Privacy Policy
Last updated: April 2026
The privacy of your data — and it is your data, not ours — matters to us. This policy explains what we collect, why we collect it, and how we handle it. We never sell your data. Never have, never will.
What we collect and why
Teacher data
When you create a teacher account, we collect:
- Email address and name — for authentication, account management, and important service communications
- Grading history — records of essays graded and feedback generated
- Credit transactions — purchase history and credit usage
Student data
We collect no personal information from students. Students are identified only by anonymous codes assigned by their teachers. No names, no emails, no accounts.
Essay content
Essays submitted for grading are sent to Anthropic Claude and OpenAI for AI processing. This is necessary to provide our grading service. Essays are not used to train AI models.
Payment data
All payment processing is handled by LemonSqueezy. ELIOR never sees or stores your card details. We only receive confirmation of successful payments and basic transaction records for your purchase history.
How we use your data
- To provide AI-powered essay grading and feedback
- To manage your account and process credit purchases
- To send important service updates (you can't opt out of these — they're necessary for the service)
- To send educational resources and product news (you can opt out anytime)
- To improve our service based on aggregate usage patterns
Who we share data with
We use a small number of trusted third-party services to run ELIOR:
- Anthropic Claude & OpenAI — AI processing of essays for grading
- LemonSqueezy — payment processing (they handle all card data)
- Supabase — authentication and database hosting
- Resend — transactional email delivery
- Vercel — cloud hosting
We don't sell data to anyone. We don't share data with advertisers. We don't use your data for purposes other than running ELIOR.
Data retention
- Challenge submissions: deleted after 30 days
- Essays and grading results: retained for 12 months from last activity
- Account data: kept until you delete your account
When you delete your account, we delete your data. Some data may persist in backups for up to 30 days after deletion.
Your rights
You have the right to:
- Access — request a copy of your personal data
- Correction — fix inaccurate information
- Deletion — request we delete your data
- Export — get your data in a portable format
To exercise any of these rights, email us at hello@m.eliorlab.com.
Student privacy commitment
ELIOR is designed from the ground up so that students never need to share personal information. Students don't create accounts. They're identified only by anonymous codes. This isn't an afterthought — it's a core design principle. We believe this is the right way to build educational technology.
Security
We take security seriously:
- All data is encrypted in transit using TLS
- Data at rest is encrypted
- We use Supabase's enterprise-grade security infrastructure
- Access to production systems is strictly controlled
If you discover a security vulnerability, please email us immediately at hello@m.eliorlab.com.
Changes to this policy
We may update this policy as our practices evolve. For significant changes, we'll notify you via email. You can always find the current version on this page.
Contact
Questions or concerns about privacy? Get in touch:
Adapted from the Basecamp open-source policies / CC BY 4.0