Student privacy, security and accessibility for schools

Summary

SpeakPad is an AAC app for iPhone and iPad. Everything a student creates or says in it stays on the device, or in the iCloud account the device is signed in to. We have no servers that receive student data, no user accounts, and no analytics, advertising, tracking or crash-reporting code in the app. We cannot see, export or delete anything on your devices, because none of it ever reaches us.

What data exists and who can see it

DataWhere it is storedWho can access it
Profile name and optional photo for each communicatorOn the deviceStaff who pass the caregiver gate on that device
Boards, words, personal photos and recorded voice clipsOn the deviceStaff who pass the caregiver gate
Usage records: word taps and spoken sentences, with timesOn the device, only while usage recording is onStaff who pass the caregiver gate. Your device management service can turn recording off with recordUsage.
Automatic backups (the five most recent)The iCloud account the device is signed in to, such as a district’s Managed Apple AccountThe account holder. Not SpeakPad. Turn off with allowICloud.
Exported .speakpad backup or board filesWherever staff choose to save or send themWhoever staff share them with
Pro purchases and licensesApple (App Store, Apple School Manager)Apple and the purchasing organization. The app checks the license on the device.

Data is protected at rest by iOS Data Protection, the device’s built-in encryption. Deleting a profile in SpeakPad removes its boards and records from the device; deleting the app removes everything stored on the device. Backups in iCloud are removed by the account holder in iCloud settings.

Network connections

SpeakPad works fully offline. It connects to the internet only in these cases, none of which carry student data to us:

ConnectionWhenWhat is sent
Apple iCloudAutomatic backup, if the device is signed in to iCloud and allowICloud is not falseThe backup, to the device’s own iCloud account, handled by Apple
Apple App Store (StoreKit)Buying, restoring or checking a Pro licensePurchase requests, handled by Apple
Apple iCloud sharing (CloudKit)Only if staff share a communicator's boards with colleaguesThe shared boards, photos, goals, sessions and notes, to the iCloud accounts of the people invited. Never usage history, and never to us.
voices.speakpadapp.com, hosted by CloudflareOnly when a member of staff chooses to download an optional SpeakPad voiceA request for the voice file. No personal data, and we keep no record of who downloaded it.

To allow-list SpeakPad on a filtered network, permit Apple’s standard iCloud and App Store services and, if you want the optional voices, voices.speakpadapp.com.

FERPA

SpeakPad does not receive, store or have access to education records. A student’s boards and usage records stay on district-controlled devices, or in the iCloud account those devices use, so no education record is disclosed to us and we do not act as a school official with access to records. Districts keep full control: staff can view, export, correct or delete a student’s profile and records on the device, which also makes parent requests to inspect or amend records straightforward to meet.

COPPA

COPPA governs the collection of personal information from children under 13 by online services. SpeakPad collects no personal information from children or anyone else: there is no account, no identifier sent to us, and nothing a child does leaves the device for our servers. Because nothing is collected, there is no need for parental or school consent to collection by SpeakPad. The app is in Apple’s Kids Category, and purchases sit behind a caregiver gate.

State laws and data privacy agreements

Laws such as California’s SOPIPA, New York Education Law 2-d, Illinois SOPPA and similar state student privacy statutes restrict how education technology providers collect, use, sell and secure student data. SpeakPad’s position under each is the same: we receive no student data, so there is nothing to sell, use for advertising, profile, retain or breach.

Security questionnaire answers

Short answers to the questions most district questionnaires ask. We will complete your own questionnaire on request.

