humdrum

Privacy Policy

Effective Date: 2026-09-11

Adult Attestation Required

Humdrum requires an adult attestation before any student content is stored. Teachers signing in through Clever must confirm they are authorized to act for their school. Identifying as a teacher is not enough. Guest users must have a teacher, parent, or guardian confirm they are supervising the student before an account is created. That supervision confirmation is not verified parental consent. For email-based sign-up, a parent or guardian's email is collected during verification, and no student writing is stored until they confirm educational use. We log attestation records (version, method, timestamp). Humdrum remains responsible for its COPPA obligations.

Our Commitment to Privacy

Humdrum is a writing tool for 4th–8th graders, used by schools and homeschool families. We follow the Children's Online Privacy Protection Act (COPPA). Humdrum remains responsible for its COPPA obligations.

For schools, a teacher or administrator may use Humdrum only if they are authorized to act for their school. Identifying as a teacher is not enough. We log the attestation they give us. That attestation is not, by itself, verified parental consent.

For families, a parent or guardian confirms educational use before any child writing is stored. This policy explains what we collect, how we use it, and the controls available to you.

Data We Collect

Student Content

We store student pen names, writing drafts, completed stories, quest progress, class preferences, and other settings required for autosave and feedback.

For students signing in through Clever: We receive whatever email address Clever provides (if any) and the student's name. Clever IDs are hashed before storage. Legacy accounts that previously stored unhashed IDs are migrated to hashed values and the raw ID is cleared on the user's next sign-in.

For guest/sandbox users: We generate a synthetic email address (not linked to any real email) for account purposes. No real email is collected from the student.

For email-based accounts (multi-writer sign-up): A parent or guardian provides their email address to create the account via a one-time verification code. This email is stored as the account owner's contact for authentication and account recovery. We also offer an optional newsletter sign-up that stores the submitted email address separately.

Teacher Accounts

When a teacher signs in with Clever we receive their email address, name, roster identifier, and school context to configure the classroom. The Clever ID is hashed before storage, and we log an attestation record (user ID, version, method, timestamp) after the teacher confirms they are authorized to act for their school and to enable Humdrum.

Guest/Sandbox Accounts

Users can access Humdrum without Clever through our guest login. Before creating any account or storing any data, we require a teacher, parent, or guardian to confirm they are supervising the student's use. We log that attestation. It is not verified parental consent.

Classroom Roster Data

When teachers sign in through Clever, we sync class information including section names, grades, subjects, and term dates. District and school identifiers help organize classrooms correctly. All Clever IDs (teacher, student, section) are hashed before storage to protect privacy.

Feedback & Bug Reports

Students can submit feedback from within the app. When feedback is submitted, we store the message text, the page URL, and an internal account identifier. The account identifier is a persistent identifier collected solely to support internal operations — specifically, debugging issues that students report. It is not used to build profiles, serve advertising, contact individuals, or for any purpose beyond resolving technical problems.

System & Analytics Data

We collect technical information (browser type, device, timestamps) needed to keep the service secure. We use our own internal analytics to operate and improve Humdrum and support teachers and students. These reports may connect activity counts to accounts and classrooms.

Storage & Security

Application records are stored in Supabase (Postgres + Auth) with row-level security so each account can only access its own records. Vercel and Supabase provide hosting and data storage for Humdrum. Clever IDs are stored as hashed values, and consent logs help us verify ongoing authorization. Internal analytics may remain linked to accounts and classrooms; they are not all anonymous or de-identified. We do not run advertising trackers or third-party remarketing tags.

Billing & Email Service Providers

We use Stripe to process adult subscription payments. Stripe receives the adult account holder's email address and internal account identifiers needed to manage the subscription.

We use Resend to deliver account and service emails, including authorization confirmations, subscription messages, and family milestone and trial emails. These emails include the recipient's email address and message content. Family milestone and trial emails may include writer pen names and writing activity counts, such as stories written, words written, or quests completed. These emails do not include the text of students' stories.

Stripe and Resend receive the information needed to perform these services for Humdrum.

Writing Analysis

Humdrum analyzes student writing in real time to detect creative techniques such as simile, metaphor, personification, alliteration, onomatopoeia, hyperbole, and imagery. This analysis powers the educational feedback students see — showing them how their writing skills are growing over time.

How it works: As a student writes, the text is periodically sent to Amazon Web Services (AWS Bedrock) for evaluation. The model identifies whether specific creative techniques are present and returns a result. The student's text is processed in real time and discarded immediately by the service — it is not stored, logged, cached, or used for model training.

When it runs: This analysis runs whenever your child writes in the app.

What we store: We store a record of each technique detected, including the technique type (e.g. simile, metaphor), confidence level (high, medium, or low), and which story it was found in. This per-story data tracks a student's writing growth over time. We do not store the text that was analyzed — no student sentences, phrases, or writing excerpts are retained from the analysis process.

Third parties: The cloud service processes the text solely for Humdrum's educational feedback. No student writing is shared with, sold to, or made available to any third party for any other purpose.

How We Use It

Classroom data powers autosave and progress tracking. Internal analytics help us operate and improve Humdrum and support teachers and students. We also analyze student writing across all writing activities to provide real-time educational feedback — see "Writing Analysis" above for details. We do not sell, rent, or use this information for advertising or marketing.

Retention & Deletion

We keep personal information only as long as needed for the purpose it was collected. We collect adult account information to complete sign-in and obtain the required authorization, as described above.

How Long We Keep Data

Active accounts: Data is retained while the account is actively used. A student's writing stays with their account, across school years, for as long as the account remains active.

