Legal & Compliance

Privacy Policy

How Sure Step Education collects, uses, protects, and never sells your student data.

Effective date: September 2, 2026  ·  Replaces all prior versions
Our core commitment

Student data collected through TransitionReady is used exclusively to support students' educational transition goals. We do not sell student data. We do not use student data for advertising. We do not share student data with third parties except as required to operate the platform or comply with law. We do not use student data to build profiles for any purpose other than providing TransitionReady services.

Contents
  1. About This Policy
  2. Who We Are
  3. Age Requirement
  4. What Data We Collect
  5. How We Use Data
  6. Who Can Access Student Data
  7. Data We Never Use It For
  8. FERPA Rights
  9. AB 1584 & SOPIPA
  10. Data Storage & Security
  11. Subprocessors
  12. Data Retention & Deletion
  13. AI-Generated Content
  14. Interview Practice (Microphone Use)
  15. Career Explorer
  16. Money Trail
  17. Feedback Form
  18. Changes to This Policy
  19. Contact & Requests
Section 1

About This Policy

This Privacy Policy describes how Sure Step Education ("we," "us," or "our") collects, uses, stores, and protects information through TransitionReady, our student transition portfolio platform. It applies to all users of TransitionReady including students, case managers, district administrators, and Sure Step Education staff.

This policy is designed to comply with the Family Educational Rights and Privacy Act (FERPA, 20 U.S.C. § 1232g), the Children's Online Privacy Protection Act (COPPA, 15 U.S.C. §§ 6501–6506), the Student Online Personal Information Protection Act (SOPIPA, Cal. Bus. & Prof. Code § 22584), California Education Code § 49073.1 (AB 1584), and applicable IDEA confidentiality provisions.

The Designated Responsible Individual for privacy compliance at Sure Step Education is Nicholas Crabtree.

Section 2

Who We Are

Sure Step Education is the operator of TransitionReady. We provide transition portfolio services to K–12 school districts under written data privacy agreements that comply with AB 1584 and applicable state and federal law.

We act as a "School Official" under FERPA when we access student education records, meaning we use that access only for legitimate educational purposes and under the direct control of the educational institution.

Section 3

Age Requirement

TransitionReady is designed exclusively for students aged 16 and older — typically high school juniors and seniors preparing for post-secondary transition. We do not knowingly collect personal information from students under 16. Students are only added to the platform through an invite link generated by a credentialed case manager or district administrator.

Because TransitionReady serves students 16 and older, COPPA (which applies to children under 13) does not apply to our student-facing services. However, we maintain COPPA-equivalent protections for all student data as a matter of policy.

If we become aware that a student under 16 has been added to the platform, we will work with the district to remove that account promptly.

District responsibility for age verification: Case managers and district administrators are responsible for verifying that students are 16 or older before generating an invite link. By generating an invite link, the staff member represents to Sure Step Education that the student meets the age requirement and has an active transition IEP. Sure Step Education relies on this representation and does not independently verify student age. Districts agree to this responsibility as part of the AB 1584 data privacy agreement required before platform activation.
Section 4

What Data We Collect

We collect only the data necessary to provide TransitionReady services. The following categories of information may be collected:

Account information: Full name, email address, role (student, case manager, district administrator), school, and district. This is provided at account creation via an invite link.

Portfolio content (students only): Information students voluntarily enter into their portfolio, including personal profile details (name, phone, address, graduation year, GPA), career interests and goals, work samples, supporting documents, and AI-generated documents such as resumes, cover letters, letters of recommendation requests, and 5-year plans.

Optional feature activity (students only): If a student uses Interview Practice, the text of their practice answers and the feedback on them (Section 14). If a student uses Career Explorer, the choices they made and the careers they were shown (Section 15). If a student plays Money Trail, the choices they made in each run (Section 15b). All three are optional, all three are stored on the student's own portfolio record, and none of them is an assessment.

