ScholarStudio ยท Feedback Refinery
Privacy Policy
This Privacy Policy explains how Feedback Refinery, a ScholarStudio service, accesses, uses, stores and shares information when you use the application. Feedback Refinery is designed to help supervisors convert written and audio feedback into clearer written comments, analyse feedback patterns, and write user-approved comments back to Google Docs.
1. Information Feedback Refinery processes
Account information
When you sign in, authentication services may process identifiers such as your user ID, email address, display name and technical sign-in information. Feedback Refinery uses Firebase Authentication to manage application sign-in.
Google Workspace information
If you connect Google Drive, Feedback Refinery may access the Google Docs and Drive information needed for the feature you request. This can include a document identifier, document comments, comment metadata, and ScholarStudio audio recordings linked from comments. When you choose to write refined feedback back to a document, the application also uses Google APIs to perform that write-back.
Google Drive access is permission-based. The Google Apps Script component is configured to act as the user accessing the web app, so its ability to read or modify a file is constrained by that user's Google permissions. Feedback Refinery does not receive your Google password.
Feedback, transcripts and AI outputs
Feedback Refinery processes the comments you select, audio transcripts, custom prompt instructions, AI-refined comments, and any Meta-comment analyses you generate. These materials can contain personal or academic information, so you should only process material you are authorised to use.
Saved history and browser storage
When you are signed in, Feedback Refinery can save document-processing runs to Cloud Firestore so that Comment history can be reopened later. A saved run may include the document ID and link, settings used for that run, comments and transcripts, refined comments, analysis reports and scores, write-back status, and timestamps.
The application also uses browser local storage for interface state, recovery of the current comment session, custom rubric choices and locally retained reports. Clearing browser site data may remove this local information.
2. How information is used
Information is used only to provide, secure and maintain Feedback Refinery and the features you request. This includes authenticating users, retrieving comments, accessing linked recordings, transcribing audio, refining feedback, producing analyses, maintaining comment history, and writing comments back when you explicitly request that action.
ScholarStudio does not sell Google user data or use it for advertising. Google user data is not used to build advertising profiles or for purposes unrelated to Feedback Refinery's user-facing functions.
3. Google API Services User Data
Feedback Refinery's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data is accessed only when required for features initiated by the user. Where information is transferred to a service provider, that transfer is limited to what is necessary to provide the requested function.
4. AI processing and OpenAI
Feedback Refinery sends selected text and audio to OpenAI through authenticated Firebase Functions. The OpenAI API credential is held server-side; users are not asked to provide or store a personal OpenAI API key in their browser.
OpenAI processes this material to generate transcriptions or requested text outputs. OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer explicitly opts in. Retention depends on the OpenAI endpoint and account data-control settings. See OpenAI's API data controls for current details.
The current transcription workflow is designed to use retrieved audio transiently for transcription rather than save a separate copy of the audio file in Feedback Refinery's Firestore history. The resulting transcript may, however, form part of a saved comment-history record.
5. Service providers
Feedback Refinery relies on service providers required to operate the application, principally Google services (including Google Apps Script, Google Drive APIs and Firebase) and OpenAI. Those providers process information under their own terms, security controls and data-processing arrangements.
6. Data retention and deletion
Local browser information remains until it is cleared by the user, replaced by newer state, or removed by application controls. Saved Comment history remains in the user's Feedback Refinery account until it is deleted through available history controls or removed as part of account/service administration, subject to technical backup cycles and legal obligations.
Third-party providers may retain service data according to their applicable terms and data-control settings.
7. Security
Feedback Refinery uses authenticated Firebase Functions for AI requests and keeps the OpenAI API credential in server-side secret storage. Google Drive access is authorised through Google rather than by collecting Google passwords. No internet service can guarantee absolute security, and users should avoid submitting information they are not authorised to process.
8. Your choices and responsibilities
You can choose whether to connect Google Drive, which comments to process, whether to use AI transformation, and whether to write results back to the source document. You are responsible for ensuring that your use of student, colleague or institutional information complies with applicable law, ethics requirements and institutional policies.
9. International processing
ScholarStudio's service providers may process information in countries other than your own. Their processing locations and transfer safeguards are governed by the provider's applicable terms and data-protection arrangements.
10. Applicable privacy law
Where applicable, ScholarStudio will handle personal information in accordance with applicable data-protection law, including South Africa's Protection of Personal Information Act (POPIA). Additional rights may apply depending on where you live or where your institution operates.
11. Changes to this policy
This policy may be updated when Feedback Refinery's features, providers or data practices change. The effective date above will be revised when material changes are published.
12. Contact
Privacy questions or requests concerning Feedback Refinery can be directed to ScholarStudio through the contact information published at scholarstudio.org.