← Back to BehaviorLog Pro
Effective Date: April 10, 2026 | Material update effective: July 10, 2026 | Last Updated: September 4, 2026
1. Introduction
BehaviorLog Pro is a web-based behavior tracking and analysis application developed by Sure Step Education for use by special education professionals in K–12 school settings. The application enables teachers to record student behavioral data (frequency, duration, intensity) during classroom observations and to write the behavior goals tracked for their students, and enables licensed behaviorists and school psychologists to conduct structured behavioral observations, administer functional assessment screening tools (QABF, FAST), score assessment results, manage behavioral goals, and generate Behavior Intervention Plans (BIP) and Functional Behavior Assessments (FBA). Access is organized by school district and by user role (teacher, behaviorist, school psychologist, district administrator, and Sure Step administrator), as described in §7.5–§7.6.
BehaviorLog Pro is accessible at blp.surestepeducation.com and is designed exclusively for educational purposes.
This Privacy Policy describes how Sure Step Education collects, uses, stores, and protects information in connection with BehaviorLog Pro. This policy is designed to comply with:
- The Family Educational Rights and Privacy Act (FERPA), 20 U.S.C. § 1232g
- The Children's Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–6506
- The Student Online Personal Information Protection Act (SOPIPA), Cal. Bus. & Prof. Code § 22584
- California Education Code § 49073.1 (AB 1584)
2. Definitions
Local Educational Agency (LEA): A school district, county office of education, or charter school that contracts with or authorizes the use of BehaviorLog Pro.
Pupil Records: Any information directly related to a student that is maintained by the LEA or by a party acting for the LEA, as defined under FERPA and California Education Code § 49061.
Personally Identifiable Information (PII): Information that can be used to distinguish or trace an individual student's identity, including but not limited to: name, date of birth, student identification number, behavioral records, and assessment data.
Operator: Sure Step Education, the entity that operates BehaviorLog Pro and processes pupil records on behalf of the LEA.
Third Party / Provider: Any external service that processes data on behalf of the Operator in connection with BehaviorLog Pro, as referenced in Education Code § 49073.1.
3. Information We Collect
3.1 Student / Pupil Records
- Student first name, last name
- Date of birth
- Student identification number
- Grade level
- School and district name
- Behavioral observation data: frequency counts, duration measurements, latency measurements, prompt counts (the number of adult prompts delivered before or during a behavior, recorded live or in manual data entry), and — in organizations that enable it — intensity ratings. Which of these are collected depends on the organization's configuration; an organization may switch a measure off, after which no new values of that kind are recorded
- Severity levels, in organizations that enable them: where a behavior has been given levels, each recorded occurrence also carries the level it reached. This is recorded by the choice the staff member makes at the moment of observation, not derived, and it is separate from the intensity ratings described above. Occurrences recorded before a behavior was given levels carry no level, and are reported as carrying none rather than being assigned one
- Severity level definitions: the wording a student's team writes to describe what each level of a behavior looks like for that student. This is staff-authored text about an identified student, held on the behavior record and visible to authorized staff recording that behavior, and it is shown in reports and charts alongside the counts for each level
- Class period, location and course/subject associated with an observation, and the observation's date and time. An administrator may additionally record the clock times each class period runs, which is organizational schedule configuration and contains no student information; where it is set, it is used to describe when incidents occur (for example "10:45am–11:30am, Period 3") in reports and in the optional AI summaries described in §6.3
- De-identified goal templates, in organizations that enable the Goal Bank feature: when a staff member explicitly chooses to save a goal for team reuse, the goal's text is stored with the student's name replaced by a placeholder before it leaves the device; templates contain no student identifiers
- Days marked as absent, in organizations that enable it: a staff member may mark a date as one on which the student was not present, so that a day with no behavioral data is recorded as an absence rather than left ambiguous in progress reporting. Only the date and the fact of absence are stored — no reason for the absence, no attendance code, and no health or medical information. This is not an attendance record of the kind an LEA maintains for reporting purposes, and it is not reconciled against one
