Legal
Privacy Policy
Last updated: July 13, 2026
This policy explains how WriteID collects, uses, and protects information. We are committed to handling all data — especially student data — responsibly.
Google User Data We Access
WriteID accesses Google user data only after a user grants the requested permissions through Google OAuth. The raw Google user data we access is:
- Google account: Google account ID, name, email address, profile photo, OAuth access and refresh tokens, granted scopes, and token expiry data.
- Google Classroom: course IDs, names, sections, rooms, enrollment codes, owner IDs, course status, group email addresses, creation and update times, the user's teacher or student role, and roster member Google IDs and email addresses.
- Coursework: assignment IDs, titles, descriptions, due dates, point values, status and timestamps; submission IDs, student IDs, state, late status, assigned and draft grades, timestamps, and links.
- Google Drive: file IDs, titles, links, thumbnail URLs, and the plain-text content of a submitted Google Doc when an authorized educator requests an authorship report.
WriteID does not access Gmail, contacts, calendars, location, microphone, camera, general browsing history, or Drive files that are unrelated to the Classroom assignments processed by WriteID.
Other Data and Derived Data
For a tracked Google Docs assignment, the WriteID browser extension records timestamps, typed key values and modifier keys, pasted text, selected text, copy and cut event occurrence, mouse-button clicks, and document focus or blur events. Typed keys, pasted text, and selected text can reveal portions of the student's writing. Tracking occurs only after the student accepts the extension's tracking disclosure and when the assignment and its class are enabled in WriteID.
WriteID derives per-submission activity statistics and an AI-generated authorship report from the final document and tracked activity. These derived records can include event counts, timing and focus patterns, writing-speed and revision measures, excerpts, anomaly findings, scores, confidence levels, and a recommended review outcome. They remain linked to the student and assignment; they are not anonymized.
WriteID does not currently create, use, or share aggregated or anonymized datasets derived from Google user data across users or institutions.
How We Use Google User Data
- Authenticate the user and maintain their WriteID session.
- Synchronize the user's Classroom courses, rosters, assignments, submissions, attachments, and grades into the WriteID interface.
- Match a tracked Google Doc to the correct assignment and submission.
- Retrieve a submitted document when an authorized user requests a Proof of Authorship report.
- Analyze the document and writing activity and display the report to authorized educators, students, and institution users.
- Maintain, secure, troubleshoot, and improve those user-facing features.
Neither WriteID nor its service providers may use Google user data to train general-purpose AI models, build advertising profiles, serve targeted or personalized ads, determine creditworthiness, make lending decisions, or for any purpose unrelated to WriteID's visible user-facing features.
Data Sharing and Transfer
WriteID does not sell Google user data or transfer it to data brokers, advertising platforms, information resellers, or lenders. Raw and derived Google user data is shared only as follows:
- Google Gemini: the submitted document text, tracked activity events, and derived activity statistics are sent to Google's Gemini API solely to generate and, when selected, reconcile the authorship report.
- Infrastructure providers: hosting, database, and operational service providers process data on WriteID's behalf only to operate and secure the service.
- Authorized institution users: educators and administrators may view Classroom records, activity, and reports only for classes and organizations they are permitted to manage. Students may view data made available for their own work.
- Legal or safety: data may be disclosed when required by applicable law or valid legal process, or when necessary to investigate security abuse.
Service providers must process data only under WriteID's instructions and for the purpose of providing or improving the applicable user-facing feature. Polar processes billing data but is not given Google Classroom, Drive, document, or writing-activity data for payment processing.
Data Protection
WriteID uses HTTPS/TLS to protect data in transit; server-side authentication and role-based authorization to restrict access; database access controls and infrastructure-provider encryption for stored data; OAuth scopes limited to read-only account, Classroom, submission, and Drive access; and restricted access to production systems and Google OAuth credentials. OAuth tokens are stored server-side and are not exposed to the browser extension. WriteID also avoids placing submitted document content or AI prompts in ordinary application logs.
No system is completely secure. Suspected unauthorized access can be reported through the feedback form in the application so that access can be investigated and contained.
Data Retention and Deletion
- Google account details, OAuth tokens, and synced Classroom and Drive metadata are kept while the WriteID account remains active and the data is needed to provide the connected features.
- Submitted Google Doc text is retrieved only when generating or regenerating a report. WriteID sends it to Gemini for that request but does not save the complete document text as a separate record in its application database.
- Writing-activity events, per-submission statistics, and authorship reports are retained until the related record is deleted by an authorized educator or administrator, or a verified deletion request is completed.
- Security and operational logs are retained only for the period reasonably necessary to operate, troubleshoot, and protect the service and are not used for advertising.
Users may revoke WriteID's Google access at any time from their Google Account permissions. Revocation stops future Google API access but does not itself delete data already copied to WriteID. To request access, correction, account deletion, or deletion of stored Google user data, use the in-app feedback form. Student requests may also be submitted through the student's institution. We complete verified deletion requests from active systems within 30 days, unless retention is required by law, needed to resolve fraud or security incidents, or required to preserve a legitimate institutional record. When an exception applies, access is limited and the data is deleted when the exception ends.
Google API Limited Use
WriteID's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Those requirements apply to raw Google user data and to data aggregated, anonymized, or derived from it. Read the official Google API Services User Data Policy.
We do not permit employees, contractors, or other humans to read Google user data except when the user gives affirmative permission for specific data, when necessary for security or troubleshooting, when required by law, or when the data is aggregated and used for lawful internal operations.
Student Privacy (FERPA / COPPA)
WriteID processes student data only under the direction of the educational institution, acting as a "school official" with a legitimate educational interest under FERPA.
Students under 13 interact with WriteID only through the browser extension under educator supervision. Institutions are responsible for obtaining all required parental consents before enabling WriteID tracking.
Your Rights
Depending on your location you may have rights to access, correct, or delete your personal data. Contact us via the feedback form in the application. For student data requests, work through your institution's designated privacy contact.
Cookies and Non-Google Data
WriteID uses session cookies necessary for authentication. We do not use advertising cookies or third-party tracking pixels. Invitation codes may be stored temporarily as cookies to complete the invitation flow.
Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via email. Continued use after the effective date constitutes acceptance.
Contact
Questions or data requests? Contact us through the feedback form within the WriteID application.