Skip to content

Privacy Policy

Last updated: September 17, 2026

1. Data Controller

Draft My Lesson, by Drafted By, is an independent digital service operated within the European Union.

JEAN-DOMINIQUE MICHAEL CASANOVA Drafted_By (trading as Drafted By), a sole trader registered in Poland in CEIDG. Business address: ul. Dęblińska 2/73, 04-187 Warszawa, Poland. NIP: 1133212109.

Contact: [email protected]

Native iOS app

This policy also covers the Draft My Lesson iPhone and iPad app. The app uses the same account, classes, pseudonymized student profiles, lessons, documents, and PDF or DOCX exports as the website. Teachers must use pseudonyms and must not enter student names or other identifying details, but teacher-entered text may still contain personal data. We process what the teacher submits to provide the requested service and apply the safeguards described here.

First-party product analytics

The app sends first-party product events for authentication, onboarding, generation and correction, classes and pseudonymized students, documents, exports, StoreKit purchase and restore actions, account deletion, sync, and deep links. These events use a stable device identifier generated for the app. After sign-in, the server adds the authoritative account and market identifiers and forwards admitted events to PostHog in the European Union. Events may be held in an analytics retry queue on the device until delivery succeeds. We use them to operate, secure, troubleshoot, and improve the service. Server product events are subject to a 25-month maximum operational retention policy, and account-linked records enter the account-deletion workflow earlier.

Native product analytics do not use advertising cookies and do not track you across other companies' apps or websites. They are not controlled by the website cookie settings. The website and Chrome extension analytics described elsewhere in this policy remain separate.

Crash and performance monitoring

Sentry receives app crash and error details, device and operating-system information, the app version, and sampled performance traces. A network request to Sentry can also expose your IP address and the approximate location derived from it; we do not collect precise location through the app. When you are signed in, these reports are linked to an opaque account ID so we can diagnose account-specific failures without sending your email or lesson text as the Sentry user identifier. We keep these diagnostics only until the project automatically expires them or an applicable account-linked deletion is completed, and no longer than needed to investigate reliability and security.

Apple services and purchases

If you use Sign in with Apple, Apple processes the authentication request and supplies the account token and any profile fields you choose to share. For an iOS subscription, StoreKit and the App Store process the purchase or restore request. We receive and store the product, transaction, original transaction, purchase and expiry dates, environment, and current subscription status needed to provide access and prevent fraud. Apple also sends App Store Server Notifications to our backend when subscription state changes. Apple, not Draft My Lesson, receives your App Store payment credentials.

Data on your device and account requests

The app stores session credentials in the iOS Keychain and keeps preferences, cached content, recent sync state, the stable device identifier, and the analytics retry queue in local app storage. When offline writes are available, an offline-mutation queue keeps the requested changes until they can be sent securely. Signing out or completing account deletion clears account-scoped local data.

You can export your account data or request deletion from Settings in the app. A deletion request may be shown as pending until the server completes the request across the account database, files, search index, and analytics systems. You can also use the contact route in section 8.

2. Data Collected

We collect the following data:

DataPurposeLegal Basis
Name, emailAccount creation and managementContract
Password (bcrypt encrypted)AuthenticationContract
Subjects, levels, teaching preferencesPersonalization of generated lessonsContract
Student nicknames, class namesPedagogical contextContract
Generated lessons and historyTeaching continuity, progress trackingContract
UTM parameters (source, medium, campaign)Marketing acquisition measurementLegitimate interest
Pageviews, product interactions, and technical dataFirst-party analytics (PostHog and Umami)Legitimate interest
Account and market identifier after sign-inAccount-attributed product operation and securityLegitimate interest and contract
Card fingerprint (pseudonymized)Abuse prevention (payment fraud)Legitimate interest

Students are identified exclusively by nicknames. We ask teachers to never enter a student's real name.