- Behavior Emergency Reports, in nonpublic-school organizations, and in any other organization for which Sure Step Education has specifically enabled the feature at that organization's request: where a behavioral emergency occurs, a staff member may file a formal report of it. This is a distinct record from the routine event-log entries described below and in §7.1, and it is retained under §11.1 rather than being deletable by staff. A report records:
- the student's name, date of birth, and — where the organization has recorded one — the student identifier held on the student's record, which may be the statewide student identifier (SSID) used for state reporting; whether the student has a Behavior Intervention Plan; and the date, time and location of the incident
- the staff member filing it, their job title, and the date it was reported; the student's teacher and therapist; and any other staff involved
- the target behaviors that occurred, a written description of what happened before, during and after the emergency, and the intervention strategies attempted
- the names of other students present or involved. The reporting form provides for this, and BehaviorLog Pro records and prints those names as entered. A Behavior Emergency Report about one student may therefore contain the name of another student, and a copy of that report disclosed to a parent under §9, or produced to a governing body, will contain it. Organizations should take this into account in deciding what to enter and to whom a report is released
- physical restraint information, where a restraint was used: the type of hold, the body areas involved, how long the hold lasted, who observed it, and the name and time of the administrator or therapist who approved it
- injuries sustained by staff or students, including the person's name, the area of the body injured, and a description of the injury
- the administrative response: who was notified of the incident and how, the reviewing administrator's decision, whether and when the school district was notified, and the state reporting codes (CALPADS Student Offense and Student Incident Result) recorded for the incident
- the typed signature of the staff member filing the report and of the administrator who reviews and finalizes it, each recorded against that person's authenticated account with the date and time. BehaviorLog Pro does not capture a handwritten or drawn signature
- Antecedent-Behavior-Consequence (ABC) data
- Session notes and observational summaries
- Functional assessment responses (QABF and FAST instruments)
- Assessment scoring results and identified behavioral function categories
- Behavioral goals and progress data, including the baseline statement a staff member may record on a goal to describe the student's starting point (ordinarily transcribed from the student's IEP)
- Linked behaviorist / shared-specialist assignment, and specialist-defined behavior targets and operational definitions
- Where an LEA uses both BehaviorLog Pro and DailyWins (another Sure Step Education product), a student's first name, last name, grade level, and DailyWins record identifier may be received automatically from DailyWins at single sign-on (see §7.7)
3.2 Teacher / Staff Information
- Full name and profile avatar (from Google sign-in, where used)
- Email address (from Google sign-in, or entered at email/password registration)
- Account password — applicable only to email/password accounts, and stored solely as a salted bcrypt hash by our authentication provider; never in plaintext and never accessible to Sure Step Education staff (see §7.2)
- User role (teacher, behaviorist, school psychologist, district administrator, or Sure Step administrator)
- Assigned school district and, where configured, site/school
- Where single sign-on from DailyWins is used, the educator's email address, role, and school are received from DailyWins to sign them in and place them in the correct district (see §7.7)
3.3 Technical Information
- Authentication session tokens
- Browser type and version (standard HTTP headers)
- A local copy of the signed-in user's authorized data is cached in the browser's local storage to support offline use and faster loading; it remains on that device only and is removed when the user signs out
- No IP addresses, device identifiers, or tracking cookies are collected or stored by BehaviorLog Pro
4. How We Use Information
All information collected through BehaviorLog Pro is used exclusively for the following educational purposes:
- Recording and analyzing student behavioral data during classroom observations
