SpeakPad is an AAC app for iPhone and iPad. Everything a student creates or says in it stays on the device, or in the iCloud account the device is signed in to. We have no servers that receive student data, no user accounts, and no analytics, advertising, tracking or crash-reporting code in the app. We cannot see, export or delete anything on your devices, because none of it ever reaches us.
| Data | Where it is stored | Who can access it |
|---|---|---|
| Profile name and optional photo for each communicator | On the device | Staff who pass the caregiver gate on that device |
| Boards, words, personal photos and recorded voice clips | On the device | Staff who pass the caregiver gate |
| Usage records: word taps and spoken sentences, with times | On the device, only while usage recording is on | Staff who pass the caregiver gate. Your device management service can turn recording off with recordUsage. |
| Automatic backups (the five most recent) | The iCloud account the device is signed in to, such as a district’s Managed Apple Account | The account holder. Not SpeakPad. Turn off with allowICloud. |
Exported .speakpad backup or board files | Wherever staff choose to save or send them | Whoever staff share them with |
| Pro purchases and licenses | Apple (App Store, Apple School Manager) | Apple and the purchasing organization. The app checks the license on the device. |
Data is protected at rest by iOS Data Protection, the device’s built-in encryption. Deleting a profile in SpeakPad removes its boards and records from the device; deleting the app removes everything stored on the device. Backups in iCloud are removed by the account holder in iCloud settings.
SpeakPad works fully offline. It connects to the internet only in these cases, none of which carry student data to us:
| Connection | When | What is sent |
|---|---|---|
| Apple iCloud | Automatic backup, if the device is signed in to iCloud and allowICloud is not false | The backup, to the device’s own iCloud account, handled by Apple |
| Apple App Store (StoreKit) | Buying, restoring or checking a Pro license | Purchase requests, handled by Apple |
| Apple iCloud sharing (CloudKit) | Only if staff share a communicator's boards with colleagues | The shared boards, photos, goals, sessions and notes, to the iCloud accounts of the people invited. Never usage history, and never to us. |
voices.speakpadapp.com, hosted by Cloudflare | Only when a member of staff chooses to download an optional SpeakPad voice | A request for the voice file. No personal data, and we keep no record of who downloaded it. |
To allow-list SpeakPad on a filtered network, permit Apple’s standard iCloud and App Store services and, if you want the optional voices, voices.speakpadapp.com.
SpeakPad does not receive, store or have access to education records. A student’s boards and usage records stay on district-controlled devices, or in the iCloud account those devices use, so no education record is disclosed to us and we do not act as a school official with access to records. Districts keep full control: staff can view, export, correct or delete a student’s profile and records on the device, which also makes parent requests to inspect or amend records straightforward to meet.
COPPA governs the collection of personal information from children under 13 by online services. SpeakPad collects no personal information from children or anyone else: there is no account, no identifier sent to us, and nothing a child does leaves the device for our servers. Because nothing is collected, there is no need for parental or school consent to collection by SpeakPad. The app is in Apple’s Kids Category, and purchases sit behind a caregiver gate.
Laws such as California’s SOPIPA, New York Education Law 2-d, Illinois SOPPA and similar state student privacy statutes restrict how education technology providers collect, use, sell and secure student data. SpeakPad’s position under each is the same: we receive no student data, so there is nothing to sell, use for advertising, profile, retain or breach.
Short answers to the questions most district questionnaires ask. We will complete your own questionnaire on request.
gatePIN), with Face ID and Touch ID unlock able to be turned off (allowBiometricUnlock).A self-assessment of SpeakPad 3.0 for iPhone and iPad against WCAG 2.1 Level AA, applied to a native app as described in WCAG2ICT, as Section 508 incorporates it. It follows the structure of the VPAT 2.5 but has not been checked by a third party. Evidence comes from Xcode Accessibility Inspector audits, VoiceOver and Switch Control reviews, and automated interface tests. Testing with physical switches and with Apple’s Eye Tracking on a real device is still in progress, so those are reported as not yet verified.
