Privacy Policy
Last updated: September 26, 2026
Overview
AdvoKid helps adults review IEPs and related educational records. These records can contain sensitive information about children and families. This page describes the information used by the service, the providers involved, and the limits of automated redaction and deletion. Upload only records you are authorized to share.
Information You Provide
- Uploaded IEP documents and related assessments, including their contents and filenames.
- Questions, conversation messages, and feedback you submit.
- An email address if you choose to have a report emailed to you; first and last names are optional.
- The state you select for legal-source context. This selection and the cited source version are included in your report.
- Your product-update choice and, if you opt in, a record of that consent.
You can download your report without providing an email address or subscribing to updates.
How Documents Are Processed
- Upload: Files are sent to the AdvoKid server and stored in encrypted form while awaiting processing.
- Text extraction: Original, unredacted documents are sent to Microsoft Azure Document Intelligence for optical character recognition (OCR). This provider receives the original document contents, including any personal information they contain. If a file is damaged, AdvoKid may first repair it on its own server, or send individual page images to the same service.
- Redaction: Extracted, unredacted text is sent to Microsoft Azure AI Language to identify personal information. AdvoKid applies those detections and additional text patterns to produce redacted text.
- Backup processing when a service is unavailable: If the OCR service cannot read a document, AdvoKid first tries to read the PDF's built-in text on its own server, with no outside service. If that is not possible, original page images are sent to the Azure OpenAI service (Microsoft) in separate requests solely to transcribe them with identifiers replaced. If the Azure AI Language service is unavailable, original extracted text is sent to Azure OpenAI solely to list identifiers, which AdvoKid then removes. These requests carry no conversation history, and AdvoKid does not store their inputs; Microsoft's own service terms govern any provider retention. In these cases page images are not used for analysis.
- Analysis and translation: Redacted text and, when visual analysis is used, redacted page images are sent to Azure-hosted AI services for analysis. AI services also process text for translation when needed, including report reading copies in your selected language. Questions and relevant analysis context are also processed by AI services when you use the conversation feature.
Service monitoring: When a step fails or a backup is used, AdvoKid records and emails its team a technical notice (error codes, counts, sizes and times). These notices never include file names, document contents or anything you type.
Automated redaction can miss identifiers. Redacted text is not guaranteed to be anonymous. Names, unusual identifiers, or details that identify a person indirectly may remain in text sent for analysis or translation and may appear in generated results. Review results before sharing them.
Browser Session and Uploaded Files
The active browser session holds document details, analysis results, and conversation history in memory. Clearing the session resets that browser state. Downloaded PDFs, copies saved elsewhere, and emailed reports remain wherever you saved or received them.
Uploaded server files have a separate lifecycle. The processing endpoint attempts to remove that session's uploaded files when processing finishes or fails. A background cleanup also checks at server startup and every five minutes while the server is running for abandoned encrypted uploads with no activity for at least one hour. Active processing refreshes that activity window. This is best-effort cleanup, not a guarantee of deletion at an exact time: downtime, storage errors, or unexpected files can delay removal. Closing the browser or clearing the browser session does not itself delete server files.
Cloud and email providers process information separately from the browser session. Resetting a session does not remove provider records, delivery logs, or copies in an email inbox. Provider retention depends on the service and its configuration.
Feedback submitted through the service is processed by AI and may be saved separately on the server for product follow-up. Avoid including names, contact details, or sensitive educational records in feedback. Clearing the browser session does not remove saved feedback.
Optional Report Email and Product Updates
If you request a report by email, AdvoKid sends your address, the report PDF, and any supplied greeting name to Resend, our email delivery provider. The PDF may contain sensitive educational information. Requesting that email does not subscribe you to marketing.
A separate, unchecked option lets you request AdvoKid product updates, new features, and future paid offerings. Only affirmative opt-ins from this form are added to the product-update contact list. For those opt-ins, we retain your email address, optional name, and the consent timestamp, wording, version, and source in Azure Table Storage, and add your contact details to the Resend audience.
Product-update consent records are separate from document sessions and remain after a browser session is cleared. You can unsubscribe from product-update emails using the unsubscribe link. To request removal of retained contact information, contact [email protected].
Analytics and Browser Storage
The site uses a browser-stored preference for optional analytics. If you accept, limited feature-usage counts are sent to Azure storage. When you accept optional analytics, Google Analytics receives allowlisted page addresses and aggregate usage events. Search-provider referrers are reduced to known domain names; search queries, document contents and arbitrary referring URLs are excluded. Automatic enhanced measurement is disabled. Our application analytics events exclude report contents, email addresses, names, document filenames, and session identifiers. Your analytics choice is separate from product-update consent.
Your preference is stored in local browser storage. You can clear this site's browser storage to see the consent choice again. Browser and network information is also used by hosting and delivery services to serve requests.
Service Providers and Security
AdvoKid uses Microsoft Azure for document processing, AI services, and storage; Resend for requested report emails and opted-in product updates; and, when enabled, Google Analytics for optional usage analytics. These services receive the information described above. Processing by these providers is not the same as processing only on your device.
Encryption of uploaded files and automated redaction reduce some risks, but they do not guarantee confidentiality or removal of every identifier. This description is not a certification of compliance with education, health, or privacy laws.
Children's Information
AdvoKid is intended for adults, including parents, guardians, and authorized advocates. Uploaded records may contain children's information, which follows the processing steps described above. Document contents and analysis are not included in the product-update contact record.
Questions, Deletion Requests, and Policy Updates
For questions about processing or requests to access, correct, or delete retained information, contact [email protected]. Describe the request without attaching sensitive records unless needed. Clearing a browser session alone does not submit a server or provider deletion request.
We may update this page as the service changes. The date above identifies the latest revision.
