Privacy Policy
Updated 1 October 2026
This policy explains how Learning Tools handles data when you study, take tests, sign in with Google, and provide work for review. We use pseudonymous accounts. This reduces the use of direct identifiers, but does not provide complete technical anonymity.
On this page
Google sign-in
We request the OpenID permission to verify sign-in only. The service does not request access to Gmail, Google Drive, Calendar, or contacts. Google provides sign-in verification and an account identifier. We verify that response and use the identifier only to return you to the same Learning Tools account.
Instead of the original Google identifier, we store a derived value protected by a server secret and a separate U code. We do not retain your Google name, email address, photo, original identifier, or Google OAuth tokens as account data. Google data is not used for advertising or shared with advertisers.
Google independently processes sign-in data under its own policy. The site also uses Google web fonts, which cause your browser to send requests to Google when they load.
Data stored by the service
- Account records: an internal identifier, U code, protected derived Google identifier, role, permissions, and access status.
- Group and assignment records: G codes, membership, manager and reviewer permissions, invitations, issued assignments, deadlines, allowances, and related action times. Academy or organization names are not collected as identity fields.
- Test records: frozen questions and materials, answers, attempt status and timestamps, R codes, evaluations, submission and summary-inclusion records, notes, and issued reports.
- Access and security records: session-token hashes, temporary sign-in and invitation records, report-link metadata, and logs of administrative actions and report access.
Answers and notes can contain information you or a reviewer enter yourself. Avoid adding names, addresses, workplaces, or other identifying information unless needed for an answer. A person who already knows who holds a code may be able to associate pseudonymous codes and results with you.
Why we process data
We process this data to sign you in, save and resume your attempts, deliver assignments, review work you explicitly provide, manage groups and permissions, prepare reports, and protect the service against abuse. In this version, Google data is not used to train artificial intelligence models.
Who can see work
Your own attempts are accessible in your account. Assignment reviewers see only completed work you explicitly provide for review. Group membership or assignment-management permission alone does not expose unsubmitted work. Administrators with a separate permission and superadmins can view formal test results; this administrative access is logged.
An anonymous result can be viewed by a signed-in controller holding its R code or by an administrator with the relevant permission. An R code does not prove identity, authorship, or a right to attach the result to an account.
A temporary link can be created for an issued report. Someone holding that link can view its permitted content without signing in while access remains valid. Recipients may save or forward a downloaded report; expiry or revocation does not remove copies already downloaded.
Providers and technical data
The service is hosted on Cloudflare. Server records are stored in Cloudflare D1, and test materials and reports in private Cloudflare R2 storage. Providers may process your IP address, browser information, request time, and other technical data to deliver and protect the service. Google is used for sign-in and web fonts. These providers also operate under their own policies.
Cookies and storage on your device
Sign-in uses necessary cookies: the account session is valid for up to 12 hours, and Google sign-in verification state for up to 10 minutes. Signing out revokes the current session.
Test recovery and traffic-rule learning progress use browser storage, including SQLite on your device. Practice data is not synchronized to the server in this version. Different accounts and anonymous use have separate storage areas. Clearing site data can remove local progress and recovery access for an anonymous attempt.
Retention and deletion
The current cleanup process covers only anonymous completed results that have not been accepted by a controller and were completed at least 30 days ago. It does not delete unfinished attempts, accepted results, account-owned work, or assignment templates. R codes expire for initial lookup after 30 days; this is separate from result retention.
Recalling an assignment, suspending an account, or archiving a group does not delete started work or history. Contact us below to request access, correction, or deletion. Requests are reviewed with account verification, other users’ rights, and applicable requirements in mind. Deletion from active storage does not mean immediate deletion from backups or report copies held by recipients.
Support correspondence
If you email support, your sender address, message, and any information you voluntarily include will be available in the support mailbox, hosted by Gmail. Including a U code can associate your email address with your account. This information is used to answer and handle your request. It is separate correspondence, not data requested during Google sign-in.
Policy changes
We will update this page if our data practices change. The date of the current version appears at the start of this document.
Contact and data requests
For questions about Learning Tools, access to your data, or deletion requests, contact learning.gorgan.app@gmail.com.
For an account request, include your U code. We may ask you to verify access to the account. An anonymous result’s R code alone does not establish authorship. Do not send your Google password, one-time sign-in code, or a link containing an access token.