Legal
Privacy Policy
Effective July 24, 2026 · Pilot and early-access service
This Policy explains what information Inline collects, why we use it, how long we keep it, and the choices you have. It also covers revision history, planned course features, and separate voluntary research. For the contract governing use of the Service, see the Terms of Service.
Key points
- Workspace drafts are never used to train or fine-tune models.
- Writing is not sent to third-party hosted model APIs.
- Personal information is never sold or used for advertising.
- Research requires a separate, affirmative consent process.
1. Scope, operator, and future features
This Privacy Policy applies to the Inline website, application, pilot, support channels, and related services (the Service). The Service is currently operated by Alexandr Tkachyov, an individual based in Pennsylvania, United States. “Inline” is the name of the Service; it is not presently a separate incorporated legal entity. In this Policy, “Inline,” “we,” “us,” and “our” refer to Alexandr Tkachyov as the Service operator.
This Policy covers visitors, students, educators, writing-center or institutional personnel, account administrators, people who receive a student-created report link, and people who contact support. A separate study consent form and research notice also apply to anyone who voluntarily joins an approved research study.
If an institution has a written agreement with Inline, that agreement may provide additional protections or instructions for institutionally controlled data. The institutional agreement controls to the extent it directly conflicts with this Policy. A study-specific consent form controls for separately collected research data.
2. Information we collect
We collect only the categories reasonably needed for the feature you choose to use. The categories below describe current collection and collection planned for the near-term features identified above.
| Category | Examples |
|---|---|
| Account and profile | Name, email address, authentication identifier and provider, optional school, academic year, field of study, writing frequency, profile image, language preference, and a student, educator, or both persona. A user-uploaded profile image is currently hosted at a publicly retrievable URL so it can render; do not use a sensitive image. Selecting an educator persona does not itself grant educator permissions. |
| Writing and learning content | Document titles, drafts, starting material, assignments, rubrics, private notes, uploaded text, generated feedback and Brainstorming cards, feedback history, and the model and prompt versions used. Uploaded PDF, DOCX, TXT, or Markdown files are processed to extract text; the original upload is not kept as a workspace file, but extracted text is stored if you save it in a document or run. |
| Course and educator data | Organization, course, term, section, membership and role, invitation and entitlement records, assignment templates, due dates, required checkpoints, roster and completion status, fixed student submissions, educator comments or review status, feedback-quality ratings and reason codes, and optional replacement questions or missed-issue notes. |
| Revision and process data | Meaningful draft checkpoints, timestamps, word counts, change sizes and checkpoint sources. If revision activity is enabled for an eligible plan, Inline may also store five-minute numeric totals for characters typed, pasted, deleted, or replaced and active time rounded into 30-second buckets. Inline does not store raw keystrokes, clipboard contents, cursor movement, window-focus history, or a second-by-second replay. |
| Reports, submissions, and sharing | The exact fields a student selects for a fixed course submission or process report, recipient scope, creation and expiration time, revocation state, and a cryptographic hash of a share token. Raw report tokens are not stored in our database. |
| Usage and technical data | Sign-up and sign-in events, feature use, feedback requests and completion, plan and quota counters, word count, response latency and status, survey deferrals, notification state, browser and device information, IP address and standard server, security, and error logs. We do not create advertising profiles or device fingerprints. |
| Communications and feedback | Support messages, survey answers, usefulness or satisfaction ratings, pilot and Pro-trial intake, notification choices, reference interest, and communications with Inline. |
| Plan and transaction data | Plan, trial dates, subscription status, entitlements, usage limits, and, if paid plans are introduced, transaction and billing identifiers. Inline does not intend to store full payment-card numbers; a payment processor will handle them under its own privacy notice. |
| Browser-stored data | Essential authentication cookies, notification and privacy-notice state, a temporary local recovery copy of an unsaved draft, and a report token kept in the current tab after the token is removed from the address bar. |
Student writing can itself contain sensitive information. Please do not include Social Security numbers, payment-card data, medical records, government identifiers, or other information that is unnecessary for writing feedback. Inline does not use writing to infer sensitive traits for advertising or eligibility decisions.
3. Where information comes from
We obtain information:
- directly from you when you create an account, enter or upload content, join a course, submit work, answer a survey, change a setting, or contact us;
- automatically from your browser and our infrastructure when you use the Service;
- from an authentication provider, such as Google, when you choose that sign-in method;
- from an educator or institution when it creates a course, assignment, invitation, membership, or institutionally authorized account; and
- from another user only when that user deliberately directs a submission, report, invitation, or collaboration to you.
