Privacy and data notice
What GroupWorks collects and where it is stored
This notice is written to support privacy review and PIA work. It is not a certification of compliance with FERPA, FIPPA, or any other legal framework.
Data We Collect
Account and course setup
Instructor and student names, email addresses, account roles, course titles, rosters, invitations, and enrollment status.
Onboarding surveys
Student survey responses used for group formation, such as availability, work preferences, role preferences, skills, and collaboration style.
Group agreements
Agreement text and structured agreement fields, including roles, communication tools, meeting cadence, response expectations, deadline policies, conflict or escalation plans, contact handles that students choose to enter, signatures, and timestamps.
Assignment workspace activity
Group-created tasks, milestones, meetings, attendance records, minutes, contribution logs, evidence links, and concern reports.
Peer evaluation
Peer-evaluation setup, ratings, comments, private comments to the instructor, submission status, and derived review flags shown to instructors.
Billing and support
Instructor subscription status and billing identifiers. Payment details are handled by Stripe, not stored directly in GroupWorks.
Where Data Is Processed
Browser requests are sent over HTTPS to the GroupWorks application hosted on Vercel. The application validates the user session and authorization before reading from or writing to the database.
Persistent application data is stored in Supabase Postgres. For the Canadian deployment, the Supabase project is configured for database storage in Canada. Vercel still transiently processes application requests before data is written to or read from Supabase.
When email features are enabled, invite emails, reminders, revision notices, and signed agreement copies may pass through the configured email provider (Resend, when configured). Instructor billing is processed by Stripe.
How Agreement Data Is Stored
Group agreements are stored in the database as structured records. The main agreement table stores JSONB fields for agreement sections, role assignments, communication cadence, response expectations, deadline policy, and related structured agreement content. Signatures are stored separately with signer IDs and timestamps.
GroupWorks does not currently encrypt agreement fields in the browser before sending them to the server, and it does not apply application-level field encryption to individual agreement columns before storing them in Supabase. Protection is provided through HTTPS in transit, provider-managed encryption at rest, authentication, server-side authorization checks, and database access controls.
Who Can Access Data
Students can access their own course and group surfaces. Group agreement content is visible to members of that group. Instructors can access data for courses they own, including rosters, group formation data, group agreements, workspace activity, concerns, and peer-evaluation review data.
Operational administrator access is limited to support, security, and account administration needs. Direct browser access uses Supabase row-level security policies where applicable; primary application access is also checked in the server-side code before data is returned or changed.
Retention And Deletion
Course data is retained while the instructor account and course remain active, unless deletion is requested or a separate institutional retention agreement applies. For deletion or privacy questions, contact GroupWorks through the support channel on the contact page.
Contact us about privacy