Optional profile photograph: If a student chooses to upload a profile photograph, it is stored only in the student's own web browser on the device used to upload it. Profile photographs are not uploaded to our cloud database or our file storage and are not accessible to case managers, district administrators, or Sure Step Education staff. Clearing browser site data will remove the photograph.

Case manager suggestions: Proposed edits submitted by a student's assigned case manager, including the field, suggested value, and status (pending, approved, or rejected by the student).

Case manager contact directory (post-graduation follow-up): A student's assigned case manager may record durable contact details for the student to support transition follow-up after graduation, including the student's name, graduation year, personal phone and personal email, social-media handles (Instagram, Snapchat, TikTok, Facebook, LinkedIn), and free-text notes. These records are owned by, and visible only to, the case manager who created them. Because their purpose is to maintain contact after a student's portfolio account is deactivated, these contact records are deliberately retained beyond the life of the student account (see Section 12) and store a snapshot of the student's name. They are not visible to other case managers, to other students, or to Sure Step Education in the ordinary course.

Usage data: Account creation date, last portfolio save timestamp, and aggregated platform activity metrics. We do not track individual browsing behavior or use third-party analytics tools.

Communications: Invite tokens generated for account creation. We do not store the content of any emails sent through the platform.

We do not collect: Social Security numbers, financial account information, health or medical records, geolocation data, or any data not directly necessary to operate TransitionReady. We do not store or transmit voice recordings — see Interview Practice in Section 14.
Section 5

How We Use Data

We use the data we collect solely for the following purposes:

We do not use student data for any purpose beyond providing and improving TransitionReady services.

Section 6

Who Can Access Student Data

Access to student data is strictly controlled by role. The table below describes what each role can and cannot access:

Role What they can access What they cannot access
Student Their own portfolio only. They can view, edit, and export their own data. They can see every case manager connected to them and can disconnect any of them at any time, and they approve or reject suggestions made by a connected case manager. Any other student's data.
Case Manager Read-only view of the portfolios of students connected to them. Can search for students at their own school and connect themselves, and can generate student invite links to add new students. Can submit portfolio suggestions for the student to approve or reject. Can keep a private contact directory (personal phone/email and social-media handles) for their own students, for post-graduation follow-up. Portfolios of students they are not connected to, or who have disconnected them. Students at any other school, including elsewhere in the same district — a case manager's search is limited to their own school. The ability to edit student portfolios directly.
District Administrator Read-only view of all student portfolios and case manager accounts in their district. Can execute data deletion upon verified request. Can generate case manager invite links. Student data from other districts. The ability to edit portfolios. Export of individual student PII.
Sure Step Founder Aggregate platform metrics only (total students, completion rates, district-level counts). Can provision and deactivate districts. Can view the system audit log. Holds narrowly scoped read access to stored portfolio files, used solely for technical support and data recovery at a district's request (see Section 10). Individual student portfolio content in the application. Student dashboards, profiles, or any student-identifiable reporting.

These access controls are enforced at the database level using Row Level Security (RLS) policies. They are not merely application-layer controls — they are enforced by the database itself and cannot be bypassed through the application interface.

Important: Case managers can only view portfolios of students connected to them. They cannot see portfolios of students they are not connected to, and they can only connect to students at their own school — never at another school or elsewhere in the district.

6.1 Connecting and Disconnecting a Case Manager

A connection between a student and a case manager can be started from either side. A student connects a case manager by entering that case manager's email address on their Profile tab and clicking “Connect.” A case manager can also connect themselves to a student at their own school, by searching for that student from their dashboard — this is how staff pick up students who already have an account. A case manager can also send a student an invite link to create an account in the first place.

A student can see everyone who is connected to them, and can disconnect any of them at any time. The list appears on the student's Profile tab, showing each person's name and the date they connected, with a Disconnect button beside each one. Disconnecting immediately revokes that person's access to the portfolio; anyone else who is connected keeps theirs.

A student may be connected to more than one staff member at once — for example a case manager and a transition specialist, or an outgoing and an incoming case manager during a handoff. Every connection is read-only: a connected case manager can view the portfolio and submit suggestions for the student to approve or reject, but can never edit the portfolio directly.

