Privacy Policy

Maintained by the Accrue ABA team

This page is maintained by the Accrue ABA team to answer common privacy questions about the Accrue ABA platform. It describes what the product does today. It is not a certification, an audit result, or legal advice. Organizations using Accrue remain responsible for their own privacy notices and agreements.

Who controls the data

Each clinic, school, or district that signs up creates its own organization workspace. That organization is the controller of the records it enters. Accrue processes those records on the organization's behalf and does not sell them, share them with advertisers, or use them to train advertising models.

What we collect

  • Account data — name, email, role, organization membership, and authentication metadata.
  • Fieldwork data — hours logged by trainees and RBTs, supervision records, competency assessments, verification forms, and signatures.
  • Student records — minimal identifiers (initials, optional school, grade, and program details), goals, behavior definitions, and session data entered by staff.
  • Operational data — audit log entries recording who viewed, created, changed, signed, or exported a record and when.

Minimal-identifier design

Accrue is designed so that clinical work can be done without storing broad protected health information. Students can be represented by initials rather than full names, and organization administrators can turn on minimal-PHI mode to hide full names, dates of birth, and diagnosis fields across the app.

Access controls

Access is scoped to an organization first, then to a role (administrator, BCBA supervisor, trainee, RBT), then to team membership on a specific student or trainee. Database-level row security enforces these boundaries, so a member of one organization cannot read another organization's records.

Retention and deletion

Each organization sets its own retention window for session and fieldwork records. Administrators can archive graduates and export data before removal. When an organization asks us to delete its workspace, we remove its records from active systems; audit entries required for accountability are retained for the organization's configured retention period and then removed.

Subprocessors

Accrue runs on Lovable Cloud infrastructure for application hosting, authentication, and database storage. Payment processing, when a plan is purchased, is handled by our payment provider; we do not store card numbers. A current list of subprocessors is available on our Subprocessors page.

Your choices and requests

Individuals should direct access, correction, and deletion requests to the organization that entered their data. Organization administrators can raise requests to us directly and we will support them. See the security and compliance page for the contact route.

Illinois SOPPA

For Illinois K-12 schools and districts, Accrue ABA provides a SOPPA Data Privacy Agreement, parent-rights request tracking, breach notification workflows, and annual subprocessor disclosures. We do not target advertising to students, amass profiles for non-school purposes, or sell or rent student information. See the SOPPA page for the full Illinois-specific disclosure.

Children and schools

Student records in Accrue are entered by school and clinic staff, not by children. Our approach to children's data and guardian consent is described on the children's privacy page. For school-directed accounts, the school district remains the record owner; see Schools & FERPA.