Privacy Policy
Last revised: September 15, 2026. Policy version: 2026-09-15.
Fingerprint ("we", "us") is a writing assistant that helps you develop your writing voice, turns your course deadlines and readings into a daily plan, and provides GPTZero reports for generated drafts and their saved edited versions.
1. Data we collect
Account identity — when you sign in using email/password or Google, we store your email, name and Google identity key where applicable. Passwords are stored only as a salted hash. We record your 18+ attestation, its text version and server timestamp; we do not collect a birthdate for this attestation.
Your content — the material you bring in and create, in a per-user workspace separate from other accounts. For hosted accounts, this workspace is on our server, not solely on your device:
- Course context you import from Canvas (course codes, names, instructors, assignment titles, due dates, descriptions, syllabi). Authorized manual and scheduled syncs also read assignment submission status and minimum identity, attempt and timestamp evidence so confirmed work leaves your active due plan.
- Documents and email imported through Google Docs / Gmail, Microsoft Outlook / OneDrive or Zoom using the access you authorize; Notion pages shared with a configured integration; and GoodNotes PDFs you manually export and import.
- The writing profile you build (samples of your own writing).
- Working drafts the assistant generates as starting points for your review and revision, reading packs, and detector results.
Section 5 sets out what we access from your Google Account through Google's APIs, and the limits we accept on that data.
Revision records — when you review and revise an AI-generated draft, we store the original generated draft and saved text versions, content hashes, version-specific approval and detector reports, along with change statistics. These records allow us to export the exact reviewed version and associate reports with the text actually scanned.
Fingerprint is a direct-to-student service. It is not affiliated with, contracted by, or acting on behalf of your school or institution.
Spoken requests — where the assistant offers a microphone, pressing it asks your browser to turn what you say into text. Fingerprint never records, stores, or receives audio: we receive only the words your browser transcribed, and we handle them exactly like something you typed. The microphone opens only while you hold or press that control, and closes on its own. See section 4 for what your browser may do with the audio before we see anything.
Usage and audit records — when the assistant calls an AI model or a detector, we record the kind of action, the model/detector, and token counts for metering and billing. We keep an append-only log of account events (sign-in, sign-up, account deletion) for security and abuse prevention. We hold the AI keys (the drafting model and the detector) server-side. You never provide them, and they are never sent to your browser.
2. How we use it
- To provide the service: generate working drafts for your review and revision, summarize your course context, and run detectors.
- To meter usage and bill your subscription.
- To prevent abuse and secure the service (rate limits on sign-in, sign-up and password reset, alerts on repeated failed sign-ins, an append-only log of account events, account suspension).
- To maintain product integrity — including recording revision statistics when you finalize a draft, to confirm the Service is used as a writing aid rather than a delivery mechanism for finished work.
We do not sell your personal information or use your essays or documents to train our own models. Provider commitments are described separately below; we do not claim contractual no-training protection from DeepSeek. We do not use your content or student data for targeted advertising, and we do not build profiles of students for non-educational purposes.
3. Storage & security
- Each user's workspace is isolated from every other user's.
- Your account and workspace are stored on servers in the United States. AI features send the relevant prompt, extracted assignment text, writing samples, and course or email context to our AI provider (DeepSeek) for processing on its servers. This also applies to automatic preparation and briefings when Autopilot is enabled. A file being stored in your workspace does not mean its text stays there when used by an AI feature.
- Hosted traffic uses HTTPS. Connector tokens and credentials are stored in per-account files on the server, encrypted at rest with a per-deployment key that is separate from the session signing key.
- AI/detector calls happen server-side; your API keys (if any) never reach the client.
4. Who receives your data
- Drafting model provider — drafts are generated using DeepSeek, a third-party AI provider. Drafting, Cynthia, study preparation, and briefings transmit the relevant text described above to DeepSeek. This can include writing profiles, filenames, excerpts or full writing samples, course/reading material, email and conversation context, and approved image inputs when used. Bounded selection reduces some prompts but does not mean only excerpts are sent. Processing happens on DeepSeek's servers (operated outside the United States). DeepSeek's terms are at https://platform.deepseek.com/downloads/DeepSeek%20Terms%20of%20Use.html.
- AI detector provider (GPTZero) receives original generated drafts and saved edited versions, including student-authored or pasted text added to them. Standalone uploaded writing samples are not offered for detector scans. GPTZero's September 1, 2026 API support response states submitted API content is not used for training and is not stored by default; content-storage opt-in remains disabled. This is API content evidence, not a signed DPA or a promise about all account metadata. Results are signals, not proof of authorship.