Case managers can only reach students at their own school. Sure Step Education does not assign, reassign, or remove case managers on a student's or district's behalf, and there is no district-administrator approval step for connecting or disconnecting — the action takes effect when the student or the case manager performs it.

Audit retention: Connections and disconnections between a student and a case manager are recorded in the audit log and retained for the duration of the student's account plus 3 years, consistent with FERPA audit-trail requirements under 34 CFR § 99.32. Audit entries contain user identifiers, timestamps, and status — they do not contain portfolio content or other student-identifying narrative.
Section 7

Data We Never Use Student Data For

We make the following absolute commitments regarding student data:

These are not aspirational commitments — they are operational realities reflected in how the platform is built and how our subprocessor agreements are structured.

Section 8

FERPA Rights

TransitionReady handles student education records as defined under the Family Educational Rights and Privacy Act (FERPA, 20 U.S.C. § 1232g). FERPA grants parents and eligible students (those 18 or older, or attending post-secondary institutions) specific rights regarding education records.

Right to inspect and review: Students 18 and older (and parents of students under 18) have the right to inspect and review education records maintained in TransitionReady. Requests should be directed to the student's district administrator or to Sure Step Education at the contact information in Section 16.

Right to request amendment: If a student or parent believes information in TransitionReady is inaccurate or misleading, they may request that Sure Step Education or the district amend the record. We will respond within a reasonable timeframe and, if we decline to amend, inform the requester of their right to a hearing.

Right to request deletion: Students and parents may request deletion of student data from TransitionReady. Deletion requests are processed by the student's district administrator and result in permanent removal of the student's profile, portfolio, and associated data from the platform. Deletion is logged in the audit trail for compliance purposes.

Right to consent to disclosure: We do not disclose student education records to third parties without written consent from the student (if 18+) or parent (if under 18), except as permitted under FERPA's "school official" exception for platform operation, or as required by law.

To exercise FERPA rights: Contact your district administrator, or contact Sure Step Education directly at the information in Section 16. We will respond within 45 days.
Section 9

AB 1584 & SOPIPA Compliance

Sure Step Education's use of TransitionReady complies with California Education Code § 49073.1 (AB 1584) and the Student Online Personal Information Protection Act (SOPIPA, Cal. Bus. & Prof. Code § 22584). These laws establish strong protections for K–12 student data in California and reflect our baseline standard for all users nationwide.

In accordance with these laws, Sure Step Education:

Student data collected through TransitionReady is used only to provide, maintain, improve, and support the educational services offered through TransitionReady. It is not used for any commercial purpose.

For California districts: Our AB 1584-compliant data privacy agreement is available upon request and is required before any district is activated on the platform. Contact us at the information in Section 16.
Section 10

Data Storage & Security

Student data is stored in Supabase, a secure cloud database platform hosted on AWS infrastructure in the United States. All data is encrypted at rest and in transit using industry-standard encryption (AES-256 at rest, TLS 1.2+ in transit).

Uploaded files — work samples and supporting documents (letters of recommendation, awards, certifications) — are stored in a private, access-controlled Supabase Storage bucket. Files are never publicly accessible: the bucket exposes no public URLs, and every retrieval is an authenticated request checked against the bucket's per-user access rules before any bytes are returned. Access controls on the file bucket are deliberately stricter than the database: each student can access only the files in their own folder. Case manager and district administrator accounts cannot read student files at all — staff see the titles, descriptions, and skills a student writes about a file, never the file itself. Sure Step Education retains narrowly scoped read access to file storage, used solely for technical support and data recovery (for example, restoring a student's file at a district's request).

One category of file flows in the opposite direction, and it is stored in its own separate bucket precisely so the rule above stays intact: a student's accommodation plan (see Section 15c), which a connected case manager uploads for the student to read. Access to it is the narrowest in the application: the student can read their own plan, a case manager currently connected to that student can manage it, and no one else — not district administrators, not other staff — can access the document or the accommodations list at all. Where a student is connected to more than one case manager, each of them has this access. When a case manager's connection to a student ends, their access to that student's plan ends with it.

