Privacy policy
Effective October 8, 2026
Summary
- ABA Tools gives teaching activities and session tools to adults who work with a learner: BTs, BCBAs, supervisors, and parents.
- ABA Tools does not ask for real names, birth dates, diagnoses, email addresses, or passwords. Learners and accounts get generated names and private codes.
- ABA Tools does not sell or share personal information. ABA Tools shows no ads and does not track you on other websites or apps.
- Saved records stay until an adult deletes them. ABA Tools deletes the records of a learner 24 months after the last activity.
- ABA Tools is not for protected health information (PHI), and it is not HIPAA compliant.
Who operates ABA Tools
The developer of ABA Tools, one person in California, operates ABA Tools (https://aba-tools.com and the iOS app). To speak to the developer, write to privacy@aba-tools.com.
ABA Tools gives teaching activities and session tools. It does not give medical advice, and it does not diagnose or treat a condition.
Who uses ABA Tools
Adults use ABA Tools: BTs, BCBAs, supervisors, parents, and RBT students. An adult makes each learner and each account.
A learner does an activity on a device that an adult controls. ABA Tools does not ask a learner for personal information. A learner cannot make information public in ABA Tools.
What ABA Tools keeps on its server
ABA Tools keeps only the data below. Each item is from a fixed list, or is a number, a date, or a code. ABA Tools has no field for free text about a learner.
Learners
A generated name and picture for each learner (for example "Blue Otter") and a private learner code. Also the date the learner was made, and the date of the last activity. The server keeps only a hash of the code.
Tool setup for a learner
The tools that are On for the learner, the setup choices of each tool, and the Next time lists. Each is an item from the lists of the tool.
Saved responses and scores
For each session: the date and time, the target, the response (an item from the list of the tool), and the result. Also the help level or condition. Flashcards also keeps the card order and the score of each card. The learner makes some responses, for example a tap on a picture in Find It or a button in Say It. An adult enters the rest, for example Observe intervals, Tiny Bites steps, and Flashcards scores.
Trace It scores and pictures
The two scores of each trace. If the setting Save trace pictures is On, also the points of each line that the learner traced. These pictures are drawings of the learner.
Assessments
Milestones Tracker, Barriers Checklist, and Transition Readiness: the date, the rater ("primary" or "second" only), and the score of each item.
Supervisor and BT accounts
A generated name for each account (for example "Red Heron"), a private account code, and the groups. Also the learners on the list of the supervisor, the learners assigned to each BT, and the prepared notes that a supervisor sends. The server keeps only a hash of the code. Group names and notes come from fixed lists.
RBT Gym study accounts
A generated name, a private study code, and the study progress: item ids, counts, dates, and the scores of practice exams. The server keeps only a hash of the code. ABA Tools does not keep the answers that a person types.
RBT Gym problem reports
When a person taps Report a problem: the study item, the version of the item, a reason from a list, and the time. ABA Tools does not keep an account, a code, a network address, or typed text with a report.
Content reviews
Adults that the developer invites to review study content: the name that the reviewer types, the marks, and the notes about the study items. Notes must not be about a learner.
Anonymous usage counts
Daily numbers: how many times the website, the app, or a tool opened, and how many times a tool started or finished. ABA Tools also counts setup choices, saves that worked or failed, errors by type, and uses of Share or a join link. On the website, ABA Tools also counts the pages that open and the visits. For each visit, it counts the type of site that the visit came from (for example "Google" or "other site"), not the address. It also counts the time on each page in groups, and the steps that a visit gets to. Also the type of device, the browser family, the size class of the screen, and speed ratings of the pages. Each of these is a separate count. Each number has only the date, the platform, and the version. A count has no device, browser, visit, learner, session, or account identifier. It has no network address, no location, no time of day, and no answers or scores.
Service records
The random identifier of each response that a person deleted, and the dates of the daily usage alert that ABA Tools sends to the developer.
Generated names do not make the records anonymous. The team of a learner can know who the learner is.
What ABA Tools does not collect
- Real names, birth dates, addresses, diagnoses, or insurance details.
- Email addresses, telephone numbers, or passwords.
- Photos, video, or sound from the camera or the microphone.
- The location of your device.
- Data for ads, or recordings of your screen.
- The answers that a person types in RBT Gym.