- Determining, from the behavior goals written for a student, which behaviors are recorded for that student: when a goal is written, the behavior it names (and its replacement behavior, where the goal specifies one) is added to that student's recording list automatically, and remains there for as long as the goal exists. If the goal names a behavior that is not already in the organization's or the author's behavior library, a behavior record is created locally under that name; a behavior record created this way is associated with the student the goal was written for, and while it remains visible to authorized staff on that student's records, it is not offered as a selectable option when staff configure other students — only behavior definitions deliberately created in the organization's settings are offered organization-wide. Where a staff-created behavior and a built-in or organization-library behavior share the same name, the staff-created one is used and the duplicate is removed from that student's recording list; observations already recorded under the removed duplicate are retained and continue to count toward the goal. Observations recorded before a goal was written are retained and shown alongside it, identified as prior to the goal, and are not counted toward its progress. These determinations are made within the application from data already held; they involve no transmission to any third party and create no new category of information. Removing the goal releases the behavior, which then stays on the recording list until a staff member removes it
- Conducting functional behavioral assessments and screening
- Scoring assessment instruments (QABF, FAST) to identify behavioral functions
- Generating Behavior Intervention Plans, Functional Behavior Assessments, and behavioral goals, using AI-assisted drafting on de-identified data as described in §7.3
- Allowing district administrators to upload standardized BIP, FBA, and goal document templates — containing formatting and section structure only, not student data — to guide AI-assisted document generation for specialists within their district
- Providing behaviorists with aggregated data visualizations and analytics
- Facilitating collaboration between teachers and specialists: a teacher may grant a behaviorist or school psychologist read access to a specific student, and in a nonpublic school or agency the school's own behaviorist and school psychologist have read access to the students at their site (see §7.5); those specialists may define behavior targets and operational definitions that the connected teacher then uses for that student
- Sending assessment forms to respondents (parents, teachers, staff) via email
- Managing user accounts, roles, and access permissions, and organizing access by school district (including district-administrator management of users within their own district)
- Providing single sign-on from DailyWins for LEAs that use both Sure Step products — signing the educator in, associating them with the correct district, and creating or updating the handed-off student's name and grade in that teacher's roster (see §7.7)
Notification of Behavior Emergency Reports. When a Behavior Emergency Report is filed, BehaviorLog Pro notifies the administrators of that organization in two ways. Within the application, the report appears in an administrator's messages panel, where it remains flagged as requiring attention until an administrator has reviewed and finalized it; the identity of the finalizing administrator and the time are recorded on the report. Separately, an email is sent to each administrator of that organization. That email contains no student information. It states only that a Behavior Emergency Report has been filed, names the organization, and directs the recipient to sign in to BehaviorLog Pro to read it; the student's name, the circumstances of the emergency, and the report's contents are never placed in the message, and the recipient must authenticate before any of it is visible to them. Routine event-log entries generate no email of any kind; they appear in the administrator's messages panel only.
5. Prohibited Uses
Sure Step Education will NOT:
- Use any student PII for targeted advertising or marketing purposes
- Create or build non-educational profiles of students
- Sell, rent, trade, or otherwise transfer student PII to any third party
- Disclose student PII to unauthorized parties
- Use student data for any purpose unrelated to the educational services provided
- Use student data for commercial purposes of any kind
- Retain student data beyond the period required to fulfill educational purposes or as required by applicable law
6. Ownership and Control of Pupil Records
All pupil records collected, maintained, or generated through BehaviorLog Pro remain the property of and under the control of the Local Educational Agency, in accordance with California Education Code § 49073.1.
Sure Step Education acts solely as a custodian of pupil records and operates as a School Official with a legitimate educational interest under FERPA (34 CFR § 99.31(a)(1)). Sure Step Education does not claim ownership of any student data processed through BehaviorLog Pro.
The LEA retains full authority to access, review, correct, and request deletion of any pupil records maintained by BehaviorLog Pro.