Authentication is invite-based: accounts can only be created through single-use, expiring invite links issued by authorized staff, and sign-in uses email and password. Passwords are stored only as salted hashes by our authentication provider (Supabase Auth) — Sure Step Education never sees or stores plaintext passwords. A case manager may issue a temporary password for a student on their caseload who is locked out; students can change their password at any time using the self-service reset flow.

Access controls are enforced at the database level using Row Level Security (RLS) policies, meaning database queries are filtered by role before data is returned — not merely filtered in the application layer after retrieval. The same per-user model is applied to the file storage bucket.

Case manager connections and disconnections, and account-lifecycle events, are recorded with timestamps and the identifiers of the users involved. These records cannot be modified through the application interface and are available for compliance review by district administrators (for their district) and Sure Step Education's founder.

In the event of a data breach that affects student data, we will notify affected districts within 72 hours of discovery and cooperate fully with any required notifications under applicable law.

Section 11

Subprocessors

We work with the following third-party subprocessors to operate TransitionReady. Each subprocessor has been evaluated for appropriate data protection terms for education use:

Supabase
Database, authentication, and file storage
Stores all student portfolio data, account information, AI-generated documents, uploaded work-sample files, uploaded supporting documents (letters of recommendation, awards, certifications), and audit logs. Does not store profile photographs, which remain only on the student's device. Hosted on AWS in the United States. SOC 2 Type II certified.
Vercel
Application hosting and delivery
Hosts and serves the TransitionReady web application. Does not store student data. Processes only the HTTP requests necessary to serve pages.
Anthropic
AI document generation
Powers AI-assisted generation of resumes, cover letters, and other documents. Student data submitted for generation is not used to train Anthropic's models per our API agreement. Data is processed transiently and not retained.
Resend
Transactional email delivery
Sends account invite links, sign-in links, password reset emails, and messages submitted through the feedback form (Section 15d). Receives only the recipient email address and email content necessary for delivery. Does not receive portfolio data.

We do not use Google Analytics, Facebook Pixel, or any third-party behavioral tracking or advertising technology.

Section 12

Data Retention & Deletion

We retain student data only as long as necessary to provide TransitionReady services or as required by law.

Active accounts: Student portfolio data is retained while the student has an active account and their district has an active contract with Sure Step Education.

Upon district contract end: When a district's contract with Sure Step Education ends, student data associated with that district will be deleted within 60 days unless the district requests a shorter or longer retention period in writing.

Upon deletion request: When a student or parent submits a deletion request, the district administrator will execute the deletion. This permanently removes the student's profile, portfolio content, case manager suggestions, and student assignment records. Deletion is logged in the audit trail. The audit log entry itself is retained for compliance purposes but contains no student PII.

Case manager contact directory: The private post-graduation contact records described in Section 4 are owned by the case manager and are designed to outlive the student account, so they are not automatically removed when the portfolio account is deleted. A student, parent, or district may request deletion of these contact records as well; on such a request the case manager or district administrator will remove them.

Backup retention: Supabase maintains encrypted backups for up to 7 days. Deleted data may persist in backups for up to 7 days before being permanently purged.

Section 13

AI-Generated Content

TransitionReady uses the Anthropic API to provide three categories of AI-assisted features:

Important: Student data sent to the Anthropic API is not used to train or improve Anthropic's AI models. This is governed by our API agreement with Anthropic. The data is processed transiently — it is used to generate the requested output and is not stored by Anthropic beyond what is necessary for the API response.

Models used: Document generation currently uses Claude Opus 4.7, and writing polish currently uses Claude Haiku 4.5, both accessed through the Anthropic API. We may move to a newer model of comparable or better capability; the protections described in this section apply regardless of which model is in use.

