Stug Connect Privacy Notice
JDIV Studios LLC · connect.jdivstudios.com
Effective date: September 26, 2026 Version: 1.0
1. About this notice
This Privacy Notice explains how JDIV Studios LLC (“JDIV Studios”, “we”, “us” or “our”) handles personal information in Stug Connect, the web portal at connect.jdivstudios.com, and in the emails and support we provide with it (together, the “Service”). Words with capitals, such as Practice, Authorized User and Student Data, have the meanings given in the Stug Connect Terms of Service.
We handle two kinds of information, in two different roles:
- Information about you, the professionals who use Stug Connect. We decide how this is used, as this notice describes.
- Student Data, which Practices put into the Service or receive through Linking. We generally process Student Data on behalf of the applicable Practice and in accordance with its instructions, our agreements with the Practice, and applicable law, including as necessary to operate, secure, maintain and support the Service. The Practice decides what goes in and who on its team can see it.
This notice doesn’t cover the Stug app (“Stug – Your Speech Companion!”) that families use. The app’s own Privacy Policy explains what it collects and what a family agrees to share when it links to a Practice.
2. Information about you that we collect
Account details. Your email address, an optional display name, your role (owner or member), your Practice’s name, and when your account was created and last used. Authentication is provided through Google Identity Platform. We do not receive or store your plaintext password.
2-step verification. If you turn on an authenticator app, we store the secret that links it to your account, encrypted.
Your team. Invitations you send or accept (the invited email address and a scrambled, single-use code) and a team log recording when people join, leave or are removed, by account ID and time only.
Billing. Payments are handled by Stripe. You enter your card details and billing address on Stripe’s own pages, and your card details never reach us. We give Stripe only your Practice’s name, the owner’s email address, an internal Practice ID and the number of Seats, and never any Student information: no Student label, ID, result or anything from a session, in any field. Stripe tells us your subscription status and billing period, and we can see your billing address and invoices in our Stripe account. To limit free trials to one per person, we keep a scrambled (hashed) form of the email address that started a trial. When you sign up, we record which versions of the Terms of Service and this notice you accepted and when, your confirmation that your Practice is based in the United States, and your agreement to automatic renewal. Once you have paid, we also record the country of your billing address and of your card (not the address or the card number) to confirm that the Service is used by U.S.-based Practices.
Support. Messages you send us through the portal and our replies, and whether you want an email when we reply.
Security records. When something security-relevant happens, such as repeated wrong codes or a rate limit being hit, we record what happened, the account ID and email address involved, the Practice and the time. We never record the code that was tried or any Student Data. Our staff’s own actions in our admin tools are also logged.
Technical information. Like most websites, the services that host the portal receive your IP address, browser and device details when you use it, and keep them in logs used to run and secure the Service: the web host’s request logs for about a day, and Google Cloud’s logs for up to 2 years (see Section 8).
Bot protection. To keep automated abuse out, the portal’s sign-in, sign-up and verification pages use Google reCAPTCHA Enterprise and Firebase App Check, which may collect or process information about your device, browser and interactions with the page for fraud-prevention and security purposes, and send it to Google. They don’t run on any page that shows Student information. Google’s Privacy Policy (policies.google.com/privacy) and Terms of Service (policies.google.com/terms) apply to that use.
3. Student Data
What it includes. Stug Connect is built to work without knowing who a Student is. A Student record holds:
- the label the clinician chooses, such as initials or a number (“A.M.” or “Student 4”);
- an age band (toddler, early reader or fluent) and, if the clinician chooses one, a speech category (stutter, apraxia, dysarthria, lisp or clutter);
- the Student’s status (invited, linked or unlinked) and which clinicians on the team can see them;
- once a family links, the results of practice in the Stug app: the word practiced, the sound or letter targeted and its position, the result, the attempt number, the time, where in the app it happened, how long it took and the app version, plus daily totals worked out from those results; and
- a record of each time a parent or guardian agreed to link or a link was ended: when, how consent was given, which version of the consent wording was shown, and the app version.
