For school management and IT
The platform processes personal data of young people. This page summarises which data that is, where it sits, how long it stays and who sees it.
Which data is created
From students: first name, surname, email address, the submissions and the marks on them. From the teacher: the name, email address, sign-in credentials and settings of the account, plus everything created in it — examinations, tasks, model answers and the teacher's own question collection. Added to that is what running the service requires: timestamps and the identifier by which the device and the browser announce themselves when someone joins an examination — from it the device and the browser are shown, «Windows · Chrome», say, so that the teacher can help when something goes wrong on a device during an examination. It is deleted together with the participation. No analytics or advertising services are embedded, and no profiles are built.
Where it sits
The database and file storage are hosted with Supabase, on servers in Switzerland. Sending the results emails runs through Resend, a provider based in the United States; the name, address and score of the person written to pass through its delivery logs. This disclosure is covered by the European Commission's standard contractual clauses, as adapted for Switzerland. Programming tasks are worked on in an environment of ETH Zurich, which the examination device loads directly from the university. ETH thereby learns the address of the device. The code a student writes is handled inside that environment, without any name and without marks: it does not learn whose work it is. In a robotics task a simulator of the micro:bit project based in the United Kingdom is added, there too only with the address of the device; which tasks those are is decided by the teacher when writing them. If a teacher has questions written with AI support, what they hand over for that goes to an AI service in the United States — the uploaded document or the desired topic; data about learners never reach it. If they add reference material to an examination, the examination device fetches it directly from whoever is linked. Both, with the bases they rest on, are set out in the privacy policy.
Retention and deletion
The teacher sets the period per exam, between 30 and 730 days; the default is 365. Counting starts when the exam starts. After that, submissions, marks and participations are deleted automatically; in the backups they remain for up to a year. Once an exam is closed, the teacher can trigger the same deletion early at any time, for instance at a family's request. The exam and its tasks remain and can be run again.
Backup
The backups are held encrypted on a device in Switzerland. A deleted submission drops out of them with the last state that contains it, after a year at the latest.
Who sees what
A teacher sees only their own exams and the submissions on them. Students see their own work and, after return, their marks, never anyone else's work.
Safe Exam Browser
Exams run in Safe Exam Browser, which restricts the device during the exam. The platform produces the necessary configuration per exam itself; the school need prepare nothing beyond installing the browser on the devices.
Availability and network failures
Availability is monitored continuously. If a single device loses the network during an exam, nothing is lost: the teacher scans the work as a QR code with their phone and sends it to tech-exam from there.
We provide a data processing agreement on request. To the privacy policy