Privacy Policy
Effective July 24, 2026
Proctorly is operated by SchoolToolz (“SchoolToolz,” “Proctorly,” “we,” “our,” or “us”). Proctorly is an online educational exam-monitoring platform that helps educators, schools, tutoring programs, homeschool users, and other educational organizations administer and review remote exams.
This Privacy Policy explains how we collect, use, disclose, store, and protect information when users access Proctorly, including through our website, teacher dashboard, student exam links, exam monitoring tools, beta features, and related services.
Proctorly is intended for educational use. Because Proctorly may be used by students, including minors and students under 13, this Privacy Policy includes additional information for schools, parents, guardians, and educators.
This Privacy Policy should be read together with our Terms of Service, Student Monitoring Notice, Beta Terms, AI Integrity Report Disclaimer, and any applicable school agreement, data protection addendum, or consent document.
1. Who We Are
Proctorly is a product operated by SchoolToolz.
Current business location: Durham, North Carolina, United States
Privacy contact: privacy@proctorly.co
For purposes of this Privacy Policy, “Proctorly” refers to the Proctorly platform, website, dashboard, student exam experience, exam monitoring tools, and related services.
2. Who Uses Proctorly
Proctorly may be used by:
- teachers;
- school administrators;
- schools;
- school districts;
- tutoring companies;
- homeschool parents or guardians;
- homeschool groups or co-ops;
- students;
- parents and guardians;
- other authorized educational users.
Proctorly is not intended for employment hiring, workplace surveillance, law enforcement, immigration screening, healthcare eligibility, government benefits determinations, or non-educational monitoring.
3. Important Notice About Students and Schools
When Proctorly is used by a school, district, teacher, or educational institution, the school or educator may control how Proctorly is used with students.
Where applicable, Proctorly is intended to process student information only for school-authorized educational purposes, such as exam administration, remote exam monitoring, academic integrity review, and related support.
Proctorly does not make final academic, disciplinary, grading, cheating, identity, or misconduct decisions. Educators and institutions remain responsible for reviewing Proctorly-generated information, applying their own policies, considering student explanations, providing appropriate accommodations, and making any final academic decisions.
4. Information We Collect From Teachers and Account Holders
When a teacher, school administrator, homeschool parent, tutor, or other account holder creates or uses a Proctorly account, we may collect:
- name;
- email address;
- password or authentication credentials;
- account role or organization affiliation;
- school, organization, or class information;
- billing and subscription information;
- plan type and subscription status;
- account settings;
- support communications;
- product usage information;
- login and authentication information;
- feedback submitted during beta or support interactions.
Payment information is processed by Stripe. We do not store full payment card numbers on Proctorly infrastructure.
5. Information We Collect From Students
Students do not create persistent Proctorly accounts to take an exam. Students generally access exams through a link provided by an educator or institution.
When a student uses Proctorly, we may collect:
- student-provided name;
- student-provided email address or school email address;
- exam session identifier;
- test or exam identifier;
- timestamps;
- session start and end times;
- tab-switch events;
- fullscreen-loss events;
- screen-share interruption events;
- monitoring status events;
- face-count events, such as whether zero, one, or multiple faces appear to be present;
- webcam snapshots;
- screen snapshots;
- ID photo or setup photo for manual educator review;
- short audio clips from the microphone around flagged events;
- integrity flags;
- teacher decisions or review notes associated with flags;
- AI-generated integrity report content;
- technical information needed to operate the exam session.
Proctorly does not collect student IP addresses, device identifiers, browser fingerprints, user agents, operating system information, or approximate location for student exam sessions, except to the extent such information may be temporarily processed by hosting, security, or infrastructure providers as part of standard internet operation.
6. Exam Monitoring Information
During an active exam session, Proctorly may use the student’s browser to support remote exam monitoring.
Depending on the educator’s selected settings, Proctorly may:
- request webcam access;
- request screen-sharing access;
- capture webcam snapshots;
- capture screen snapshots;
- capture short audio clips from the microphone around flagged events;
- detect tab switching;
- detect fullscreen loss;
- detect screen-share interruption;
- detect whether zero, one, or multiple faces appear to be present;
- generate integrity flags for educator review;
- generate post-exam integrity reports.
Proctorly may capture baseline webcam and screen snapshots during an exam and may also capture additional snapshots when certain events are detected. Some settings may use selective capture rather than continuous baseline capture.
Proctorly does not record full continuous webcam video or audio. Proctorly may capture short audio clips from the microphone around flagged events to help educators understand what may have triggered a flag.
7. Face Detection and Biometric Clarification
Proctorly uses on-device face-presence or face-count detection to help determine whether zero, one, or multiple faces appear to be present during an exam session.
