โ† Back to home
๐Ÿ”’

Privacy Policy

ShortHand is built by a teacher who understands how sensitive student data is. This policy explains exactly what we collect, why, and how we protect it.

Last updated: September 2026

The short version
  • Classroom records come from you. You type or import student notes, parent contacts, accommodations, and related classroom information. We also store the account information needed to sign you in.
  • We do not use data for advertising tracking. ShortHand does not sell student data, does not use it to advertise, and does not use advertising identifiers to track you.
  • Web analytics stay on the web. The website and web app use analytics and crash-reporting tools described below. Those tools are turned off in the native iOS app.
  • Your data is encrypted. All data is stored on Supabase, which is SOC 2 Type II certified and encrypts data at rest with AES-256. Data in transit is protected by HTTPS.
  • Other teachers can't see your students. Row-level security means every query is scoped to your account only: no other teacher can access your data. As the operator, I technically have access to the database, but I commit to never looking at your data unless you ask me to (for example, to help fix a problem).
๐Ÿ‘ค
Who This Applies To
ShortHand is a documentation tool for teachers. When you create an account, you are the user. Student data, parent or guardian contact information, and any IEP, 504, RTI, or other accommodation information you enter is entered by you, the teacher, and is stored under your account only. Students do not create ShortHand accounts.
๐Ÿ“‹
What We Collect
Your account: Your email address and, if you use email sign-in, your password (managed securely by Supabase Auth). ShortHand also supports Google sign-in and Sign in with Apple. Sign in with Apple is available in the native iOS app and may provide an Apple Private Email Relay address instead of your personal email. We store your name when Google, Apple, or your profile provides it.

Billing and subscription information: If you buy ShortHand Pro or another paid feature on the website, Stripe processes the payment. We do not store your card details ourselves. We store subscription or entitlement status and Stripe's reference IDs for your account. The native iOS app does not sell subscriptions or other in-app purchases. If you already have a Pro subscription or other entitlement from the web, the iOS app can still read that status and give you the matching features.

Student data you enter: Information you type or import about your students, which may include names, class periods, notes, behavior tags, goals, attendance, shoutouts, birthday information, calendar-related data, photo URLs, and parent communication logs.

Parent and guardian contact data: Parent or guardian names, email addresses, and phone numbers, when you enter or import them so you can use parent-communication features.

Disability-related and special-education information: If you enter IEP, 504, RTI, or other accommodation information, that is stored with the student record. This can include disability-related information you choose to record for your own teaching and documentation.

Google Classroom (optional): If you connect Google Classroom, we access your course list and student names, emails, and profile photos to help you import your roster. We store a token to keep you connected. You can disconnect at any time.

Optional website emails: If you leave your email on getshorthandapp.com to request a resource or restore a purchase, we store that email to send what you asked for.

AI features: Some features use AI to help with drafting, summaries, import, and similar tasks. See the โ€œHow ShortHand Uses AIโ€ section below for full details.
๐Ÿค–
How ShortHand Uses AI
Some ShortHand features can send the information needed for that request to third-party AI providers. ShortHand uses OpenAI as the primary provider, with Groq as an approved fallback if OpenAI is temporarily unavailable. Both providers are configured so your data is not used to train their models.

What may be sent depends on the feature you use. That can include notes, first names, and other content needed for the selected feature. Some flows may also include parent or guardian information, accommodation information, goals, or birthday-matching data. ShortHand does not limit AI input to first names only.

In the native iOS app, AI consent is explicit and fails closed. Before AI data is shared, ShortHand asks for your permission and names the providers. If you decline, that request is not sent. You can withdraw consent later in Settings, and no further AI requests are sent until you allow them again. If the approved providers are unavailable, the AI request is not sent to another unapproved provider.

We never send student or parent data to AI for advertising, and we don't sell your data.
๐Ÿ“Š
Web Analytics and Crash Reporting
The ShortHand website and the web app at app.getshorthandapp.com use Google Analytics (GA4) and Vercel Analytics to understand how pages and features are used. The web app also uses Sentry for crash reporting, and first-party usage analytics and marketing attribution so we can see which features are used and how people found ShortHand. These tools may use cookies or similar identifiers. They are used to operate and improve the service, not to advertise to students or parents.

