Security and Compliance
How we protect your child's data, where it is stored, and the rules that apply.
VoiceBloom is built for families and children. Your data is encrypted, never sold, and protected by industry-leading standards.
All traffic to VoiceBloom is encrypted in transit via HTTPS with TLS 1.2+. Data at rest is encrypted by our infrastructure providers: Supabase encrypts all database storage and Vercel encrypts static assets. Both providers hold SOC 2 Type II certifications. Payment data is handled entirely by Stripe and never touches VoiceBloom servers.
VoiceBloom enforces strict security headers including HSTS, X-Frame-Options, and Content-Type protection on all pages.
VoiceBloom is a Canadian business, and our data is stored in the United States. Our database and sign-in service run on Supabase, hosted on Amazon Web Services in Northern Virginia (us-east-1). The functions that handle student information, including the ones that build reports and exports, run on Vercel in Washington, D.C. (iad1). Two small functions that serve public configuration and marketing images run in the Vercel region nearest the visitor, and they carry no student information. Data is encrypted in transit with TLS and encrypted at rest. This applies to student information in school board accounts as well as to family and clinic accounts. We do not offer Canadian hosting today, so if data location matters to your organisation, please raise it with us before you sign anything.
VoiceBloom is not a system of record for clinical care, electronic health records, or medical billing. Therapists, clinics, and organizations who use VoiceBloom must maintain their primary clinical documentation in their own HIPAA-compliant or otherwise appropriate records system.
VoiceBloom is built on HIPAA-eligible infrastructure. Supabase and Vercel both offer Business Associate Agreements (BAAs) for healthcare use cases. If your practice or organisation requires a BAA, contact info@voicebloom.ca and we will work with you to put the appropriate agreements in place.
VoiceBloom uses Supabase Row Level Security (RLS) on every database table. RLS policies ensure that users can only read and modify their own data, including profiles, subscriptions, child profiles, sessions, symbol taps, weekly reports, billing events, and consent records. All API keys are stored in environment variables and never exposed in client-side code.
VoiceBloom is a Canadian business. We follow the Personal Information Protection and Electronic Documents Act (PIPEDA) for the personal information we control, which means family and clinic accounts. For school board accounts, the board remains responsible for student information under Ontario's Municipal Freedom of Information and Protection of Privacy Act (MFIPPA), and we act as the board's service provider. Our practices include:
- Express parental consent collected during family onboarding before any child data is processed, with a timestamped record
- Students added by a school board are covered by the board's agreement with us instead, so we hold no parental consent record authorising the collection of their information. The one consent we do record for a board student is a guardian's confirmation, with a timestamp, that they want the daily progress email
- Self-service data export (download all your data as JSON)
- Self-service account deletion (permanently removes all data)
- Mandatory breach reporting procedures in place
- Privacy Officer contactable at info@voicebloom.ca
For full details, see our Privacy Policy and Your Privacy Rights page.
For a public school board in Ontario, the board is the institution with custody and control of student personal information under the Municipal Freedom of Information and Protection of Privacy Act, R.S.O. 1990, c. M.56. The definition of "institution" in section 2(1) names a school board directly. The board decides the purpose of the collection, gives the notice of collection set out in section 29(2), and holds any consent record. VoiceBloom acts as the board's service provider and handles student information on the board's instructions.
Section 32(d) of MFIPPA allows a board to disclose personal information to an officer, employee, consultant or agent of the institution who needs the record in the performance of their duties, where the disclosure is also necessary and proper in the discharge of the board's functions. Both parts have to be met. Whether a board relies on that clause for VoiceBloom is the board's own determination and depends on the agreement between us, so we do not claim that status for ourselves.
VoiceBloom is not the Ontario Student Record. A pupil record kept under clause 265(1)(d) of the Education Act, R.S.O. 1990, c. E.2, is privileged under section 266 of that Act. VoiceBloom does not replace that record and is not a system of record. If board staff save a VoiceBloom report into a student's OSR, that copy becomes the board's record under the Education Act, and the board's OSR rules apply to it from then on.
Notices under O. Reg. 52/26. Since 1 July 2026, a board has to notify the parent or guardian of a student under 16 when the student's personal digital information will be disclosed to a third-party app operator such as VoiceBloom. The notice names the data elements, the legal authority, the purpose, the app and its operator, a board contact, and the family's rights, and it goes out as early in the school year as is operationally feasible. Students aged 16 and 17 are notified themselves. That duty belongs to the board. Our part is to give the board an accurate list of what we hold: ask us and we will put together a written list of every data element we store for a student, why we hold it, and who can see it.
Cyber security under O. Reg. 51/26. That regulation places duties on school boards, not on vendors, so it puts no duties on us directly. A board's duties can still reach us through its agreement with us: an incident on our side can start the board's own reporting clock. We support a board's programme in the ways a vendor can: we answer security questionnaires, and we report incidents affecting a board's students to the board promptly so the board can meet its own reporting deadlines.
Student data from board accounts is stored in the United States, as set out above, and school staff see school-hours activity only. Our privacy policy sets all of this out in full under students added by an Ontario school board. School districts in the United States are covered by a different law: see our FERPA addendum page.
VoiceBloom respects your data rights under GDPR and CCPA. You can download all of your personal data or permanently delete your account directly from your account settings. You can also request access, corrections, or deletion by emailing info@voicebloom.ca. We respond to all requests within 30 days.
VoiceBloom is designed for use by adults (parents, therapists, teachers) on behalf of children. All accounts are created and managed by adults. For family accounts, we require express parental consent during onboarding before collecting any child data. For students added by a school board, the board handles notice and any consent under its own policies, and we act on the board's instructions. We do not knowingly collect personal data directly from children under 13 without parental authorisation, in accordance with COPPA guidelines.
VoiceBloom relies on the following trusted third-party providers:
| Provider | Purpose | Certifications |
|---|---|---|
| Supabase | Database and authentication | SOC 2 Type II |
| Vercel | Hosting and edge delivery | SOC 2 Type II |
| Stripe | Payment processing | PCI DSS Level 1 |
| Anthropic | Cloud processing (Claude) | Data not used for training |
| Resend | Email delivery | — |
VoiceBloom maintains a comprehensive breach response plan in accordance with PIPEDA's mandatory breach reporting requirements.
1. Detection and assessment. We monitor our systems for unauthorised access. When a potential breach is identified, we immediately assess the scope, severity, and type of data affected.
2. Containment. Affected systems are isolated, compromised credentials are revoked, and vulnerabilities are patched to prevent further exposure.
3. Notification. If a breach creates a real risk of significant harm, we will notify affected users and report the incident to the Privacy Commissioner of Canada as soon as feasible, the standard PIPEDA s.10.1 sets. Notifications include what happened, what data was affected, and the steps we are taking in response. If a breach affects students from a school board account, we notify the board without delay so that it can meet its own obligations, including its reporting duties under Ontario law.
4. Contact. If you believe your account has been compromised or you have a security concern, contact us immediately at info@voicebloom.ca.
Read our complete Data Breach Response Plan for full procedural details.