Draft, not yet adopted
This page describes what SDP Companion actually does today. It has not yet been reviewed and signed off by Beth or SDTA's counsel, and it is not yet available in Spanish. Do not treat it as SDTA's adopted privacy policy until both of those are done.
SDP Companion Privacy Policy
Status: Draft, under review
Owner: Self-Determination Tech Alliance (SDTA), a California 501(c)(3) nonprofit
Contact: support@sdta-np.com
If you read nothing else
- You choose, when you first set up SDP Companion, whether your information stays only on your device (Local Tier) or is saved to an account so you can use it from more than one device (Cloud Tier). This choice changes everything else on this page.
- On Local Tier, your budget, Spending Plan, and payment records never leave your device. There is nothing for SDTA to see, because SDTA's servers never receive it.
- On Cloud Tier, that same information is stored securely so you can sign in from another device. Only you can see it.
- When you ask the AI advisor a question, we send it only the proposed change, the affected service's name and dollar amounts, and your FMS model. We do not send your name, your Regional Center or FMS contact information, or your payment history.
- Any FMS statement, budget letter, or Spending Plan file you upload is read and processed on your own device. The file itself is never uploaded to a server.
- We do not use cookies or any tool to track you across other websites, and we do not sell or share your information with advertisers.
- If you are on Cloud Tier, you can delete your account at any time. Deleting it deletes your information; it does not sit around afterward.
1. Who we are and what SDP Companion is
SDP Companion is built and operated by the Self-Determination Tech Alliance ("SDTA"), a California 501(c)(3) nonprofit. It helps people enrolled in California's Self-Determination Program (SDP) understand and manage their Individual Budget: track spending, upload FMS statements, build a Spending Plan, and get plain-language guidance on proposed changes.
This policy explains what information SDP Companion collects, how it is used and protected, who can see it, and what choices you have. It does not cover DAN, SDTA's separate free navigation tool, which has its own privacy policy.
2. Two ways to store your information, chosen by you
Before you enter any information, SDP Companion asks you to choose one of two storage tiers. You can move from Local Tier to Cloud Tier later; there is currently no path back the other way.
Local Tier (on this device only)
Everything you enter, your Individual Budget amount, your Spending Plan, your payment records, your notes, is stored in your browser's own storage on your device (a technology called IndexedDB). No account is created. SDTA's servers never receive this information. The only things SDP Companion still fetches from a server on Local Tier are the shared reference information everyone sees (service categories, current program rules) and, if you use it, the AI advisor (see Section 4). If you clear your browser data or lose the device, this information is gone unless you exported a backup yourself.
Cloud Tier (account required)
If you create an account (email and password), your budget, Spending Plan, transactions, and advisor interaction history are stored on SDTA's behalf by Supabase, our database provider, so you can sign in from more than one device. Row-level security rules enforce that your account can only read and write your own rows; SDTA staff do not browse participant data as a matter of course.
3. What we collect and keep (Cloud Tier)
On Cloud Tier, your account holds:
- Your email address and password (Supabase handles authentication; SDTA does not see your password)
- Your profile: Regional Center name, FMS provider name, FMS model, and (if you use a future facilitator-sharing feature) a linked facilitator email
- Your budget cycles: start and end dates and your Individual Budget amount
- Your Spending Plan: service categories, provider names, and authorized amounts
- Your transactions: the payment records you upload or enter by hand
- Your AI advisor interaction history: the change you proposed, the advisor's classification and response, kept for your own records
- Your display and alert settings (text size, contrast, warning thresholds)
A support facilitator you invite to see your information is a planned feature. It is not available yet: today, only you can see your Cloud Tier data.
4. The AI advisor: what we send, and what we do not
When you ask the advisor about a proposed Spending Plan change, or ask for help with a flagged budget issue, SDP Companion sends a request to Anthropic's Claude language model to generate a response. That request is built server-side and contains only:
- The change you described, in your own words
- The affected service category's name, its authorized amount, and the amount spent so far (or a plain-language description of the flagged issue)
- Your FMS model (Bill Payer, Co-Employer, or Sole Employer), because some guidance differs by model
It never includes your name, your Regional Center or FMS contact information, your provider names, or your transaction history. Anthropic processes this text to generate a response and, under our API agreement, does not use it to train models or retain it beyond the time needed to respond.
