IDoc Privacy Policy

Effective date: August 1, 2026

Draft pending review by course staff

This policy describes how IDoc collects, uses, stores, and protects personal information. IDoc is a document authoring and assessment platform operated for coursework at Rutgers University as part of the Knowsy educational platform. It is operated by course staff, runs on infrastructure controlled by course staff, and is not a commercial service. IDoc displays no advertising and uses no third-party analytics.

This policy is written from the software's actual behavior. Where a capability exists in the software but is disabled in this deployment, this policy says so.

1. Who operates IDoc

IDoc is operated by the course staff of the Knowsy educational platform at Rutgers University. Contributors: Dov Kruger and Satrajit Ghosh. Questions about this policy or about your data should be directed to your course instructor from your Rutgers email address. Section 10 describes your formal rights.

2. Information we collect

2.1 Account information

When an account is created for you, we store your Rutgers NetID, your name, and your email address. These identify your account, associate you with your course enrollment, and allow us to send you account email such as address verification and password reset messages.

We store a cryptographic hash of your password, produced with the Argon2id algorithm. We do not store your password itself and cannot recover it.

2.2 Coursework

Documents you write in IDoc are stored in a private workspace assigned to your account. No other student can access your workspace.

When you submit work for an assignment or exam, we store the submission, your answers, the grades assigned to them, and the history of any grade corrections. Grade corrections are recorded as new entries; prior entries are retained so that the correction trail is complete.

2.3 Access and security records

We maintain an append-only audit log of security-relevant events, including successful sign-ins, failed sign-in attempts, grade changes, permission changes, and staff access to education records. The audit log records that an event occurred, who performed it, and when. It does not record the contents of documents. Entries in the audit log are never modified or deleted.

2.4 Exam integrity records

While a proctored exam is open, and only then, the software records exam session events: window focus changes, exits from full-screen mode, and paste events. You are shown a notice describing exactly what is recorded before the exam begins, and beginning the exam is recorded as your acknowledgment of that notice. These records exist to protect the integrity of the examination. They are stored encrypted, are readable only by the instructor of the course, and every staff access to them is itself recorded in the audit log. No recording of any kind occurs outside an open exam session.

Keystroke recording is not implemented and is not in use in this deployment. If it is ever added, this policy will be updated before it is enabled, and the pre-exam notice will describe it.

3. Google account data

Connecting a Google account is optional. If you never connect one, IDoc requests nothing from Google and receives nothing from Google.

If you choose to connect a Google account, IDoc requests only the following authorization scopes:

drive.file
This scope permits access only to files that you create with IDoc or that you explicitly open through IDoc. It does not permit IDoc to read, list, or search the rest of your Google Drive. IDoc uses it for one purpose: storing your IDoc documents in your own Drive, if you select Drive as your document workspace instead of the server.
calendar.events
This scope permits reading and writing calendar events. It does not extend to calendar sharing settings or to other users' calendars. IDoc uses it to place scheduled course events, such as an exam window, on a calendar.
openid, email, profile
These provide your Google account identifier, email address, and display name. IDoc uses them solely to associate the Google account with your IDoc account.

IDoc does not request access to Gmail or to any Google service other than those listed above.

Google access and refresh tokens are stored encrypted at rest. Disconnecting your Google account from your IDoc profile deletes the stored tokens. You may also revoke IDoc's access at any time from your Google Account security settings at https://myaccount.google.com/permissions.

Limited Use disclosure. IDoc's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular: Google user data is used only to provide the user-facing features described above; it is not transferred to third parties except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with notice to users; it is not used for advertising; and it is not read by humans except with your explicit consent, for security purposes, to comply with applicable law, or in aggregated and anonymized form for internal operations.

4. What we do not do

We do not sell, rent, or trade personal information. We do not use your coursework or your personal data to train machine learning models. We do not send your work to third-party artificial intelligence services for grading; where assisted grading is used, it runs on hardware controlled by course staff. We do not serve advertising, we do not use third-party analytics, and we do not set tracking cookies. The only cookie IDoc sets is the session cookie that keeps you signed in.

5. Who can see your work

Your workspace is private to you. Other students cannot access it under any circumstances.

Instructors and teaching assistants of a course can see the work you submit for that course and the grades on it. Their access is limited by a per-course permission system: a person's role in one course grants no access in another.

If you share a document with another user, that user can access that document, and only that document, for as long as the share remains in place. You may revoke a share at any time.

Every access by staff to a student's education records is recorded in the audit log, so there is a permanent record of who accessed what and when.

6. Data retention

Coursework, submissions, and grades are retained for as long as Rutgers University requires academic records to be kept.

Backups are encrypted at rest and retained on a rolling fourteen-day window, after which they are deleted. Independent disk snapshots of the records database follow the same fourteen-day window.

Exam integrity records are retained with the exam they belong to and are deleted with it.

The audit log is append-only and is retained without deletion. It records access events, not document contents.

7. Data deletion and correction requests

You may request deletion of data that is not part of a required academic record, and correction of data that is inaccurate, by contacting your course instructor from your Rutgers email address. Requests concerning official academic records follow the University's formal process through the Rutgers Registrar, described in Section 10. Disconnecting a linked Google account deletes the stored Google tokens immediately, as described in Section 3.

8. Security

All traffic between your browser and IDoc is encrypted in transit. IDoc is served over HTTPS only; plain HTTP requests are redirected.

Passwords are hashed with Argon2id. Sensitive fields in the records database, including exam integrity records, are encrypted at rest with AES-256-GCM. The encryption key is currently held in the application server's protected configuration, separate from the records database, which is on a different machine; migration of that key to a managed key service is in progress.

Education records are held on a dedicated database server with no public network address. It is reachable only from the application server, over a private network, and accepts connections from no other source.

Code that you run inside an exercise executes in an isolated sandbox with no network access, a read-only filesystem, and fixed resource limits.

Backups are integrity-checked when created, stored with restricted permissions, and restored into a test environment to verify that they work.

9. Where data is processed

IDoc runs on Google Cloud infrastructure in the northamerica-northeast1 region. If you connect a Google account, data you store in Google Drive is held by Google under Google's own terms and privacy policy.

10. Your rights under FERPA

Your education records are protected by the Family Educational Rights and Privacy Act (FERPA). Under FERPA you have the right to inspect and review your education records, to request correction of records you believe to be inaccurate, and to obtain a record of disclosures. To exercise these rights, contact your course instructor, or follow the University's formal process through the Rutgers Registrar.

11. Changes to this policy

If this policy changes materially, the effective date above will be updated and course staff will announce the change through course announcements. The current version is always available at https://idoc.page/privacy.

12. Contact

Questions about your data, or requests to inspect, correct, or delete it: contact your course instructor from your Rutgers email address.