Privacy Policy

Last updated: September 28, 2026 · Effective: September 28, 2026

VoiceBloom is built for families and children. We collect only what we need, never sell your data, and give you full control over your information at any time.

1. Who We Are

VoiceBloom ("we", "us", or "our") operates the VoiceBloom communication platform, accessible at voicebloom.ca. We provide augmentative and alternative communication (AAC) tools for children, their families, therapists, and organizations.

VoiceBloom is based in Canada. This privacy policy is written in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), as well as GDPR and CCPA where applicable.

Privacy Officer: For questions about this policy or to exercise your data rights, contact our Privacy Officer at info@voicebloom.ca.

2. Information We Collect

Information You Provide to Us

Information We Collect Automatically

Information We Do Not Collect

3. How We Use Your Information

We do not use your child's communication data to train models, and Anthropic does not use our inputs for training under our API agreement. Claude (Anthropic) is used in three places, and only these: drafting your weekly and daily report summaries; answering questions you ask in Coach, where the request includes a summary of that day's symbol activity so the answer is specific to your child; and drafting IEP progress notes for school staff, where the student's name is replaced with a placeholder before the request is sent and restored on your device afterwards, so no identified student record leaves the device. The child's communication board itself sends nothing: the animated character's replies are generated on the device. Anthropic deletes inputs and outputs within 30 days under their standard commercial terms.

4. Consent

Under PIPEDA, we collect and use your personal information only with your knowledge and consent. By creating a VoiceBloom account, you consent to the collection and use of information as described in this policy.

5. Parental Consent and Children's Privacy (COPPA)

VoiceBloom is used with children but is operated by adults (parents, therapists, or organization administrators). We do not collect personal information directly from children under 13. All child data is provided by an adult account holder on the child's behalf.

Verifiable Parental Consent

Before any child data is collected in a family, clinic or therapist account, the responsible adult must provide consent during onboarding, in accordance with the U.S. Children's Online Privacy Protection Act (COPPA) and applicable Canadian privacy law (PIPEDA, with provincial extensions where they apply, including Quebec's Law 25 and BC's PIPA):

Consent records (method, timestamp, account identity, and adult-attestation evidence) are stored in our database and can be produced on request. We do not collect consent from families for students added by a school board: any notice or consent records for those students are held by the board. You may withdraw consent at any time and request deletion of all child data (see the section below).

VoiceBloom is set up and managed by adults (parents, legal guardians, and the professionals who support a child); children do not create or control accounts. In family, clinic and therapist accounts we obtain verifiable parental consent before a child's information is used, scaled to how that information is used: we use it to operate VoiceBloom and to generate the parent's reports, we do not sell it, and we share it only with the service providers contractually bound to process it solely for us.

The 30-day free trial does not require a credit card. During the trial, verifiable parental consent (VPC) is established by the responsible adult creating and authenticating into an account they control and confirming, during onboarding, that they are the parent or legal guardian, or that they are acting under that parent's authorization. That confirmation is logged with a timestamp, the consent method, and the account identity, and can be produced on request, together with the account-holder authentication and our contractual data-use restrictions on service providers. When an account holder continues on a paid Family or Therapy plan, the payment transaction — processed through Stripe on our website, or through Apple or Google for a purchase made inside the app — adds the "monetary transaction" verification method recognised by the Federal Trade Commission's COPPA Rule (16 CFR § 312.5(b)) and a further record of who consented and when.

For an Education account in Ontario, consent is not the route by which student information reaches VoiceBloom. The school board is responsible for the student information it adds, under Ontario's Municipal Freedom of Information and Protection of Privacy Act (MFIPPA), and we act as the board's service provider. This is set out in the next subsection. For school districts in the United States, FERPA applies instead.

If a future regulatory requirement makes an even stronger verification method necessary for your jurisdiction, we will add it before further data collection and update this policy accordingly.

Students added by an Ontario school board

When an Ontario school board adds a student to VoiceBloom, the board is the institution with custody and control of that student's personal information under the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA, R.S.O. 1990, c. M.56), which names a school board as an institution in section 2(1). The board decides the purpose of the collection, gives the notice of collection required by section 29(2), and holds any consent record its own policies call for. VoiceBloom acts as the board's service provider: we use the student's information only to provide VoiceBloom to the board, on the board's instructions.