- Your school (when you import via Canvas) already holds the course data; we do not disclose your drafts or detector results to your school unless you choose to share them.
- Canvas reads and manual submission: Fingerprint imports permitted course and submission status through ordinary sync. Programmatic submission, upload for submission and calendar writes are disabled. You copy/export a reviewed draft and independently upload and submit it in Canvas. Opening Canvas, preparing a form or uploading a file does not establish accepted submission.
- Our issue tracker (GitHub) receives bug and idea reports you submit through the feedback form. We file these automatically so they reach the people who can fix them. Before a report is filed we remove email addresses, links, IP addresses, and your name and account identifier from its text, and a report that appears to contain a password, key, or other credential is held for private review instead of being filed. The tracker is private to our team. Screenshots are never filed; they stay in private review. Reports about billing, privacy, or anything you send under "Other" are never filed to the tracker. The text you write is otherwise reproduced as submitted, so please do not include anything in a report you would not want on file — see "Scope of deletion" below.
- Your browser's speech vendor — when you use the microphone, the transcription is done by your browser's own speech recognition, not by us. Most browsers do this on their servers rather than on your device: Chrome sends the audio to Google, and other browsers use their own maker's service. That transfer happens between your browser and its vendor before Fingerprint receives anything, under that vendor's privacy policy rather than ours — we have no way to see, prevent, or log it. You can always type instead of speaking, and nothing is transcribed unless you press the microphone yourself. Only the resulting text reaches us; if you would rather no audio leave your device, type the request instead — every spoken action can also be done by typing or clicking.
- Payments and transactional email: Stripe processes subscription, payment, consent and invoice information. Resend or the configured SMTP service delivers account, billing and notification email. Mail delivery/retry records are kept for operational recovery.
- Network services: Cloudflare Tunnel/Access can process connection and access metadata when used by the hosting configuration. Connected Google, Microsoft, Notion, GoodNotes and Zoom services process requests under their own terms and the access you grant.
- Database provider — your account, workspace metadata, and subscription records are stored in Supabase (hosted Postgres). Supabase processes this data as our database provider under its own security and subprocessor terms: https://supabase.com/legal/dpa.
- App hosting provider — the application itself runs on AWS Lightsail, in a U.S. region. Your workspace files (essays, drafts, connector tokens) live on that server's disk, encrypted at rest as described above.
Fingerprint provides this service directly to students and does not claim an institutional school-official role. Canvas access still processes education information and remains subject to applicable requirements and service terms.
5. Use of Google user data
This section describes how we handle the Google user data we receive through Google's APIs, and the limits we accept on it. It applies in addition to sections 1 to 4; where this section is narrower, this section governs.
What we ask for. You connect Google yourself, from the Sources page in the
Service, and Google asks your permission before anything is read. Signing in
with Google asks only for your identity — openid, email and profile: your
name, email address and Google account identifier, used to create your account
and sign you in. Connecting a source then asks for the narrowest read-only scope
that makes that source work, and for nothing else:
drive.readonly— read and export the documents you choose, and see their file names and modified dates inside Drive.gmail.metadata— Gmail message metadata: sender, subject, date and labels, plus the short preview snippet Gmail returns alongside them. With the read-bodies option enabled on a deployment,gmail.readonlyinstead, which also reads full message bodies.
We never request a Google scope that can create, change, move, share, or delete anything in your Drive or mailbox, and we request no Google Cloud, BigQuery, or Cloud Storage access of any kind.
What we do with it. Imported Google content lands in your own workspace on the Service so that you can work with your own material: see your documents and messages in the app, and measure the documents you select into your writing profile, which reports them as summary figures about your own style. Imported email is kept in its own store and excluded from those measurements. We store the imported text and the Google file or message identifiers needed to keep it up to date when you re-import. It is used for that, and for the features in section 2. We do not build advertising profiles from it, and we do not use it to train our own models.
Transfer to our AI provider. The model provider described in section 4 also processes your Google data, and only when an AI feature uses that material — drafting a response to an assignment using your own writing as the style reference, preparing study material, or a briefing that includes course or email context. That includes the automatic preparation and briefings described in section 3 when Autopilot is enabled. The transfer happens because that feature ran, not because you connected Google. Nothing else receives it, apart from the infrastructure providers named in section 4 that host and secure the Service, and disclosures the law requires. We limit each transfer to what the feature you asked for needs. Excluding an imported document stops it counting toward your writing profile; it does not recall text a provider has already processed, which is the same limit described in section 6.
What we never do with it. We do not sell Google user data. We do not transfer it to advertising platforms, data brokers, or information resellers, or use it to serve ads, including retargeting, personalized or interest-based advertising. We do not use it to determine credit-worthiness or for lending. We do not use it to identify you to third parties for any of those purposes.