7. Data Storage and Security
7.1 Data Storage
All data processed by BehaviorLog Pro is stored on servers located within the United States:
- Database and authentication: Supabase (AWS infrastructure, US regions)
- Application hosting and serverless functions: Vercel (US regions)
- A local copy of the signed-in user's authorized data may be cached in browser local storage to enable offline use and faster loading; this cache is limited to that user's authorized data, remains on that device, and is removed when the user signs out
- District document templates: a district administrator may upload the district's standardized BIP, FBA, and goal document templates, which are stored as structure guides (section headings and formatting) shared with that district's specialists. Uploaded template files (.txt, .pdf, or .docx) are converted to plain text within the user's browser before storage; these templates are not pupil records and are not intended to contain student personally identifiable information
- Assessment responses submitted via emailed links: when a behavior specialist emails a QABF or FAST assessment form to a respondent (parent, teacher, or staff member), the emailed link contains a single-use, randomly generated token. The respondent's completed responses are transmitted over HTTPS to our database and are readable only by the specialist who sent that link (enforced by Row-Level Security); the token cannot be reused after one submission. If the form is opened without a valid link token (for example, completed together in person on the specialist's device), responses are saved only in that device's browser storage and are not transmitted
- Student event log: staff may record timestamped incident documentation for a student (what happened, people involved or notified, follow-up, and the entry author). Entries are stored in a database table scoped to the organization, with visibility enforced by Row-Level Security according to organization type: in nonpublic-school organizations, entries are readable by that organization's staff members, subject to the author's own controls described next; in public school districts, an entry is readable only by its author and the district's administrators; in individually subscribed accounts, entries are readable only by the account holder. The author of an entry controls its reach: an entry may be shared with the student's team, or left unshared, in which case it is readable only by the author and by staff senior to the author; a behaviorist or school psychologist may additionally mark an entry confidential, which restricts it to the author alone, the organization's administrators included. Teachers' entries default to shared and teachers do not have the confidential option. These restrictions are enforced by Row-Level Security on the server, not only in the interface. Entries a nonpublic-school director marks private are stored only in that director's own account data and are not shared. Entries may be corrected after the fact by their author or a director, and corrected entries are flagged as corrected. Where an organization has linked its DailyWins school account, event entries recorded in DailyWins are copied into the same student event log and are read-only within BehaviorLog Pro
- Behavior Emergency Reports: a report filed under §3.1 is stored in its own database table, separate from the student event log, with visibility enforced by Row-Level Security. A report is readable by its author and by the administrators of the organization it belongs to. It is not readable by the student's wider team, by staff senior to the author, or by other staff at the author's site, and those restrictions are enforced on the server, not only in the interface. Sure Step Education personnel have no standing read access to these reports; a report is reachable by Sure Step only through the audited support access described in §7.6. A report is a draft from the moment staff submit it until an administrator has reviewed and signed it; the administrator's signature is what makes it the organization's record, and a printed copy of a draft is marked as one. Once submitted, the author cannot alter their report: corrections are made by an administrator, so that a single person is responsible for the wording of a restraint record. An administrator's corrections during that first review complete the report and are not treated as amendments. A change made after the report has been finalized is an amendment: it is made in place and the report is flagged as amended, together with the administrator who amended it and the date — a flag that also appears on any printed or exported copy, so that a reader outside the organization can see the report was changed after it was finalized. Prior wording is not separately retained. There is no facility for any user, at any permission level, to delete a Behavior Emergency Report; see §11.1. Because a report may name other students (§3.1), releasing a copy of one discloses those names along with the report
- Behavior documents (BIP, FBA, and goal documents drafted with the AI assistance described in §7.3): a specialist's working drafts are stored private to their author; when the author marks a document complete, the finished document becomes readable by the student's owning teacher and the organization's administrators (enforced by Row-Level Security). Working notes and drafts used in developing these documents remain private to the author
7.2 Security Measures
- TLS 1.2+ encryption for all data in transit (HTTPS enforced)
- AES-256 encryption for data at rest (provided by Supabase/AWS)
- Authentication via Google OAuth 2.0 or email/password. For email/password accounts, credentials are stored only as salted bcrypt hashes by our authentication provider (Supabase) — never in plaintext and never accessible to Sure Step Education staff
- Row-Level Security (RLS) policies on database tables restricting each user to their authorized data — their own records, plus the specific district-scoped or shared-student data an administrator or specialist is authorized to access
- Role-based access control (teacher, behaviorist, school psychologist, district administrator, Sure Step administrator) enforced at both the application and database levels
- API keys stored exclusively as server-side environment variables, never exposed to the browser
- Serverless proxy architecture for all third-party API calls
- Invite-based registration system preventing unauthorized account creation
7.3 AI-Powered Features
BehaviorLog Pro uses the Anthropic API (Claude) to generate draft Behavior Intervention Plan (BIP), Functional Behavior Assessment (FBA), and behavioral goal documents from the behaviorist's own structured observation data for a student.
