Scope and our role
This notice covers The School OT websites, account registration, demo requests, and workspaces. OT Bestie LLC controls website, account, security, and direct business-contact information. A school, district, practice, or independent clinician ("Customer") normally controls student, patient, clinical, education-record, and claim information placed in a workspace, and OT Bestie processes that information for Customer under its instructions and applicable agreements.
Information we collect
We collect account and business information such as name, work email, password hash, workspace, role, job title, time zone, plan, security settings, verification state, and agreement acceptance. If you request a demo or support, we collect the details you submit. The product stores the caseload, service plan, schedule, availability, session, goal, consultation, supervision, progress, team, and other records an authorized user chooses to enter.
If Customer enables claim functions, the Service may also process billing-entity identifiers, provider credentials, payer and enrollment records, coverage and subscriber data, member identifiers, diagnosis codes and protected source references, consent and notice evidence, eligibility responses, claim versions, clearinghouse and payer receipts, claim status, and remittance information. The Service does not use claim information to create family invoices or consumer payment balances.
Information generated by use
We generate session and security data needed to operate and protect the Service, including timestamps, request identifiers, authentication results, role and record actions, device session state, and audit events. Network addresses used for security logging are transformed with a keyed hash rather than stored in readable form in the application audit record. We use a necessary session cookie to keep users signed in and protect requests. We do not use the Service for cross-site behavioral advertising.
Sources
We receive information from users and Customer; from activity in the Service; and, when Customer separately authorizes claim functions, from Stedi, selected payers, transaction intermediaries, payer directories, enrollment systems, and responses to Customer-directed transactions. Customer is responsible for ensuring that it has authority to provide information about students, patients, subscribers, clinicians, and other people.
How we use information
We use information to create and secure accounts; provide the workspace; show due work; build schedule drafts; document services; support supervision and reports; prepare, transmit, receive, and reconcile authorized claim transactions; preserve required record history; respond to requests; prevent misuse; troubleshoot; recover service; enforce agreements; and meet legal or contractual obligations. We do not sell personal information or use student, patient, clinical, or claim information for advertising, marketing, or unrelated product development.
Student and patient information
Only enter identified student or patient information when Customer has authorized that use and the workspace has been activated for the applicable FERPA, HIPAA, or combined path. Identity fields and clinical note bodies are encrypted before storage. Workspace roles, student assignments, and record state limit access inside the application. The Service is for adult professional users and does not offer student or patient accounts. OT Bestie does not ask children to submit information directly; authorized adults enter records for Customer's institutional or professional purposes.
Service providers and claim disclosures
We use contracted infrastructure, email, security, support, payment, and other providers to operate the Service, with access limited to their function and the agreements in place. Account email and payment providers must not receive student, clinical, or claim content unless separately approved for that data class.
When Customer has accepted the Claims Processing Addendum and enables an authorized transaction, OT Bestie may disclose the minimum necessary claim information to Stedi, Inc., the selected payer, and any transaction intermediary needed for eligibility, 837P professional claims, 277CA acknowledgments, 276/277 claim status, or 835 remittance. We may also disclose information when Customer directs us, when required by law, to protect rights and security, or as part of a business transaction with appropriate safeguards.
Retention
We keep information for as long as needed to provide the Service, follow Customer instructions, meet contractual and legal duties, resolve disputes, preserve security and audit evidence, support payer reconciliation, and maintain records that must remain immutable. Retention for education, clinical, and claim records depends on Customer requirements, applicable law, payer or program rules communicated by Customer, legal holds, and signed agreements; there is no single period for every record. Protected backup copies age out through the backup lifecycle unless needed for legitimate recovery.
Security
Security controls include MFA, session limits, encryption, scoped access, request protection, immutable or append-only history for selected records, audit-chain verification, and tested export boundaries. Customer remains responsible for its authorized users, devices, networks, downloads, exports, and downstream systems. No system can eliminate every risk.
Your choices and requests
You can update your profile and security credentials from your account. Workspace owners can manage members and export supported records. For access, correction, deletion, portability, or privacy questions, contact contact@theschoolot.com. Requests about student, patient, education, clinical, or claim records normally must go through the Customer that controls the workspace. We may verify identity and authority before acting, and we may retain information when law, an active dispute, security evidence, a payer obligation, or an immutable-record requirement prevents deletion.
Changes and prior versions
We may update this notice as the product, providers, data flows, or legal requirements change. The version and effective date identify the current text. We will provide notice of material changes when required. This archived version was followed by version 2026-08-12.2.
Contact
Contact OT Bestie LLC at contact@theschoolot.com for privacy, security, or claims-data questions.