MFIPPA section 32(d) allows an institution to disclose personal information to a consultant or agent who needs the record to perform their duties, where the disclosure is also necessary and proper in the discharge of the institution's functions. Both parts have to be met. Whether a board relies on that clause for VoiceBloom is the board's own determination and depends on the agreement between us, so we do not claim that status for ourselves.

VoiceBloom is not the Ontario Student Record. Under the Education Act, R.S.O. 1990, c. E.2, section 266, a pupil record is privileged. VoiceBloom is not that record, does not replace it, and is not a system of record. If board staff save a VoiceBloom report into a student's Ontario Student Record (OSR), that copy becomes the board's record and is handled under the board's OSR procedures.

Where student information is stored. Student information from school board accounts is stored in the United States. Our database and file storage run on Amazon Web Services in the us-east-1 region through Supabase, and every serverless function that handles student information runs in the United States on Vercel (iad1). Two small functions that serve public configuration and marketing images run at the Vercel location nearest the visitor, including Montreal for Canadian visitors, and neither one handles student information. Information is encrypted in transit and at rest. We do not host student data in Canada, and a board should treat this as a transfer outside Canada when it does its own assessment.

Notice about digital technology (O. Reg. 52/26). Since July 1, 2026, Ontario Regulation 52/26 under the Enhancing Digital Security and Trust Act, 2024 requires a school board to notify the parent or guardian of a student under 16, and to notify students aged 16 and 17 themselves, about digital technology that collects their personal information, as early in the school year as is operationally feasible. That duty belongs to the board. Our part is to give the board an accurate list of what we hold: on request we will prepare and send a written student data inventory setting out the data elements, what each is used for, and the service providers involved, so the board can write its notice.

Cyber security (O. Reg. 51/26). Ontario Regulation 51/26 places cyber security duties on school boards, not on vendors, so it puts no duties on us directly. A board's duties can still reach us through its agreement with us: an incident on our side can start the board's own reporting clock. We support a board's programme by answering its security questionnaires and by telling the board about an incident that affects its students as soon as we have confirmed it.

If you are a parent and your child's profile was created by the school. The board controls that information, so ask the board first. Its privacy or freedom of information office handles access and correction requests under MFIPPA, and we help the board respond. If you are not satisfied with the board's answer, you can raise it with the Information and Privacy Commissioner of Ontario at ipc.on.ca.

Agreements. We do not ask an Ontario board to sign a United States school privacy contract. A board can work from its own information sharing agreement or privacy schedule, or we will prepare terms with the board.

School districts in the United States. FERPA (20 U.S.C. 1232g) applies to educational agencies and institutions that receive funding from the United States Department of Education. It does not apply to Ontario school boards. For a United States district, whether the district treats us as a school official with a legitimate educational interest under 34 CFR § 99.31(a)(1) is the district's own determination, and it depends on the terms we agree and the control the district keeps over the records. The district is responsible for parental notice and any direct consent its own policy requires. See our FERPA addendum for details.

Specific Uses of Child Data

Child data (communication events, session activity, profile information, and any IEP / progress notes generated) is used only to:

We do not use child data for advertising, profiling, behavioral targeting, or any secondary purpose. We do not sell child data. Our third-party service providers are contractually prohibited from using child data for any purpose other than operating VoiceBloom.

Optional Features and Opt-Out

Several features that process child data are optional and can be turned off without deleting the account: weekly progress reports, IEP note generation, Coach conversations, and therapist sharing via a linked code. You can toggle these from account settings or simply not use them.

Newsletter and product emails are separate from all of that. Every one carries an unsubscribe link at the bottom, and using it stops them immediately. You do not need to close your account or give a reason, and it does not stop the service emails you still need, such as receipts and password resets.

Child Data Handling

Every child profile is created by an adult: a parent, a clinician, or a member of school board staff. In a family or clinic account, child data (including names, ages, communication levels, and session activity) is associated with that adult account and subject to the adult's data rights. A profile created by a school board belongs to the board's account rather than to a family account, and the board controls it.

