TypeWriter

Legal

Privacy Policy

Effective date: 12 August 2026 Last updated: 14 August 2026


Who we are

TypeWriter is operated by TypeWriter Education LLC, an Illinois limited liability company ("TypeWriter," "we," "us").

Contact: privacy@typewriter.education

This policy explains what we collect, why, and what we do with it. A separate Terms of Use governs use of the service.

If your school or district has signed a data privacy agreement with us, that agreement controls. Where this policy and a signed district agreement (including any NDPA or state addendum) conflict, the signed agreement governs for that district's data.


1. The short version

TypeWriter is a classroom assessment tool for teachers. It is built so that we do not know who any student is.

  • We do not collect student names, email addresses, birthdays, phone numbers, addresses, photos, or locations.
  • A student is identified only by a class code their teacher assigns, such as SMITH-p3-05.
  • The mapping from a code to a real child exists only in the teacher's own records. We cannot connect a class code to a person.
  • We do not sell data, we do not serve advertising, and we send nothing to any AI service.

2. Information we collect

2.1 Teacher and administrator accounts

To provide the service to educators we collect:

DataWhy
Name and email addressTo create and identify the account, and to send account email
PasswordStored only as a bcrypt hash, never in readable form
From a teacher's access request: school, district, U.S. state, subject area, and the classes you teach — plus, optionally, the name of whoever at your district approves classroom toolsTo confirm you are an educator, set up your classes, and follow up about district approval
From an IT or administrator information request: role, district, U.S. state, approximate number of students, and what prompted the enquiryTo answer the request and understand what a district review would involve
Last-active timestampTo identify dormant accounts
Content the teacher createsAssessments, questions, rubrics, materials, uploaded images and PDFs, feedback, and any posts to the teacher community or forum

Teacher accounts are created by invitation. There is no public self-signup.

2.2 Students

We collect the following, all keyed to a class code and never to a name:

DataWhy
The class code assigned by the teacherServes as the student's username
A student-chosen passwordStored only as a bcrypt hash
Submitted work: essay text, selected answers, marked-complete receiptsSo the teacher can grade it
Autosaved drafts and word countsSo a student does not lose work
Scores, rubric levels, and teacher-written feedbackTo return results to the student
Submission and activity timestampsTo order and display work
Extended-time accommodation, if the teacher sets oneTo give that student their accommodated clock

On assessments a teacher marks "secure," we additionally record a test-integrity log: event type (such as leaving fullscreen or switching tabs), a timestamp relative to the start of the test, and how long the student was away. We do not record keystrokes, screen contents, camera, microphone, or location.

We never ask a student for any personal information. There is no field anywhere in the student experience that requests a name, email, or any personal detail.

One honest caveat. Essay and short-answer responses are free text. A student could type identifying information into an answer. We do not request it, and we do not scan responses for it. Teachers are told at onboarding to instruct students not to put personal details in their answers.

2.3 Technical data

  • A session cookie (httpOnly, and Secure in production) keeps a login active. It is strictly necessary for the service to function.
  • IP address and browser user-agent may appear transiently in standard server request logs kept by our hosting provider. They are not stored in our application database and are not linked to any student.

We use no advertising, analytics, or tracking technologies. There are no third-party trackers, pixels, or advertising cookies in the product.


3. How we use information

We use the information above only to:

  1. Operate the service: authenticate users, deliver assessments, save work, and return grades and feedback.
  2. Support the account: respond to requests, send password resets and account email.
  3. Keep the service secure and working: prevent abuse, debug faults, and maintain integrity of tests.
  4. Meet legal obligations.

We do not:

  • Sell, rent, or share personal information for money or for cross-context behavioral advertising
  • Use student data to build a profile for any purpose other than the educational purpose the school authorized
  • Use student data to train any machine-learning model, ours or anyone else's
  • Send student work, or any teacher content, to any artificial intelligence service

Where AI helps a teacher write an assessment, it is bring-your-own: the teacher uses their own AI tool outside TypeWriter and pastes the finished text in. TypeWriter only ever receives text a teacher chose to paste.