We do not purchase personal data from data brokers or obtain student writing from third parties for advertising or model training.
4. How and why we use information
We use personal information to:
- create and secure accounts, authenticate users, assign scoped roles, and provide support;
- save writing, extract text from a user-selected file, generate and display Socratic feedback, restore drafts, keep history, and provide exports;
- operate classes, assignments, invitations, fixed submissions, educator review, student-controlled sharing, and permitted institution-level administration;
- enforce plan limits, administer trials and entitlements, and process payments if paid plans are introduced;
- send service notices and, according to your settings, product updates or tips;
- prevent abuse, investigate security incidents, debug errors, maintain audit records, and protect users and the Service;
- evaluate reliability and usefulness using surveys, ratings, and de-identified or aggregate operational measures; and
- comply with law and enforce our Terms of Service.
Where applicable law requires a legal basis, we rely on performance of our contract with you; legitimate interests in operating, securing, and improving the Service without overriding your rights; your consent for optional communications, research, or other uses identified at the point of collection; and compliance with legal obligations. When we process education records for an institution, we follow the institution's documented instructions and written agreement.
Inline feedback, draft-stage labels, revision measures, and aggregate course trends are not used by Inline to make decisions that produce legal or similarly significant effects. Inline does not produce an authorship, cheating, or AI-detection score.
5. AI processing and the model-training boundary
Drafts, assignments, rubrics, and starting material are processed to return the requested feedback or Brainstorming questions and to keep the history the user asks us to save. Production inference uses a model selected and controlled by Inline on private GPU infrastructure. We do not send workspace writing to third-party hosted model APIs such as general-purpose commercial chat or model providers.
Infrastructure providers necessarily transmit and process encrypted requests on Inline's behalf to host the application, database, and controlled inference systems. They are service providers, not independent recipients permitted to train their models on student writing.
Inline may use a user's voluntary survey response, an educator's usefulness rating, and de-identified or aggregate service measures to improve prompts, interfaces, reliability, and operations. We do not use the associated student draft or other workspace content for model training. A linked student artifact may enter research or model development only through the separate consent process described in Section 14.
6. Revision history and process reports
Revision history is private by default and is available only when the feature is enabled for the student's plan. Inline saves meaningful checkpoints after specified changes or student actions; it is not a keylogger or continuous screen recorder. Full checkpoint text is visible to the student through the ordinary product and only to a recipient when the student explicitly includes those versions in a fixed report, subject to exceptional, audited operator access needed for security or support.
A student may create a fixed process report, preview exactly what it contains, and create a revocable read-only link that expires in no more than 30 days. Reports are summary-only by default and can include dates, word-count and change totals, and checkpoint sources. The student may separately choose to include coarse activity totals and the exact text of all saved versions shown in the preview. A third, independent choice may include the completed Inline feedback rounds saved for that document, including the highlighted student passages and exact questions or observations. Older versions and feedback excerpts may contain passages later removed. Reports always exclude assignments, rubrics, Brainstorming content, private notes, unselected feedback, and other documents. Later edits do not silently update a shared report.
Anyone with an active link can view the fixed report, so students should share it only with intended recipients and revoke it if it is forwarded. Report recipients may generate ordinary server logs when they open the page. A report shows changes over time; it does not prove who wrote a document or whether AI was used. Report links are read-only and do not collect recipient ratings or comments.
7. Courses, educators, and institutional features
When course features are available, roles are scoped to a specific organization and course. A person may be both a student and an educator in different contexts. A profile choice alone never grants access to a roster or student work.
Depending on the feature and authorization, an educator may see course membership, published assignments, submission or completion status, the exact fixed artifact a student deliberately submits, educator-owned comments and review status, and privacy-suppressed aggregate course measures. A student previews the payload before submitting it; later private edits do not change it. Course submissions and expiring process report links are separate actions.
Educators and institutional administrators do not receive a role-based view of private drafts, unsubmitted work, private feedback history, revision checkpoints or diffs, deleted text, raw or coarse editing activity, private notes, unrelated documents, or a student's research participation. Inline does not provide roster-level paste ratios, authorship rankings, AI-likelihood scores, or automated integrity alerts.
Planned behavioral analytics suppress groups smaller than 10. Ordinary course-management counts, such as roster size and whether an assignment has been submitted, may be shown without that threshold because they are needed to administer the course. Sensitive access and exports may be logged, and students may be shown what they submitted, when, and to which course.