Chrome extension and Chrome Web Store Limited Use

The Draft My Lesson Chrome extension uses the same account and lesson service as the website. It handles only the data needed to sign you in, build the lesson you request, show generation progress, and measure whether those extension features work.

Page context and lesson generation

The extension uses the activeTab and scripting permissions only after you choose the page-to-lesson button. That button reads the active page URL and title and, when available, the text you selected. The context-menu command uses only the URL and title supplied by Chrome. The extension does not read your browsing history or monitor pages in the background.

The page context becomes part of the lesson references. The extension sends it, together with the lesson settings you entered and any class or student-profile identifier you chose, over HTTPS to draftmylesson.com. The generation service processes that information as described in sections 4 and 5. The extension does not send captured page URLs, selected text, or lesson content to advertising services.

Data stored in Chrome

chrome.storage.local stores your session token and account email, lesson-form preferences, onboarding status, a random analytics identifier, a one-time page prefill, and recent generation-job state. The prefill is removed after the lesson builder opens. Completed and failed job records are kept for no more than 24 hours unless you dismiss them sooner. Signing out removes the local session. Removing the extension or clearing its data removes the remaining local records.

First-party extension analytics

The extension sends operational events to PostHog in the European Union using the random analytics identifier. Events cover sign-in method, logout, use of the page-to-lesson action, generation start, completion or failure, the generated course identifier on completion, extension version, duration option, model mode, and whether curriculum support was selected. PostHog does not receive your email, lesson text, captured URL, or selected text from these events. Extension analytics are not cookie-based and are separate from the website cookie controls. We retain extension analytics events for 12 months.

Permission use

  • storage: local session, preferences, page prefill, analytics identifier, and recent job state
  • activeTab and scripting: the user-requested page-to-lesson feature
  • sidePanel and contextMenus: the lesson builder and its explicit page command
  • identity: Google OAuth sign-in
  • notifications and alarms: background generation status, completion notices, and job cleanup

Limited Use and deletion

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements. We use extension data only to provide or improve the extension's disclosed lesson-planning purpose. We do not sell extension data, use it for personalized advertising or lending decisions, or transfer it to advertising platforms or data brokers. We do not allow humans to read it except with your explicit consent for specific support, when needed for security or legal compliance, or in aggregated and anonymized form for internal operations.

You can remove local extension data through Chrome. To request access to or deletion of server-side account data, generated lessons, or extension analytics linked to an available identifier, contact [email protected].

3. Cookies and Trackers

The website uses an essential session cookie. Active first-party measurement is provided by PostHog and Umami. PostHog captures pageviews, product interactions, and session replay; all form inputs are masked, sensitive content zones are blocked, and request bodies, headers, and console logs are not recorded. Umami measures pageviews and technical data.

CookiePurposeDuration
cookie_consentRemember your cookie choicePersistent (localStorage)
pmc_sessionAuthentication session7 days (httpOnly cookie)
PostHog and Umami first-party storageProduct events, masked session replay, and pageview measurementUnder each active provider retention rule described in section 7

Private infrastructure and object storage retain account documents and exports under the deletion procedure below. Telegram receives operational notifications that may include name, email, subscription status and generation metadata such as title, subject and counts. Notification copies and mailbox correspondence are distinct from application data. Operational monitoring is based on legitimate interest. Retention and training conditions at AI providers depend on the selected model, endpoint and account; routing alone does not guarantee zero retention.

Website cookie controls do not control the extension analytics or the native non-cookie telemetry described above.

4. Use of Artificial Intelligence

To generate lessons, student handouts, and exercises, we transmit the pedagogical information you enter (subject, level, duration, teaching direction, lesson history) to language models provided by third-party vendors (see table below). We reserve the right to change providers or models at any time in order to improve service quality. This processing is necessary for the execution of the service.

Teachers are instructed to use student pseudonyms and not to enter names, email addresses, or other identifying details. Because lesson prompts and uploaded material are free-form, they may nevertheless contain personal data. We transmit the pedagogical content you submit only as needed to generate the requested material.

