Privacy Policy
ProseBird holds two things that matter: the writing you submit, and the Google account you sign in with. This page says exactly what happens to both.
Effective 28 July 2026 · ProseBird
Who this covers
This policy applies to ProseBird, an invite-only writing-feedback tool for Flourish learners and their tutors. It covers everyone who signs in, and anyone who reads the public landing page without signing in.
ProseBird is operated from India. For the purposes of the Digital Personal Data Protection Act 2023 we are the Data Fiduciary for the personal data described below, and you are the Data Principal.
There is no self-registration. An account exists only because a tutor created it, and no Google account can sign in unless a tutor has already added that address. That single design decision is why this policy is as short as it is: there is no open population of users to profile.
Google account data
Signing in uses Google solely to establish which email address is at the keyboard. We request three OAuth scopes and no others:
openid— your Google account identifier, so that a returning sign-in is recognised as the same person even if the display name changes.email— your email address, which is matched against the list of learners a tutor has added. This is the only thing that decides whether you get in.profile— your name and profile picture, shown to you in the app and to your tutor on the People page, so a class list reads as people rather than addresses.
From these we store your Google account identifier, your email address, your name, and the URL of your profile picture. We use this data for exactly one purpose: signing you in and showing your tutor whose work is whose. It is not used for advertising, not sold, not shared with anyone outside the services listed in section 7, and not used to train any machine learning model.
We do not request offline access and never receive a refresh token, so ProseBird cannot reach your Google account when you are not actively signing in. We hold no access to Gmail, Drive, Calendar, Contacts, or any other Google service — those scopes are never requested, so they could not be granted.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke our access at any time from your Google account permissions page; doing so stops you being able to sign in, and does not by itself delete the data already held here — see section 10.
What else we hold
What you give us
- The writing you submit, along with its title and any context you add about the assignment.
- The age you state for the author of each piece. This changes what the reviewer looks for, so it is stored with the piece.
- The feedback that comes back, and which suggestions you accepted or applied — so your page of past work can show what changed between drafts.
What is created as you use it
- Session records. Each sign-in stores a SHA-256 hash of your session token, when it expires, and the browser user-agent string. The token itself is never stored, so a copy of that table is a list of expiry times rather than a set of working credentials.
- Credit history. Every grant, charge and refund, with who made the change and why.
- Review metadata. Word count, number of suggestions, which model answered, tokens used and the cost of the call — so a tutor can see what the class is spending.
- Timestamps for when you were invited, first signed in, and were last seen.
Server logs may briefly record errors and request details in the ordinary course of running the service. They are not used to build any profile of you.
What we do not collect
- No third-party analytics, no advertising networks, no tracking pixels.
- No advertising or device identifiers, and no cross-site tracking.
- No payment details — learners never pay ProseBird anything.
- No behavioural profiling and no automated decision-making that produces a legal or similarly significant effect. The feedback on your writing is machine-generated, but it is advice on a page, not a decision about you.
- No location data beyond whatever an IP address implies in transit, which we do not store against your account.
Sending writing to an AI reviewer
Feedback is produced by a large language model. When you submit a piece, the text you pasted or uploaded, its title, any context you added, and the age you stated are sent to whichever provider the service is configured to use — currently Anthropic or OpenAI.
Your name, email address and account identity are never sent to the model. The reviewer is given a piece of writing and an age, and nothing that identifies who wrote it.
These providers act as processors for us, under their API terms: data sent through their APIs is not used to train their models. Their handling is governed by their own policies, linked above. If a piece contains personal details about you or anyone else, those details go to the provider along with the rest of the text — so it is worth not putting anything into a submission that you would not want processed this way.
Where the service runs with no API key configured, reviews come from a built-in rule-based reviewer and nothing leaves the server at all.
Children and parental consent
ProseBird is built for school-age writers, and many of the people using it are children. Under the Digital Personal Data Protection Act 2023 that means anyone under eighteen.
There is no way for a child to sign themselves up. An account exists only because a tutor created it, and it is the tutor's or school's responsibility to obtain verifiable consent from a parent or lawful guardian before adding a learner's address. If you are a parent or guardian and an account was created for your child without your consent, write to [email protected] and we will delete it.
In line with the Act, for children we do not:
- carry out any tracking or behavioural monitoring;
- show any advertising, targeted or otherwise;
- build profiles, or process their data in any way likely to have a detrimental effect on their well-being.
A parent or guardian may ask at any time to see what is held about their child, to have it corrected, or to have the account and its writing deleted. We do not require the child's involvement to act on that request.
How long we keep things
- Your account is kept while it exists on the tutor's list. Disabling an account keeps the record but blocks sign-in; removing it deletes the account outright.
- Your writing and its feedback are kept so that your page of past work stays useful across a term. If an account is deleted, its reviews stop being attributed to anyone.
- Sessions expire after 30 days, and are deleted when you sign out.
- Credit history is kept for as long as the account, because it is the record of what was spent.
You can ask us to delete a specific piece of writing, or everything we hold about you, at any time. Ask your tutor, or write to [email protected].
Your rights
Under the Digital Personal Data Protection Act 2023 you may:
- Access a summary of the personal data we hold about you and what we do with it.
- Correct anything inaccurate, and complete anything missing.
- Erase your personal data where we no longer need it for the purpose it was given.
- Withdraw consent at any time, as easily as it was given. Withdrawing it means the account can no longer be used.
- Nominate another person to exercise these rights on your behalf if you become unable to.
- Raise a grievance with us, and escalate to the Data Protection Board of India if our answer does not resolve it.
Write to [email protected] from the address on your account, or ask your tutor to pass the request on. We aim to answer within 30 days.
Security
- Traffic is served over HTTPS, and the session cookie is marked
Securein production. - Session tokens are stored only as SHA-256 hashes, so the database never holds a usable credential.
- The session cookie is signed, so a cookie edited by the browser stops verifying.
- Access is invite-only. A Google account not on a tutor's list cannot sign in, whatever it presents.
- Every API route checks authorisation for itself rather than relying on the interface to hide anything.
- If we ever suspect the signing secret has leaked, rotating it signs everybody out immediately.
No system is perfectly secure. If you find a vulnerability, please report it to [email protected] rather than disclosing it publicly, and we will work with you on it.
Where your data is processed
ProseBird runs on cloud infrastructure that may be located outside India, and the AI providers named in section 6 process submissions on servers outside India. By using the service you accept that your data is transferred and processed in those locations, under contractual terms that require the provider to protect it and to use it only to provide the service to us.
Changes to this policy
If we change how data is handled we will update this page and move the effective date at the top. Where a change materially affects you — a new category of data, a new recipient — we will tell account holders directly rather than relying on you to notice.
Contact and grievances
For anything about your data, including access, correction, erasure or a complaint, write to [email protected].
If you are not satisfied with how we handle a grievance, you may complain to the Data Protection Board of India.