Data & privacy

It's your child's record. You decide who reads it.

Parla holds more than a word count. It can hold sleep, incidents, toileting, medication and engagement — and it's built to export into IEP meetings and clinical reports. That's useful, and it's exactly why the rules below are written down.

Version 2026-08-02 · Effective August 2, 2026 · support@tryparla.app

Optional by default

Only a name is required. Every metric can be switched off.

Role-based

Teachers see progress, not personal-care entries.

Delete means delete

Removed from reports, exports and backups.

What we hold, and who sees it

Child profile

DevelopmentalRequired

First name or nickname, age band, communication stage.

Raw entries
Everyone on the care team
Trends & reports
Everyone on the care team
Kept for
Kept while the account is open.

AAC board activity

CommunicationOptional

Words tapped, unique vocabulary, time of day, repeat-tap rate.

Raw entries
Parents and anyone they mark as clinical
Trends & reports
Everyone on the care team
Kept for
Rolling 24 months, then aggregated to monthly totals.

Milestones & skills

DevelopmentalOptional

First requests, imitation, two-word combinations, skill movement.

Raw entries
Parents, SLPs, OTs, teachers
Trends & reports
Everyone on the care team
Kept for
Kept while the account is open — it's the child's history.

Parent logs & Pip conversations

Health & personal careOptional

What you type or say about a day, and what Pip pulls out of it.

Raw entries
Parents only
Trends & reports
Care team sees extracted milestones and patterns, never the raw text
Kept for
Rolling 24 months unless you delete sooner.

School & therapy session notes

DevelopmentalOptional

What a teacher, SLP or OT documented in a session.

Raw entries
The author, parents, and anyone the note is shared with
Trends & reports
Everyone on the care team
Kept for
Kept while the account is open.

Daily health & personal care

Health & personal careOptional

Sleep hours, meltdowns or incidents, toileting successes, vitamins or medication taken, appetite, gut/digestion notes.

Raw entries
Parents only, plus any clinician a parent explicitly grants clinical access
Trends & reports
Only people with clinical access. Teachers and general caregivers never see these day-level entries.
Kept for
Rolling 12 months, then reduced to monthly averages.

The questions people actually ask

What is mandatory to log?

Only a name for the child so the app has something to call them. Every metric — sleep, toileting, incidents, vitamins, engagement, motor scores — is optional and can be turned off in Parent mode without breaking anything else. Skipping a day never penalises you, which is also why the streak counts days you showed up, not days your child performed.

Who can see raw day-level entries?

Parents and account owners always. Invited members see only what their role allows: a teacher or general caregiver sees board activity and milestones, not personal-care or health entries. Clinical access — which unlocks health trends — is granted per person by a parent and can be revoked at any time from the Care team screen.

What goes into an export or IEP pack?

You choose the date range and the sections before anything is generated, and you see the full document before it leaves the app. Health and personal-care detail is excluded from provider-facing exports unless you explicitly include it.

How long is data kept?

Health and personal-care entries: 12 months at day-level detail, then reduced to monthly averages. Board activity and parent logs: 24 months. Milestones and session notes are kept for the life of the account because they are the child's developmental history.

What does deleting actually do?

Deleting a single entry removes it from the database and from every future report or export — it is not soft-hidden. Deleting the child's record removes the profile, board, visual board, logs, notes and metrics within 30 days, including from backups. Exports you already downloaded or shared are copies we no longer control.

Do you sell or train on this data?

No. We never sell data and we never use an identified child's records to train models. AI features process your text to produce your own summaries and reports.

Who owns it?

The family. A clinician or school who loses access to a child keeps their own session notes, not the family's logs. Parents can export everything at any time.

The full policy

Who this policy covers

Parla is a communication and progress-tracking app for children who use AAC (augmentative and alternative communication) and the adults around them — parents, caregivers, speech-language pathologists, occupational therapists, teachers and school teams.

This policy applies to the Parla web app at tryparla.app, the installable phone version of it, and any report or export Parla generates. It is written for the adult who creates the account: in almost every case a parent or legal guardian, or a school or clinic acting with parental consent.

Children do not create accounts and are never asked for personal information by the app. A child using the board is using an adult's account.

What we collect

There are four sources of data in Parla, and they behave differently:

  • What you type or say — daily logs, session notes, answers to Parla's check-in questions, goals, and free-text observations.
  • What the board records automatically — which words were tapped, how many, at what time of day, in which category. This is counted activity, not audio: Parla does not record or transmit microphone audio from the board, and speech is synthesized on your device.
  • What you configure — the child's profile, the vocabulary on the board, the visual board, photos you upload, care-team members and their roles.
  • Ordinary account and technical data — the email address you sign in with, sign-in timestamps, device and browser type, and error reports we use to fix crashes.

The data table

The table further down this page is the operative part of this policy. For every category of data it states what it contains, how sensitive it is, whether it is required, who can see the raw day-level entry, who can see it only as an aggregated trend, and how long it is kept. Where anything in this prose and that table appear to disagree, the table governs.

