TypeWriter

Student Privacy

We don't know your students.

TypeWriter asks for no student names, emails, or personal details. Every student is just a class code.

No student names or emails.

Students are identified only by a class code the teacher assigns, like SMITH-p3-05. We never ask for, collect, or store a student's real name, email, birthday, or any personal detail.

Nothing is sent to AI.

Grading in TypeWriter is human, we make no AI calls at all. When AI helps a teacher build an assessment, they bring their own AI tool and paste the result in. No student work, and nothing a teacher creates, is ever sent to an AI service, sold, or used to train a model.

No roster to import.

There's no student list to upload and no district data feed to connect, because there are no names to sync. A teacher can start with their own classes, and export or delete everything whenever they want.

Encrypted and access-controlled.

Everything travels over HTTPS and lives in a secured, encrypted database. Passwords are hashed, never stored in plain text.

What we store

We keep the smallest amount of data needed to run assessments and return grades:

  • Teacher account: name, email, and a securely hashed password.
  • Classes: a period, a class name, and a student count. We generate the class codes from these.
  • Student work: the responses students submit, plus the scores, feedback, and when it was submitted, all tied to the class code.

What we don't store

We never ask a student for a name, email, phone number, birthday, photo, or location, and there is no field anywhere in TypeWriter that collects one. A student signs in with a class code and a password they choose.

A class code only maps to a real student through the roster the teacher keeps in their own gradebook. That link never lives in TypeWriter.

A class code still belongs to one student, and the teacher can match it up, so laws like Illinois SOPPA treat it as student data. We do too.

Students also write in their own words, and sometimes that includes personal details. We never ask for any, and we never read responses looking for them.

Useful with no students involved

A teacher doesn't have to put student work in TypeWriter to get value from it. It can work purely as an assessment builder: write or upload questions or essay prompts, then generate polished, ready-to-print materials, including scrambled paper versions, answer keys, bubble sheets, and editable Word or PDF files.

How AI is used

TypeWriter makes no AI calls of any kind. Grading is done by the teacher. When AI helps create an assessment, it is bring-your-own: a teacher uses their own AI tool, with a prompt supplied by TypeWriter, and pastes the finished result in as an editable draft. The app never sends student work or a teacher's content to an AI service, never sells that data, and never uses it to train a model.

Secured tests

A teacher can mark an assessment secure. It opens in fullscreen, copy and paste are switched off, and if the student leaves the page the questions blur until they come back. Stay away too long and the test locks until the teacher unlocks it.

There is no camera, no microphone, and no screen capture. Nothing is installed on the device and we have no control over it. We know only that our own page lost focus, and never where a student went instead.

Security

Traffic is encrypted in transit with HTTPS, and data is stored in a secured, access-controlled database that is encrypted at rest with AES-256. Teacher and student passwords are stored only as salted hashes, never in plain text. Access to production data is limited to what's required to operate the service. TypeWriter is hosted in the United States, and our hosting provider is SOC 2 Type II audited.

Who else is involved

One company hosts the application and its database. The host is named on the subprocessor list.

Data retention

Live data is kept while a teacher's account is active. When a teacher deletes a class or their account, that data is removed from the live database right away, and any copy in our host's automatic backups rolls off within about 7 days. We keep no long-term archives.

Teachers own their data

From the Account page, a teacher can export everything they own (classes, assessments, and every student submission and grade) as a single file, anytime. From Students, deleting a class permanently erases that class's roster, assessments, and all student submissions and grades. When it's gone, it's gone.

If there is ever a breach

If we confirm a security incident affecting a school's data, we will notify that school's contact within 72 hours, with what we know and the steps we've taken. Because we hold no student names or contact details, a breach cannot expose them.

FERPA and state student-privacy laws

We never sell student data, never advertise to students, never build profiles, and never use anything to train a model. We delete on request from the school or district. Holding no names, contact details, or demographics removes most of what these laws exist to protect in the first place.

This page is a plain-language description of how we work. The formal Privacy Policy is published and is the document that governs. A Terms of Use is still with counsel. Districts with their own review process are always welcome to run it, and we will hand over a completed schedule of data on request.

Last updated: August 2026 · Questions?