Skip to main content
Legal

Privacy Policy

epPractitioner Mobile Application · Effective date: July 29, 2026

What epPractitioner never does

  • A practitioner can never add a student to their caseload without the student's caregiver explicitly approving it.
  • We never show advertising of any kind.
  • We never sell, rent, or share your data, or your students' data, with third parties.
  • We never use your data to train AI models.
  • epPractitioner is a professional support tool, not a medical device, and does not diagnose or treat any condition.

EnrichPoint (“we,” “us,” or “our”) operates the epPractitioner mobile application (the “App”). epPractitioner is a caseload-management companion for speech-language pathologists, occupational therapists, special educators, and other practitioners who support people using EnrichPoint apps such as epSpeak. This Privacy Policy explains how we collect, use, store, and protect information when you use the App.

For the EnrichPoint corporate-level legal terms (account auth, billing, dispute resolution) that apply across every EnrichPoint app, see our site-wide Privacy Policy. This document is the epPractitioner-specific addendum and takes precedence for matters specific to this app.

1. A cloud, account-based tool

Unlike our consumer apps, epPractitioner is account-based and cloud-backed by design: a practitioner signs in with an EnrichPoint account, and their caseload, classes, notes, goals, and the usage analytics they review are stored on our servers so they sync across devices and to the web portal at enrichpoint.com/epspeak/practitioner.

2. Who uses epPractitioner

  • Practitioners: the person managing a caseload. Practitioners hold an EnrichPoint account with a practitioner role and an epSpeak practitioner subscription.
  • End users (students/clients): the people a practitioner supports. End users are created and owned on the family/caregiver side; a practitioner only gains access to an end user after that end user's caregiver approves the practitioner's request.
  • Caregivers: the parent, family member, or guardian who owns the end user's account and approves (or revokes) practitioner access.

3. Information We Collect

Practitioner account

  • Email address and display name (from sign-up, or from Google/Apple if you use those providers).
  • Your role and subscription/entitlement (epSpeak practitioner tier).
  • A device notification token, if you enable push notifications.
  • Sign-in and authorization events (used for security and to detect abuse).

Caseload and classes

  • The end users linked to you (added only after caregiver approval), and their email/display name.
  • Classes you create and which students belong to each, and pending add/approval requests.
  • Pairing codes you look up to identify a student before requesting access.

Clinical/support content you author

  • Notes you write about a student, and whether a note is shared with the student's family.
  • Goals: individual goals and class-wide goals, including targets, deadlines, and progress.
  • Categories you design and send to students (subject to caregiver approval to install).
  • Lessons (learning activities) you create and assign to a student or a class, and the lesson content itself. Lesson content is screened for safety before it can reach a student's device, and a student's caregiver can remove any assigned lesson.

Usage analytics you review

  • Derived AAC usage data for the students on your caseload (e.g. counts of item/category use, streaks, vocabulary growth) and printable student reports. This is aggregated activity data, not audio, video, or message content.
  • Lesson results and progress for students you support, completion status, accuracy, and which items are hard. Used to show you how a student or class is doing against assigned lessons.

What we do NOT collect

  • Audio recordings, video, or photos of students.
  • Location data of any kind.
  • Contacts, calendar, or other device data outside the app.
  • Behavioral profiles for advertising or third-party sharing.

4. The caregiver-approval consent chain

A practitioner cannot unilaterally see a student's data. To add a student, you send a request; the student's caregiver must approve it before any roster link, notes, goals, or analytics become available to you. A caregiver can revoke a practitioner's access at any time, which removes your link to that student.

5. Children's Privacy

Students supported through epPractitioner are frequently minors. epPractitioner is a tool for the professionals and caregivers who support them, not a service directed to children, and we do not knowingly let a practitioner collect a child's information without that child's caregiver's approval (see §4). We do not sell, share, or use children's data for advertising or profiling. A caregiver can remove a practitioner's access, or clear/close their own child's account, at any time from the caregiver tools.

6. How We Use Information

  • Provide the service: maintain your caseload and classes, store notes/goals, and surface the usage analytics you review.
  • Notifications: alert you to approvals, requests, and (if enabled) relevant activity.
  • Improve the product: aggregated, non-identifying analytics about which features are used and where bugs occur. We do not read individual notes for product decisions.
  • Security and abuse: log auth events to detect fraud or compromised accounts.

7. How We Store and Protect Information

  • Data is stored on Google Firebase (Firestore, Authentication, Cloud Functions) within Google Cloud's US infrastructure.
  • Data in transit uses TLS 1.2+; data at rest is encrypted by Firebase using AES-256.
  • Access to production data is restricted to a small number of EnrichPoint engineers, with audit logging on administrative actions.

8. Third-Party Services

  • Firebase (Google): authentication, database, and functions.
  • Apple / Google: if you sign in with Apple or Google, your name, email, and provider identifier are shared with us per their respective terms.

We do not include any third-party advertising SDKs or social-media tracking libraries in the App.

9. Data Retention

  • Account and caseload data: retained while your account is active.
  • When a caregiver revokes your access to a student, your link and your view of that student's data are removed.
  • Deleted account / data: removed from production systems within 30 days; backup copies are purged on the next backup rotation cycle (up to 90 days).

10. Your Rights

11. International Users

epPractitioner is operated from the United States. If you use the App from outside the US, you consent to processing your data in the US. EU and UK users have additional rights under GDPR and UK GDPR, contact support@enrichpoint.com to exercise them.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be announced in the App and on this page. The “Effective date” at the top reflects the most recent version.

13. Contact

Privacy questions or data requests: support@enrichpoint.com.