How we use it

We use your data to run the features you asked for and for nothing else. Concretely, that means: displaying the board and your child's vocabulary; turning your logs and the board's activity into the trends, streaks and progress views inside the app; suggesting next words, sounds and activities; generating the reports and IEP packs you request; sending you the account and check-in messages you have not turned off; and keeping the service secure and working.

We do not build advertising profiles, we do not run third-party advertising or tracking pixels in the app, and we do not sell, rent or trade personal data. We do not use an identified child's records to train AI models, and our AI providers are contractually bound not to train on the content we send them.

How the AI features work

Several parts of Parla — the daily check-in, the coach, restating a parent note in clinical language, and report drafting — send your text to a large-language-model provider to produce your own output. Only the text needed for that specific task is sent. It is used to generate your result, is not retained by the provider for training, and no advertising or profiling is performed on it.

AI output in Parla is a draft for a human to accept, edit or reject. It never silently changes your child's record, and it is not medical advice. Suggestions are never presented as clinical findings, and where we cite research we cite the actual source.

Who we share it with

Inside your account, sharing is entirely your decision: each person you invite gets a role, and clinical access — which is what unlocks health and personal-care trends — is granted per person and revocable at any time from the Care team screen.

Outside your account, we share data only with the service providers that make Parla run, each under a contract limiting them to processing on our instructions:

  • Our cloud hosting and database provider, which stores the data and runs the app.
  • Our AI provider, for the features described above.
  • Our email provider, for account and notification email.
  • Our payment processor, for subscriptions and store orders. Card details go directly to them; Parla never sees or stores a card number.

Reports, exports and QR guest passes

Reports and IEP packs are generated only when you ask for one. You choose the date range and the sections first, and you see the finished document before it leaves the app. Health and personal-care detail is excluded from provider-facing exports unless you explicitly include it.

A guest QR pass opens the communication board only. It gives no access to the parent dashboard, logs, health entries, progress data or care-team settings, and it does not create an account for the person scanning it. Passes can be revoked at any time.

Once you download, print or send an export, that copy is outside the app and outside our control.

How long we keep it

Retention is set per category in the table below. In summary: health and personal-care entries are held at day-level detail for 12 months and then reduced to monthly averages; board activity and parent logs are held for 24 months; milestones and session notes are kept for the life of the account because they are the child's developmental history.

If an account is closed, we delete its data within 30 days, including from backups on their normal rotation.

Your rights and how to use them

You can do most of this yourself, immediately, without contacting us:

  • Access and portability — export everything from the Reports screen at any time.
  • Correction — edit any entry, note, goal or profile field in place.
  • Deletion — delete a single entry, or delete the child's record entirely. Deletion removes it from the database and from every future report or export; it is not soft-hiding.
  • Restriction — switch off any metric in Parent mode. Skipping a metric or a day never degrades the rest of the app.
  • Withdrawing sharing — change a role or revoke clinical access from the Care team screen.
  • Objection or complaint — write to us and we will respond. Depending on where you live you may also have the right to complain to your data protection authority.

Schools, districts and clinics

Where a school, district or clinic sets up Parla for a student, that organization is the controller of the student's record and Parla acts as its processor under its instructions. Student data is used only to deliver the service to that organization, is never sold, and is never used for advertising or for training AI models. We will sign a data processing agreement, and we will return or delete student data at the end of the engagement on request.

This is a description of how we operate the product. It is not a claim of certification under any specific standard or framework; if you need contractual or compliance wording for a procurement process, write to us and we will provide it.

Security

Data is encrypted in transit and at rest by our hosting provider. Access inside the app is enforced at the database level by row-level rules, not just in the interface — a teacher's account cannot read a health entry even if a request is made directly to the API. Uploaded photos are served through short-lived signed links rather than public URLs. The adult dashboard sits behind a parent PIN so a child holding the device cannot wander into it.

No system is perfect. If we ever have a breach affecting your data, we will tell affected account owners without undue delay and describe what happened and what to do about it.

Where data is stored

Parla's database and file storage are operated by our cloud provider, and some of our processors (AI, email, payments) operate in the United States. If you use Parla from outside the United States, your data may be processed there under the contractual safeguards our providers offer.

Cookies and local storage

Parla uses browser storage for the things it cannot work without: keeping you signed in, remembering board settings and voice preferences on the device, and queuing check-in prompts so they appear on the parent dashboard instead of interrupting a child mid-sentence. We do not use advertising cookies or third-party tracking pixels.

Changes to this policy

If we change this policy in a way that affects what we collect, who can see it or how long we keep it, we will raise the version, update the date at the top, and ask you to acknowledge the new version the next time you sign in. Minor wording fixes will not trigger a re-acknowledgement.

Contact

Write to support@tryparla.app for anything in this policy: a data request, a deletion you cannot complete yourself, a processing agreement for a school or clinic, or a security concern. We answer privacy requests within 30 days.

Change who sees what, any time.

Every invite sets a role and a clinical-access switch, and both can be changed or revoked from the Care team screen.

Open care team settings