TeachAIFlow

Privacy Policy for the TeachAIFlow Trace extension

This policy explains which data the TeachAIFlow Trace browser extension processes, where it is stored (in your browser or on our server), for what purpose, on which legal basis and how you can delete it. It complements the general TeachAIFlow Privacy Policy, which still applies to your account; for anything concerning the extension, this page prevails.

Last updated: September 3, 2026Browser extension · GDPR Art. 13 · Chrome Web Store

1. In one screen

TeachAIFlow Trace is a Chrome and Edge extension that records your conversations with AI assistants (ChatGPT, Claude, Gemini, Grok, DeepSeek and NotebookLM, plus TeachAIFlow's Flow chat) so you can cite them in your assignments with a sealed reference your teacher can verify.

  • Without signing in it records nothing. It only records once you have signed in with your TeachAIFlow account and the “Recording” switch is on.
  • What it records stays in your browser, in the extension's local storage. It is not sent to any server and we cannot see it.
  • The only thing that leaves your browser is what you choose to seal by pressing “Reference”: that snapshot is stored on our server, in the European Union, with your name and email, for 18 months or until you delete it.
  • The reference can be seen by anyone who holds the TF-XXXX-XXXX code. Only you hand out that code, by pasting it into your assignment.
  • The extension uses no artificial intelligence, makes no automated decisions, carries no analytics or third-party cookies, reads no website outside the list in section 12, and we do not sell data.

Simple rule: what is local is yours and we do not see it; what is sealed is exactly what you chose to show.

2. Who is the data controller

The data controller is Javier Tur Murcia (Spanish tax ID 43223966C), Carrer des Canari 7, 07141 Sa Cabana, Illes Balears (España), operator of TeachAIFlow (Arts. 4(7) and 13(1)(a) GDPR). Contact for privacy matters and rights requests: teachaiflowapp@gmail.com.

This policy is specific to the extension and applies together with the general Privacy Policy, the Terms of Service and the Legal Notice of TeachAIFlow. Anything not covered here (account, billing, website cookies) is governed by those pages.

If your university or school deploys the extension for its students and decides what the references are used for, that institution is the controller of that processing and TeachAIFlow acts as its processor under the contract required by Art. 28(3) GDPR. If you install it on your own, we are the controller.

3. Who this applies to, and minimum age

It applies to anyone who installs the extension and creates or uses a TeachAIFlow account from its panel (usually university students) and to the teachers who verify a reference with its code.

To create an account you must be at least 14 years old (Art. 7 of the Spanish LOPDGDD). When you sign up you declare your date of birth and we check it before the extension is allowed to record. Between 14 and 17 you may use the extension with a free account, under the same rules as on the website: you cannot purchase the PRO plan and you receive no profiling-based advertising.

Under 14: you cannot sign up on your own. Students below that age can only use TeachAIFlow through a school that has contracted the service and governs their accounts, with the school as controller. The extension is not designed for that channel and blocks anyone who declares an age under 14.

4. What it stores in your browser (and we never see)

When you are signed in and recording is on, an extension script runs only on the websites in section 12 and stores in the extension's local storage (chrome.storage.local):

  • The prompts you write to the AI assistant: the text of the input box at the moment you send it.
  • The assistant's replies, as they appear on the page or as they arrive over that same website's connection.
  • What you copy from a reply, so the citation can show what you used verbatim. It is detected inside the AI page itself; the extension does not read the system clipboard.
  • Context data: assistant, conversation identifier from its URL, date and time, and whether a reply was regenerated.
  • Your session: a device token (never your password) plus your name and email to show them in the panel.

This data does not leave your browser. TeachAIFlow cannot access it: there is no sync, no backup and no telemetry. It is deleted automatically after 48 hours, with a cap of 3,000 captures, and immediately when you sign out, unlink the device from the website, press “Delete all” or uninstall the extension. The only thing the extension checks when you open the panel is the codes of your already sealed references (never the captures), to remove from the list the ones you deleted from another device or from the website.

Not captured: voice, generated images, the content of files you upload to the assistant, or anything from other tabs or other websites.

Think of local storage as your own notebook: you carry it, you erase it, and we do not have the key. If you share a computer, sign out when you finish: the captures in that browser are deleted.