Proctorly does not:
- use facial recognition to identify students;
- compare a student’s face to an enrollment photo;
- create faceprints;
- create facial templates;
- create face embeddings;
- create persistent biometric identifiers;
- infer race, gender, age, emotion, stress, attention, gaze, or demeanor;
- store facial landmarks, face bounding boxes, or face confidence scores;
- use student images for model training.
Proctorly may store an ID photo or setup photo for manual educator review only. The educator, not Proctorly’s software, is responsible for any manual identity review.
If Proctorly’s face detection features materially change, this Privacy Policy should be updated before the changed feature is used with students.
8. AI Integrity Reports
Proctorly may use AI tools to help generate post-exam integrity reports or communication drafts based on exam flags and session metadata.
AI-generated integrity reports are advisory only. They are not final proof of cheating, misconduct, identity fraud, or academic dishonesty. A flag does not prove misconduct, and the absence of a flag does not prove compliance.
Educators and institutions must independently review relevant context before making any academic, disciplinary, grading, or misconduct decision.
For AI processing:
- webcam images are not sent to AI model providers;
- screen captures are not sent to AI model providers;
- exam answers are not sent to AI model providers;
- teacher-authored exam questions are not sent to AI model providers;
- flag data and text summaries may be sent to AI providers for report generation;
- AI email-generation workflows do not send raw student or teacher names, test names, or institution names to AI providers. Names, test titles, and institutions are replaced with placeholders before the prompt is sent and are reinserted after the response is returned locally.
Before using Proctorly in production school environments, Proctorly should configure AI vendors to avoid student personally identifiable information where practical and should use zero-data-retention or equivalent protections where available.
9. How We Use Information
We may use information to:
- provide and operate Proctorly;
- create and manage teacher or school accounts;
- administer exams;
- support student access through token links;
- monitor exam sessions as configured by educators;
- generate integrity flags;
- generate advisory AI integrity reports;
- show educators exam-session information;
- support teacher review of exam sessions;
- provide customer support;
- process subscriptions and payments;
- send transactional emails;
- maintain security and prevent misuse;
- debug errors and improve reliability;
- enforce our Terms of Service and Acceptable Use rules;
- comply with legal obligations;
- protect the rights, safety, and security of Proctorly, users, students, schools, and others.
We do not use student information for targeted advertising. We do not sell student personal information. We do not build commercial advertising profiles about students.
10. Student Data Use Limits
For student data, Proctorly’s intended use is limited to educational purposes authorized by the applicable teacher, school, institution, parent, or guardian.
We do not use student data to:
- sell student information;
- serve targeted advertising to students;
- target advertising to parents based on student information;
- create commercial profiles of students unrelated to educational use;
- train AI models, unless separately disclosed and legally authorized;
- make automatic academic or disciplinary decisions;
- identify students using facial recognition;
- infer sensitive traits from student images.
11. Children Under 13
Proctorly may be used in educational settings involving students under 13 only where there is a legally appropriate authorization path.
Depending on the context, that path may include:
- authorization by a school or district for educational use;
- consent by a parent or guardian;
- authorization by a homeschool parent or legal guardian;
- another legally valid consent or authorization path.
For school-based use, Proctorly expects the school or institution to provide required notices and obtain or coordinate any required consents where applicable. Proctorly may provide schools with notices, templates, and information about Proctorly’s data practices to support this process.
Individual teachers may not use Proctorly with students under 13 unless they have authority from the school, district, institution, homeschool parent, legal guardian, or other legally valid consent source.
Parents or guardians may contact the relevant school or educator to request access to, correction of, or deletion of a child’s information. For homeschool, tutoring, or direct-parent contexts, parents or guardians may contact Proctorly directly at privacy@proctorly.co.
12. FERPA and School-Controlled Information
When Proctorly is used by a school or educational institution subject to the Family Educational Rights and Privacy Act, certain information processed by Proctorly may be considered education records or personally identifiable information from education records.
Where applicable, Proctorly is intended to act as a school service provider or school official under the school’s direction and control. Proctorly will use student information only to provide and support the educational services authorized by the school or institution and will not redisclose student information except as permitted by the applicable agreement, law, or school instruction.
Requests by parents or eligible students under FERPA should generally be directed to the school or institution. Proctorly will support schools in responding to valid access, amendment, deletion, export, or similar requests as required by applicable agreements and law.
13. California Student Privacy
For California K–12 users, Proctorly is intended to comply with applicable California student privacy obligations, including restrictions on targeted advertising, sale of student information, non-educational profiling, and unauthorized disclosure of covered student information.