Data minimization: We send only the fields necessary for each feature. For writing polish, we send only the text being checked — never the student's name, school, district, grade, disability status, IEP content, or any surrounding portfolio context. For document generation, we send only the portfolio fields the document requires; the student's name is included only where it must appear in the generated document itself (such as a cover letter heading and signature). We never send school or district identifiers, grade level, disability status, IEP content, or any other special education data to the AI service. For Interview Practice, we send only the practice question, the text of the student's spoken answer as transcribed on their own device, and the delivery measurements for that answer — never the student's name, school, district, grade, disability status, IEP content or any other portfolio information, and never audio.

Scope of writing polish: The writing polish feature is constrained by system instructions to correct only spelling, grammar, and punctuation. It is instructed not to change the student's voice, vocabulary, tone, sentence structure, or content. The student's pre-correction text is not retained by Sure Step Education once the student either accepts or rejects the suggestion — only the final portfolio text is stored. A flag is retained on each field indicating whether the student used the polish tool on that field, which case managers may see as a small "AI-polished" badge.

Student control: All AI-assisted features are student-initiated. No correction or generated content is ever applied to a student's portfolio without the student's explicit action. Students retain full control over whether to use, keep, edit, or delete AI-assisted content.

Section 14

Interview Practice (Microphone Use)

Interview Practice lets a student rehearse interview questions out loud and receive feedback on how they answered. It is optional; nothing else in TransitionReady depends on it.

The recording never leaves the student's device. Audio is captured by the browser, analysed on that same computer, held in memory only long enough for the student to play their answer back, and then discarded. It is never uploaded to Sure Step Education, never sent to any third party, and never written to storage. No voiceprint, voice template, or other biometric identifier is created or retained at any point.

Speech is converted to text on the student's own device. The software that does this is served from TransitionReady and runs inside the student's browser. No audio is transmitted in order to perform it.

That text is sent to our AI partner to write the student's coaching. We send the practice question, the transcribed answer, and the delivery measurements — never the student's name, school, district, grade, disability status, IEP content, or any other portfolio information, and never audio. As with every other AI feature in TransitionReady, this data is not used to train any model and is not retained beyond the request (see Section 11, Subprocessors, and Section 13).

What is saved is the text of the student's answer, the coaching they received, the delivery measurements — for example volume consistency, number of long pauses, an approximate count of hesitation sounds, and answer length — and the questions practised, the date, and the points earned. The text is saved so a student can reread what they said alongside the advice about it before practising the question again. Audio is never saved. Nothing saved can be used to reconstruct or identify a voice.

A transcript is a machine transcription, not a verbatim record. Speech recognition makes mistakes, particularly with accents, quiet speech, background noise, and names. Saved answers are labelled as machine transcriptions everywhere they appear, including in the case manager's view, and should not be treated as an exact record of what a student said.

Who can see it: the student, and the case manager they have connected to their portfolio. Interview Practice awards points for practising, returning, and applying feedback; it produces no score or rating of a student's speech, ability, or performance, and nothing it stores is an assessment. It is not used for evaluation, grading, or eligibility decisions of any kind.

Student control: a student can delete any individual practice session, or their entire practice history, from within the tool. Only the twenty most recent sessions are kept in any case. All practice data is removed when the student's account is deleted (see Section 12).

Microphone access is requested only when the student opens Interview Practice, and the browser will ask permission. Declining means the feature cannot run; nothing else in TransitionReady is affected.

If a student is prompted twice about inappropriate language in a single session, the session ends and a request to check in is sent to their case manager, including the machine transcription. This is a prompt for a conversation, not a disciplinary finding, and a case manager can turn the check off for a student for whom it is not appropriate.

Section 15

Career Explorer

Career Explorer lets a student work through a series of everyday scenarios — pairs of activities, choosing which they would rather do — and see careers that line up with the pattern of their choices. It is optional; nothing else in TransitionReady depends on it.

It is not a test and it is not an assessment. There are no right answers, no timer, and no result that describes a student's ability, aptitude, or suitability for anything. What it produces is a list of careers to look at, and it is not used for evaluation, grading, placement, or eligibility decisions of any kind.