Do you host or store customer data?
No. SpeakPad has no backend that receives customer data. Optional voice files are served from Cloudflare and contain no personal data.
How is data encrypted?
At rest by iOS Data Protection on the device. iCloud backups are encrypted by Apple in transit and at rest. Voice downloads use HTTPS.
Authentication and access control?
No accounts. Caregiver functions are behind a gate that can be a four-digit PIN set by device management (gatePIN), with Face ID and Touch ID unlock able to be turned off (allowBiometricUnlock).
Third-party code and sub-processors?
One open-source library for reading and writing backup archives (ZIPFoundation), which makes no network connections. No SDKs for analytics, advertising, attribution or crash reporting. Apple provides iCloud and the App Store; Cloudflare hosts the optional voice files.
Logging and monitoring?
The app sends no logs or telemetry. Usage records exist only on the device, for staff to read.
Vulnerability reporting?
Report to [email protected]. We acknowledge within 48 hours and give an initial assessment within 5 business days.
Penetration testing and certifications?
No third-party penetration test or certification (such as SOC 2) has been carried out. With no server holding customer data, the app’s attack surface is the device itself, which your device management service controls.
Data retention and deletion at the end of a contract?
Nothing to return or delete on our side. Remove the app, or delete profiles, on your devices, and remove iCloud backups in the device’s iCloud account. Licenses simply lapse; boards already on a device keep working.
Business continuity?
SpeakPad runs offline with no service of ours in the loop, so it keeps working if our systems are unavailable. Each profile can be exported to a file the district holds.

Accessibility conformance report

A self-assessment of SpeakPad 3.0 for iPhone and iPad against WCAG 2.1 Level AA, applied to a native app as described in WCAG2ICT, as Section 508 incorporates it. It follows the structure of the VPAT 2.5 but has not been checked by a third party. Evidence comes from Xcode Accessibility Inspector audits, VoiceOver and Switch Control reviews, and automated interface tests. Testing with physical switches and with Apple’s Eye Tracking on a real device is still in progress, so those are reported as not yet verified.

CriteriaLevelRemarks
1.1.1 Non-text contentSupportsEvery symbol button has a text label that VoiceOver reads; decorative images are hidden from assistive technology.
1.3.1 Info and relationshipsPartially supportsButtons, headings and lists expose their roles. Some audit findings on caregiver screens are still open.
1.3.4 OrientationSupportsBoards can follow the device in either orientation. A board can be locked to one orientation where a fixed motor plan or keyguard makes that essential.
1.4.1 Use of colorSupportsWord categories use color plus shape badges, and Differentiate Without Color is honored.
1.4.3 Contrast (minimum)Partially supportsMost text meets 4.5:1; some audit findings about text and contrast are still open.
1.4.4 Resize textPartially supportsCaregiver screens follow Dynamic Type. Board labels have their own size setting so that buttons never move; at the largest sizes some labels are capped to keep the grid stable.
2.1.1 KeyboardPartially supportsAll communication is reachable with Switch Control and with SpeakPad’s own scanning. Full Keyboard Access has not been fully evaluated.
2.2.1 Timing adjustableSupportsScanning speed, dwell time and hold durations are adjustable; nothing times out the user.
2.3.1 Three flashesSupportsNo flashing content. Reduce Motion is honored.
2.5.1 Pointer gesturesSupportsEvery action works with a single tap; no multi-finger or path gestures are required.
2.5.3 Label in nameSupportsAccessible names come from the visible labels, so the words on screen are the words to use with Voice Control.
3.1.1 Language of pageSupportsSpeech and labels follow the chosen language, including two languages at once in bilingual mode.
3.2.1 / 3.2.2 Predictable focus and inputSupportsTapping a word speaks it or opens its folder; settings never change on focus.
4.1.2 Name, role, valuePartially supportsStandard controls expose name, role and value. Some audit findings on caregiver screens are still open.
Physical switches and Apple Eye TrackingNot yet verifiedImplemented and tested in software; hardware validation on a real iPad is in progress.

Accessibility features available at no cost: Switch Control and in-app scanning (row-column, linear and group), dwell selection for head tracking and pointer access, Touch Accommodations, VoiceOver, Personal Voice, Assistive Access, adjustable button and label sizes, and a scanning highlight color. Report an accessibility problem to [email protected].

Supplier and purchasing details

Supplier
Jonathan Mullan, the developer listed on the App Store, trading as SpeakPad.
How do we buy?
The app is free. Pro licenses for student iPads are bought through Apple School Manager or Apple Business, which handles invoicing and sales tax, when Apple opens volume purchasing on October 22, 2026. See the schools page for pricing.
Contact
[email protected]. Please don’t include student names or personal information.