Proctorly does not knowingly:
- engage in targeted advertising using student information;
- target advertising to students or parents based on student information;
- sell student information;
- use student information to build commercial profiles unrelated to school-authorized educational purposes.
Proctorly uses student information for educational exam-monitoring and academic-integrity support purposes.
14. Vendors and Subprocessors
We use service providers and subprocessors to host, operate, secure, monitor, and support Proctorly.
These may include:
- Supabase: authentication, database, and storage infrastructure;
- Cloudflare R2: storage for snapshots, ID photos, short screen-share clips, and short audio clips;
- Stripe: subscription billing and payment processing;
- Resend: transactional and support email;
- Sentry: error monitoring;
- OpenRouter: AI report and email-generation workflows;
- Google (storage.googleapis.com): delivery of the MediaPipe face-detection model to the student browser;
- jsDelivr (cdn.jsdelivr.net): delivery of the MediaPipe face-detection WASM files to the student browser;
- Vercel: hosting and content delivery;
- PostHog: product analytics for teacher-facing areas, with student routes excluded;
- Vercel Analytics: teacher-facing pageview analytics.
We expect vendors that process personal information on our behalf to use the information only to provide services to us and to protect it using appropriate safeguards. Vendor and subprocessor details may be provided in a separate Subprocessor List.
15. Analytics and Cookies
Proctorly may use limited analytics on teacher-facing pages to understand product usage, improve performance, and support the service.
Proctorly is designed so that student exam routes are excluded from PostHog product analytics, and session recording is disabled.
We do not use student exam-session data for behavioral advertising.
16. Data Retention
We retain information only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required by law, school agreement, accounting requirements, dispute resolution needs, or legitimate security needs.
Current retention periods include:
- webcam snapshots: database records are deleted after 30 days by default, configurable 1–365 days by the school or teacher; the underlying R2 storage objects are deleted by the scheduled daily automated R2 deletion job before the corresponding database record is removed, with failed deletions retried on the next run;
- screen snapshots: database records are deleted after 30 days by default, configurable 1–365 days by the school or teacher; the underlying R2 storage objects are deleted by the scheduled daily automated R2 deletion job before the corresponding database record is removed, with failed deletions retried on the next run;
- short audio clips: database records and R2 storage objects are deleted the same as screen snapshots, with R2 objects deleted before the corresponding database record is removed;
- ID photos: no automated deletion; removed only when a session or test is deleted, or when the account is closed;
- short screen-share clips: Proctorly does not capture short screen-share video clips; screen activity is captured through screen snapshots, which are retained and deleted as described in item 2;
- integrity flags: no automated deletion; removed only when a session or test is deleted, or when the account is closed;
- AI reports: no automated deletion; removed only when a session or test is deleted, or when the account is closed;
- student session metadata: no automated deletion; removed only when a session or test is deleted, or when the account is closed;
- teacher account data: retained while the account remains active and for a reasonable period afterward;
- billing records: retained as required for tax, accounting, and legal compliance;
- error logs: governed by the Sentry project's plan setting, not by this Privacy Policy;
- backups: governed by the Supabase project's backup plan, not by this Privacy Policy.
17. Deletion, Access, and Correction
Schools and institutions may request access, export, correction, or deletion of student information according to the applicable school agreement and law.
Parents and students should generally direct requests about school-controlled student records to the school or educator. For homeschool, tutoring, or direct-parent contexts, parents or guardians may contact Proctorly at privacy@proctorly.co.
We may need to retain certain information for legitimate legal, security, accounting, backup, or dispute-resolution purposes.
18. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information processed by Proctorly.
Current or planned safeguards may include:
- HTTPS encryption in transit;
- private storage buckets or restricted storage access;
- row-level security and account-based access controls;
- teacher access limited to the teacher’s own exam/session data;
- presigned upload URLs;
- restricted staff access;
- error monitoring with redaction of sensitive information;
- secrets stored outside source code;
- vendor-provided infrastructure security;
- additional planned controls such as HSTS, signed download URLs, admin MFA, audit logging, vulnerability disclosure, and incident response procedures.
No system is perfectly secure. Proctorly will continue improving its security practices as the product matures.
19. International Use
Proctorly is intended for use in the United States at launch. Proctorly is not intended for European Union or United Kingdom school use at launch.
Users should not use Proctorly for EU or UK students unless Proctorly has approved that use in writing and appropriate legal, privacy, data transfer, and AI compliance terms are in place.
20. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide notice as required by law or by applicable agreement.
The “Last Updated” date above shows when this Privacy Policy was last revised.
21. Contact Us
Questions or requests may be sent to:
SchoolToolz / Proctorly
Durham, North Carolina, United States
Email: privacy@proctorly.co