4. Who we share it with

We do not sell data and we do not share it for advertising. We share only with the service providers that make the product run:

ProviderPurposeStudent data involved
Render (render.com)Application hosting and managed PostgreSQL database, United States (Oregon)Yes — the application and database run there. This is our only sub-processor of student data.

We may also disclose information if required by law, to protect rights and safety, or in connection with a merger, acquisition, or sale of assets — in which case student data remains subject to this policy or a successor policy at least as protective, and we will give notice to affected schools.


5. Where data lives, and how long

Data is stored in the United States, in Render's Oregon region.

Two different things, two different rules. Teacher content is a teacher's own professional work and is not student data. Student work is the covered information, and it is the part with a clock on it.

DataRetention
Teacher account and content (assessments, rubrics, classes)For the life of the account
Student work, scores, and feedbackDeleted on the triggers below
Test-integrity event logsWith the submission they belong to
Session recordsUntil expiry or sign-out

Student work is deleted when any of these happens:

TriggerWe delete within
A school or district asks us to30 days
A teacher deletes the classImmediately (it cascades)
A teacher closes their account30 days
A class goes 12 months untouchedAutomatically

Deletion is a real delete, not a flag. Data is removed from live systems within the window above and ages out of our host's encrypted backups within a rolling 7 days after that. We will not claim data is gone from backups sooner than it actually is.


6. Security

  • In transit: HTTPS/TLS everywhere; database connections use SSL in production.
  • At rest: stored in Render's managed PostgreSQL, encrypted at rest with AES-256. Render is SOC 2 Type II audited.
  • Passwords: bcrypt hashes only, for teachers and students alike. We cannot read anyone's password.
  • Access: teachers see only their own classes and content. Administrative functions sit behind a separate admin login.
  • Sessions: stored server-side and tied to a signed, httpOnly cookie.

No system is perfectly secure, and we do not claim otherwise. If we confirm a security incident affecting a school's data, we will notify that school's designated contact within 72 hours, with what we know, the categories of data involved, and the steps we have taken. Where a signed data privacy agreement sets a shorter or more specific requirement, that agreement controls.


7. Children's privacy, FERPA, and schools

TypeWriter is offered to schools for classroom use, not directly to children or families.

  • FERPA. To the extent student work in TypeWriter constitutes an education record, we act as a school official with a legitimate educational interest under 34 CFR § 99.31(a)(1), performing a function the school would otherwise perform itself. We use the data only for the purpose the school directs, and we do not redisclose it.
  • COPPA. Where students under 13 use TypeWriter, the school provides consent on behalf of parents, consistent with FTC guidance permitting schools to consent to the collection of student information used solely for an educational purpose. We collect no personal information from students beyond a teacher-assigned code and a password.
  • State student-privacy laws. We intend to comply with applicable state student-data-privacy laws. TypeWriter currently operates in Illinois and complies with SOPPA (105 ILCS 85). As we work with districts in other states we will comply with those states’ laws and update this page.
  • The school or district is the data owner. Parent and student rights — access, correction, deletion — are exercised through the school, and we support the school in fulfilling them.

We do not knowingly collect personal information from a child outside this school-authorized context. If you believe a student has entered personal information into a free-text response, contact us at privacy@typewriter.education and we will work with the school to remove it.


8. Your choices and rights

  • Teachers can export all of their data at any time as a JSON file and as a gradebook export, and can delete a class or their whole account from within the product.
  • Schools and districts may request export or deletion of their data at any time by contacting us.
  • Students and families should direct requests to the school, which controls the record. We will assist the school promptly.

Where we operate. TypeWriter is offered in the United States only. We do not market to, or knowingly serve, users in the EU or the UK, so no GDPR lawful-basis disclosure is made here. If we begin serving districts in California or outside the United States, we will add the disclosures those laws require before doing so, and update this page.


9. Changes

If we make a material change to this policy we will update the date above and notify account holders by email. For districts under a signed agreement, we will follow the notice terms of that agreement.


10. Contact

privacy@typewriter.education