| Criteria | Level | Remarks |
|---|---|---|
| 1.1.1 Non-text content | Supports | Every symbol button has a text label that VoiceOver reads; decorative images are hidden from assistive technology. |
| 1.3.1 Info and relationships | Partially supports | Buttons, headings and lists expose their roles. Some audit findings on caregiver screens are still open. |
| 1.3.4 Orientation | Supports | Boards can follow the device in either orientation. A board can be locked to one orientation where a fixed motor plan or keyguard makes that essential. |
| 1.4.1 Use of color | Supports | Word categories use color plus shape badges, and Differentiate Without Color is honored. |
| 1.4.3 Contrast (minimum) | Partially supports | Most text meets 4.5:1; some audit findings about text and contrast are still open. |
| 1.4.4 Resize text | Partially supports | Caregiver screens follow Dynamic Type. Board labels have their own size setting so that buttons never move; at the largest sizes some labels are capped to keep the grid stable. |
| 2.1.1 Keyboard | Partially supports | All communication is reachable with Switch Control and with SpeakPad’s own scanning. Full Keyboard Access has not been fully evaluated. |
| 2.2.1 Timing adjustable | Supports | Scanning speed, dwell time and hold durations are adjustable; nothing times out the user. |
| 2.3.1 Three flashes | Supports | No flashing content. Reduce Motion is honored. |
| 2.5.1 Pointer gestures | Supports | Every action works with a single tap; no multi-finger or path gestures are required. |
| 2.5.3 Label in name | Supports | Accessible names come from the visible labels, so the words on screen are the words to use with Voice Control. |
| 3.1.1 Language of page | Supports | Speech and labels follow the chosen language, including two languages at once in bilingual mode. |
| 3.2.1 / 3.2.2 Predictable focus and input | Supports | Tapping a word speaks it or opens its folder; settings never change on focus. |
| 4.1.2 Name, role, value | Partially supports | Standard controls expose name, role and value. Some audit findings on caregiver screens are still open. |
| Physical switches and Apple Eye Tracking | Not yet verified | Implemented and tested in software; hardware validation on a real iPad is in progress. |
Accessibility features available at no cost: Switch Control and in-app scanning (row-column, linear and group), dwell selection for head tracking and pointer access, Touch Accommodations, VoiceOver, Personal Voice, Assistive Access, adjustable button and label sizes, and a scanning highlight color. Report an accessibility problem to [email protected].
SpeakPad is an AAC app for iPhone and iPad. Everything a pupil creates or says in it stays on the device, or in the iCloud account the device is signed in to. We have no servers that receive pupil data, no user accounts, and no analytics, advertising, tracking or crash-reporting code in the app. We cannot see, export or delete anything on your devices, because none of it ever reaches us.
| Data | Where it is stored | Who can access it |
|---|---|---|
| Profile name and optional photo for each communicator | On the device | Staff who pass the caregiver gate on that device |
| Boards, words, personal photos and recorded voice clips | On the device | Staff who pass the caregiver gate |
| Usage records: word taps and spoken sentences, with times | On the device, only while usage recording is on | Staff who pass the caregiver gate. Your device management service can turn recording off with recordUsage. |
| Automatic backups (the five most recent) | The iCloud account the device is signed in to, such as a school’s Managed Apple Account | The account holder. Not SpeakPad. Turn off with allowICloud. |
Exported .speakpad backup or board files | Wherever staff choose to save or send them | Whoever staff share them with |
| Pro purchases and licences | Apple (App Store, Apple School Manager) | Apple and the purchasing organisation. The app checks the licence on the device. |
Data is protected at rest by iOS Data Protection, the device’s built-in encryption. Deleting a profile in SpeakPad removes its boards and records from the device; deleting the app removes everything stored on the device. Backups in iCloud are removed by the account holder in iCloud settings.
SpeakPad works fully offline. It connects to the internet only in these cases, none of which carry pupil data to us:
| Connection | When | What is sent |
|---|---|---|
| Apple iCloud | Automatic backup, if the device is signed in to iCloud and allowICloud is not false | The backup, to the device’s own iCloud account, handled by Apple |
| Apple App Store (StoreKit) | Buying, restoring or checking a Pro licence | Purchase requests, handled by Apple |
| Apple iCloud sharing (CloudKit) | Only if staff share a communicator's boards with colleagues | The shared boards, photos, goals, sessions and notes, to the iCloud accounts of the people invited. Never usage history, and never to us. |
voices.speakpadapp.com, hosted by Cloudflare | Only when a member of staff chooses to download an optional SpeakPad voice | A request for the voice file. No personal data, and we keep no record of who downloaded it. |
To allow-list SpeakPad on a filtered network, permit Apple’s standard iCloud and App Store services and, if you want the optional voices, voices.speakpadapp.com.