Before any data is transmitted, BehaviorLog Pro de-identifies it within the user's browser: the student's name, the names of other students on the user's roster, and staff names known to the application are removed and replaced with neutral placeholders (for example, "[STUDENT]" and "[BEHAVIORIST]"). Only this de-identified text is sent to the Anthropic API through a secure server-side proxy. The real names are re-inserted locally, on the user's own device, after the draft is returned — they are not part of the transmitted request. The de-identified text is presented to the user for review and requires the user's explicit confirmation before any transmission occurs, and the user may edit that text to remove additional details at that point.
This de-identification operates on the names known to the application and is not a guarantee that every possible identifier has been removed. Names of individuals who are not on the user's roster, or other identifying details typed into free-text notes, may remain unless the user removes them at the review step. Users are instructed to review the de-identified text and remove any remaining identifying details before sending.
Anthropic does not train its models on, or retain, data submitted through its API for these requests. All generated documents are drafts that must be reviewed, edited, and approved by a licensed behaviorist before use in any official record.
In organizations where the administrator has enabled AI features, BehaviorLog Pro also uses the same de-identified, server-side proxy pathway for two smaller drafting aids: (1) analyzing the text of a written behavior goal to pre-fill the goal's tracking setup (behavior, measurement type, and target date) for the author's review, and (2) generating a short written summary of a goal's recorded progress data. Because behavior goals may be written by any staff member with access to the student, including a teacher, these two aids are available to any such staff member — unlike BIP and FBA document generation, which remains restricted to behaviorists, school psychologists, and administrators. A goal written by any role may be included, reproduced as written, in a BIP or FBA drafted by a specialist. For the progress summary, the data transmitted consists of the de-identified goal text, the goal's de-identified baseline statement where the team has entered one, and de-identified weekly aggregate figures only — for each week, the week's date, counts, targets and met/not-met status; together with the length in days of the span the goal is scored over (taken from the goal's own text), the current streak, and average prompt counts. No figure is transmitted that is not one of these aggregates, and never free-text observation notes or session records. A baseline statement is text a staff member composes to describe the student's starting point for that goal, ordinarily transcribed from the student's IEP; it is treated exactly as the goal text is, and the same in-browser removal of student, peer, and staff names is applied to it before transmission. The summary is presented as a data-based suggestion for the education team; determinations about goal mastery are made by staff, not by the AI. The same in-browser de-identification described above is applied before transmission, and each request is recorded in the audit log as metadata only (document type and model — never student data).
7.4 Designated Responsible Individual
Name: Nicholas Crabtree
Title: Co-Founder, Sure Step Education
Email: nicholas@surestepeducation.com
7.5 User Roles and District Organization
Access is organized by school district, and each user holds a role that determines what they can see and do:
- Teacher — records behavioral data for their own students, and writes the behavior goals tracked for those students. Teachers do not administer assessments and cannot generate Behavior Intervention Plan or Functional Behavior Assessment documents; those remain restricted to behaviorists, school psychologists, and administrators, and that restriction is enforced on the server, not only in the interface. In a nonpublic school or agency (an organization whose whole enrollment is served by one team), a teacher additionally has read access to the behavioral sessions recorded by other staff at their site, so that the team can see the same record of a student's behavior — for example a teacher covering another teacher's class, or a teacher reviewing a behaviorist's observation of their own student. That access is read-only: a teacher cannot add to, edit, or delete another staff member's students, sessions, or goals. It does not extend to event-log entries, which carry their own author-controlled sharing described in §7.1 — an entry a behaviorist or administrator has not shared, or has marked confidential, remains unavailable to teachers. In a public school district, a teacher's access remains limited to their own students.
