1. Who we are and how to reach us
Instupituous, LLC (California entity B20260295390), doing business as Beehave. Questions about this policy, a request to review or correct information, or a report of a security concern: privacy@beehaveur.com.
2. The information Beehave holds, and why
Staff accounts (collected from you)
- Name, work email, role, and organization — to sign you in and decide what you may see.
- Optional profile details you enter: phone, photo, home address (used only to calculate mileage reimbursement, if your organization uses that feature).
- Sign-in details: a password hash if you use a password, or the identity Google confirms if you sign in with Google. We never see your Google password.
- Technical records: the pages you open and the actions you take inside Beehave, for security and support; your browser type and screen size if you send us feedback.
Student education records (entered by district or agency staff)
- A student's name, grade, school, placement, and parent or guardian contact details.
- Behavior goals, session data, observations, assessments (including questionnaires answered by parents and staff), behavior intervention plans, and uploaded documents such as an IEP.
These are education records under FERPA. They belong to the school district, which controls them. Beehave holds them only as the district's service provider (a “school official” under 34 CFR 99.31(a)(1)(i)(B)) and uses them only to provide the service the district contracted for.
Respondents to an assessment form
A parent or staff member who is emailed a link to a questionnaire enters their answers and their name. The link is single-use and expires. The form shows the student's first name only.
3. Children
Beehave has no child-facing features. Children do not create accounts, sign in, or submit information. Information about children is entered by adults employed by the district or its contracted agency. The Children's Online Privacy Protection Act (COPPA) governs information collected online from children; it does not reach information about children entered by adults (FTC COPPA FAQ, A.8). If Beehave ever adds a feature that a student uses directly, we will obtain the school's authorization as the FTC's guidance for schools describes, give the school the notice a parent would receive, and honor the school's right to review and delete a child's information — before that feature is turned on.
4. What we will never do
- We do not sell personal information. We do not sell, rent or trade student information.
- We do not use student information for targeted advertising, and Beehave carries no advertising.
- We do not build a profile of a student for any purpose other than the district's own educational purposes.
- We do not use student information to train or develop any artificial-intelligence model, and our AI vendor is contractually barred from doing so.
- We do not place analytics, advertising or tracking scripts on Beehave. There are no third-party cookies and no cross-site tracking.
- We do not disclose student information except to the subprocessors listed below, under written terms at least as protective as our agreement with the district, or as the law requires.
5. AI features
Beehave has three optional features that use a large language model (Anthropic's Claude) to draft text a clinician then reviews and signs: a session-note draft, a narrative for a functional behavior assessment, and a draft behavior intervention plan from an IEP. These features are off for every district until that district gives written consent (the California Student Data Privacy Agreement, Exhibit G). When they are on, the student's name is replaced by a code before anything is sent, the vendor does not use the data to train models, and we request zero data retention from the vendor. A clinician remains the author of record of every document.
6. Who can see student information
Only staff of the district that owns the record and of the agency the district has contracted to serve that student, and only what their role and assignment justify: an aide sees the strategies for the child in front of them, a clinician sees the assessment. Every account is invitation-only. Reads of assessment narrative are logged. Beehave staff access a district's data only to provide support, only through an audited “view as” session, and never for any other purpose.
7. Subprocessors
We use the following service providers to run Beehave. Each is under a written data-protection agreement. The current list, with each one's purpose and region, is always at /subprocessors; we give districts notice before adding one.
- Neon (Databricks) — PostgreSQL database — all application data.
- Railway — Application hosting (Next.js server, logs).
- AWS S3 — Document storage: BIP/FBA PDFs, uploaded student documents, feedback screenshots.
- Anthropic (Claude API) — Drafting session notes, FBA narrative, BIP text from student data.
- Resend — Transactional email: assessment links to parents, invitations, timesheet PDFs, digests.
- Stripe — Billing (organization contacts only; no student data).
- Google Identity (OAuth) — Staff sign-in.
- GitHub — Source hosting; one Actions workflow (reap-sessions) calling the production reaper.
- OpenStreetMap / OpenTopoMap tile servers; US Census geocoder; OSRM router — Map tiles for school/site maps; staff home-address geocoding; route distance.
8. Security
Data is encrypted in transit and at rest. Accounts are invitation-only; administrative accounts sign in through Google with two-step verification; sessions expire; failed sign-ins are throttled. Access is limited by role and by assignment, tested by an automated cross-organization check on every build. A written information-security program, an incident-response plan and a tested backup-and-restore procedure are maintained. Details for reviewers are at /security.
9. How long we keep information
| Record | Kept |
|---|---|
| Student records, goals, sessions, assessments, plans | For the life of the district's agreement; deleted within 30 days of the district's instruction at the end of it, with a written certification of deletion |
| Staff accounts | While the person is an active member of an organization, plus 30 days |
| Access and audit logs | 6 years |
| Feedback screenshots and diagnostic details you send us | 30 days |
| Assessment-form links and respondent details | 90 days after the form is submitted or expires |
| Email at our email provider | 30 days (provider retention) |
| Text sent to the AI provider | Not retained when zero data retention is enabled; otherwise deleted by the provider within 30 days |
10. Your rights, and a parent's rights
Staff may review and correct their own account details in Settings. A parent or eligible student who wants to review or correct a student record asks the school district; the district owns the record, and Beehave provides the district whatever it needs to answer within the time FERPA allows. A district may instruct us to delete a student's records or its whole account at any time.
11. If something goes wrong
If we learn of unauthorized access to student information, we notify the affected district without undue delay and within the time our agreement with it sets, with what happened, what information was involved, and what we are doing about it, so the district can notify parents as the law requires.
12. Do Not Track, and cookies
Beehave uses only the cookies needed to keep you signed in and to remember your own display preferences. Because we do no cross-site tracking, a browser's Do Not Track signal changes nothing: we already do not track you. No other party collects information about you across sites through Beehave.
13. Changes to this policy
We post changes here with a new effective date and version, and we notify each district in writing before a change that affects student information takes effect. Material changes to the terms under which we hold a district's data require that district's agreement.
14. California
Beehave is designed and marketed for K-12 school purposes and is an operator under the Student Online Personal Information Protection Act (Cal. Bus. & Prof. Code §22584). Our agreements with districts carry each term required by Cal. Ed. Code §49073.1. This policy is posted under Cal. Bus. & Prof. Code §22575.