5. Sub-Processors and Data Transfers

Sub-ProcessorServiceLocationData Concerned
Google GeminiContent generation (LLM)United StatesSubmitted pedagogical content, which may include personal data
OpenAIContent generation (LLM)United StatesSubmitted pedagogical content, which may include personal data
OpenRouterAPI routing & semantic embeddingsUnited StatesPedagogical content, indexed text
Amazon SESTransactional emailsAWS: sending region IrelandEmail address, message content and delivery metadata
CloudflareCDN, DNS, tunnelInternationalNetwork traffic
PostHog Cloud EUFirst-party web, extension, and native product analyticsEuropean UnionProduct events, account and device identifiers, no lesson text in analytics events
UmamiWebsite pageview measurementEuropean UnionPageview and technical data
SentryCrash, error, and performance monitoringEuropean Union / United StatesDiagnostics linked to an opaque account ID when signed in
AppleAuthentication, App Store billing, StoreKit, subscription notificationsInternationalApple account token, purchase and subscription data
StripePayment and billingUnited States / EUEmail, name, payment data

Since 17 September 2026, application email is sent through Amazon SES in the eu-west-1 sending region (Ireland). MXroute hosts mailboxes used for manual correspondence and replies. Historical contact and event archives remain with Resend; migration does not mean that these records have been erased. Applicable consent, unsubscribe and suppression records are retained in our systems.

International data transfers are governed by Standard Contractual Clauses (SCCs) where applicable, and comply with relevant data protection frameworks including GDPR (EU/UK), the Australian Privacy Act 1988, PIPEDA (Canada), and the New Zealand Privacy Act 2020.

6. Storage and Security

  • Data is stored on self-hosted infrastructure in Europe (EU).
  • Passwords are encrypted with bcrypt (salt 12).
  • Communications are protected by HTTPS (TLS 1.2+).
  • Authentication tokens expire after 7 days.
  • Data access is restricted by role-based access controls.
  • The iOS app uses Keychain for session credentials and local app storage for cached content and retry queues.

7. Data Retention

DataDuration
User accountUntil account deletion
Generated lessonsUntil deleted by user or account deletion
PostHog extension analytics12 months
Server logs30 days
Native and server product events and device identifierNo more than 25 months under the operational retention policy; account-linked records enter the deletion workflow earlier
Sentry diagnosticsUntil the project's automatic expiry or an applicable account-linked deletion, and no longer than needed to investigate reliability and security
StoreKit transaction and subscription recordsThe account-linked subscription identifier is kept while the subscription account remains active. StoreKit webhook delivery records become eligible for scheduled deletion after 180 days and are deleted earlier when the account is deleted. Notifications received after deletion are not retained.
Card fingerprintUntil account deletion

8. Your Rights

In accordance with applicable data protection regulations — including the EU/UK GDPR, the California Consumer Privacy Act (CCPA/CPRA), the Australian Privacy Act 1988, PIPEDA (Canada), and the New Zealand Privacy Act 2020 — you have the following rights:

  • Right of access: obtain a copy of your personal data
  • Right to rectification: correct inaccurate data
  • Right to erasure: request deletion of your data
  • Right to data portability: receive your data in a structured format
  • Right to object: object to the processing of your data
  • Analytics choices: object to analytics processing by contacting us; website cookie controls, when shown, apply only to consent-gated website providers and do not control native app or extension telemetry

To exercise these rights, contact us at [email protected]. We will respond within 30 days.

You may also file a complaint with the relevant data protection authority in your jurisdiction.

For California residents (CCPA/CPRA): We do not sell your personal information. You have the right to know what personal information we collect, request deletion, and opt out of any future sale. To exercise these rights, contact us at the email above.

For Australian residents: You may also contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au if you believe your privacy has been breached.