Your school is the controller of any personal data on its devices, including the data SpeakPad stores there. SpeakPad (the developer) does not receive, store or otherwise process pupil personal data, so we are not a processor for your school and an Article 28 processing agreement is not needed. If your data protection officer would still like that in writing, we will sign a statement confirming it, or review your school’s or trust’s own agreement.
Apple acts for you when you use iCloud, Managed Apple Accounts and Apple School Manager, under your organisation’s agreement with Apple. If you would rather keep backups off iCloud altogether, set allowICloud to false through your device management service; boards can still be exported to a file you control.
Subject access, correction and erasure requests are handled on the device: staff can view, export, edit or delete a profile and its records in SpeakPad. There is nothing held by us to search.
.speakpad file and restore it on a family iPad or at the next school, free and without a licence.SpeakPad was built for children, and its design matches the ICO’s Age appropriate design code:
For the Department for Education’s digital and technology standards, SpeakPad needs no school network services beyond Apple’s, stores nothing with us, and its accessibility report is below.
Short answers to the questions most school and trust questionnaires ask. We will complete your own questionnaire on request.
gatePIN), with Face ID and Touch ID unlock able to be turned off (allowBiometricUnlock).A self-assessment of SpeakPad 3.0 for iPhone and iPad against WCAG 2.1 Level AA, applied to a native app as described in WCAG2ICT, the standard that EN 301 549 uses for software and that the UK’s public sector accessibility regulations rely on. It follows the structure of the VPAT 2.5 but has not been checked by a third party. Evidence comes from Xcode Accessibility Inspector audits, VoiceOver and Switch Control reviews, and automated interface tests. Testing with physical switches and with Apple’s Eye Tracking on a real device is still in progress, so those are reported as not yet verified.
| Criteria | Level | Remarks |
|---|---|---|
| 1.1.1 Non-text content | Supports | Every symbol button has a text label that VoiceOver reads; decorative images are hidden from assistive technology. |
| 1.3.1 Info and relationships | Partially supports | Buttons, headings and lists expose their roles. Some audit findings on caregiver screens are still open. |
| 1.3.4 Orientation | Supports | Boards can follow the device in either orientation. A board can be locked to one orientation where a fixed motor plan or keyguard makes that essential. |
| 1.4.1 Use of color | Supports | Word categories use color plus shape badges, and Differentiate Without Color is honoured. |
| 1.4.3 Contrast (minimum) | Partially supports | Most text meets 4.5:1; some audit findings about text and contrast are still open. |
| 1.4.4 Resize text | Partially supports | Caregiver screens follow Dynamic Type. Board labels have their own size setting so that buttons never move; at the largest sizes some labels are capped to keep the grid stable. |
| 2.1.1 Keyboard | Partially supports | All communication is reachable with Switch Control and with SpeakPad’s own scanning. Full Keyboard Access has not been fully evaluated. |
| 2.2.1 Timing adjustable | Supports | Scanning speed, dwell time and hold durations are adjustable; nothing times out the user. |
| 2.3.1 Three flashes | Supports | No flashing content. Reduce Motion is honoured. |
| 2.5.1 Pointer gestures | Supports | Every action works with a single tap; no multi-finger or path gestures are required. |
| 2.5.3 Label in name | Supports | Accessible names come from the visible labels, so the words on screen are the words to use with Voice Control. |
| 3.1.1 Language of page | Supports | Speech and labels follow the chosen language, including two languages at once in bilingual mode. |
| 3.2.1 / 3.2.2 Predictable focus and input | Supports | Tapping a word speaks it or opens its folder; settings never change on focus. |
| 4.1.2 Name, role, value | Partially supports | Standard controls expose name, role and value. Some audit findings on caregiver screens are still open. |
| Physical switches and Apple Eye Tracking | Not yet verified | Implemented and tested in software; hardware validation on a real iPad is in progress. |
Accessibility features available at no cost: Switch Control and in-app scanning (row-column, linear and group), dwell selection for head tracking and pointer access, Touch Accommodations, VoiceOver, Personal Voice, Assistive Access, adjustable button and label sizes, and a scanning highlight color. Report an accessibility problem to [email protected].