Privacy policy.
Last updated: 24 June 2026 · Effective: 24 June 2026
SayaLab is built for educators who need to trust what comes out of an AI tool. That standard applies to how we handle your data too. This policy explains what we collect, why, and what goes where — including the parts most tools leave out.
1. Who we are
SayaLab operates the website at sayalab.net and the application at app.sayalab.net (together, the “Service”). We provide educators with AI-assisted assessment generation software.
SayaLab
contact@sayalab.net
2. What data we collect and why
2.1 Account data
When you register or sign in, we collect:
- Email address — to identify your account and send transactional communications.
- Display name (optional) — a name you choose to show within the product.
- Password — stored and managed exclusively by our authentication provider. We never receive or store your password in plaintext.
- Account tier (“free”, “pro”) — to enforce usage quotas and billing entitlements.
Legal basis (GDPR): Performance of a contract (Art. 6(1)(b)) — account data is necessary to provide the Service.
2.2 Content you upload
To generate assessments, you upload source material — PDFs, Word documents, presentations, plain text, or images. We process and store the original file, extracted text and chunked representations, pedagogical metadata we extract (learning objectives, key concepts, audience level, Bloom's taxonomy levels, and coverage summaries), and which learning objectives you confirmed, edited, or removed.
Your uploaded files and extracted text remain stored until you delete the content item. Deleting an item removes the file and all associated database records.
Legal basis (GDPR): Performance of a contract (Art. 6(1)(b)) — without processing your material, we cannot generate assessments.
2.3 Assessments and questions
When you generate an assessment, we store the assessment configuration, every generated question (including question text, answer options, the correct answer, explanations, and per-question quality metadata), the source passage from your material that grounds each answer, and assessment-level quality summaries.
Legal basis (GDPR): Performance of a contract (Art. 6(1)(b)).
2.4 Export history
When you export an assessment, we log the export event, the format chosen (PDF, CSV, JSON, QTI, Google Form), the options selected, the outcome, and the file size. We do not store the exported file itself.
Legal basis (GDPR): Legitimate interests (Art. 6(1)(f)) — to maintain an accurate record of outputs produced on your behalf and to support dispute resolution.
2.5 Usage and billing data
We collect quota records (questions generated per 30-day window), LLM usage logs (task type, provider, model, token counts, estimated cost, latency, and success or failure status — linked to your user ID), and subscription records (plan, billing interval, status, and references to your payment processor identifiers).
Legal basis (GDPR): Performance of a contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) for cost monitoring and fraud prevention.
2.6 Google account (if you use Google Forms export)
If you connect your Google account to export assessments as live Google Forms, we store your Google account email address, an OAuth access token and refresh token (encrypted at rest), and the OAuth scope granted (limited to Google Forms creation only).
We use these credentials solely to create Google Forms in your Google Drive on your instruction. We do not read, modify, or access any other content in your Drive.
You can disconnect your Google account at any time via Settings, which deletes the stored tokens and revokes our authorisation.
Legal basis (GDPR): Performance of a contract (Art. 6(1)(b)) and your explicit authorisation through the OAuth consent screen.
2.7 Analytics data
We use Google Analytics 4 (GA4) on both sayalab.net and app.sayalab.net. GA4 is loaded only if you accept analytics cookies via our consent banner. If you decline, GA4 is not loaded and no analytics data is collected.
When enabled, GA4 collects pages visited, time spent, device type, browser, coarse geographic region, referral source, and product interaction events. GA4 does not receive your email address, your uploaded content, or your generated questions.
Your consent preference is stored in your browser's local storage under sl-analytics-consent. You can change it at any time via the cookie banner.
Legal basis (GDPR): Consent (Art. 6(1)(a)).
2.8 Contact form submissions
If you submit a message via sayalab.net/contact, we collect your name, email address, organisational role, and the message text. We use this only to respond to your enquiry and to improve the Service. We do not use contact form submissions for marketing without your separate consent.
Legal basis (GDPR): Legitimate interests (Art. 6(1)(f)) — to respond to enquiries and improve the Service.
2.9 Waitlist submissions
If the Service is in closed beta and you submit your email address to join the waitlist, we store your email, optional name, and an optional note explaining your intended use. We use this only to notify you when access becomes available.
Legal basis (GDPR): Consent (Art. 6(1)(a)).
4. Third parties who receive your data
4.1 AI providers
The text of your uploaded material, extracted learning objectives, and generated questions are transmitted to one or more of the following providers to perform the analysis and question generation that is core to the Service:
| Provider | Purpose |
|---|---|
| Anthropic, PBC | Content analysis, question generation, quality validation |
| OpenAI, LLC | Content analysis, question generation (fallback) |
| Google LLC (Gemini) | Image-to-text extraction for image uploads |
What is transmitted: extracted text from your material, learning objectives, assessment configuration, and draft questions. Your email address and account identifiers are not included in these requests.
