Understand the data flow.
Vecole is educator authoring software. Student records are not needed to generate assessments. This overview describes implemented controls; it is not an independent audit, security certification, or guarantee that incidents cannot occur.
Accounts and authorization
Studio uses authenticated sessions and ownership checks for educator content. Access is arranged through our team. Google connection is an optional authorization flow tied to the signed-in Vecole account; it does not automatically merge accounts based on email.
Google tokens
Google refresh tokens are encrypted server-side with AES-256-GCM and account-bound authenticated data. OAuth state is one-use and expires; PKCE protects the authorization exchange. Tokens are not placed in quiz images or student links. Disconnect removes the local connection and attempts Google revocation.
Published and exported content
Teacher review precedes publication and explicit sharing. PDF answer keys and QTI packages contain scoring information and must be handled as teacher material. Forms answer keys are sent to Google as quiz grading configuration. Teachers must check when Google releases scores and correct answers.
Legacy student worksheet links and temporary image URLs are bearer links: possession permits access while the link is valid. They are not proof of class membership. Google Forms responder permissions are controlled in Google, not by a Vecole roster check.
Providers and institutional review
Read Privacy for the service providers and processing purposes. Ask us for deployment-specific details on hosting, retention, backup handling, access controls, and contracts before a district rollout. We do not claim SOC 2 certification, guaranteed data residency, or FERPA/COPPA certification on this page.
Report a concern
Email contact@vecole.com. Use synthetic examples and do not include secret credentials or student data in the report.