Skip to content

Privacy Policy

Last updated October 5, 2026

What Daybook keeps, what it is used for, which services process it, and how long it is kept.

Who is responsible

Daybook is an Elevate Grade product, operated by SchoolConex Inc. (“we”, “us”). For the information a school keeps in Daybook about its students and staff, the school is the controller. We process that information on the school's instructions, to provide Daybook.

What Daybook keeps

  • Accounts. Each user's name, email address and role, teacher or administrator. Passwords are held by the sign-in service, not in Daybook's own records. For each sign-in, the time it was last used. For whoever made a school by signing up, which Terms of Service and Privacy Policy they accepted, and when.
  • Signing in with Google. Someone who signs up or signs in with Google is known to the sign-in service by what Google gives it: their name, email address, the address of their Google profile picture, and Google's id for their account. Nothing else is asked of Google to sign in.
  • The school. Its name, time zone and plan; its terms and days off; its courses, classes and weekly timetable; and which teachers teach which classes.
  • Students. Each student's full name and email address, their Ontario Education Number when the school has it, and the classes they are in, from when to when.
  • Attendance. Every mark given to a student in a session: present or absent, the time of a late arrival, an early departure or time away, the reason an absence or lateness was excused when one is given, and who gave the mark and when.
  • Recordings. The audio a teacher records, from the microphone or the computer's sound, with its title, class, date and length. Its transcript: what was said, when, and by which speaker, with the names a teacher gives the speakers. The teacher's own notes, the notes written from the transcript, and whether the teacher marked those notes good or not.
  • Questions. The questions a teacher asks about their notes and the answers they get, the recipes they save, and whether they marked an answer good or not.
  • Usage. A record of each recording, by its length, and of each AI action, to hold each teacher to their plan's monthly allowance.
  • Records of changes. Who changed what, and when, for users, password resets, the school and its calendar, courses, classes, students, enrolments, and sessions started, cancelled or restored.
  • Google, when a teacher connects it. What is kept is set out under Google user data.
  • Error reports. When something fails on Daybook's server, Daybook keeps the time, the part of Daybook it happened in, and a short description of the error, with email addresses, long numbers and anything that looks like a key or a token taken out. It never keeps the contents of the request.
  • Page views and page speed. Daybook counts visits to its pages and measures how quickly they load, with Vercel Web Analytics and Speed Insights. A page's address is sent without anything after a question mark, so what someone searched for is not sent.
  • Billing. Payments are handled by Stripe, which keeps the card and the invoices. Daybook keeps, for a school that pays by subscription, Stripe's ids for the school and its subscription, the subscription's plan, status, number of seats and dates. Never a card number.

How it is used

  • To provide Daybook to the school: its timetable and attendance, its recordings, transcripts and notes, and answers to questions about them.
  • To hold each teacher to their plan's monthly allowance, and to limit how many changes one account can make in a short time.
  • To keep accounts safe. A session ends 12 hours after signing in, or after 2 hours without activity.
  • To find and fix faults, and to see which pages are used and how quickly they load.
  • To bill the school, and to send email about its account.

Recordings, transcription and AI

When a teacher saves a recording, its audio is sent to a transcription service, which makes the transcript and tells the speakers apart. Daybook uses Soniox. Where Soniox is not available it uses ElevenLabs, and where neither is, Google Gemini. While a teacher records, their browser can also send the sound straight to Soniox or ElevenLabs for a live transcript, with a key Daybook makes for that one recording.

To write notes and answer questions, Daybook sends an AI model the transcript, the teacher's own notes and the names given to the speakers. The model is Anthropic's Claude, or Google Gemini when Claude cannot answer. A question about a class, or about all of a teacher's notes, sends at most the twelve latest recordings the teacher can read. The attendance recap recipe also sends each student's name and mark for that class's session on the day of the recording. It never sends an email address, or the reason an absence was excused.

When Soniox makes a transcript, Daybook deletes the uploaded audio and its transcription from Soniox as soon as it has read the transcript, or as soon as the attempt fails. Under Anthropic's commercial terms, what is sent through its API is not used to train its models; Anthropic processes it in the United States. We do not use your content to train any AI models of our own.

Transcripts never change attendance. A recording, its transcript and the notes written from it never mark a student or change a mark. Only a teacher or an administrator does that.

Notes and answers are written by AI and can be wrong, as Daybook says where questions are asked. A person should check them before relying on them.