Withdrawing Consent for Child Data

You may withdraw consent for your child's data at any time by:

Withdrawing consent will result in the permanent deletion of your child's communication data, session history, and progress reports. This action cannot be undone.

If you believe we have inadvertently collected personal data directly from a child under 13, please contact us at info@voicebloom.ca and we will delete it promptly.

6. HIPAA (Therapy and Education Plans)

VoiceBloom is not a system of record for clinical care, electronic health records, or medical billing. Therapists, clinics, and organizations who use VoiceBloom must maintain their primary clinical documentation in their own HIPAA-compliant or otherwise appropriate records system. VoiceBloom is intended as a collaboration and progress-sharing tool, not a substitute for an EHR.

That said, VoiceBloom is built on HIPAA-eligible infrastructure. Our providers Supabase and Vercel both support Business Associate Agreements (BAAs) for healthcare use cases.

To discuss HIPAA requirements or request a BAA, email info@voicebloom.ca.

7. Data Sharing

We do not sell, rent, or trade your personal information. We share data only with the following third-party service providers, solely to operate VoiceBloom:

We may disclose information if required by law, court order, or to protect the safety of any person.

8. Data Retention

You can trigger the 30-day deletion window yourself at any time from account settings → "Delete my account". See section 9 below for the full self-service flow.

9. Your Data Rights

Under PIPEDA, GDPR, and CCPA, you have the following rights over your personal data:

If your child's profile was created by an Ontario school board, the board controls that information under MFIPPA. Send access and correction requests to the board, and we will help the board respond. See Students added by an Ontario school board.

How to Exercise Your Rights

We have built self-service tools so you can exercise your rights immediately:

We respond to all data rights requests within 30 days. For full details about your rights, see our Your Privacy Rights page.

10. Cookies

VoiceBloom uses essential cookies required for authentication (keeping you logged in) and security. With your consent, we also set optional analytics cookies (Vercel Analytics, Google Analytics, and HeyCatch) to understand how the site is used. You can decline these by choosing "Essentials only" in the cookie banner, and you can change your choice at any time using "Manage cookies" in the footer. We do not use advertising cookies, and we do not use cookies for cross-site advertising or behavioral targeting. The apps do not use cookies for analytics.

11. Security

We protect your data using industry-standard safeguards including TLS encryption in transit, encryption at rest provided by our infrastructure providers, and row-level access controls ensuring users can only access their own data. Our infrastructure providers hold SOC 2 Type II certifications. For full details, see our Security and Compliance page.

Despite these measures, no internet transmission is 100% secure. If you suspect your account has been compromised, please contact us immediately.

12. International Transfers

VoiceBloom is a Canadian business, and our data is stored in the United States. Our database and file storage are hosted on Amazon Web Services in the us-east-1 region through Supabase, and our serverless functions that handle account and child data run on Vercel in the United States (iad1). Stripe and most of our other service providers are in the United States as well. This includes student information from school board accounts. Each provider is bound by contract to protect that information and to use it only to operate VoiceBloom for us, with safeguards consistent with PIPEDA requirements. For users in the European Economic Area (EEA) or UK, transfers are governed by Standard Contractual Clauses.

13. Changes to This Policy

We will notify you of material changes to this policy by email and by posting a notice in the app at least 14 days before changes take effect. Your continued use of VoiceBloom after changes take effect constitutes acceptance of the updated policy.

14. Contact Us

VoiceBloom is operated by a Canadian business. Counter-party legal details (registered business name, BIN, CRA numbers) are provided on signed agreements upon request.

Privacy Officer / data requests: info@voicebloom.ca
General / support: info@voicebloom.ca
HIPAA / BAA requests: info@voicebloom.ca
EU / UK GDPR representative: to be appointed and listed before public launch in EU/UK markets

You also have the right to lodge a complaint with the Office of the Privacy Commissioner of Canada (priv.gc.ca), and, depending on your residence, your local data protection authority (e.g., your EU supervisory authority for GDPR matters, the ICO in the UK, or the California Privacy Protection Agency for CCPA matters). If your child's profile was created by an Ontario school board, raise your concern with the board first, and then with the Information and Privacy Commissioner of Ontario (ipc.on.ca).