Skip to main content
SDP Companion
Back to budget

Draft, not yet adopted

This page describes what SDP Companion actually does today. It has not yet been reviewed and signed off by Beth or SDTA's counsel, and it is not yet available in Spanish. Do not treat it as SDTA's adopted privacy policy until both of those are done.

SDP Companion Privacy Policy

Status: Draft, under review

Owner: Self-Determination Tech Alliance (SDTA), a California 501(c)(3) nonprofit

Contact: support@sdta-np.com

If you read nothing else

1. Who we are and what SDP Companion is

SDP Companion is built and operated by the Self-Determination Tech Alliance ("SDTA"), a California 501(c)(3) nonprofit. It helps people enrolled in California's Self-Determination Program (SDP) understand and manage their Individual Budget: track spending, upload FMS statements, build a Spending Plan, and get plain-language guidance on proposed changes.

This policy explains what information SDP Companion collects, how it is used and protected, who can see it, and what choices you have. It does not cover DAN, SDTA's separate free navigation tool, which has its own privacy policy.

2. Two ways to store your information, chosen by you

Before you enter any information, SDP Companion asks you to choose one of two storage tiers. You can move from Local Tier to Cloud Tier later; there is currently no path back the other way.

Local Tier (on this device only)

Everything you enter, your Individual Budget amount, your Spending Plan, your payment records, your notes, is stored in your browser's own storage on your device (a technology called IndexedDB). No account is created. SDTA's servers never receive this information. The only things SDP Companion still fetches from a server on Local Tier are the shared reference information everyone sees (service categories, current program rules) and, if you use it, the AI advisor (see Section 4). If you clear your browser data or lose the device, this information is gone unless you exported a backup yourself.

Cloud Tier (account required)

If you create an account (email and password), your budget, Spending Plan, transactions, and advisor interaction history are stored on SDTA's behalf by Supabase, our database provider, so you can sign in from more than one device. Row-level security rules enforce that your account can only read and write your own rows; SDTA staff do not browse participant data as a matter of course.

3. What we collect and keep (Cloud Tier)

On Cloud Tier, your account holds:

A support facilitator you invite to see your information is a planned feature. It is not available yet: today, only you can see your Cloud Tier data.

4. The AI advisor: what we send, and what we do not

When you ask the advisor about a proposed Spending Plan change, or ask for help with a flagged budget issue, SDP Companion sends a request to Anthropic's Claude language model to generate a response. That request is built server-side and contains only:

It never includes your name, your Regional Center or FMS contact information, your provider names, or your transaction history. Anthropic processes this text to generate a response and, under our API agreement, does not use it to train models or retain it beyond the time needed to respond.

If you are on Cloud Tier, the proposed change and the advisor's response are saved to your account afterward, as described in Section 3, so you can look back at past guidance.

5. FMS statements and other documents you upload

When you upload an FMS statement, Regional Center budget letter, or Spending Plan file (PDF or spreadsheet), SDP Companion reads and extracts the information entirely in your own browser. The file itself is never uploaded to a server. Only the payment records, dates, and amounts you review and confirm are saved, to your device (Local Tier) or your account (Cloud Tier), the same as if you had typed them in by hand.

6. What we deliberately do not do

7. Third parties that help us run SDP Companion

ProviderWhat they doWhat they receive
AnthropicPowers the AI advisorThe minimum-necessary advisor request described in Section 4, for the time needed to generate a response
SupabaseStores Cloud Tier accounts and data; handles sign-inThe information described in Section 3, for Cloud Tier users only
Google Cloud RunHosts the SDP Companion applicationStandard web traffic; no Participant Data is stored at this layer

Local Tier information never reaches any of these providers except Anthropic, and only when you use the advisor.

8. Who can see your information

On Local Tier, only you, on your own device. On Cloud Tier, only you, enforced by database rules that restrict your account to your own rows. A small number of SDTA staff have the technical ability to access the Cloud Tier database for maintenance and support, but do not browse participant data as a matter of course.

9. How long we keep information

On Local Tier, your information stays on your device until you delete it, clear your browser, or lose the device. On Cloud Tier, your information is kept for as long as your account is open. If you delete your account (Settings), it and everything in it are deleted, not retained.

10. Your choices

11. How we handle a data incident

In the event of a security incident affecting Cloud Tier information, SDTA will take reasonable steps in accordance with applicable California law, including California Civil Code §1798.82. We will notify the SDTA Board promptly, notify affected account holders without unreasonable delay describing what happened and what to do, contain the incident, and notify the California Attorney General if it affects more than 500 California residents, as required by law.

12. Children

SDP Companion is designed for adult SDP participants and the adults who support them. It is not directed to children, and we do not knowingly collect information directly from children. When a parent or family member uses SDP Companion on behalf of a minor participant, the information they enter is information about the participant supplied by the adult user, not information collected from a child.

13. Changes to this policy

We will review this policy annually and whenever we add or remove a data processor, begin collecting a new category of information, change how long we retain information, or a material change in applicable law requires it. Material changes will be posted here with an updated effective date.

14. Contact

Questions, deletion requests, or other privacy-related requests: support@sdta-np.com

Glossary

Ask DANFree, bilingual answers about your Regional Center, any hour (opens in a new tab)