Last updated: August 24, 2026
Mr. A's Writing Tools is built for classrooms. We collect only what's needed for learning, we never sell student data, and we give schools full control over their information.
This privacy policy explains what data we collect, how we use it, and the rights you have. We comply with the Family Educational Rights and Privacy Act (FERPA) and the Children's Online Privacy Protection Act (COPPA).
| Data Type | What | Why |
|---|---|---|
| Account Information | Name, email address, and profile picture (from Google Sign-In) | To create your account and identify you |
| Student Writing | Essays, responses, and drafts submitted through assignments | To provide AI-powered feedback and track progress |
| Progress Data | Scores, completion status, time spent, and skill mastery levels | To show progress to students and teachers |
| Class Information | Class name, class code, teacher-student associations | To organize students into classes and deliver assignments |
| Usage Data | Pages visited, features used, browser type | To improve the product and fix bugs |
| Language & Accessibility | English language proficiency level, home language (if provided by teacher) | To provide appropriate scaffolding and language support for English Language Learners |
| Learning Preferences | Interest categories selected by the student (e.g., sports, animals, science) | To personalize assignment topics and content |
Student data is used exclusively for educational purposes:
We never use student data for advertising, marketing, or any non-educational purpose. We never sell, rent, or share student data with third parties for their own purposes.
An AI that grades student writing has to be checked. We do that in two ways, and both are described here so schools know exactly what happens to student work.
Aggregate statistics. Every week we compute statistics across submitted work — score distributions per assignment, whether feedback improved students' next drafts, how often teachers adjusted an AI grade, and which practice items nearly everyone misses. These are counts and averages only. They contain no student writing, no names, and no student identifiers, and they are what we use to find scoring problems.
De-identified writing excerpts. When the statistics point to a scoring problem, we may keep a small number of individual writing samples as fixed test cases, so that we can verify a fix actually works and does not break later. Before any excerpt is retained for this purpose:
Because these excerpts carry no identifiers and no link back to a student, they are not part of a student's education record and are not returned or removed by an account deletion request. If your school would prefer that none of its students' writing be retained this way even after de-identification, contact us and we will exclude your school.
Under FERPA, schools control student education records. As a school-authorized service provider, we:
Schools may request a Data Processing Agreement (DPA) template that formalizes these commitments. The template is a starting point intended for legal review with district counsel.
Our platform serves students as young as grade 2 (approximately age 7). For students under 13:
We protect student data with industry-standard security measures:
We use a third-party AI provider ("our AI sub-processor") to generate coaching feedback on student writing. The vendor's identity, processing location, and the categories of data we send are published in our sub-processor list.
We do not transmit student names, email addresses, or account identifiers to our AI sub-processor. Submitted content is associated only with an opaque token internal to our system.
This section describes coaching feedback, which is on for everyone. The separate, optional feature described under Teacher-Connected AI Assistants below works differently, and we say so there rather than leaving it as an unstated exception.
Student writing submitted for coaching feedback is processed by our AI sub-processor solely to generate that feedback. It is not used to train, fine-tune, or improve any AI model. Our agreement with the sub-processor prohibits training on submitted content, and we have not opted in to any data-sharing programs.
Our AI sub-processor may retain submitted content for up to 30 days for safety and abuse monitoring, after which it is deleted. This retention is required by the sub-processor's safety policy and is not used for model improvement, advertising, or any commercial purpose.
Data in transit is encrypted using TLS 1.2 or higher. Data at rest with our AI sub-processor is encrypted using AES-256. Our sub-processor maintains SOC 2 Type 2, ISO/IEC 27001:2022, and ISO/IEC 27701:2019 certifications, and publicly states support for customer compliance with FERPA, GDPR, and CCPA.
Our written agreement with the sub-processor extends California's SOPIPA and AB 1584 protections to processing performed on our behalf: no targeted advertising directed at students, no profiling outside the educational service, and no sale of student data.
A teacher may connect their Writing Tools account to a service they already use. There are two: an outside AI assistant (for example Claude), and Google Classroom. Each is off unless a teacher turns it on.
These are integration partners rather than sub-processors: the teacher connects their own account with that provider, data moves at the teacher's direction, and the provider handles it under its agreement with the teacher or their school. Because a teacher authorizes these with the Google account they use to sign in here, teachers should sign in with the account their school issued them, not a personal one, so student information stays inside the school's own agreements.
If a teacher links a class to a Google Classroom course, we post the assignment title, description, due date, and a link to the student's workspace into that course, and write the resulting grade back to the Classroom gradebook. Students are matched to the course's existing roster by school email address or Google account ID. No student writing content is sent. This lands in the school's own Google Workspace for Education tenant — the same place its roster and gradebook already live. Unlinking the class stops it.
When a teacher connects an assistant and asks it about their classes, we send class names, student display names, grade level, assignment titles and due dates, completion status, scores, and last-active dates — for that teacher's own classes only.
We do not send student writing content, student email addresses, passwords, or login credentials through this connection, and we never send data from another teacher's classes. The assistant cannot write, revise, or submit work on a student's behalf.
Before anything is shared, the teacher sees a screen naming the assistant and stating that their students' names and progress will be sent to it, and must approve. The teacher can disconnect at any time from their Connected apps page; access ends immediately. Every request made through a connection is logged against that teacher's account, so a school can be told exactly what was accessed and when.
Data sent through this connection arrives in the teacher's or school's own account with that assistant's provider, and is handled under the agreement between that account holder and the provider — not under our AI-inference agreement. Schools that need particular training, retention, or data-residency commitments should confirm them on their own plan with that provider. Our sub-processor list names the provider and the exact data categories.
A school with a signed Data Processing Agreement may instruct us in writing to disable this feature for its teachers, and we will do so.
We use a small number of cookies that are essential for the service to function:
We do not use advertising cookies, tracking pixels, or any third-party cookies beyond those listed above.
| Service | Purpose | Data Shared |
|---|---|---|
| Google OAuth | Authentication (sign-in) | Name and email, provided by user during sign-in |
| AI sub-processor (see sub-processor list) | AI inference for coaching feedback | Student writing content and assignment context, associated only with an opaque internal token (no student names, email addresses, or account identifiers) |
| Render | Application hosting | All application data (encrypted at rest) |
| Sentry (optional) | Error monitoring | Technical error details (no student writing content) |
| Google Analytics (GA4) | Anonymous usage analytics | Aggregated page views and feature usage (no student writing content, no personally identifiable information). See Google's privacy policy. |
We do not use advertising networks or social media tracking pixels. Google Analytics data is used solely to understand aggregate product usage and improve the service.
For schools and teachers:
For parents and guardians:
We may update this privacy policy to reflect changes in our practices or legal requirements. We will notify schools of material changes at least 30 days before they take effect. The "Last updated" date at the top reflects the most recent revision.
If you have questions about this privacy policy or want to exercise your data rights, please contact us:
Mr. A's Writing Tools
Email: aaron@writingtools.org
We aim to respond to all privacy inquiries within 5 business days.