Nothing a student chooses is sent anywhere. The scenarios and the career information are files served from TransitionReady, and the matching runs entirely inside the student's own browser. No part of Career Explorer contacts our AI partner or any other third party, and no responses are transmitted for scoring.

What is saved is the student's choices, the date they finished, and the careers they were shown. This is stored on the student's own portfolio record, under the same protections as the rest of their portfolio described in Section 10. If a student chooses to add a career to their portfolio goals, that career appears in their portfolio like anything else they entered themselves.

Who can see it: the student, and the case manager they have connected to their portfolio — the same access described in Section 6. Sure Step Education staff do not see individual responses.

Where the career information comes from: pay and job-growth figures are drawn from published U.S. Bureau of Labor Statistics data, and the interest information from the U.S. Department of Labor's O*NET database. These are public reference data compiled in advance and shipped with the application; using Career Explorer does not send a request to either source, and neither receives any information about the student.

Section 15b

Money Trail

Money Trail is a game. A student plays roughly ages eighteen to forty of their own future — where they live, how they get to work, whether they train for the job they want — and sees what those choices add up to. It is optional; nothing else in TransitionReady depends on it.

Nothing is transmitted anywhere. The entire simulation runs inside the student's browser. There is no AI involved, no microphone, no camera, and no third party of any kind. The game can read its screens aloud using the browser's own built-in voice; that also happens entirely on the device — nothing is recorded and nothing leaves it. The game also makes small sounds — a spin, a point, a badge. The browser makes them on the device. No sound file is downloaded and nothing is recorded. The only network requests it makes are for TransitionReady's own data files, which are the same for every student and contain no information about anyone.

What is saved is a run's starting conditions and the choices the student made in it. A saved run also holds the surprise cards the run dealt, the two point totals those choices earned, whether either total beat that student's own earlier best, whether the run was ended before age forty, the date the run was started and the date it was finished, and the net worth it ended with, which the game prints beside the run in the list of past runs. Nothing else about the run is kept. The simulation is deterministic, so the money month by month, the outcomes and the whole recap are recalculated on demand from the saved choices rather than stored. Only the ten most recent runs are kept. A student can delete any run, or all of them, from inside the game.

The credit score in the game is simulated. Money Trail shows a credit score that rises and falls with the choices made inside the run. It is computed by the game from the run's own pretend loans and payments — it is not a real credit score, it is not obtained from any credit bureau, and nothing about a student's real finances is asked for or used. Like everything else in a run, it is recalculated from the saved seed and choices and is never stored on its own.

The pictures are drawn in the page. Money Trail's scenes use simple drawings built into the site. No image, font or script for Money Trail loads from a third party, and no request leaves the device when a screen is shown.

Who can see it: the student, and the case manager they have connected to their portfolio — the same access described in Section 6. It is stored on the student's own portfolio record, under the protections in Section 10.

Money Trail is not an assessment and is never a grade. The game awards points for decisions and experiences inside a run — putting a month's costs aside, getting covered, keeping a card paid on time, writing a will, and the things a life is actually for. Points are never a grade and they never compare one student to another: the only comparison the game makes is a student's own run against their own earlier runs on the same road. Not one point comes from how much money a run ended with, and how much money a student ends a run with still has no effect on anything the app records about them — including their progress meter, which counts only whether a run was finished. Two students who finish a run contribute exactly the same amount whether one ended wealthy and the other ended in debt. The points are stored only as part of the run itself, on the student's own portfolio record; they are calculated in the browser from the run's own choices, and nothing new leaves the device. Money Trail is not used for evaluation, grading, or eligibility decisions of any kind, and a student cannot do badly at it.

Where the numbers come from: wages are the published U.S. Bureau of Labor Statistics figures already used by Career Explorer. Tuition, loan and mortgage rates, insurance costs and average household spending are drawn from named public sources — among them the U.S. Department of Education, the Federal Reserve, the IRS, the California Legislative Analyst's Office, KFF and the Bureau of Labor Statistics — and every figure in the game carries its source in the data file. These are public reference data shipped with the application; playing the game does not send a request to any of them.

