lightningSPED Privacy Notice
Effective date: August 3, 2026. Material changes to this notice are announced prominently in advance — see “Changes to this notice.”
LightningSPED — a service operated by SageWorks Inc., a Delaware corporation — provides special-education case management, data collection, and compliance tooling to school districts. This notice explains what data we handle, how we use it, and the rights that attach to it, as required by Washington’s Student User Privacy in Education Rights Act (RCW 28A.604.020).
Two kinds of data, two sets of rules
Student data. School districts provide us with student education records so we can perform services on their behalf. We act as a “school official” under FERPA (34 CFR 99.31(a)(1)) at each district’s direction, under a signed data privacy agreement (we offer the SDPC National Data Privacy Agreement v2.2 with the Washington exhibit). Where this notice and a district’s signed agreement differ, the signed agreement governs for that district’s student data. This notice never expands what we may do with student data.
Staff and account data. Districts also provide staff rosters (names, work emails, roles) so school personnel can sign in and be authorized. This is not student data; we use it only to operate the service.
Student data we collect
Only what districts provide or their staff enter in the course of the services (the complete element-level inventory is disclosed to districts at signature as NDPA Exhibit B):
- Enrollment and demographic information, including name, date of birth, student identifiers, school, and grade
- Special-education records: IEPs, evaluations, eligibility, services, placements, and district-uploaded documents (which may include health-related and behavioral-health information)
- Instructional goals, objectives, progress-monitoring and data-collection results, and behavior observations
- Staff notes related to service delivery
- Parent/guardian contact information
- The record of access: who viewed each student’s record, when, and for what purpose (itself part of the education record, inspectable by parents through the district)
How we use student data
Solely to provide the contracted services to the district. That includes AI-assisted processing: we use Anthropic’s Claude API to extract structured data from district-provided IEP documents and to help draft and revise IEP goals, objectives, and instructional content. This processing uses student information as each function requires: document extraction processes the full document; drafting and revising a student’s goals and objectives uses records that identify the student; reusable instructional materials are generated from de-identified facts only. Anthropic is contractually prohibited from training AI models on this data and deletes API inputs and outputs within 30 days (content flagged by its automated safety systems may be retained up to 2 years for abuse prevention).
We do not:
- Sell student data, ever (RCW 28A.604.030)
- Use student data for targeted advertising, or any advertising
- Profile students except as needed for the authorized educational purposes in the district’s agreement
- Use student data — even de-identified — for product improvement, analytics, or model training
- Collect student data directly from students (districts and their staff are the only sources)
Who receives student data
Subprocessors that host or process data to deliver the service, each bound by contract to purpose limitation and no onward sale: Supabase (database and document storage), Vercel (application hosting), WorkOS (authentication and authorization), and Anthropic (AI processing, as described above). Our transactional-email and telemetry providers receive no student data. The current subprocessor list with data categories is available to districts on request and disclosed at signature. Beyond subprocessors: only the district itself, and disclosures required by law.
Parent and guardian rights
Parents (and adult students after rights transfer) exercise their rights through their school district, which owns the education record: full record inspection, correction/amendment requests, statements of disagreement, and destruction requests. The product gives districts the tools to honor each of these, including a complete printable education record and the per-student access log. If a parent contacts us directly, we refer them to their district and support the district’s response.
Retention and deletion
Student data is retained per each district’s instructions and Washington’s K-12 records-retention schedule, and destroyed on district request — including full return/deletion within 60 days at contract end, certified in writing. We never auto-delete education records without district action.
Security
Safeguards include encryption in transit and at rest, role- and record-level access control with row-level security backstops, an append-only log of every access to a student record, audit trails on every change, and production access limited to named personnel. Our written security program follows CIS Controls v8 and is available to districts, with our annual self-assessment, under NDA on request.
Changes to this notice
Material changes are announced prominently — on this page and by direct notice to district contacts — at least 30 days before they take effect (RCW 28A.604.020). We do not make material changes to how student data is handled during a district’s term without the agreement’s amendment process.
Contact
Privacy and security contact: Jonathan Geibel, Founder — privacy@swcollective.com. Districts may also use their designated support channel.