- Behaviorist / School Psychologist — conduct assessments, define behavior targets and operational definitions, manage goals, and generate BIP/FBA documents; may be granted read access to a specific student by that student's teacher. In a nonpublic school or agency (an organization whose whole enrollment is served by its own clinical staff), the behaviorist and school psychologist additionally have read access to the students recorded by staff at their site, without a per-student grant, so that they can review behavior data across the site and mark which recorded sessions inform a Functional Behavior Assessment or Behavior Intervention Plan. That site-wide access is read-only plus those FBA/BIP markings: the specialist cannot add to, edit, or delete another staff member's students, sessions, or goals, and the markings are stored with the specialist's own account rather than on the teacher's record. In a public school district, specialist access remains per-student: a behaviorist or school psychologist sees a student only when that student's teacher, or their district administrator on the teacher's behalf, grants access to that specific student.
- District Administrator — manages users and invitations within their own district, and for oversight and recordkeeping can read (and, on request, delete) the student records and behavioral data held by any user in their own district. A district administrator never sees data from another district.
- Sure Step Administrator (Founder) — Sure Step personnel who provision districts and oversee organization-level information such as per-district user counts and contract/billing details. In the ordinary course they see only this organization-level information and do not view student or staff records, except via the audited support access described in §7.6.
Shared-caseload organizations. Some nonpublic-school organizations operate a shared caseload, enabled per organization at the school's direction. In such an organization, student records, recorded sessions, and goals entered by any staff member are visible to all of that school's authorized staff, rather than staying visible only to the staff member who entered them; each entry remains attributed to the staff member who created it. Organizations that have not enabled this mode are unaffected, and it does not change the confidential and private controls on event-log entries described in §7.1.
Individually subscribed accounts. An educator or clinician who purchases an individual BehaviorLog Pro subscription operates as a single-user organization. Student records in an individually subscribed account are never shared with any other account: these accounts cannot share students with other users, cannot receive students shared by other users, and have no organization caseload — restrictions enforced both in the application and at the database layer (Row-Level Security).
7.6 Administrative Access, Support Sessions, and Audit Logging
To provide technical support and troubleshooting, authorized Sure Step personnel may temporarily sign in to and use the application as a specific user (a "support session"). Consistent with Sure Step Education's role as a School Official with a legitimate educational interest under FERPA (34 CFR § 99.31(a)(1)), such access is limited to legitimate support and educational purposes. Every support session requires a stated reason, is limited to a fixed period after which it closes automatically, displays a persistent on-screen banner naming the account being accessed, and is recorded in the audit log described below. A support session that cannot be recorded is not started.
There are two kinds, and they differ in what the person may do:
- Break-glass access (read-only). The application presents a read-only support view: record changes are disabled in the interface for the duration of the session. Limited to 15 minutes.
- Act-as access (able to make changes). Some problems can only be diagnosed by reproducing what a user actually does — recording a session, saving a goal, running an export. In this mode the interface is not restricted, so changes made during the session are saved to the account's real records. Limited to 60 minutes. The audit record identifies the Sure Step person who made them, and the reason given.
An administrator acting as a user in DailyWins may carry that support session into BehaviorLog Pro through the single sign-on link described in §7.7. Such a session is subject to the same reason, banner, time limit, and audit requirements, and its audit record identifies the administrator rather than the user being acted as.
BehaviorLog Pro maintains an audit log of sensitive administrative actions — including support sessions of either kind, data export, data deletion, and changes to a user's role or district assignment — recording who performed the action, the affected account, the reason given, and the time it occurred. Audit records are available to Sure Step Administrators and, for actions scoped to a single district, to that District Administrator.
7.7 Connection with DailyWins (Sure Step Single Sign-On)
BehaviorLog Pro and DailyWins are both products of Sure Step Education. Where an LEA uses both, an authorized DailyWins user may open BehaviorLog Pro directly from DailyWins through a secure single sign-on (SSO) link. When this occurs, DailyWins transmits to BehaviorLog Pro a short-lived, cryptographically signed token containing: the educator's email address and role, the school's DailyWins identifier and name, and — when a teacher opens a specific student — that student's DailyWins identifier, first and last name, and grade level.
BehaviorLog Pro uses this information solely to sign the educator in, associate them with the correct district, and create or update the corresponding student's name and grade in that teacher's roster (kept in sync with DailyWins at each sign-on). The SSO token itself carries no behavioral observation data, assessment responses, goals, or generated reports. Each SSO sign-in is recorded in the audit log described in §7.6.
