Privacy Policy
How Writopus protects teacher and student data.
This Privacy Policy explains how Writopus collects, uses, stores and protects personal data when teachers use the website, create an account, upload writing tasks, generate corrections or contact us.
Last updated: 16 July 2026
Important before public launch
The legal holder details in this policy must be completed with the final legal name, tax identification number and business address before the service is opened publicly or used for paid plans.
Basic data protection information
Controller
Writopus, operated by Alex Pedrol. Full legal holder details will be completed before public launch.
Main purposes
Account access, teacher workspace setup, writing correction, student profile storage, reports, support, security and billing when payments are enabled.
Legal bases
Performance of a contract, legitimate interest, consent where required and compliance with legal obligations.
Data recipients
Service providers used to run Writopus, including Clerk, Supabase, Vercel, OpenAI, Resend and Stripe when payments are enabled.
International transfers
Some providers may process data outside the European Economic Area using appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms.
Rights
Access, rectification, erasure, objection, restriction, portability, withdrawal of consent where applicable and complaint to a supervisory authority.
1
Who is responsible for your data?
The controller of the personal data processed through Writopus is:
Service: Writopus
Operator: Alex Pedrol
Legal name / company name: [To be completed before public launch]
Tax ID: [To be completed before public launch]
Business address: [To be completed before public launch]
Privacy contact: hello@writopus.com
If a school, academy or teacher uploads student information to Writopus, that school, academy or teacher is responsible for having a valid legal basis to process and upload that student data. Writopus processes that student-related data to provide the correction and reporting service.
2
What data do we collect?
Writopus only asks for data that is necessary to provide and improve the writing correction workflow. Depending on how the service is used, we may process the following categories:
- Teacher account data: name, surname, email address, authentication identifiers and workspace settings.
- Student-related data entered by teachers: student name, surname, class or group, writing text, task prompts, corrections, marks, feedback, mistake patterns and generated reports.
- Google Docs import data when a teacher chooses to use it: the selected document text and basic file name needed to import the writing into Writopus. Writopus does not modify the original Google Doc or store Google access tokens for this flow.
- Usage and technical data: timestamps, plan, correction allowance, saved submissions, API usage metadata, security logs, device/browser information and error diagnostics.
- Billing data when paid plans are enabled: customer identifiers, subscription status, invoices and payment metadata processed by Stripe. Writopus does not store full card numbers.
- Support and contact data: messages sent to Writopus, email address, role, topic and any information voluntarily included in support requests.
Teachers should avoid uploading unnecessary sensitive data. Writopus is designed for exam writing practice and should not be used to store health data, official identity documents, special category data or information unrelated to writing correction.
3
Why do we use the data?
We process personal data for the following purposes:
- Create, authenticate and secure teacher accounts.
- Set up and maintain each teacher workspace and plan.
- Receive writing tasks and student answers submitted by teachers.
- Import text from a Google Doc selected by the teacher when the plan includes Google Docs import.
- Generate AI-assisted writing corrections, marks, feedback, inline edits and PDF-ready reports.
- Store student profiles, writing history, progress and repeated mistake patterns when the plan includes those features.
- Provide support, respond to questions and investigate technical issues.
- Monitor abuse, enforce correction limits and protect the security of the service.
- Manage billing, subscriptions, invoices and payment status when paid plans are enabled.
- Comply with legal, accounting and regulatory obligations.
4
What is the legal basis?
The legal basis depends on the purpose of processing:
- Performance of a contract: to create accounts, provide the correction service, store workspace data, manage plans and deliver requested features.
- Legitimate interest: to secure the service, prevent misuse, debug technical issues, improve reliability and keep basic operational logs.
- Consent: where legally required, for optional cookies, marketing communications or optional processing not strictly necessary for the service.
- Legal obligation: to comply with accounting, tax, consumer, data protection or other applicable legal requirements.
5
AI processing and student writings
Writopus uses AI models to generate writing corrections. When a teacher submits a task, student answer or handwritten image, the relevant content may be sent to OpenAI so that the correction, marks, comments, inline edits or transcription can be generated.
Teachers are responsible for ensuring that student data is uploaded only where they have a valid legal basis to do so. We recommend using the minimum personal data necessary: for example, initials or internal student names where possible.
Writopus does not sell student writings or teacher data. We do not use teacher or student content for advertising profiling.
5A
Google Docs import
If a teacher uses Google Docs import, Writopus asks Google for temporary access so the teacher can select a document and import its text into the writing field. The import is initiated by the teacher, limited to the selected document and used to provide the requested correction workflow.