We don’t collect a Student’s name, date of birth, address, contact details, photos, location or voice recordings, and our database rejects name, date of birth and email fields on Student records. Progress reports are created in the clinician’s web browser and downloaded to their own computer; we don’t keep a copy. Leaving names out reduces what we hold, but for a Practice covered by HIPAA we treat all Student Data as protected health information (see Section 11). We apply the protections described in this notice to Student Data regardless of whether the Practice is subject to HIPAA. Where additional federal or state health-privacy requirements apply, we process Student Data in accordance with those requirements and our agreement with the Practice.
How it is used. Only to provide the Service to the Practice that holds it: to show it to that Practice’s Authorized Users, to calculate totals and progress, and to let the Practice export or delete it. We don’t sell Student Data, use it for advertising, build profiles of Students, share it for anyone else’s purposes, or use it to train artificial intelligence or machine learning models.
Who can see it. The Practice’s Authorized Users (and, where the owner has turned on assignments, only the clinicians assigned to that Student, plus the owner). Our admin tools show Practice-level information such as how many Students a Practice has, but not labels or results. We access Student Data directly only when the Practice asks us to for support, when the law requires it, or when needed to investigate or fix a security or reliability problem.
Families. A family’s practice results reach a Practice only after a parent or guardian enters the Practice’s code in the Stug app, completes a verifiable parental consent process as required by applicable law, and then agrees, on a separate screen that names the Practice and lists what will be shared, to connect their child to that Practice. We keep a record of the consent or verification event as needed to document compliance. The applicable direct notice or consent flow will describe the verification method and the information handled by any verification provider. A parent or guardian can end the link or delete their child’s data in the app at any time. Ending the link stops new results and ends the Practice’s access to past results at once; we delete those results 30 days later (see Section 8). Asking the Stug app to delete the child’s data deletes the app’s record and ends the link in the same way. It does not by itself delete records a Practice keeps. A Practice controls its own records and may be required or permitted by law to keep them; until the results are deleted, the Practice owner can download that Student’s record for the Practice’s own files, and we tell the Practice when a family has asked. A parent or guardian may request deletion of information collected through the Stug app as described in the Stug app Privacy Policy. Where information has been shared with a Practice through Linking, the Practice may independently maintain records that it controls and may have legal or professional obligations to retain those records. We will process a parent’s request as required by applicable law and, where the request concerns records controlled by a Practice, notify or refer the request to that Practice and assist it in responding.
4. How we use information about you
- to provide the Service, including sign-in, your team, your Practice and support;
- to keep the Service and accounts secure, including 2-step verification, bot protection, rate limits and monitoring for misuse;
- to bill you, handle refunds and work out tax;
- to send you service emails, such as support replies, security notices, billing messages and notice of changes to our terms. We do not currently use your account information to send marketing emails.
- to comply with the law and enforce our Terms; and
- to understand in aggregate how the Service is used so we can improve it, without identifying you, anyone on your team or any Student.
We don’t sell your personal information, share it for cross-site advertising, or use it to train artificial intelligence or machine learning models.
5. Who we share information with
We use service providers to help operate Stug Connect. We limit the information made available to them based on the services they provide and our applicable contractual and legal requirements.
- Google Cloud and Firebase (Firestore database, Identity Platform sign-in, Cloud Functions, Cloud Logging, Secret Manager and backups): hosts and processes the Service’s data and sign-in, in the United States. The only provider that receives Student Data.
- Google reCAPTCHA Enterprise (with Firebase App Check): bot protection on the sign-in pages. Receives device and browser information, never Student Data.
- Stripe: payments, subscriptions and invoices, as our payment processor. Receives billing information only (your Practice’s name, the owner’s email, the billing address, the number of Seats and your payment details; for a school or district, its name, billing contact, PO number and number of SLPs) and never Student Data. JDIV Studios configures the Service so that Student Data is not transmitted to Stripe.
- Vercel: hosts the portal’s web pages. Your browser gets the pages from Vercel and then exchanges your data with Google directly, so Vercel never receives Student Data.
- Resend: sends our emails. Notification emails never include the text of a support message or any Student information.
- Google Workspace: our own email, including support@jdivstudios.com. Please use Help in the portal, not email, for anything about a Student.