5. What reaches our server (only what you send)

Only the following data reaches our server (teachaiflow.com, hosted in the European Union):

  • Account: name, email, password (stored only as a hash), date of birth, language, and the date and version of your acceptance of the Terms and the Privacy Policy. If you choose “Continue with Google”, we receive from Google your name, verified email and an account identifier; nothing else.
  • Email verification: when you create the account we send a 6-digit code to your address.
  • Device token: when you sign in from the panel, the server issues a token for that browser. We store only its SHA-256 hash, a label derived from browser and operating system (“Chrome on Windows”) and the creation, last-use, expiry and revocation dates. We store neither the full User-Agent nor an IP address linked to the token.
  • Sealed references: when you press “Reference” you choose what to send (a whole conversation or only the turns you tick). The server receives that snapshot (selected prompts, replies and copies, with assistant and dates), computes its SHA-256 hash and the TF-XXXX-XXXX code, records the sealing date and time together with your name and email as they appear in your account at that moment, and stores it all in the ext_references table. The hash covers the content; who sealed it is fixed by the server from your token.
  • Technical security logs: our hosting transiently records the IP address and time of each request to limit abuse (requests per minute) and detect incidents. They are not linked to your profile or used for anything else.

Each reference is an independent snapshot: if you delete the captures in your browser, the sealed reference stays in your account; if you delete the reference, the server removes it and the code stops working.

6. What the extension does not do

  • It does not read or run on any website outside the list in section 12. It has no browser permission to do so.
  • It uses no artificial intelligence at any point, neither our own nor third-party. TeachAIFlow sends nothing captured or sealed to OpenAI, Anthropic, Google or any other AI provider. What you write to the assistant is received by that assistant under its own policy, not ours.
  • It carries no analytics, pixels, third-party cookies or advertising. It does not measure how you use it.
  • It does not capture your password for ChatGPT, Claude, Google or any other website. It only reads the content of the conversation.
  • It does not sell personal data, does not share it with third parties for their own purposes, and does not use it for purposes other than those described on this page.
  • It records nothing without a signed-in session and, when it records, it shows it: a red dot on the icon and a “Recording” switch in the panel.

8. What your teacher sees with the code, and why

You decide what gets sealed: the whole conversation or only the turns you tick. Before sealing, the panel shows you exactly what will be sent.

You hand out the TF-XXXX-XXXX code yourself, by pasting it into your assignment. It is not published in any listing, the reference page is not indexed by search engines, and the code cannot be guessed: it is derived from the hash of the content.

Whoever opens teachaiflow.com/ref/<code> sees that the reference is authentic, the sealing date and time, the assistant used, your name, your MASKED email (for example a•••••@uib.es: the first letter and the domain) and the content you chose to seal. That is enough for the teacher to confirm the reference belongs to whoever signs the assignment, without your full address being available to anyone holding the code. Only you see your full email, in your panel and with your session open.

The teacher may also upload the assignment (PDF, Word or text) so the server marks which passages are verbatim from the reference. That assignment is processed in memory and not stored: no copy remains at TeachAIFlow.

If the teacher belongs to a university or school, that institution handles the result under its own assessment rules. TeachAIFlow plays no part in grading.

Before pressing “Reference”, review the snapshot. If it contains other people's data or sensitive data (health, beliefs, sexual orientation, etc.), remove it or select only the turns you need: whatever you seal will be visible to anyone with the code.

9. How long we keep the data

We apply the storage-limitation principle (Art. 5(1)(e) GDPR):

  • Captures in your browser: 48 hours from capture, or up to 3,000 captures; sooner if you sign out, unlink the device, press “Delete all” or uninstall.
  • Sealed references: 18 months from sealing (the academic year in which you submit the assignment and the next one, for reviews and appeals), or until you delete it. After that period an automatic purge removes it from the server.
  • Device tokens: 12 months from issue, or until you sign out or revoke it from /account/extension. A revoked or expired token stops working immediately.
  • Account data: for as long as the account exists, as set out in the general Privacy Policy. Deleting the account deletes its tokens and references.
  • Technical security logs: a short period, the one the hosting provider needs to operate and troubleshoot incidents.

10. Recipients, processors and transfers

We do not share your data with third parties for their own purposes. To operate the extension we use only the following processors, under contracts compliant with Art. 28(3) GDPR:

  • Vercel: hosting and execution of the teachaiflow.com server. It handles the extension's requests and serves the /ref pages.
  • Neon: the PostgreSQL database holding your account, the tokens (hash only) and the sealed references.
  • Resend: delivery of the email containing the verification code when you create the account. It receives your email address and the code.

TeachAIFlow's server (Vercel functions) and database (Neon) run in Frankfurt, Germany (eu-central-1 region), inside the European Union; only the website's static content (pages, scripts, images, no personal data) is delivered from Vercel's global network. These providers are companies headquartered in the United States: any access from outside the European Economic Area (for example, technical support) is covered by the European Commission's standard contractual clauses incorporated into their processing agreements (Art. 46(2)(c) GDPR).

If you choose “Continue with Google”, Google handles your sign-in as an independent controller under its own privacy policy. We receive from Google only your name, verified email and an identifier.

The AI assistants you talk to (OpenAI, Anthropic, Google, xAI, DeepSeek) are independent controllers of what you send them. The extension sends them nothing extra and does not alter what you write.

We may disclose data to public authorities when the law requires it (Art. 6(1)(c) GDPR). There is no other recipient: the extension has no analytics, advertising or AI providers.