How ABA Tools gets the data
The website and the app send data to the server of ABA Tools when an adult makes a learner or an account. They also send data when a person uses a tool for a learner. A tool saves only for a learner that an adult selected, and only when the tool is On for that learner. In guest mode, ABA Tools saves nothing on the server.
Anonymous usage counts: the website and the app count use. In the app, an adult can set Usage analytics to Off in Privacy and analytics. Then the app counts nothing and sends nothing.
Page visits: on the public pages for adults, Cloudflare Web Analytics counts page visits for ABA Tools. It does not operate on the screens that a learner uses, or in an activity.
Data that stays on your device
Some data stays only on your device:
- The codes of your learners and accounts. In the app, the codes are in the iOS Keychain, only on this device.
- The setup choices of each tool, and your light or dark choice.
- Saves that wait for a connection.
- Parent Lessons progress, and the Token Board balance of a guest.
- On the website, a short note for the usage counts. It has the time of the last use of the visit, and the steps that the visit got to. It has no identifier. ABA Tools does not send it. The browser deletes it when you close the tab.
To remove this data, use Remove from this device or Sign out, clear the website data in your browser, or delete the app. A person who uses your device can see this data.
How ABA Tools uses the data
- To operate the tools and save the records of each learner.
- To show dashboards and CSV exports to the persons who have the code of the learner or an account of the team.
- To let a supervisor and BTs work with the same learners.
- To keep the service secure and to stop abuse.
- To count use and to find errors, with the anonymous counts and Cloudflare Web Analytics only.
- To repair the study content, and to answer your messages.
ABA Tools does not use the data for ads, for profiles of persons, or to contact a learner.
How long ABA Tools keeps the data
ABA Tools keeps each kind of data only as long as the list below says. Then ABA Tools deletes it.
- Learners
- Until an adult deletes the learner, or deletes the supervisor account that made the learner. ABA Tools deletes a learner with no saved data 90 days after the learner was made. ABA Tools deletes each learner, with all the records of the learner, 24 months after the last activity.
- Tool setup for a learner
- With the learner.
- Saved responses and scores
- Until the person who saved a response takes it back (in the first 30 minutes), a supervisor deletes it, or the learner is deleted.
- Trace It scores and pictures
- Scores: with the response. Trace pictures: 180 days. Then ABA Tools deletes them.
- Assessments
- Until an adult deletes the assessment, or the learner is deleted.
- Supervisor and BT accounts
- Until the account is deleted. A BT can delete the BT account. A BT account also goes when the supervisor removes the BT or deletes the supervisor account. ABA Tools deletes a supervisor account with no learners and no BTs 90 days after it was made. Learners are separate records (see Learners).
- RBT Gym study accounts
- Until the person deletes the study account. ABA Tools deletes a study account that never saved progress 90 days after it was made.
- RBT Gym problem reports
- ABA Tools keeps the reports and the versions of the items as the repair history of the content. They have no data about a person.
- Content reviews
- Until the developer turns off the review link. Then ABA Tools deletes the names, marks, and notes 365 days later.
- Anonymous usage counts
- Usage counts: daily numbers for 25 months. Then ABA Tools adds them into monthly numbers, which it keeps without a time limit. Share and join counts: without a time limit. A count cannot identify a person. ABA Tools keeps the random identifier of each batch only to count the batch one time.
- Service records
- Identifiers of deleted responses: 7 days. Alert dates: 365 days.
- Backup copies of the databases
- Cloudflare keeps restore copies for 7 days (30 days on a paid plan). After an adult deletes data, a restore copy can hold it until the copy expires.
- Network addresses
- ABA Tools uses a network address for 60 seconds to limit requests. ABA Tools does not keep network addresses.
- Service logs
- Cloudflare keeps the log lines of ABA Tools for 3 days (7 days on a paid plan). The lines have no codes, identifiers, names, or network addresses.
- Data on your device
- Until you remove it. See "Data that stays on your device".
- Messages to the developer
- The developer keeps your message for 24 months after the last message, to answer it and to show what the developer did.
How to see, correct, or delete data
- See: open the dashboard of the learner with the code of the learner, or with an account of the team. Export the records as a CSV file.
- Correct: change the setup in the tool. A supervisor can delete a session or one response on the dashboard.
- Delete a learner: in the learner menu, select Delete for everyone and type the name. All records of the learner go. A BT cannot delete a learner.
