Student Data
Access to educator accounts follows your school or district's structure, which your administrators control:
- A teacher can access the students on their own caseload.
- Teachers in the same school may share school-wide caseloads (e.g., to co-assign services), where enabled by the school.
- A principal may access caseloads of teachers in their school; a district administrator may access schools in their district.
- A person with a valid share link can access only the limited experience that link was created for (for example, one practice set or one tutor session), not the educator's full account.
There is no access across unrelated schools or districts. Casemate personnel do not access customer student data except as needed for support, security, or legal compliance.
8. Subprocessors
We do not share your data with third parties for marketing. We use the following subprocessors to operate the service, each contractually bound to protect data:
- Google Cloud — Firebase Authentication, Firestore (storage), Cloud Functions (compute), Vertex AI (AI inference), Document AI (PDF OCR), Secret Manager
- Netlify — application hosting / CDN
- Stripe — payment processing
- Resend — transactional invitation email (staff email addresses only)
We can provide a Data Privacy Agreement (DPA) and a current subprocessor list to schools and districts on request.
9. Data Retention and Deletion
You can delete your account and associated data at any time by contacting us. We will delete your data within 30 days of a valid request, except where we must retain it for legal or operational purposes. On termination of a school or district agreement, student data is deleted or returned per that agreement. Expired or closed share-link sessions may remain associated with the educator account for progress history until deleted under those same rules.
10. Your Rights
You may access, correct, or delete your personal information. For requests, contact us at the email below. If you are in a jurisdiction with additional privacy rights (e.g., GDPR, CCPA), we will honor those rights where applicable. Parents seeking access to student education records should contact their school or district, which controls that data.
11. Children's Privacy & Student Access
Casemate accounts are intended for educators and authorized school/district staff, not for children to self-register. Students do not create Casemate accounts.
Students may interact with limited, educator-created experiences (such as practice activities or AI tutor sessions) when an educator or school shares a link for instructional purposes. Those interactions process student responses and session content on behalf of the school under FERPA, using the minimal identifiers described above (typically initials and grade). Schools remain responsible for obtaining any consents or authorizations required by their policies and applicable law for such instructional tools.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date.
13. Contact Us
Vaccaro Ventures LLC
For privacy inquiries: privacy@iepcasemate.com