1. About this policy
SayaLab provides assessment-generation tools for educators. This policy explains how we handle personal information on sayalab.net and app.sayalab.net, including information used to generate and export assessments.
For privacy questions or requests, email contact@sayalab.net.
2. Information we collect and how we use it
- Account information. We use your email address, optional display name, account permissions, and subscription status to provide and manage your account. Your password passes through our server to our authentication provider; it is not stored in our application database.
- Teaching materials and assessments. We store materials you submit, including files, images, text, and source links, along with extracted content, learning objectives, generated questions, answers, explanations, and your edits. We use this information to analyse materials, generate assessments, and provide editing and export features.
- Usage and export records. We record generation activity, AI processing costs, export formats, export results, and links to Google Forms we create. We use these records to apply plan limits, show your export history, and investigate errors.
- Billing information. We store subscription and payment-service references to manage paid plans. Stripe handles payment details directly; we do not receive your full card number.
- Messages and access requests. We store information you send through our contact form or waitlist, such as your name, email, role, and message. We use it to respond, review access requests, and send invitations. Our email provider records delivery events and can record when service emails are opened or their links are clicked. Invitation and review records may remain after a request is accepted or declined.
- Technical information. Our hosting services process information such as IP addresses, browser details, request paths, and errors to deliver and maintain the service. Some operational records are associated with your account.
- Optional analytics. If you accept analytics, Google Analytics measures visits and interactions, including device and browser information, referral information, and approximate location. See the cookies section for your choices.
Providing account information and teaching materials is necessary to use the corresponding features. Google Forms export and analytics are optional.
3. AI processing and service providers
Generating an assessment involves sending teaching material and assessment content to external AI services. These requests may contain extracted text, images used for text extraction, learning objectives, question drafts, and instructions you provide. If personal information appears in that content, it can also be sent to the AI provider.
We share information with the following service providers to operate SayaLab:
- Hosting, authentication, database and file-storage providers: processing account and technical information to run the service, and storing the teaching materials and assessments you save.
- Google Gemini, Anthropic, and OpenAI: extracting or analysing content, generating questions, and checking their quality. The provider used depends on the task and service configuration.
- Stripe: payments and subscription management.
- Email-delivery providers: processing email addresses, message contents and delivery information to send service emails, invitations and contact messages.
- Google Analytics: optional website and app usage measurement.
- Google Forms: creating forms when you choose that export option.
OpenAI and Anthropic do not use API inputs and outputs to train their models by default. Google’s paid Gemini API terms say prompts and responses are not used to improve its products. Optional data sharing can change how providers use information; these protections depend on the service and settings used.
AI requests may still be stored for security monitoring, caching, or debugging. We have disabled request logging for future calls in our Gemini project. Previously stored request logs remain subject to the prior rolling 55-day retention setting. Other provider-held records follow their own retention rules, including exceptions for safety or legal requirements. Deleting material in SayaLab does not itself delete copies already processed by an AI provider. Please do not submit student-identifying information or other sensitive personal information in materials or instructions.
You can read the providers' information at Google, Gemini API terms, Anthropic, OpenAI, and Stripe.
4. Connecting Google Forms
If you connect Google, we store encrypted access credentials, the permission you grant, and your Google email address if Google provides it. We use the connection to create and fill forms with the assessment content you choose to export, including answer keys when requested.
The permission allows viewing, editing, creating, and deleting specific Drive files you use with SayaLab, including forms it creates. It does not give access to your entire Drive. The integration uses this permission to create forms; it does not read student responses.
Disconnect Google in Settings to remove the credentials stored by SayaLab. We also request revocation from Google. You can remove access directly through Google Account connections. Disconnecting or deleting an assessment in SayaLab does not delete forms already created in your Drive; you manage those in Google.
Information received through Google APIs is used for this export feature in accordance with the Google API Services User Data Policy, including its Limited Use requirements.
6. Keeping and deleting information
We retain account information and saved materials so you can continue using them. You can delete assessments and source materials in the app. A source may need to be removed from assessments that use it before it can be deleted.
Deleting source material removes its application record and requests deletion of the stored file. File deletion can fail separately, so contact us if you need confirmation that a file has been removed. Export and usage records can remain after an assessment is deleted.
We remove detailed AI usage and export history after 90 days, and completed export-job records after 90 days without updates. Quota counters are removed 90 days after their usage window closes. Resolved contact messages are removed after 12 months without updates, and waitlist records after 6 months without updates unless an invitation is still valid. Cleanup runs daily; saved materials and assessments remain until you delete them or request account deletion.
To request removal of these records or deletion of your account, email contact@sayalab.net. Our team handles verified account-deletion requests by removing the login, saved materials and files, assessments, Google credentials, and related account records. Payment records, provider-held copies, and forms already in Google Drive are handled separately as described below.
Some information may need to be retained to meet applicable legal obligations or resolve an outstanding billing matter. Provider-held records and any backup copies may follow separate retention processes. We will explain any limits that apply to your deletion request.
7. Where information is processed and how it is protected
SayaLab uses providers operating in multiple countries. Information may be processed outside your country, including in Singapore and the United States. The location depends on the service and its configuration.
We use HTTPS for connections to our public services, access controls for account data, and encryption for stored Google access credentials. No online service can guarantee complete security. Contact us if you suspect unauthorised access to your account.
For questions about a provider's processing location or safeguards for an international transfer, contact contact@sayalab.net.
8. Your choices and privacy rights
You can update your display name, delete materials and assessments, export assessments, disconnect Google, and change your analytics choice. Contact us to request access to, correction of, or deletion of other personal information, including your account.
Depending on the law that applies to you, you may also have rights to receive a portable copy of your information, restrict processing, object to certain uses, or complain to a data protection authority. Where we rely on consent, you can withdraw it without affecting processing that took place before withdrawal.
Where a legal basis is required, we process account, teaching-material, and subscription information to perform our agreement to provide the service you request. We rely on our legitimate interests in maintaining the service, understanding operating costs, troubleshooting, and responding to enquiries for related operational and support records. Optional analytics relies on your consent, and legally required records are kept to meet those obligations.
Send requests to contact@sayalab.net. We may need to verify your identity and will respond within the time required by applicable law. Assessment exports are available in the app; requests for a copy of your personal information are handled separately.
9. Students and children
SayaLab is designed for educators, not for student accounts. Do not upload student names, contact details, grades, health information, or other information that identifies students. If you believe such information has been submitted, contact us so we can help address it.
10. Changes to this policy
We will update the date above when this policy changes. Material changes to how we handle personal information will be communicated through the service or by email. If a new use requires consent, we will ask for it separately.