Privacy & Security

Privacy and security designed for modern therapy workflows.

SLP Spark is built with privacy-first architecture — secure storage, protected access controls, and privacy-conscious AI workflows to help support responsible handling of student information.

From session recordings to AI-generated documentation, therapists stay in control of what is captured, reviewed, and finalized.

Secure Session Storage

Session recordings, transcripts, and notes are stored using protected cloud infrastructure with access controls designed for clinical workflows.

Therapist-Controlled Workflows

SLPs stay in control of recordings, documentation, and generated notes with the ability to review and edit before finalizing.

Privacy-Conscious AI

AI-generated documentation is designed to support therapist workflows while minimizing unnecessary exposure of student information.

Designed with HIPAA Safeguards

SLP Spark is built with privacy-first architecture and designed with HIPAA safeguards as the platform matures. Vendor BAA review is in progress.

Security practices

How we design SLP Spark to reduce risk and keep clinicians in control. For collection and use details, see our Privacy Policy.

Data minimization

We encourage collecting only what you need for documentation and progress tracking. Workflows support student initials or identifiers rather than requiring full names, and many fields are optional based on your caseload and district policies.

You decide what to record, upload, and store. Avoid entering unnecessary sensitive information whenever your workplace policies allow.

PHI redaction before cloud AI processing

When AI-powered transcription or SOAP note generation is requested, audio or text may be transmitted to third-party AI processing providers over encrypted connections.

  • Personally identifiable information (PII/PHI) may be minimized or obfuscated before transmission when possible
  • AI providers are used solely to process the outputs you request
  • We do not sell recordings or session data

AI features remain therapist-controlled — review and edit all generated content before use.

Encryption in transit

Connections between the SLP Spark app, website, and our backend use encryption in transit (HTTPS/TLS). Authentication and database access use industry-standard encrypted channels through our cloud providers.

Encryption at rest

Clinical and account data stored in our database is hosted on infrastructure providers that apply encryption at rest. Access to production systems is restricted to authorized personnel and operational needs.

Local and on-device handling

Whenever possible, session recordings are initially stored locally on your device. You maintain control over recordings on the device and may delete them there.

Cloud sync and web dashboard features transmit only the data needed to provide the service you use.

Access controls

Account data and clinical records are scoped to your organization with access controls designed for therapist workflows. Row-level security and authentication help ensure users access only the data their account is permitted to see.

Vendor review

SLP Spark relies on trusted third-party providers for hosting, authentication, billing, and AI processing, including:

  • Vercel (website hosting and serverless functions)
  • Supabase (authentication and database)
  • Apple App Store (billing and Sign in with Apple)
  • Google and Microsoft (optional sign-in)
  • AI transcription and language model providers (selection in progress)

A full list of subprocessors and how they handle data is in our Privacy Policy.

Business Associate Agreements (BAAs)

Vendor BAA review is in progress. We are working to execute Business Associate Agreements with vendors that may process clinical or student data, where required. BAA status may vary by vendor and product configuration.

HIPAA compliance for your organization depends on signed BAAs, proper configuration, workforce policies, and how you use the product — not on marketing copy alone.

Data deletion requests

You may request deletion of account data and associated clinical records where applicable. To submit a request, email us with the address tied to your account.

  • We verify requests to protect account security
  • We aim to respond within a reasonable timeframe
  • Some records may be retained where required by law or for legitimate operational needs (for example, billing reconciliation)

Deleting the app from your device does not automatically delete cloud-synced data — contact us if you need account-level deletion.

Privacy and security contact

For privacy, security, or data-handling questions — including access, correction, export, or deletion requests — contact:

support@slp-spark.com

Please do not include sensitive student or patient information in email. Use in-app workflows for clinical data whenever possible.

Privacy, trust, and therapist control are built into the foundation of SLP Spark.

SLP Spark is designed with privacy and security safeguards for clinical workflows. We do not represent that the service is HIPAA compliant unless and until we complete legal review, execute required Business Associate Agreements, and any third-party verification we choose to publish. Your organization's HIPAA compliance depends on signed BAAs, proper configuration, workforce policies, and appropriate use of the product. HIPAA compliance roadmap in progress.

See also our Privacy Policy and Terms of Service, including the section on HIPAA Business Associate status.