The scenarios are fiction. The events in a run — a car repair, a month that does not add up, a small inheritance — are story beats chosen to be plausible, not predictions about the student or claims about what will happen to them.

Section 15c

Self-Advocacy

This tool is not currently available in TransitionReady — it has been withdrawn while we continue developing it. No accommodation plans can be uploaded and no practice conversations occur while it is withdrawn. This section is retained so the practices below are on record for when the tool returns.

Self-Advocacy is a tool where a student learns what is in their own accommodation plan, in plain language, and practises asking for their accommodations out loud. It is optional; nothing else in TransitionReady depends on it.

The accommodation plan is provided by the student's case manager, for the student. A connected case manager can upload the plan document and type the list of accommodations from their dashboard. This is disability-related information, and its access is the narrowest in the application: the student can read their own plan, a case manager currently connected to that student can manage it, and no one else — including district administrators — can access the document or the list at all. Where a student is connected to more than one case manager, each of them has this access. The document is stored in its own private storage bucket, separate from student-uploaded files, under the protections in Section 10. If a case manager's connection to the student ends, so does their access.

The plain-language explanations are not AI. The tool matches common accommodations to a fixed, human-written dictionary of what each one means and how a student might ask for it. An accommodation the dictionary does not recognize is shown as written, with a prompt to ask the case manager about it — the tool never guesses at what a student's rights are.

The practice conversations use AI, on the student's action only. When a student chooses to practise asking, the text they typed, the practice situation they picked (for example "before a test"), and the wording of the accommodation they chose are sent to our AI provider (Anthropic) through the same protected route as every AI feature in this application (see Section 13) to generate coaching feedback. No name, no student identifier, and no plan document is included in the request. The feedback and the student's practice text are shown once and not stored — what is saved is only that a practice was finished, when, and which accommodation and situation were chosen.

Self-Advocacy is not an assessment and produces no score. The coaching feedback is never graded, stored, or shown to staff, and the student's progress meter counts only what the student did — accommodations they marked as understood and practices they finished — never how well anyone asked. Marking "I use this" or choosing not to use an accommodation has no effect on anything the app records.
Section 15d

Feedback Form

Every signed-in student and staff member can open a “Send feedback” link and tell us what is broken, confusing, or missing. It is entirely optional, it is never required to use any part of TransitionReady, and choosing not to use it has no effect on anything the application records.

Feedback leaves the application and arrives as ordinary email. This is the one place in TransitionReady where something a user writes is delivered to a person by email rather than stored inside the protected database. Messages are delivered through Resend (Section 11) to Sure Step Education's founder. Because it is email, it is not covered by the database protections described in Section 10, and it is retained in that mailbox rather than under the deletion schedule in Section 12.

Because of that, the form is built to carry as little as possible. Before anyone types, the form states in plain words that they should not include a student's name or personal details. Only five things are transmitted: the message the person wrote, the category they picked, the name of the tool they were using, the page address, and their browser version. The sender's own email address is included so that we can reply to them.

No portfolio data can travel with a feedback message. The application decides what accompanies the message from a fixed list of permitted fields, so no student identifier, name, portfolio content, assessment answer, accommodation, or uploaded file can be attached to a report — whether by accident or by a future change to the form. A person can still type anything they choose into the message box, which is why the warning above the box asks them not to.

Only signed-in users can send feedback, and a sender may send one message per minute. We use feedback to fix and improve the application. We do not use it to evaluate any student, we do not add it to any student's record, and we do not share it with a student's district.

Section 16

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will update the effective date at the top of this policy and notify active district administrators by email.

Continued use of TransitionReady after the effective date of any update constitutes acceptance of the revised policy. If you have questions about any changes, please contact us at the information below.

Section 17

Contact & Requests

For questions about this Privacy Policy, to exercise FERPA rights, to submit a data deletion request, or to request our AB 1584 data privacy agreement, contact:

Sure Step Education

Designated Responsible Individual for Privacy Compliance

Nicholas Crabtree
nick@surestepeducation.com

We respond to privacy inquiries within 45 days.