Security
Last updated October 5, 2026
How Daybook protects a school's records. What Daybook keeps, and which services process it, is in the Privacy Policy.
Who can read what
Every request is checked by the database itself, not only by Daybook's pages. Row level security on every table decides what each person may read and change, so the same rules hold for anyone who reaches the database directly with a signed-in session.
- A teacher reads their own recordings and notes, and works with the classes they teach.
- An administrator reads everything at their school, every recording and note included, but not a teacher's chats, their Google connection or the emails they sent.
- Each school's data is kept apart from every other school's.
Signing in
- A password must have at least 8 characters, with a lower-case letter, an upper-case letter, a number and a symbol.
- An administrator who gives someone a temporary password can require a new one at their first sign-in. Until it is changed, the account can open nothing else.
- Changing a password needs the current one.
- A session ends 12 hours after signing in, or after 2 hours without activity. Signing out, or an administrator deactivating an account, ends its access at once: the database refuses the session from then on.
- The session's cookies cannot be read by scripts, and are sent only over HTTPS.
In the browser
- Daybook is served only over HTTPS, and tells browsers to keep to it.
- A Content-Security-Policy made for each request lets only Daybook's own scripts run, and lets a page connect only to Daybook and to its live transcription service.
- No other site can show Daybook's pages in a frame.
- The microphone and screen capture are allowed for Daybook alone, and the camera for no one.
Recordings
- Audio is kept in private storage, never public, and Daybook serves it only to people who may read the recording.
- A recording runs for 15 minutes at most, and its size and kind are checked before it is sent to be transcribed.
- For a live transcript, the browser gets a key that works for that one recording only. The services' own keys never leave Daybook's server.
- A teacher's Google token is sealed with AES-256-GCM under a key only Daybook's server holds, and bound to the teacher's account, so that a copy of it opens for no other account.
- Daybook asks Google only to send email and to read calendars. It cannot read anyone's email.
Limits and records
- The database limits how many changes one account can make in ten minutes, which bounds how much one account can change.
- Every change to users, password resets, the school, its calendar, courses, classes, students and enrolments is recorded with who made it and when, and that record cannot be changed. Attendance marks are never changed or removed.
- The secret key Daybook's server holds may do only a few named things in the database.
Backups and monitoring
- The database is backed up every day, and the last seven backups are kept.
- Errors on Daybook's server are recorded without the contents of the request, and whether Daybook is up is checked every 10 minutes.
- Row level security is tested from inside the database, as each kind of user.
Where data is kept
Daybook's database and recordings are kept by Supabase, in the United States. The services that process them are listed in the Privacy Policy.
Reporting a problem
To report a security problem, write to support@elevategrade.com. We will tell a school without undue delay after we become aware of a personal data breach affecting its data.