11. Your rights and how to exercise them

You have the rights set out in Arts. 15 to 22 GDPR and Arts. 12 to 18 LOPDGDD: access, rectification, erasure, restriction, portability, objection and withdrawal of consent. The most useful ones are already built into the product:

  • Delete a reference: in the extension panel (“Delete” button) or at teachaiflow.com/account/extension, section “My references”. It is removed from the server and the code stops working.
  • Sign out or unlink a device: from the panel (“Sign out”) or from /account/extension, section “Linked devices”. The token is revoked and the local captures in that browser are deleted.
  • Delete everything local: “Delete all” button in the panel, or uninstall the extension.
  • Portability (Art. 20 GDPR): “Export” in the panel downloads your captures and references as JSON; “Download” does the same for a single reference.
  • See what we hold about you: at /account/extension you can see your linked devices and your references, with their code and hash.

For any other request (full access, rectification of your account data, account deletion), write to teachaiflowapp@gmail.com from your account's email address. We reply within one month at most (Art. 12(3) GDPR).

If you believe we have not honoured your rights, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) or with the supervisory authority of your country (Art. 77 GDPR).

12. Websites where the extension runs and permissions it requests

The extension runs only on the following addresses, declared in its manifest (host_permissions). On any other website it does not load and cannot read anything:

  • chatgpt.com and chat.openai.com (ChatGPT, OpenAI).
  • claude.ai (Claude, Anthropic).
  • gemini.google.com (Gemini, Google).
  • grok.com (Grok, xAI).
  • chat.deepseek.com (DeepSeek).
  • notebooklm.google.com and notebook.google.com (NotebookLM, Google).
  • teachaiflow.com: the /flow path (TeachAIFlow's Flow chat) for capture and /account/extension to link the account from the website. The rest of the domain is only used to talk to our server (API).

Browser permissions and what they are for: storage and unlimitedStorage (keeping captures and references in your browser without the default quota truncating them) and sidePanel (the side panel). Those three are the only ones this version requests: it asks for no permissions over tabs, browsing history, cookies or downloads, runs no remote code, and “Continue with Google” is not available in it (if a future version enables it, that version will also request the identity permission and you will see it when updating).

13. No artificial intelligence, no automated decisions

The extension and the /ref pages use no AI model. The seal is a SHA-256 hash with a timestamp; the check is a literal comparison of text fragments. There is no probabilistic “AI detector”, no score and no student profile.

We make no automated decisions with legal or similarly significant effects about you (Art. 22 GDPR). If a teacher makes an academic decision, the teacher makes it, with the reference as evidence of what you chose to show.

Because the extension embeds no AI system, the transparency obligations of Regulation (EU) 2024/1689 (the AI Act) do not apply to it. The AI tools of the TeachAIFlow platform have their own AI Transparency page.

14. Security

Technical and organisational measures (Art. 32 GDPR) behind this policy:

  • All communication with the server is encrypted (HTTPS). The extension rejects any server other than https://teachaiflow.com.
  • Device tokens are stored hashed and compared in constant time; they expire and can be revoked from the website.
  • Passwords are stored hashed; the extension never keeps yours.
  • Extension routes authenticate only by token and website routes only by session cookie: a stolen token does not open the website and a cookie cannot seal from elsewhere.
  • Per-minute rate limits on sign-in, sealing, /ref reads and checks.
  • The server recomputes the hash and code of every reference: it does not trust what the client declares.

Known limit: malware with access to your browser's storage could use your token. If you suspect it, unlink the device from /account/extension and change your password. If we detect a security breach affecting your data, we will notify it in accordance with Arts. 33 and 34 GDPR.

15. Limited Use (Chrome Web Store)

TeachAIFlow Trace complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically: we only use user data to provide or improve the extension's single purpose (recording and referencing your use of AI assistants), which is visible from its own interface; we only transfer it to third parties where necessary to provide that purpose, to comply with the law, to protect against fraud or abuse, or as part of a merger or acquisition with prior notice; we do not use or transfer it to serve advertising, to determine creditworthiness or for lending purposes; and no human reads that data except with your explicit consent, for security purposes, to comply with the law, or in aggregated and anonymised form for internal operations.

The use of information received from Chrome APIs and, where Google sign-in is used, from Google APIs by TeachAIFlow Trace will adhere to the Chrome Web Store User Data Policy and to the Google API Services User Data Policy, including the Limited Use requirements.

16. Changes to this policy and contact

We will update this policy when the extension changes which data it processes, where or for how long, or when the law changes. If the change is material we will tell you in the panel and ask you to accept the new version before recording continues. The date in the header identifies the version in force.

For questions about this policy, write to teachaiflowapp@gmail.com. If your university or school wants a data processing agreement or information for its students about the extension, write to the same address.