Prompt caching:we use Anthropic's prompt-caching feature, which stores system prompts on Anthropic's infrastructure for up to one hour to reduce latency and cost. User content (your material's text) is not cached.
All three providers process data in the United States. As of the effective date of this policy, Anthropic and OpenAI do not use API inputs to train their models by default. See Section 7 for how we address international transfers.
4.2 Cloud infrastructure
We use cloud providers for database hosting, authentication, and file storage. All personal data described in this policy is stored within these systems, hosted on infrastructure located in the United States.
4.3 Stripe
We use Stripe to process payments and manage subscriptions. When you subscribe to a paid plan, Stripe collects your payment card details directly — we never receive or store your card number. We share with Stripe your email address, subscription plan, billing interval, and webhook event metadata.
4.4 Google (OAuth and Analytics)
If you connect your Google account, see Section 2.6. Google's privacy policy applies to data processed through their APIs. If you accept analytics cookies, see Section 2.7.
4.5 Email delivery
We use a transactional email provider to forward contact form submissions to our team. The name, email, role, and message you submit are transmitted to this provider solely for delivery purposes.
4.6 Hosting infrastructure
The Service is hosted on cloud infrastructure. Standard HTTP request metadata (IP address, User-Agent, request path, response status) may be processed by our hosting provider as a function of operating the service. This data is not combined with your SayaLab account data.
5. How long we keep your data
| Data category | Retention period |
|---|---|
| Account data (email, name, tier) | Until you request account deletion |
| Uploaded files and extracted text | Until you delete the content item |
| Generated assessments and questions | Until you delete the assessment |
| LLM usage logs | 24 months from creation |
| Export audit logs | 24 months from creation |
| Google OAuth tokens | Until you disconnect your Google account or request deletion |
| Usage quota records | 13 months from creation |
| Contact form submissions | 24 months from submission |
| Waitlist submissions | Until admitted, declined, or removed on request |
| Analytics data (GA4) | Subject to Google's retention settings (default: 14 months) |
| Payment and subscription records (Stripe) | Up to 7 years for legal and tax compliance |
If you request deletion of your account, we will delete or anonymise all of your personal data within 30 days, except where we are required by law to retain records for a longer period.
6. Your rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access. Request a copy of the personal data we hold about you.
- Rectification. Ask us to correct inaccurate personal data.
- Erasure. Ask us to delete your personal data. You can delete content and assessments directly in the product. To request full account deletion, email contact@sayalab.net. We will complete deletion within 30 days.
- Restriction of processing. Ask us to restrict processing of your data in certain circumstances.
- Data portability. Export your assessments in multiple formats (PDF, CSV, JSON, QTI) from within the Service. To request a structured export of all personal data associated with your account, email contact@sayalab.net.
- Objection. Object to processing based on legitimate interests. We will cease that processing unless we have compelling legitimate grounds that override your interests.
- Withdraw consent. Where processing is based on your consent (analytics cookies, waitlist), you may withdraw at any time without affecting the lawfulness of prior processing.
- Lodge a complaint. Lodge a complaint with your local data protection authority. If you are in the EEA, the supervisory authority of your member state has jurisdiction.
To exercise any of these rights, contact us at contact@sayalab.net. We will respond within 30 days and may ask you to verify your identity before fulfilling the request.
7. International data transfers
SayaLab and its sub-processors operate in multiple countries. Your personal data may be transferred to and processed in countries outside your own, including the United States.
Where we transfer personal data from the European Economic Area or the United Kingdom to a country without an equivalent level of data protection, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or an adequacy decision issued by the relevant supervisory authority.
The following recipients may receive transfers outside the EEA: Anthropic (US), OpenAI (US), Google LLC (US), Stripe (US), and our cloud infrastructure and email delivery providers (US).
8. Security
We implement the following technical and organisational measures to protect your personal data:
- Session tokens are HTTP-only and Secure cookies — not accessible to JavaScript.
- Google OAuth credentials are encrypted at rest before database storage.
- All data in transit is encrypted via TLS.
- File storage access is scoped to our application; individual users do not have direct bucket access.
- Access to production infrastructure is limited to authorised personnel.
No transmission over the internet and no storage system can be guaranteed to be 100% secure. If you believe your account has been compromised, contact us immediately at contact@sayalab.net.
9. Children
The Service is intended for educators and is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data without parental consent, please contact us at contact@sayalab.net and we will take steps to delete it.
Educators may upload teaching materials that reference students. Such materials should not include personally identifiable student information. We are not responsible for the content of materials you upload.
10. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you by email or by displaying a prominent notice within the Service before the changes take effect. The “last updated” date at the top of this page reflects the most recent revision.
Your continued use of the Service after a material change constitutes acceptance of the updated policy. If you do not agree with the changes, you should stop using the Service and request deletion of your account.
11. Contact
If you have any questions about this policy or how we handle your personal data, email us at contact@sayalab.net with the subject line “Privacy enquiry”. We aim to respond within 5 business days.