These analytics and crash-reporting systems are web behavior. They are not used in the native iOS app. See the next section.
๐Ÿ“ฑ
The Native iOS App
The native iOS app stores the same classroom and account data you enter, but it is set up more tightly than the web app:

Google Analytics, Vercel Analytics, Sentry, and first-party usage analytics and attribution are turned off.

The app does not write presence records or AI token-usage records.

The in-app voice dictation controls are hidden.

There is no advertising SDK, no Identifier for Advertisers (IDFA) tracking, no location collection, no access to device contacts, and no access to the iOS photo library.

There is no in-app purchase flow. Existing subscription or entitlement status from the web may still be read so Pro features you already have continue to work.

ShortHand does not use data for advertising tracking on iOS or anywhere else.
๐Ÿšซ
What We Don't Do
We do not sell your data or student data to anyone. Ever.

We do not use student data for advertising.

We do not use data for advertising tracking, including IDFA-based tracking.

We do not share your data with third parties except the services required to run ShortHand, listed in Third-Party Services below.

No other teacher can access your students' information. As the operator, I can access the database directly if needed for support, but I will never do so without your request.
๐Ÿ”
How We Protect Your Data
All student data is stored on Supabase, which is SOC 2 Type II certified and encrypts all data at rest with AES-256.

All data is stored with Row Level Security (RLS) enabled, meaning every query is scoped to your account only: no other teacher can see your data. As the operator, I technically have access to the database, but I commit to never looking at your data unless you ask me to (for example, to help fix a problem).

All communication between the app and our servers uses HTTPS encryption.

API endpoints require authentication. Your session token is verified on every request.
๐Ÿ—‘๏ธ
Your Rights
You can delete all your data at any time from within the app (Settings โ†’ Danger Zone โ†’ Factory Wipe).

You can permanently delete your account, your notes, and your student data from within the app (Settings โ†’ Danger Zone โ†’ Delete My Account). Billing and subscription records may be retained after deletion where needed for accounting, disputes, fraud prevention, or legal compliance; see our account deletion page for details.

You can export a copy of all your data at any time (Settings โ†’ Your Data โ†’ Export My Data).

In the native iOS app, you can turn AI features off in Settings. After you turn them off, ShortHand does not send further AI requests until you allow them again.

You can disconnect Google Classroom at any time, which removes your stored Google tokens.

If you cannot sign in to the app, you can also request account deletion by emailing info@getshorthandapp.com from the email address associated with your ShortHand account. For account security, we may ask you for additional verification before processing the deletion. See all account deletion options โ†’
๐ŸŒ
Third-Party Services
ShortHand uses the following third-party services to operate:

Supabase: database and authentication (privacy policy)
Stripe: payment processing for web purchases and Pro subscriptions (privacy policy)
OpenAI: primary AI language model processing (privacy policy)
Groq: fallback AI language model processing, used if OpenAI is temporarily unavailable (privacy policy)
Vercel: hosting, and web analytics on the website and web app (privacy policy)
Google: Google sign-in and optional Google Classroom integration (privacy policy)
Apple: Sign in with Apple in the native iOS app, including Apple Private Email Relay when you hide your email (privacy policy)
Google Analytics: website and web-app analytics. Not used in the native iOS app (privacy policy)
Sentry: crash reporting for the web app. Not used in the native iOS app (privacy policy)
Resend: transactional email, such as purchase-restore messages (privacy policy)
Upstash: rate limiting for API routes (privacy policy)
๐ŸŽ“
Student Privacy Pledge
ShortHand follows the principles of the Student Privacy Pledge. This means:

We will never sell student data to anyone, for any reason.

We will never use student data for targeted advertising, not to students, parents, or anyone else. ShortHand does not use data for advertising tracking.

We will never share student data with third parties beyond the services required to operate the app.

We will always allow teachers to delete their student data at any time.
๐Ÿซ
For Schools & Districts
Need a Data Processing Agreement (DPA) for district approval? View our DPA โ†’

Canadian teachers: Our DPA includes a section addressing PIPEDA and provincial privacy laws (BC FIPPA, Quebec Law 25). Data is stored on US servers. Schools with data residency requirements should contact us before signing up.
โœ‰๏ธ
Contact
Questions about this policy or your data? Reach out anytime:

info@getshorthandapp.com

We're a small team and we'll respond personally.