We maintain information about subprocessors that may process Student Data. Where required by our agreement with a Practice or applicable law, we will provide notice of material changes to those subprocessors. We may also share information:
- within your Practice: the owner can see team members’ email addresses and roles, and members can see the Practice’s name and Students as the owner allows;
- when the law requires it, such as a valid court order, and we’ll tell the affected Practice first where the law allows;
- to protect people or the Service, such as to investigate fraud or a security incident; and
- in a business transfer, if JDIV Studios or Stug Connect is sold or merged, to a successor bound by this notice.
6. Where information is kept
Student Data is stored and processed only on Google Cloud, in the United States (the us-east1 region, South Carolina), under Google’s HIPAA Business Associate Agreement: the database, sign-in, server functions, logs and backups. Your browser and the Stug app send it straight to Google. Our other service providers (Section 5) don’t receive Student Data, and the Service is designed so that they don’t: Vercel serves the portal’s web pages (no Student appears in any web address), Stripe processes payments (billing details only), Resend sends notification emails (nothing about Students, and never the text of a support message), and Google reCAPTCHA protects the sign-in pages only. The Service is intended for U.S.-based Practices and is not currently offered for use by Practices established outside the United States.
7. How we protect information
We use administrative, technical and organizational safeguards designed to protect personal information and Student Data. These include encryption in transit and at rest, access controls, multi-factor authentication for administrative access, data-separation controls, expiring or single-use linking credentials where appropriate, logging and monitoring, and limits on employee access. We regularly review these safeguards in light of the nature of the information we process and developments in security practices. No security measure can eliminate all risk, so please keep your credentials secure and tell us promptly if you believe your account has been misused.
8. How long we keep information
We keep each kind of information for as long as its purpose needs, then delete it. Deleted information is removed from active systems in accordance with the periods below and ages out of our rolling backups through our normal backup lifecycle, currently within seven days.
- Your account: while your account exists. When a Practice is deleted, its members’ sign-in accounts are deleted too, usually within an hour, unless a member still belongs to another Practice or school.
- What a Practice enters about a Student (label, age band, category): until the Practice deletes the Student or the whole Practice (after a 7-day hold during which the owner can cancel), or 30 days after the Practice’s Subscription ends if it isn’t restarted. We email the owner when the Subscription ends and again before deletion.
- Practice results from the Stug app: while the child is linked. When the link ends, whoever ends it, the Practice loses access at once and we delete the results 30 days later; if the family relinks to the same Practice within that time, they come back. A parent’s deletion request in the app is handled the same way for the Practice’s copy (the Practice owner can download it until then); the app’s own copy is deleted at once.
- Consent records (when a parent agreed to link and when a link ended, with no results in them): as long as the Practice’s Student record exists, as evidence of consent.
- Support conversations: deleted with the Practice; otherwise 2 years after the conversation is closed.
- Copies of notification emails: 30 days.
- Security records (sign-in attempts, code guesses, alerts): 2 years.
- Our admin audit log (what our own staff looked at or changed): 6 years. Google Cloud access logs (which account read or wrote which record): 2 years.
- Deletion records: when a Practice or Student is deleted we keep a single record of when it happened and how many items were removed, with no labels or content, as proof of deletion, for 6 years.
- Billing records: kept by Stripe and by us for as long as tax and accounting law requires, which under our schedule is seven years after the end of the tax year they relate to.
- Records of your agreements: which versions of the Terms and this notice you accepted and when, for 6 years, and for as long as your account exists if that is longer; your agreement to automatic renewal, for 3 years, or 1 year after your Subscription ends if that is later. The country of your billing address and card is kept with your Practice’s records.
- Backups: a rolling 7 days (point-in-time recovery and daily backups), after which each copy is gone.
We keep something longer than the period above only when the law requires it, to deal with a dispute or legal claim, or to investigate a security incident, and then only the part that’s needed and only for as long as that lasts; or where it has been properly de-identified in accordance with applicable law so that JDIV Studios no longer maintains information that identifies or is reasonably linkable to the individual.
9. Your choices and rights
- See and correct: you can see and change your account details on your Profile page.
- Export: the Practice owner can download all of the Practice’s data as JSON and CSV files at any time.
- Delete: the Practice owner can delete the whole Practice. To delete your own sign-in account, email support@jdivstudios.com.