Human access. Our staff do not read your imported Google content. It is read by a person only with your affirmative agreement to review specific messages or files — for example when you ask us to look at something through support — or where it is necessary to investigate a bug or abuse, or to comply with the law. Anyone with server access at our hosting provider is bound by that provider's terms, but the rule we hold to is the one here.
Keeping the promise true. We do not change the way we use Google user data without first updating this policy. If we ever want to use this data in a way this section does not describe, we will update the policy and tell you before we do it. Google access stays read-only: we will not add a Google scope that can change anything in your Drive or mailbox without asking you and disclosing it here first.
Ending access. The saved Google connection is a token stored on our server, encrypted at rest with a per-deployment key (section 3). Use Disconnect on the Sources page to stop Fingerprint's access and delete it: we attempt to revoke the grant at Google at the same time, and if that revocation does not complete, the app tells you and it needs follow-up. You can also remove Fingerprint from your Google Account's third-party access settings at https://myaccount.google.com/permissions at any time, which stops us reading anything further. Deleting your account removes the tokens and the imported content, subject to the limits described in section 6. Content already imported stays in your workspace until you delete it or your account.
Fingerprint's use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements. The Google data we receive is handled as described here and in sections 1 to 4 — nothing in those sections is meant to permit any use this section prohibits.
6. Data rights & deletion
- You may request a copy or correction of your account data.
- Deleting your account requests removal of the account and workspace, including writing samples, profiles, drafts, revisions and connector tokens. Product processing is restricted when deletion is requested. Busy jobs, filesystem or provider failures can leave tasks pending; minimum recovery records remain outside the workspace so operations can retry and verify them. Billing cancellation, workspace removal and provider tasks have separate outcomes. Pending work is not a claim that every copy has been erased. Google access revocation is attempted; failures need follow-up. For Microsoft and Zoom, remove Fingerprint from your third-party access settings.
- Scope of deletion. Deletion covers the workspace data we hold in our own systems and the account record. It applies to Fingerprint's systems; it does not extend to data that has already been transmitted to our third-party providers (DeepSeek, GPTZero), which may retain it under their own terms. A feedback report already filed to our issue tracker is outside the reach of automatic deletion for the same reason; ask us at [email protected] and we will remove it by hand, quoting the ticket reference from your confirmation email. Restricted users and authorized representatives can exercise account rights without making an 18+ attestation.
- The security/audit log is append-only and is retained after deletion (target retention 84 months; automated deletion of older entries is not yet in place) because it documents account and billing events, not the content of your work. This period is based on applicable statutes of limitations for contract and regulatory claims. The audit log does not contain your academic work, writing samples, or draft content.
To exercise your data rights (access, correction, deletion, or to opt out of any sale or sharing of personal information), use our privacy request form, email us at [email protected], or use the account-deletion feature in the Service. We will respond to verified requests within 45 days, free of charge.
7. Children
Fingerprint is available only to people 18 and older. New users must make a current 18+ attestation; earlier 13+ confirmations do not qualify. Existing accounts lacking current evidence have restricted product access while retaining cancellation, account recovery and privacy rights. Known-under-18 accounts are restricted and handled through the account-rights process.
Where the Service offers a microphone, it is never listening on its own — it opens only on a press, for one request, and closes itself. We keep no audio. Because your browser's speech vendor may receive that audio before we do (section 4), a student who would rather that not happen can type or click instead; nothing in the Service requires speaking.
A parent or guardian may contact us to review, correct, or delete the personal information we hold about a minor, or to report an under-18 account. If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will promptly delete that information. If you believe a child under 13 has provided us with personal information, please contact us at the address below.
8. California and state privacy rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) provides you with additional rights regarding your personal information. We do not sell or share (as defined by the CCPA/CPRA) your personal information. You have the right to: know what personal information we collect and how it is used; request deletion of your personal information; request correction of inaccurate personal information; and opt out of the sale or sharing of personal information (which we do not engage in). To exercise these rights, submit a privacy request or see Section 6. We will not discriminate against you for exercising your privacy rights. This section applies to the extent required by applicable state consumer privacy laws, including the CCPA/CPRA, VCDPA, CPA, and CTDPA.
9. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy and updating the "Last revised" date above. If a change materially affects your rights or our use of your data, we will provide notice before it takes effect — by email, in-product notification, or a prominent notice on our website.
10. Contact
Fingerprint Tool, Corp., a Delaware corporation — [email protected] — 131 Continental Dr, Suite 305, Newark, Delaware 19713
Effective date: September 3, 2026.