Event log synchronization. Separately from sign-on, where an LEA has linked its DailyWins school account to its BehaviorLog Pro organization, timestamped student event entries recorded in DailyWins (what happened, people involved or notified, follow-up, and the entry author) are transmitted to BehaviorLog Pro over an authenticated, server-to-server connection and stored in the same per-student event log described in §7.1. These synchronized entries are read-only within BehaviorLog Pro — they can be viewed by the organization's authorized staff but not edited or deleted there; corrections are made in DailyWins, where the entry originated. No data flows from BehaviorLog Pro back to DailyWins through this channel.
Because DailyWins is a Sure Step Education product and not a third party, this is an internal transfer between systems operated by Sure Step Education on behalf of the same LEA; the data remains subject to this policy and the LEA's agreements. Data collected within DailyWins itself is governed by the DailyWins privacy policy.
8. Breach Notification
In the event of an unauthorized disclosure of, or access to, pupil records, Sure Step Education will:
- Notify the affected LEA within seventy-two (72) hours of discovering the breach
- Provide a detailed description of the nature and scope of the breach
- Identify the types of information involved
- Describe the steps being taken to investigate and remediate the breach
- Describe measures being implemented to prevent future occurrences
- Notify affected parents and guardians as directed by the LEA and in accordance with applicable law
9. Parental Rights
Parents and guardians of students whose data is maintained in BehaviorLog Pro have the right to:
- Review their child's pupil records maintained in the system
- Request correction of inaccurate records
- Request deletion of their child's records
All parental requests should be directed to the student's school or LEA. Sure Step Education will cooperate promptly with any LEA request to facilitate parental rights under FERPA and California Education Code § 49061 et seq.
10. Pupil-Generated Content
BehaviorLog Pro does not collect content directly generated by students. All data in the system is entered by authorized school personnel (teachers, behaviorists, administrators) or by assessment respondents (parents, teachers, staff) completing functional assessment screening tools.
If future features introduce pupil-generated content, this policy will be updated to describe how students retain possession and control of such content and how it may be transferred to personal accounts.
11. Data Retention and Deletion
Sure Step Education retains pupil records only for as long as necessary to fulfill the educational purposes described in this policy, or as required by the LEA or applicable law.
Archived students. In shared-caseload organizations, a site administrator may archive a student. Archiving removes the student and their records from staff working rosters; the student's sessions and goals are retained in full and remain available to site administrators through the archived-students view. All of the student's records, including event-log entries, are retained and are not automatically deleted; deletion happens only at the school's request, under its data-processing agreement (see §17).
11.1 Behavior Emergency Reports
A Behavior Emergency Report is a formal record of a behavioral emergency and may be produced to a governing body. Accordingly, BehaviorLog Pro provides no facility for any user — including an organization's administrators — to delete one. A report that was filed in error is corrected by an administrator under §7.1, which leaves the record and any amendment to it visible, rather than removed.
This limitation governs what users of the application can do. It does not place Behavior Emergency Reports beyond the LEA's control or outside the deletion obligations set out below: they are pupil records, they belong to the LEA under §6, and on the LEA's instruction or on termination they are returned and deleted on the same terms and within the same periods as every other pupil record. Nor does it exempt them from a parent's rights under §9.