8. When we disclose information
We do not sell personal information, rent it, provide it to data brokers, or disclose it for targeted or cross-context behavioral advertising. We do not serve third-party ads. We disclose information only in the following circumstances:
- Service providers. Vendors process information for us to provide hosting, authentication, storage, controlled compute, email delivery, security, support, and future payment processing.
- At your direction. We disclose the fixed course submission or report you choose to send, or open a third-party destination you select.
- Institutions.Under an institutional agreement, we disclose only data authorized by that agreement, an applicable role, or the student's deliberate submission. Institutional administrators do not automatically receive access to a student's private workspace.
- Law, safety, and rights. We may disclose information if reasonably necessary to comply with valid legal process, protect users, investigate fraud or security incidents, or establish or defend legal rights. Where lawful, we will seek to narrow the request and provide notice.
- Business transition. If the Service is reorganized, incorporated, financed, acquired, or transferred, information may be disclosed under confidentiality safeguards and transferred to the successor that assumes this Policy. We will provide notice of a material change in controller or use.
Current core providers and their limited functions include:
| Provider | Function and data involved |
|---|---|
| Supabase | Authentication, database, storage, access controls, and backups for account and Service data. |
| Vercel | Web application hosting, routing, and standard operational and security logs. |
| Modal | GPU infrastructure on which Inline runs its selected and controlled inference model. Modal provides compute infrastructure rather than a separate consumer AI model service. |
| Email delivery providers | Authentication, transactional, account, pilot, and optional product communications, including delivery metadata. |
| Google, if selected | Optional Google identity sign-in. Opening Google Docs or a future source-search destination takes the user to Google or another external service under that service's privacy policy. |
| Cloudflare | Turnstile anti-abuse checks for email signup, sign-in, and password recovery, using browser and network security signals without sending student writing. |
Providers and hosting locations may change as the Service develops. We require providers to handle data only for the services they supply to Inline and apply appropriate confidentiality and security measures. We will update this Policy if a change materially affects user privacy.
9. External links, searches, and integrations
Current Google Docs export copies draft text to the user's clipboard and opens a blank Google document; Inline does not automatically upload the draft to Google. The user decides whether to paste it. External sites receive information according to their own privacy policies once the user visits or submits information to them.
A planned source-suggestion feature will use Inline's controlled model to propose neutral search terms. The student will be able to review and edit the query before choosing to open Google Scholar, OpenAlex, a library search, or another destination. No query will be sent to an external search service until the student acts, and Inline will not place the raw draft in the query.
If Inline later offers a browser extension, Google Docs integration, LMS connection, or single sign-on, we will provide contextual notice of the requested permissions, data flow, and choices before activation. An integration will receive only the data the user or institution authorizes for that integration.
11. Retention and deletion
We retain information only for the period reasonably needed for the purposes described here, then delete or de-identify it. The principal rules are:
- Accounts and workspace content: retained while the account or document exists. Deleting a document deletes its related runs, feedback, checkpoints, reports, and shares from the active database. Account deletion removes account-linked active data; encrypted provider backups are overwritten within 30 days, except where law requires a narrowly limited record.
- Anonymous product statistics: a usage event may be retained without its user identifier after account deletion. We may retain information that has been irreversibly aggregated or de-identified because it can no longer reasonably identify a person.
- Revision data: checkpoints remain while the document exists; numeric activity buckets are deleted after 180 days. A share stops working immediately when revoked or expired, and expired or revoked share and report rows are purged within 30 days.
- Course data, when enabled: active membership, assignments, and submissions are retained while needed to operate the course and ordinarily no more than 12 months after the course is archived, unless the student deletes eligible data sooner or a written institutional agreement or applicable education-record rule requires a different period. We will disclose a different course retention period before it applies.
- Security, access, and support records: retained for the time reasonably needed to investigate incidents, document sensitive access, prevent repeat abuse, resolve support matters, and establish or defend legal rights. We minimize personal detail when a full identifier is no longer needed.
- Billing and tax records, if applicable: retained for the period required by financial, tax, and accounting law.
- Research data: retained under the separate study consent, protocol, and withdrawal rules, not the workspace retention period.
12. Security
Inline uses safeguards appropriate to the nature of the Service, including encryption in transit, authentication controls, per-user and scoped row-level database authorization, least-privileged administration, private inference credentials, rate and input limits, audit logging for sensitive administrative actions, and deletion cascades. Share links use high-entropy tokens, and the database stores only a token hash.