School accounts: Data is tied to the school's authorization. We delete student content, roster data, and account information when that authorization ends, including when:

  • A school or district revokes Humdrum through Clever
  • A student is removed from the school's Clever roster
  • A school notifies us it is ending its use of Humdrum

Students can download their saved writing while they have authorized access. Parents, guardians, and authorized school representatives can contact us for help with review, export, or deletion requests. We verify the requester's identity and authority before providing access to a student's information. Please contact us before a planned end of school use to arrange an export. Any retention during an account closure must be limited to what is reasonably necessary for the applicable purpose and consistent with deletion obligations.

Family accounts: Data is retained while the account is active. After 12 months with no sign-in activity, we notify the parent or guardian at their registered email. If no action is taken within 30 days, we delete the account and all associated student content, writing data, skill tracking, and account information.

Feedback messages: Deleted when the associated account is deleted, or after 12 months if the account no longer exists.

Consent records: Retained for 3 years after account deletion for compliance defense purposes, then deleted.

Analytics data: Internal reports may use account and classroom records and remain linked to them. We retain personal information used for analytics only as long as needed to operate and improve Humdrum and support its users. Aggregate, de-identified reports are distinct from reports linked to accounts or classrooms.

Writing analysis: As described in the Writing Analysis section, student text sent for real-time analysis is processed and discarded immediately. Per-story detection records (technique type, confidence level) are stored to track growth, and these are deleted when the account is deleted. No student text is retained.

Deletion Process

When data is deleted, whether by request, inactivity, or end of school authorization, we remove student writing, pen names, quest progress, skill tracking data, account information, and associated feedback from the production database. Backups containing deleted data are purged within 30 days.

Your Rights

Parents, guardians, teachers, and school administrators can request a data export or deletion at any time by contacting hello@noticehumdrum.com. We will complete deletion requests within 30 days. You may also request to review any personal information we hold about your child or students.

If a school revokes authorization through Clever, we disable the classroom and delete associated data following the school account timeline above.

<!-- legal-approval-required -->

Google Classroom

A teacher can choose to connect Google Classroom to import class names and selected student roster names into Humdrum. The teacher must be authorized to act for their school. Identifying as a teacher is not enough. Connecting Classroom is not verified parental consent. Humdrum remains responsible for its COPPA obligations. This is a teacher-initiated roster import. It is not student sign-in with Google, and it is not a Google partnership or approval.

Access

Humdrum requests only these Google scopes:

  • https://www.googleapis.com/auth/classroom.courses.readonly
  • https://www.googleapis.com/auth/classroom.rosters.readonly

Humdrum reads the names of active classes the teacher teaches and, for classes the teacher selects, student roster names and Google user identifiers. Humdrum does not request student email addresses, profile photos, coursework, or permission to change Google Classroom.

Use

Humdrum uses that data only to create and update the selected Humdrum class lists and seats. Google Classroom data is not used for advertising, sale, credit decisions, or to train a shared machine-learning model. Student writing analysis is a separate path and does not use Classroom API data.

Storage

Google course and student identifiers are hashed before storage. Roster names are stored as enrollment names on the Humdrum class. The teacher UI shows hashed course identifiers, not raw Google IDs.

Humdrum does not keep a raw Google access token in the browser. The browser holds only a short-lived opaque handle cookie. A short-lived access token is encrypted (AES-256-GCM) and stored on the server only long enough to finish the import or re-sync.

Sharing

Humdrum shares this data only with the service providers that operate the service (today: Vercel and Supabase). Humdrum does not sell this data or share it with advertising platforms, data brokers, or information resellers. Humans do not read Classroom roster data except for security, legal compliance, or documented user consent.

Retention

The encrypted Google token is revoked at Google and deleted after a successful import or re-sync, disconnect, logout, denied or failed access, expiry, or an unauthorized grant.

<!-- legal-approval-required -->

Imported class names and hashed seats stay after disconnect. Humdrum does not auto-delete them after a set number of days. A later re-sync marks departed seats. Deleting the teacher's Humdrum account removes that teacher's Google Classroom sections and hashed seats, including seats with no linked student account. Teachers can review imported roster names on My Classroom.

Students who leave the Google Classroom roster are marked removed on the next re-sync. Writing already saved in Humdrum is not deleted by a re-sync. Disconnecting Google Classroom does not by itself delete imported class names or hashed seats. Email hello@noticehumdrum.com to ask Humdrum to review or delete imported Classroom roster names and hashed seats.

Notice and school authorization

Before Connect and before Re-sync when Google access is missing, Humdrum shows an in-product notice and requires the teacher to confirm they are authorized to act for their school. A checkbox is not verified parental consent. Humdrum records the teacher's Humdrum user id, the school email domain if that email is already on the Humdrum account, the time, and the notice version. Reconnecting requires that notice and confirmation again. Humdrum does not read a Google hosted-domain or userinfo field for this record.

Deletion and revocation

A teacher can disconnect Google Classroom in Humdrum (My Classroom, then Disconnect Google Classroom). Disconnecting revokes the Google access token, deletes the encrypted token, and clears the opaque handle. It does not by itself delete imported class names or hashed seats.

Anyone can also revoke Humdrum at https://myaccount.google.com/permissions.

To review imported roster names, open My Classroom. To ask Humdrum to review or delete imported Classroom roster names and hashed seats, email hello@noticehumdrum.com.

Limited Use

Humdrum's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Parent, Teacher & School Controls

Parents and guardians can contact us at any time to review, export, or delete their family's data. Teachers and administrators can reach us at hello@noticehumdrum.com to review classroom data, request exports, or withdraw authorization. Withdrawing authorization stops future data collection, and we will delete retained records following the timelines described above.

Contact Us

If you have any questions about our privacy policy, please contact us at hello@noticehumdrum.com.

Questions? Email us at hello@noticehumdrum.com