Privacy, in plain words.
This page explains what Scriblune saves, how tutoring uses your work, and the controls available to you.
Your assignments and conversation
Private sessions require an account. Originals, rendered pages, annotations, messages, rubrics, reviews, and final versions are stored in private Supabase resources. Uploaded files are preserved unchanged. The app uses ownership checks and database row policies to restrict access.
AI processing
After the upload disclosure, relevant document text, page images, selected crops, annotations, conversation, and enabled learning preferences may be sent to the configured OpenAI API for tutoring, visual indexing, or review. API requests use store:false. That setting does not override the provider’s applicable processing or abuse-monitoring retention terms. No privileged credentials are included in tutor context.
Account security and email
Resend delivers one-time verification codes to your email address. Signup requires a code. You can also enable two-factor verification with email codes, an authenticator app, or passkeys in account settings. Email codes expire after ten minutes. Security records contain hashed codes and encrypted temporary sessions; expired code records are removed after one day. Email recovery can restore account access.
Payments and usage
Stripe handles payment details directly. Scriblune keeps Stripe customer and subscription identifiers, plan status, credit balances, and usage records to apply your allowances. Card numbers and security codes do not pass through our server. The Owner can look up verified accounts and grant plans or bonus credits; these changes are audited. Billing and usage records are not public forum data or tutor context.
Private session feedback
Your feedback is private to the Scriblune team and linked to your account. It will not appear in your session history. Authorized staff may review feedback and internal issue tags; access is audited. After you send it, stored feedback is not available through student APIs, Realtime, search, normal exports, or the tutor. Your browser can see the answers while you type and transmit them.
Public community profiles and forum
Your forum username, optional picture, discussions, replies, reactions, and published attachments are public. Your account email and private study sessions are not included in your forum profile. Only upload material you want to share publicly. Images are resized and stripped of metadata. PDFs are offered as downloads. Unpublished attachments expire after one day.
You can edit or remove your posts. Moderators can review reports, edit, remove, or restore content and suspend forum participation. A forum suspension does not restrict your study account. Moderation records, including earlier versions of edited or removed content, are visible only to authorized moderators. Forum content is not included in the tutor’s private-session context. Use account settings to request a governed data export or account deletion.
Local storage and microphones
The sample workspace saves only sample work on this device. Optional recovery for a private session temporarily stores unsaved drawing actions in the current browser tab, with a visible opt-in. Recovery data is cleared on save or sign-out. Browser dictation starts only when you activate it and may use the browser or device vendor’s speech service.
Retention and privacy requests
The default implementation retains saved sessions and feedback until a governed deletion request is completed; it does not silently expire your work. Request access, correction, or account deletion from your account preferences. Authorized staff must verify the request, address applicable obligations, remove storage objects and database records as appropriate, and record completion. Backups and provider retention follow the configured services’ policies.
Families and schools
Parents, guardians, and schools should review how assignments and conversations are processed before a child uses Scriblune. Share only material needed for the lesson, and avoid names, addresses, or other sensitive details in uploads. Contact us for help with a child’s data. Email verification confirms control of an inbox; it does not verify age or parental consent.