Writopus uses the Google access granted for that import flow only. We do not store your Google access token, and we do not modify, delete or write comments to the original Google Doc. The imported text is treated as writing content inside Writopus and processed under this Privacy Policy.
Teachers remain responsible for ensuring they have permission to process any student data contained in the selected document and for importing only the data needed for writing correction.
6
Who can access the data?
Access to data is limited to what is necessary to operate Writopus. We may use trusted providers acting as processors or independent providers for specific services:
Clerk
Authentication, user sessions and account management.
Supabase
Database storage for teacher profiles, student profiles, submissions, plan state and related application data. The current project is configured in Europe.
Vercel
Hosting, deployment, serverless functions, logs and platform security.
OpenAI
AI processing used to generate writing corrections, feedback, inline edits and transcription when enabled.
Optional Google Picker and Google Docs import selected by the teacher. Writopus requests access to the chosen document to import its text, does not edit the original file and does not store Google access tokens for this flow.
Stripe
Payment processing, subscriptions, invoices and fraud prevention when paid plans are enabled.
Resend
Transactional email for account notifications and welcome messages.
We may also disclose data if required by law, court order, regulatory request or to protect the rights, safety and security of Writopus, users or third parties.
7
Where is data stored and transferred?
Writopus uses cloud providers to operate the service. The Supabase database project is currently configured in Europe. Some providers, such as hosting, authentication, AI and payment providers, may process data in countries outside the European Economic Area.
Where international transfers occur, Writopus relies on the safeguards offered by those providers, such as adequacy decisions, Standard Contractual Clauses, Data Processing Agreements or equivalent lawful transfer mechanisms.
8
How long do we keep data?
We keep data only for as long as necessary for the purposes described in this policy, unless a longer retention period is required by law.
- Account and workspace data: while the teacher account remains active.
- Student profiles, submissions, corrections and reports: while the teacher keeps them in the workspace or until deletion is requested or performed.
- Billing records: for the legally required tax and accounting retention period once paid plans are enabled.
- Security and diagnostic logs: for a limited period necessary to protect and maintain the service.
- Support emails: for as long as needed to resolve the request and keep an appropriate support history.
9
Your rights
Under applicable data protection law, you may have the right to:
- Access your personal data.
- Request correction of inaccurate or incomplete data.
- Request deletion of your data.
- Object to certain processing activities.
- Request restriction of processing.
- Request portability of data you provided.
- Withdraw consent where processing is based on consent.
- Lodge a complaint with the Spanish Data Protection Agency (AEPD) or another competent supervisory authority.
To exercise your rights, contact us at hello@writopus.com. We may need to verify your identity before processing the request.
Signed-in teachers may request a machine-readable copy of their Writopus data by contacting hello@writopus.com. When a teacher account is deleted, Writopus receives a signed deletion notice from its authentication provider and removes personal-workspace data. Records that belong to an Academy workspace may be retained for the Academy but are disconnected from the deleted teacher identity. Legal, billing or fraud-prevention records may be retained where applicable law requires it.
10
Children and students
Writopus is intended for teachers, tutors, schools and academies, not for direct use by children. Students should not create accounts unless a future student product is expressly launched with appropriate consent and notices.
When a teacher uploads student writing, the teacher or educational organisation is responsible for complying with applicable education, privacy and parental consent requirements. Writopus provides the technical correction service requested by the teacher.
11
Security
Writopus applies technical and organisational measures designed to protect personal data, including authenticated access, Row Level Security policies in the database, HTTPS, restricted access to production systems, environment variable protection and service provider security controls.
No online service can guarantee absolute security. If you believe there has been a security issue affecting Writopus, contact us immediately at hello@writopus.com.
12
Cookies and similar technologies
Writopus uses strictly necessary cookies or similar technologies for authentication, security and session management. Google Analytics is only loaded after a visitor accepts analytics cookies. Optional marketing or tracking cookies will only be used where permitted by law and, when required, after obtaining consent.
A separate Cookie Policy explains the cookies and similar technologies in more detail.
13
Changes to this policy
We may update this Privacy Policy to reflect changes in the service, providers, legal requirements or data processing practices. The latest version will always be available on this page and will show the date of the latest update.
If a change materially affects how personal data is processed, we will take reasonable steps to notify users through the website, email or the application.
Questions about privacy?
Contact Writopus before uploading sensitive or unnecessary student data.
