← GroupWorks

Privacy and data notice

What GroupWorks collects and where it is stored

This notice is written to support privacy review and PIA work. It is not a certification of compliance with FERPA, FIPPA, or any other legal framework.

Data We Collect

Account and course setup

Instructor and student names, email addresses, account roles, course titles, rosters, invitations, and enrollment status.

Onboarding surveys

Student survey responses used for group formation, such as availability, work preferences, role preferences, skills, and collaboration style.

Group agreements

Agreement text and structured agreement fields, including roles, communication tools, meeting cadence, response expectations, deadline policies, conflict or escalation plans, contact handles that students choose to enter, signatures, and timestamps.

Assignment workspace activity

Group-created tasks, milestones, meetings, attendance records, minutes, contribution logs, evidence links, and concern reports.

Peer evaluation

Peer-evaluation setup, ratings, comments, private comments to the instructor, submission status, and derived review flags shown to instructors.

Billing and support

Instructor subscription status and billing identifiers. Payment details are handled by Stripe, not stored directly in GroupWorks.

Where Data Is Processed

Browser requests are sent over HTTPS to the GroupWorks application hosted on Vercel. The application validates the user session and authorization before reading from or writing to the database.

Persistent application data is stored in Supabase Postgres. For the Canadian deployment, the Supabase project is configured for database storage in Canada. Vercel still transiently processes application requests before data is written to or read from Supabase.

When email features are enabled, invite emails, reminders, revision notices, and signed agreement copies may pass through the configured email provider (Resend, when configured). Instructor billing is processed by Stripe.

How Agreement Data Is Stored

Group agreements are stored in the database as structured records. The main agreement table stores JSONB fields for agreement sections, role assignments, communication cadence, response expectations, deadline policy, and related structured agreement content. Signatures are stored separately with signer IDs and timestamps.

GroupWorks does not currently encrypt agreement fields in the browser before sending them to the server, and it does not apply application-level field encryption to individual agreement columns before storing them in Supabase. Protection is provided through HTTPS in transit, provider-managed encryption at rest, authentication, server-side authorization checks, and database access controls.

Who Can Access Data

Students can access their own course and group surfaces. Group agreement content is visible to members of that group. Instructors can access data for courses they own, including rosters, group formation data, group agreements, workspace activity, concerns, and peer-evaluation review data.

Operational administrator access is limited to support, security, and account administration needs. Direct browser access uses Supabase row-level security policies where applicable; primary application access is also checked in the server-side code before data is returned or changed.

Retention And Deletion

Course data is retained while the instructor account and course remain active, unless deletion is requested or a separate institutional retention agreement applies. For deletion or privacy questions, contact GroupWorks through the support channel on the contact page.

Contact us about privacy