Google user data

A teacher can connect their own Google account to Daybook in Settings. It is optional, and Daybook works without it. Daybook asks Google for the permissions below, and the teacher can allow or refuse each one on Google's own screen.

  • openid and email: which Google account was connected, so that Settings can show it and email is sent from that address.
  • https://www.googleapis.com/auth/gmail.send: to send an email the teacher has written and reviewed, from their own Gmail, when they press Send. Daybook never sends an email by itself. This permission does not let Daybook read, list or delete anyone's email, and Daybook never does.
  • https://www.googleapis.com/auth/calendar.readonly: to read up to 20 events of the teacher's main calendar, from the start of today to the end of the next day with classes (or of tomorrow, when there is none), and show that day's and today's in Coming up on their home page. Daybook reads each event's title, its times, whether it was cancelled, and whether the teacher declined it. It never reads an event's description, its place or its guests' addresses, and it never changes the calendar.

What Daybook keeps from Google

Daybook keeps the connected account's email address, the permissions it granted, and the token that lets Daybook act for the teacher, sealed with AES-256-GCM under a key only Daybook's server holds. Calendar events are read each time the home page is shown and are not kept. For each email sent, Daybook keeps its subject, the number of people it went to, the note it was about and when it was sent. It never keeps the addresses or the message.

Only the teacher can see their Google connection and the emails they sent through it. The school's administrators cannot.

How Daybook uses it

Information received from Google is used only for the two things above, for the teacher who connected. It is not sold, not used for advertising, and not given to anyone else; what is kept is kept only in Daybook's own database. Calendar events are never sent to an AI model, and Daybook does not use information received from Google APIs to develop, improve or train AI or machine-learning models.

Daybook's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Ending the connection

A teacher can disconnect Google in Settings at any time. Daybook then asks Google to end its access and deletes the token it kept. The access can also be removed from the Google Account itself, under Security.

Who processes it

  • Supabase: Daybook's database, its sign-in, and the storage of recordings' audio, in the United States.
  • Vercel: hosts Daybook's pages and server, and counts page views and page speed.
  • Soniox, and ElevenLabs as a fallback: transcription.
  • Anthropic, through the Claude API: notes and answers, in the United States.
  • Google: the Gemini API, as a fallback for transcription, notes and answers; the Gmail and Google Calendar APIs, only for a teacher who connects their Google account; and signing in, only for someone who chooses Google to sign in.
  • Stripe: payments.
  • Resend: account and receipt emails.

We will give reasonable notice before adding or replacing one of these services, so that a school can object.

Sharing

We do not sell personal information, and do not use it for advertising. We share it only with the services above, to run Daybook, and where the law requires. Each school's data is kept apart from every other school's.

How long it is kept

  • Recordings, their transcripts and notes are kept until the teacher who made them, or an administrator, deletes them. Deleting a recording deletes its audio, its transcript and its notes.
  • The record of usage stays when a recording is deleted: it holds how long the recording was and when, not the recording.
  • A chat is kept until the teacher starts a new one, which deletes it.
  • Attendance marks are kept in the order they were given. A mark is corrected by giving a new one; marks are never changed or removed.
  • Users are deactivated, not deleted, and students are archived, not deleted. Records of changes are kept and never changed.
  • A Google connection is kept until the teacher disconnects it. Calendar events are not kept.
  • The database is backed up every day and the last seven backups are kept, so a deleted record can stay in a backup for up to seven days.
  • When a school stops using Daybook, we delete its personal data or, if it asks, return it, within a reasonable period, except where the law requires us to keep it.

Your choices and rights

Subject to applicable Canadian privacy law, including PIPEDA, you may ask for access to, correction of, or deletion of the personal information we hold about you. For information a school keeps about its students and staff, please make the request through that school.

In Daybook itself:

  • A teacher can delete their recordings, edit their notes and the names of speakers, delete a chat by starting a new one, delete their own recipes, and disconnect Google.
  • An administrator can delete any recording, correct a student's details, archive students and classes, and deactivate users.

Students

Students do not sign in to Daybook. Their names, email addresses, Ontario Education Numbers and attendance are entered by their school, and their voices can be heard in a recording of a class. The school decides whether a class may be recorded, and remains responsible for notice and consent as required, including a parent's.

A student, parent or guardian who wants a student's information corrected or deleted should ask the school.

Security

How Daybook protects this information is set out on the Security page. We will tell a school without undue delay after we become aware of a personal data breach affecting its data.

Contact

Privacy questions: support@elevategrade.com.