Security and privacy
The question a faculty senate asks first is what does it not do.
A tool that records students has to be able to state its limits precisely, in public, without a sales call. This page is that statement. If something you need is not answered here, ask us and we will put the answer on this page rather than in an email.
Hard limits
Six things EssayGuard will not do, by design.
These are not settings. There is no administrator switch that turns any of them on, because the capability is not in the product.
What is recorded
How the document was built, and nothing about the person.
EssayGuard captures the shape of the writing process. That is enough to show a paper being written and not enough to profile a student.
Kept
Edits to the assignment document, with their timing. Insertions, deletions, revisions, pauses between them, and pastes with their length and destination. The reconstructed text of the draft at each point.
Not kept
Anything typed outside the assignment document. Clipboard source. Other tabs, applications, files, or windows. Screen contents. Anything from the camera or microphone, which are never accessed. Ordinary technical information such as an IP address is handled as described in the privacy policy.
Visible to the student
That the recorder is running, what it captures, and their own completed record, which they can export. Transparency is the point rather than a concession. A record only defends a student who knows it exists.
Where it lives and who can reach it
The institution controls the record. We hold it for them.
Storage and transport
Hosted in the United States.
Application data is held in Postgres on Supabase, with the application served from Vercel. All connections use HTTPS and TLS. Row level security is enforced at the database, so an instructor account can read only the sessions belonging to their own assignments.
- Encrypted in transit on every connection
- Row level security scoped to the owning instructor
- Service credentials never exposed to the browser
Access
A short list of people.
The instructor who created the assignment, the student who wrote the session, and anyone the instructor deliberately shares an exported report with. On department and campus plans, an integrity office can be given read access to the sessions attached to an open case and nothing else.
- No default institution-wide visibility
- Exports are generated by a person, never pushed
- Support access requires a written request from the account owner
Retention
Set on the assignment, not on the campus.
Every assignment carries its own retention window, chosen when the assignment is created and changeable afterward. A first year writing course and a doctoral thesis do not need the same answer, so EssayGuard does not force one.
30 days
Enough to cover grading and an appeal window. The usual choice for weekly low stakes work.
90 days
The default. Covers a full term plus the period in which an integrity question is normally raised.
365 days
For programs whose integrity proceedings can run past the end of the academic year.
Deletion at the end of the window, and deletion on request at any time by the institution, are both commitments we make in the data processing agreement. Under FERPA those requests are handled through the institution rather than directly with the student. The privacy policy sets out the rest.
Compliance
What we can say today, and what we cannot.
What is EssayGuard’s role under FERPA?
When an institution uses the platform, EssayGuard acts as a School Official with a Legitimate Educational Interest. Student records remain under the institution’s control, and access, correction, and deletion requests are handled through the institution. The full language is in the privacy policy.
Will you sign a data processing agreement?
Yes. A standard DPA is published in full at essayguard.io/dpa so your counsel can read it before anyone talks to us. Campus agreements can be executed against your institution’s own paper.
Are you SOC 2 certified?
Not today, and we will not imply otherwise. EssayGuard is a small product and a SOC 2 Type II report is on the roadmap rather than in hand. If your procurement process requires one, tell us where you are in your cycle and we will be straight with you about whether we can meet it.
Do you sell or share student data?
No. Student work is never sold, never licensed, never used for advertising, and never used to train a model. The subprocessors we rely on to run the service are listed in the DPA.
Can a student refuse to be recorded?
That is a question for your institution rather than for us, because it is an assignment design decision. What we can tell you is that the student always knows the recorder is running, and that the record is theirs to export as well as yours to read.