No online system is perfectly secure. Users should use a unique password, protect their account and active share links, sign out of shared devices, and notify us promptly at hello@inlinetutor.com if they suspect unauthorized access. We will provide legally required notices if a security incident affects protected personal information.
13. Your choices and privacy rights
Depending on the feature, users can:
- review, edit, export, and delete documents;
- inspect and compare their own revision checkpoints;
- preview a report or course submission, revoke an active report link, and see what was submitted to a class;
- change notification choices and end signed-in sessions in Settings;
- leave eligible courses or withdraw submissions under course rules;
- export workspace documents and delete the account in Settings; and
- decline or withdraw from separate research according to the study consent without losing ordinary Service access.
Depending on where you live and applicable law, you may also have the right to request access, correction, portability, deletion, restriction or objection, withdrawal of consent, an explanation of processing, or an appeal of a denied request. You may be entitled to use an authorized agent and to receive equal service without unlawful discrimination for exercising a privacy right.
Submit a request to hello@inlinetutor.com. We may ask for information reasonably necessary to verify identity and authority. We will respond within the period required by applicable law. Some records may be exempt from deletion or access, including another person's information, security records, records controlled by an institution, and records we must retain by law. Users may also complain to their local data-protection authority where that right applies.
Inline does not sell or share personal information for cross-context behavioral advertising, so there is no sale or targeted-advertising opt-out needed for our current practices. If that practice ever changes, we will provide the legally required notice and choice before it begins.
14. Education records and FERPA
FERPA applies to covered educational agencies and institutions, not automatically to every direct-to-consumer product account. When a written institutional agreement designates Inline to perform an institutional service involving education records, Inline will process those records only for the authorized educational purpose, under the institution's control and agreement, and will not re-disclose them except as the agreement or law permits.
The institution determines which records are education records and is responsible for the notices, consents, approvals, and legitimate educational-interest determinations required for its deployment. Parents and eligible students should direct FERPA access or amendment requests to the institution so it can verify identity and coordinate the response. Direct account and privacy requests may also be sent to Inline.
An educator should not introduce Inline for required course use without any approval required by the institution. Joining a course is not research consent, and a professor will not be told whether a student participates in a separate study.
15. Separate voluntary research
A research study requires a separate invitation and affirmative consent that identifies the investigator, purpose, data, permitted uses, safeguards, retention, compensation if any, withdrawal process, and relevant institutional or IRB review. Declining research does not affect grades, course standing, ordinary account access, or Service limits, and instructors do not receive a student's research decision.
Educator account activity, surveys, or feedback judgments enter a research export only if the educator has provided the required study consent. Student-linked writing or feedback enters only when the student has also provided the required consent and authorized the applicable document or artifact. No linked record becomes eligible for model fine-tuning until the approved protocol and every applicable student and educator consent expressly permit that use.
Approved research data is kept in a restricted research environment, is not sent to third-party AI services for labeling, generation, or evaluation, and is governed by its study documents. A research participant should follow the withdrawal instructions in the applicable consent form.
16. Age and minors
Direct account registration is currently limited to people who are at least 18 and able to agree to the Terms. The Service is not directed to children under 13, and we do not knowingly collect their personal information.
A person under 18 may use Inline only if we expressly enable that access under a written school or institutional arrangement and the school, parent, or guardian supplies any authorization required by law. An ordinary invitation code or inaccurate age statement does not create that authorization. If you believe a child has provided information outside an authorized arrangement, contact us so we can investigate and delete it as appropriate.
17. International users and transfers
Inline is operated from the United States, and the Service and its providers may process information in the United States and other countries where they operate. Those countries may have different data protection rules than the user's location. Where applicable law requires a transfer mechanism or additional safeguard, we will use one before making the covered transfer.
The Service is currently designed primarily for United States college users and invited testers. Users or institutions that require a particular regional hosting, data-transfer agreement, or statutory addendum should contact us before deployment.
18. Changes, controller transfer, and contact
We may update this Policy as the Service and law change. We will post the revised Policy with a new effective date. For a material change, we will provide reasonable advance notice in the Service or by email and request consent where law requires it. Prior versions may be requested by email.
If a corporation or other entity is formed to operate Inline, we may transfer responsibility for the Service and its data to that entity, provided it assumes the obligations described here. We will identify the new controller and provide legally required notice before or when that transfer takes effect.
The current data controller and Service operator is Alexandr Tkachyov, Pennsylvania, United States. Privacy, security, and legal requests may be sent to hello@inlinetutor.com.