If you are on Cloud Tier, the proposed change and the advisor's response are saved to your account afterward, as described in Section 3, so you can look back at past guidance.
5. FMS statements and other documents you upload
When you upload an FMS statement, Regional Center budget letter, or Spending Plan file (PDF or spreadsheet), SDP Companion reads and extracts the information entirely in your own browser. The file itself is never uploaded to a server. Only the payment records, dates, and amounts you review and confirm are saved, to your device (Local Tier) or your account (Cloud Tier), the same as if you had typed them in by hand.
6. What we deliberately do not do
- We do not use cookies or any tool to track you across other websites
- We do not sell or rent your information
- We do not share your information with advertisers
- We do not send your information to Regional Centers, DDS, or any other government agency
- We do not use your conversations with the advisor to train AI models
- We do not currently collect any payment information. If SDP Companion adds a paid tier, this policy will be updated to describe exactly what changes before that happens, not after
7. Third parties that help us run SDP Companion
| Provider | What they do | What they receive |
|---|---|---|
| Anthropic | Powers the AI advisor | The minimum-necessary advisor request described in Section 4, for the time needed to generate a response |
| Supabase | Stores Cloud Tier accounts and data; handles sign-in | The information described in Section 3, for Cloud Tier users only |
| Google Cloud Run | Hosts the SDP Companion application | Standard web traffic; no Participant Data is stored at this layer |
Local Tier information never reaches any of these providers except Anthropic, and only when you use the advisor.
8. Who can see your information
On Local Tier, only you, on your own device. On Cloud Tier, only you, enforced by database rules that restrict your account to your own rows. A small number of SDTA staff have the technical ability to access the Cloud Tier database for maintenance and support, but do not browse participant data as a matter of course.
9. How long we keep information
On Local Tier, your information stays on your device until you delete it, clear your browser, or lose the device. On Cloud Tier, your information is kept for as long as your account is open. If you delete your account (Settings), it and everything in it are deleted, not retained.
10. Your choices
- Local Tier: export a backup file at any time (Settings), and import it to restore or move to a new device
- Cloud Tier: view and correct your account email and password at any time (Settings)
- Cloud Tier: delete your account at any time (Settings); this permanently deletes your account and everything in it
- Move from Local Tier to Cloud Tier at any time (Settings); your Local Tier data is copied to your new account and then cleared from the device
11. How we handle a data incident
In the event of a security incident affecting Cloud Tier information, SDTA will take reasonable steps in accordance with applicable California law, including California Civil Code §1798.82. We will notify the SDTA Board promptly, notify affected account holders without unreasonable delay describing what happened and what to do, contain the incident, and notify the California Attorney General if it affects more than 500 California residents, as required by law.
12. Children
SDP Companion is designed for adult SDP participants and the adults who support them. It is not directed to children, and we do not knowingly collect information directly from children. When a parent or family member uses SDP Companion on behalf of a minor participant, the information they enter is information about the participant supplied by the adult user, not information collected from a child.
13. Changes to this policy
We will review this policy annually and whenever we add or remove a data processor, begin collecting a new category of information, change how long we retain information, or a material change in applicable law requires it. Material changes will be posted here with an updated effective date.
14. Contact
Questions, deletion requests, or other privacy-related requests: support@sdta-np.com
Glossary
- FMS: Financial Management Services, the company that processes payments in the Self-Determination Program
- Individual Budget: the total annual dollar amount DDS authorizes for an SDP participant
- Regional Center (RC): the agency that authorizes services and oversees the SDP for each participant
- SDP: Self-Determination Program, the California program that lets eligible Regional Center clients direct their own services through an Individual Budget
- SDTA: Self-Determination Tech Alliance, the nonprofit that operates SDP Companion
- Spending Plan: the document that breaks the Individual Budget into service categories
