Security and Compliance

How we protect your child's data, where it is stored, and the rules that apply.

VoiceBloom is built for families and children. Your data is encrypted, never sold, and protected by industry-leading standards.

PIPEDA Followed
COPPA Built to meet
GDPR Rights supported
HIPAA Eligible infrastructure
Data location United States (AWS us-east-1)
Data Security

All traffic to VoiceBloom is encrypted in transit via HTTPS with TLS 1.2+. Data at rest is encrypted by our infrastructure providers: Supabase encrypts all database storage and Vercel encrypts static assets. Both providers hold SOC 2 Type II certifications. Payment data is handled entirely by Stripe and never touches VoiceBloom servers.

VoiceBloom enforces strict security headers including HSTS, X-Frame-Options, and Content-Type protection on all pages.

Where your data is stored

VoiceBloom is a Canadian business, and our data is stored in the United States. Our database and sign-in service run on Supabase, hosted on Amazon Web Services in Northern Virginia (us-east-1). The functions that handle student information, including the ones that build reports and exports, run on Vercel in Washington, D.C. (iad1). Two small functions that serve public configuration and marketing images run in the Vercel region nearest the visitor, and they carry no student information. Data is encrypted in transit with TLS and encrypted at rest. This applies to student information in school board accounts as well as to family and clinic accounts. We do not offer Canadian hosting today, so if data location matters to your organisation, please raise it with us before you sign anything.

HIPAA

VoiceBloom is not a system of record for clinical care, electronic health records, or medical billing. Therapists, clinics, and organizations who use VoiceBloom must maintain their primary clinical documentation in their own HIPAA-compliant or otherwise appropriate records system.

VoiceBloom is built on HIPAA-eligible infrastructure. Supabase and Vercel both offer Business Associate Agreements (BAAs) for healthcare use cases. If your practice or organisation requires a BAA, contact info@voicebloom.ca and we will work with you to put the appropriate agreements in place.

Access Controls

VoiceBloom uses Supabase Row Level Security (RLS) on every database table. RLS policies ensure that users can only read and modify their own data, including profiles, subscriptions, child profiles, sessions, symbol taps, weekly reports, billing events, and consent records. All API keys are stored in environment variables and never exposed in client-side code.

PIPEDA

VoiceBloom is a Canadian business. We follow the Personal Information Protection and Electronic Documents Act (PIPEDA) for the personal information we control, which means family and clinic accounts. For school board accounts, the board remains responsible for student information under Ontario's Municipal Freedom of Information and Protection of Privacy Act (MFIPPA), and we act as the board's service provider. Our practices include:

For full details, see our Privacy Policy and Your Privacy Rights page.

Ontario school boards

For a public school board in Ontario, the board is the institution with custody and control of student personal information under the Municipal Freedom of Information and Protection of Privacy Act, R.S.O. 1990, c. M.56. The definition of "institution" in section 2(1) names a school board directly. The board decides the purpose of the collection, gives the notice of collection set out in section 29(2), and holds any consent record. VoiceBloom acts as the board's service provider and handles student information on the board's instructions.

Section 32(d) of MFIPPA allows a board to disclose personal information to an officer, employee, consultant or agent of the institution who needs the record in the performance of their duties, where the disclosure is also necessary and proper in the discharge of the board's functions. Both parts have to be met. Whether a board relies on that clause for VoiceBloom is the board's own determination and depends on the agreement between us, so we do not claim that status for ourselves.

VoiceBloom is not the Ontario Student Record. A pupil record kept under clause 265(1)(d) of the Education Act, R.S.O. 1990, c. E.2, is privileged under section 266 of that Act. VoiceBloom does not replace that record and is not a system of record. If board staff save a VoiceBloom report into a student's OSR, that copy becomes the board's record under the Education Act, and the board's OSR rules apply to it from then on.

Notices under O. Reg. 52/26. Since 1 July 2026, a board has to notify the parent or guardian of a student under 16 when the student's personal digital information will be disclosed to a third-party app operator such as VoiceBloom. The notice names the data elements, the legal authority, the purpose, the app and its operator, a board contact, and the family's rights, and it goes out as early in the school year as is operationally feasible. Students aged 16 and 17 are notified themselves. That duty belongs to the board. Our part is to give the board an accurate list of what we hold: ask us and we will put together a written list of every data element we store for a student, why we hold it, and who can see it.

Cyber security under O. Reg. 51/26. That regulation places duties on school boards, not on vendors, so it puts no duties on us directly. A board's duties can still reach us through its agreement with us: an incident on our side can start the board's own reporting clock. We support a board's programme in the ways a vendor can: we answer security questionnaires, and we report incidents affecting a board's students to the board promptly so the board can meet its own reporting deadlines.

Student data from board accounts is stored in the United States, as set out above, and school staff see school-hours activity only. Our privacy policy sets all of this out in full under students added by an Ontario school board. School districts in the United States are covered by a different law: see our FERPA addendum page.

GDPR and CCPA

VoiceBloom respects your data rights under GDPR and CCPA. You can download all of your personal data or permanently delete your account directly from your account settings. You can also request access, corrections, or deletion by emailing info@voicebloom.ca. We respond to all requests within 30 days.

Children's Privacy

VoiceBloom is designed for use by adults (parents, therapists, teachers) on behalf of children. All accounts are created and managed by adults. For family accounts, we require express parental consent during onboarding before collecting any child data. For students added by a school board, the board handles notice and any consent under its own policies, and we act on the board's instructions. We do not knowingly collect personal data directly from children under 13 without parental authorisation, in accordance with COPPA guidelines.

Third-Party Providers

VoiceBloom relies on the following trusted third-party providers:

Provider Purpose Certifications
Supabase Database and authentication SOC 2 Type II
Vercel Hosting and edge delivery SOC 2 Type II
Stripe Payment processing PCI DSS Level 1
Anthropic Cloud processing (Claude) Data not used for training
Resend Email delivery —
Data Breach Response Plan

VoiceBloom maintains a comprehensive breach response plan in accordance with PIPEDA's mandatory breach reporting requirements.

1. Detection and assessment. We monitor our systems for unauthorised access. When a potential breach is identified, we immediately assess the scope, severity, and type of data affected.

2. Containment. Affected systems are isolated, compromised credentials are revoked, and vulnerabilities are patched to prevent further exposure.

3. Notification. If a breach creates a real risk of significant harm, we will notify affected users and report the incident to the Privacy Commissioner of Canada as soon as feasible, the standard PIPEDA s.10.1 sets. Notifications include what happened, what data was affected, and the steps we are taking in response. If a breach affects students from a school board account, we notify the board without delay so that it can meet its own obligations, including its reporting duties under Ontario law.

4. Contact. If you believe your account has been compromised or you have a security concern, contact us immediately at info@voicebloom.ca.

Read our complete Data Breach Response Plan for full procedural details.