Privacy policy
Last updated September 16, 2026. Covers vecole.com and Vecole Studio at studio.vecole.com.
Vecole is an assessment-authoring service for educators. Contact the Vecole team at contact@vecole.com with questions about this policy or the organization providing your account. Access is arranged directly; student accounts and student test-taking in Vecole are not part of the current offering.
Information we receive
- Website inquiries: the name, email, role, grade band, organization, and other information you choose to send in a demo request or support message.
- Educator accounts: account and authentication information, teaching preferences, and school or district affiliation you provide. Affiliation is self-reported and does not by itself grant institutional access.
- Assessment content: prompts, selected standards, generated and edited questions, figures, keys, published versions, and export or delivery records.
- Technical information: information needed to operate and protect the service, such as request logs, IP addresses, browser details, errors, and usage records. Hosting providers also process requests made to the site.
We use this information to provide accounts, generate and manage assessments, respond to requests, maintain the service, and investigate problems or misuse.
AI-assisted authoring
Generation sends relevant teacher-supplied content, curriculum information, and assessment instructions to our model provider, OpenAI. Generated output is returned to Vecole for checks, storage, and teacher review. Do not include student names, IDs, scores, IEPs, health information, or other sensitive personal information in prompts or assessment content.
Not requiring student records does not mean that information typed into a free-text field cannot contain personal data. If you submit such information by mistake, contact us without sending an additional copy of the sensitive content.
Google Classroom and Google Forms
Connecting Google is optional. We receive the connected Google account identifier and email, the permissions granted, and authorization tokens. Refresh tokens are encrypted on the server so the connection can work without asking you to authorize every request.
At your request, Vecole lists active classes you teach, creates and populates a Google Forms quiz with questions and answer keys, reads quiz configuration and point values, publishes it for responses, and creates a Classroom assignment containing its responder link. We retain form and assignment identifiers, class names, version references, and delivery state so we can show history and avoid duplicate sends. Recovery may read coursework links in the selected class to find an unconfirmed assignment.
The integration does not import rosters or read student submissions, Forms responses, or student grades. The permissions Google grants can be broader than these implemented actions. We use them for the user-facing integration described here, not as permission to collect unrelated student records.
Diagram and formatted-choice images are made available to Google through unguessable, expiring image URLs during quiz creation. These image endpoints return student-visible PNGs, not answer-key JSON. Google hosts the resulting quiz and handles student responses under its own terms and the teacher's responder-access and grade-release settings.
Vecole's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. Google API data is not used to train generalized AI models or for advertising. Our Google integration does not send rosters, student responses, or Google authorization tokens to the model provider.
Service providers and disclosure
Operating the service involves hosting, database, rate-limiting, model, and communications providers. The deployment configuration uses Render for the public static site and Studio services, MongoDB Atlas for application storage, Upstash for rate limiting, OpenAI for generation, and Google for optional Classroom and Forms features. Demo inquiries are submitted to the Studio backend and sent through Resend to our contact inbox. The visitor's email is used as the reply address. Inquiries are not stored in the application database by the demo endpoint, but the email provider and our inbox process and retain email records under their applicable settings. Contact us for deployment-specific provider and institutional vendor-review details before submitting sensitive information.
Providers receive information needed for their role. We may also disclose information where required by law or necessary to investigate abuse or protect the service and its users. Contact us for the applicable provider and contractual details for your deployment rather than assuming a particular data location or district agreement.
Cookies and local storage
Studio uses session cookies for authentication and temporary cookies to protect the Google authorization flow. The public site uses browser functionality for navigation and display. This site does not include advertising trackers in its application code. Hosting logs and any provider-side measurement are separate from advertising tracking. Blocking necessary cookies can prevent login or Google connection.
Retention, deletion, and disconnecting
Account and assessment records remain while needed to provide the service, maintain delivery history, address support requests, and meet applicable obligations. We do not promise a single retention period for every category: active records, operational logs, backups, and records held by providers can have different lifecycles. Contact us for retention requirements before an institutional rollout.
To request access, correction, or deletion, email contact@vecole.com from your account address. State the account and the request, without including passwords, tokens, or student records. We may need to verify your authority. We will explain any limits on deletion, including records that must be retained and backup handling.
Disconnecting Google removes the stored connection credentials from Vecole and attempts to revoke Google's authorization. It does not automatically erase delivery history, delete your Google Forms, or remove Classroom assignments. You can also revoke access in Google Account connections. Delete Forms and Classroom content in Google separately. Deleting an assessment in Vecole does not delete its independently owned Google quiz.
Educators, children, and education records
Vecole accounts are intended for educators and authorized adult staff, not children. Assessment authoring does not require student records. Some shared assessment links can be viewed without an account; the current Vecole worksheet view does not collect student answers. Do not use the service to upload education records until your institution has reviewed the arrangement and any required agreement is in place.
This policy is not a claim of FERPA or COPPA certification and does not replace a district's legal review. If you believe a child has submitted personal information directly to Vecole, contact us so we can investigate.
Changes and contact
We will update this page when our practices change and revise the date above. Material changes affecting existing accounts will be communicated as appropriate. Privacy and data-handling questions can be sent to contact@vecole.com.