teachvatoryOpen workspace

Privacy policy

Effective September 6, 2026

This policy describes Teachvatory, the teaching-team workspace at teachvatory.com, including its optional connected-course tools. For privacy questions or requests to delete stored data, contact the workspace operator at maximiliano.rod.ra@gmail.com.

Information we access and why

  • Google account information. Google sign-in provides account identity, including your email, name, and profile image. We use it to authenticate you, enforce the invited-account list, display your account, and associate saved workspace settings with you.
  • Course information. Sources you configure can provide student names and identifiers, enrollment, assignment submissions, scores, and profile attributes. Teachvatory uses this information to display course views, match rosters, build filters, and prepare analyses and teaching briefs. Selected profile attributes can include sensitive information such as demographic details.
  • Google Drive and Sheets. Teachvatory reads configured course folders, file metadata, and spreadsheet contents for course tools. Where roster publishing is enabled, its separate Google connection requests permission to see, edit, create, and delete all Drive files. This broad permission supports existing folder and file IDs supplied by the teacher. The roster publisher uses it to locate or create the configured spreadsheet and update its selected roster and filter tabs. It does not delete Drive files or change their sharing permissions. Merely connecting does not publish a roster.

Storage and credentials

Session cookies keep you signed in. Browser storage retains workspace preferences, course configuration, cached results, and personal credentials you enter. When workspace sync is configured, settings and saved workspace state are also stored on the server to make them available across devices. Personal API credentials are excluded from ordinary workspace sync.

Optional roster publishing separately stores an encrypted Google refresh token. When you explicitly save a publishing setup, it stores encrypted Canvas and Teachly credentials so authorized runs can work without your browser being open. Connection email, course identifiers, destination settings, and run outcomes are also stored. Turning publishing off pauses writes; it does not remove the saved connection or settings.

Services that process information

Vercel hosts the application and processes requests and operational logs. Upstash Redis stores configured workspace state, teaching briefs, and publishing records. Google, Canvas, and Teachly process requests for their respective connected services. Roster publishing sends the roster and selected attributes to the configured Google spreadsheet, whose existing sharing settings determine who can see that output.

If AI features are used or configured, the content needed for the selected analysis or brief is sent to OpenAI or Anthropic, depending on the selected provider. That content can include course data and teacher-provided text. The roster publishing operation itself does not call an AI provider. Vercel Web Analytics collects website usage information. These services process information under their applicable service and privacy terms.

Use of Google user data

Teachvatory uses Google user data to provide its teaching-workspace features. It does not sell that data, use it for advertising, or use it to train generalized AI models. Teachvatory's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Retention, deletion, and your controls

Workspace state and saved publishing connections persist until replaced or removed; stopping a schedule does not delete them. Daily server briefs expire after two days, while their comparison baselines persist. Publishing run history expires after 90 days without a new recorded run. Browser data remains until cleared or removed by the workspace's account controls. Hosting providers may retain operational records under their own policies.

Where publishing controls are available, you can pause publishing, remove a course's saved setup and source credentials, or disconnect its Google authorization from Teachvatory. Disconnecting forgets the stored publishing token; to revoke Google's authorization itself, remove Teachvatory in your Google Account connections. Revoking access can also require you to sign in again. Neither action deletes existing spreadsheet outputs; manage those files in Google Drive.

For removal of server-stored workspace data, connections, or history, email the operator using the address above and identify the account and course concerned. Do not include passwords, tokens, or student records in your initial request. Students with questions about source records should also contact their teaching team.

Changes

Updates to this policy will be published on this page with a revised effective date. Review it when enabling a new connection or feature.