- Emails: you can turn off support-reply emails on your Profile page. Service emails about security, billing and legal changes can’t be turned off while you have an account.
Depending on applicable law, you may have rights concerning your personal information. These may include rights to access, correct or delete certain information or obtain a copy of it. We will respond to valid requests as required by applicable law. We may also choose to honor certain requests when not legally required to do so. We do not sell personal information or use it for targeted advertising. Email support@jdivstudios.com from the address on your account; we may need to confirm it’s you. We won’t treat you differently for making a request. If we decline, you can ask us to reconsider by replying to our answer, and we’ll explain how to contact your state attorney general if you disagree.
For Student Data controlled by a Practice, the Practice generally determines how to respond to access, correction, retention and deletion requests and may have legal or professional obligations concerning those records. We will assist the Practice with requests as required by applicable law and our agreement with the Practice. Requests concerning information collected through the family-facing Stug app are also subject to that app’s Privacy Policy and applicable children’s privacy law. Where a Practice uses Stug Connect for a school or district, records may be subject to FERPA, IDEA, state student-privacy laws or other requirements, and requests concerning school-controlled records should ordinarily be directed to the school or district.
Cookies and similar technology. The portal uses no advertising or analytics cookies. Your browser stores your sign-in session so you stay signed in, and reCAPTCHA sets its own cookies to tell people from bots. We do not use the Service to track users across unaffiliated websites for targeted advertising. Because we do not engage in sales or targeted advertising through the Service, browser-based opt-out signals such as Global Privacy Control do not change how we process information in the Service. The Service does not respond differently to browser Do Not Track signals because we do not use the Service for cross-site behavioral advertising.
10. Children
Stug Connect is for adults working in a professional role, and children can’t use it. It holds information about children only as Student Data, handled as Section 3 describes. The Stug app, which children use with their families, has its own Privacy Policy that explains how it complies with the Children’s Online Privacy Protection Act. Where information collected through the Stug app is shared with a Practice through Linking, JDIV Studios will continue to process parental requests and meet other obligations that apply to it as operator of the Stug app in accordance with applicable children’s privacy law.
11. HIPAA, FERPA and School Records
HIPAA. Where a Practice is a HIPAA covered entity or business associate and JDIV Studios’ provision of the Service makes JDIV Studios its business associate or subcontractor, JDIV Studios will enter into a Business Associate Agreement governing the applicable protected health information. For Student Data governed by that agreement, we treat Student Data as protected health information, use and disclose it only to provide and secure the Service and as the agreement permits, and follow the agreement’s rules on safeguards, incident and breach notice, and returning or destroying the information when the service ends. The agreement controls where it differs from this notice. The service provider that stores and processes that information for us, Google Cloud, does so under its own business associate agreement with us.
When a school or district uses the Service and designates JDIV Studios as a school official or otherwise authorizes JDIV Studios to receive education records under FERPA, JDIV Studios handles those records subject to the applicable FERPA requirements and its agreement with the school or district. School customers may also be subject to IDEA, state student-privacy laws and other requirements. The school or district remains responsible for determining the laws applicable to its records and for providing any notices or obtaining any consents required of it. Any applicable school data privacy agreement controls where it differs from this notice.
State privacy laws. Where a state law, such as Washington’s My Health My Data Act or the Colorado Privacy Act, treats a Practice as the regulated entity or controller for Student Data, we process that Student Data as the Practice’s processor under the Terms of Service (Section 5.7), and requests about it go to the Practice as Section 9 describes.
12. If something goes wrong
If we discover a security incident affecting personal information or Student Data, we will investigate and provide notices to affected Practices, individuals, regulators or others as required by applicable law and our contractual obligations. For Student Data processed under a Business Associate Agreement or other data protection agreement, the notification requirements in that agreement apply.
13. Changes to this notice
We’ll post any update here with a new effective date. For material changes, we’ll email Practice owners and show a notice in the portal before the change takes effect when required by applicable law or our agreements, and otherwise within a reasonable period appropriate to the nature of the change. We won’t use information in a materially different way from what this notice described when it was collected without providing any notice or obtaining any consent required by applicable law.
14. Contact us
JDIV Studios LLC. Email: support@jdivstudios.com. We aim to respond promptly.