- Delete an account: on the Team page, a supervisor or a BT can delete their own account and type its name. A supervisor can also remove a BT account. When a supervisor deletes the supervisor account, ABA Tools also deletes each learner that the supervisor made, with all the records of the learner. Learners that the supervisor added with a learner code stay. A BT account goes with its notes; its learners stay with the supervisor. A person can delete a study account in RBT Gym.
- Stop the use of a code: select Reset code. Other devices then cannot open the learner.
- If you cannot do it yourself, write to privacy@aba-tools.com. Give the generated name of the learner or account, and the name of the BCBA or clinic. The developer does not know the real names of learners.
Children
Many learners are children. ABA Tools is a tool for adults, but it gives special care to the data that a learner makes.
- What ABA Tools collects from a learner: the responses that the learner makes in an activity, for example the picture that the learner taps. Also the buttons that the learner pushes in My Way and Say It. If Save trace pictures is On, also the trace pictures.
- How ABA Tools uses it: only to show the progress of the learner to the adults of the team of the learner.
- Who receives it: no person or company, other than Cloudflare, which keeps it for ABA Tools. A learner cannot make it public.
- Identifiers: the learner code and the learner identifier are persistent identifiers. ABA Tools uses them only to save and show the records of the learner, to keep the service secure, and to count each save. ABA Tools does not use them to contact a person or to make a profile.
- How long: see "How long ABA Tools keeps the data". Trace pictures go after 180 days. All records go 24 months after the last activity.
A parent or guardian can see the records of the learner, delete them, and stop more collection. To see them, open the dashboard with the code of the learner. To delete them, select Delete for everyone. To stop more collection, ask the team to set the tools of the learner to Off, or delete the learner. If you do not have the code, ask the BCBA of the learner, or write to the developer.
ABA Tools does not ask for more information than an activity needs.
Health data (Washington, Nevada, Connecticut, and other states)
Some state laws protect consumer health data. The records of a learner can show data about a behavioral intervention. ABA Tools collects this data only to give the service that an adult asks for: to save and show the progress of a learner.
- Kinds of data: the responses, scores, assessments, and setup of a learner (see "What ABA Tools keeps on its server").
- Source: the adults who use ABA Tools, and the learner in an activity.
- Use: only to save and show the progress of the learner.
- Sharing: none. Cloudflare keeps the data for ABA Tools. ABA Tools does not sell health data.
- Your rights: you can see the data, delete it, and withdraw your consent. To withdraw consent, delete the learner, or stop the use of the tools for the learner.
To use these rights, or to appeal a decision, write to privacy@aba-tools.com. The developer answers in 45 days or less.
Not for protected health information
ABA Tools is not for protected health information (PHI) as HIPAA defines it, and ABA Tools is not HIPAA compliant. The developer does not sign business associate agreements.
Do not use ABA Tools as the clinical record of a clinic. Do not put real names, birth dates, diagnoses, or other identifiers in ABA Tools.
Security
The server keeps only a hash of each code. All connections use HTTPS. Each request must have the correct code, and ABA Tools limits how fast a person can try codes. The logs of ABA Tools have no codes, identifiers, names, or network addresses. The developer has a written security program and examines it each year.
No system is fully secure. Give a code only to the team of the learner. If a person has a code that they must not have, select Reset code.
To report a security problem, write to privacy@aba-tools.com. If a breach occurs, the developer puts a notice on the website and in the app. The developer also tells the supervisors and clinics that the developer can contact. The developer gives each notice that the law requires, in the time that the law gives.
Do Not Track and other websites
ABA Tools does not track you over time or on other websites or apps. Thus ABA Tools does the same thing when your browser sends Do Not Track or Global Privacy Control.
No other company collects data about your activity on other websites through ABA Tools. Only two scripts of another company operate on ABA Tools. The Cloudflare security check operates only when an adult makes a learner or an account. Cloudflare Web Analytics operates only on the public pages for adults.
California
ABA Tools does not sell or share personal information, as California law defines these words. If you live in California, you can ask which data ABA Tools has about you. You can also ask for its correction or deletion (see "How to see, correct, or delete data").
Changes to this policy
If the developer changes this policy, this page and the app show the new effective date. Before a large change to the data that ABA Tools collects from learners, the website and the app show a notice. The same applies to a large change in how ABA Tools uses that data. Earlier versions are available by email.
Contact
Write to the developer of ABA Tools at privacy@aba-tools.com.