Upon termination of the agreement with an LEA, or upon request by the LEA:
- User access to the organization's account is disabled promptly upon termination; pupil records are securely retained (but no longer accessible to users) during the return-and-deletion window below
- All pupil records will be returned to the LEA in a machine-readable format (JSON export)
- All pupil records will be deleted from BehaviorLog Pro systems within sixty (60) days
- Sure Step Education will provide written certification of deletion to the LEA
- Backup copies will be purged according to standard data lifecycle procedures, not to exceed ninety (90) days
12. FERPA Compliance
Sure Step Education operates as a School Official with a legitimate educational interest under 34 CFR § 99.31(a)(1). In this capacity:
- We perform institutional services or functions that the LEA would otherwise perform itself
- We are under the direct control of the LEA with respect to the use and maintenance of education records
- We use education records only for authorized educational purposes
- We meet the criteria set forth in the LEA's annual notification of FERPA rights
- We maintain jointly with the LEA all records and compliance documentation required under FERPA
13. SOPIPA Compliance
In compliance with the Student Online Personal Information Protection Act (Cal. Bus. & Prof. Code § 22584), Sure Step Education:
- Does not use student information for targeted advertising
- Does not use student information to create advertising profiles
- Does not sell student information
- Does not disclose student information except as described in this policy for educational purposes
- Implements and maintains reasonable security procedures
- Deletes student information upon request or when no longer needed for educational purposes
- Does not make material changes to this privacy policy without prior notice
14. COPPA Compliance
BehaviorLog Pro is a teacher-facing and staff-facing application. Students do not directly interact with or input data into BehaviorLog Pro. All student behavioral data is entered by authorized school personnel.
The QABF and FAST assessment forms are completed by adult respondents (parents, teachers, staff) and do not collect information directly from children under 13.
Accordingly, COPPA's parental consent requirements for direct collection from children do not apply. If future features introduce student-facing functionality, Sure Step Education will obtain verifiable parental consent or rely on the school consent exception under 16 CFR § 312.5(c)(1).
15. Third-Party Services and Subprocessors
| Service | Purpose | Data Processed |
| Supabase | Database hosting, user authentication, cloud storage | All user and student data, authentication tokens |
| Google OAuth | Optional user sign-in (email/password, handled by Supabase Auth, is the alternative) | Email address, display name, profile avatar |
| Vercel | Application hosting and serverless function execution | HTTP requests, environment variables (API keys) |
| Resend | Transactional email delivery (assessment links, share notifications, invites, password resets, and Behavior Emergency Report notifications) | Recipient email address and email content. Because some of these messages identify the student they concern (for example, an assessment request or a "student shared with you" notice), a student's name may appear in the subject line or body of those emails. No other student records (behavioral data, assessments, goals) are sent through Resend. Behavior Emergency Report notifications are the exception in the other direction: they carry no student identifier at all — only the organization's name and an instruction to sign in — so no pupil record reaches Resend through them. Unlike the Anthropic transmission, these emails are not de-identified. |
| Stripe | Subscription payments for individual (standalone) subscribers only. District- and agency-licensed accounts are invoiced directly and no data about them reaches Stripe. | Subscriber name, email address, billing address, and payment-card details — entered on Stripe's own hosted checkout page. Card data never passes through or is stored by BehaviorLog Pro. Sure Step receives back only the subscription status, the card brand and last four digits, and Stripe's customer and subscription identifiers. No student data is sent to Stripe. |
| Anthropic (Claude API) | AI-assisted report generation (BIP, FBA, Goals) | De-identified behavioral data — student, peer, and staff names are removed and replaced with placeholders before transmission (see §7.3) |
Sure Step Education ensures that all third-party subprocessors maintain security practices consistent with the obligations described in this policy. No subprocessor is authorized to use student data for any purpose other than providing the specific service described above.
16. Changes to This Privacy Policy
Sure Step Education will provide at least thirty (30) days written notice to all affected LEAs before making material changes to this privacy policy. The updated policy will be posted at the BehaviorLog Pro website with a revised effective date.
Non-material changes (typographical corrections, formatting) may be made without advance notice.
17. Data Processing Agreements
Sure Step Education is prepared to enter into Data Processing Agreements with LEAs to formalize data protection obligations. We support:
- The California Student Data Privacy Agreement (CSDPA) template, developed by CITE (California IT in Education, formerly CETPA)
- The National Student Data Privacy Agreement template, developed by the Student Data Privacy Consortium (SDPC)
- Custom district-specific data privacy agreements as required
18. Contact Information
For questions, concerns, or requests regarding this Privacy Policy or BehaviorLog Pro's data practices, please contact:
Organization: Sure Step Education
Contact: Nicholas Crabtree, Co-Founder
Email: nicholas@surestepeducation.com
Product URL: https://blp.surestepeducation.com