Privacy
Oritavo collects the minimum needed to run assessments honestly, and nothing is ever sold or used for advertising.
What we collect
Account basics (username, email, role, and — for students — a student ID for gradebook matching), the assessments and questions instructors author, and submission records: answers, scores, timestamps, attempt counts, pause events, and tab-switch counts during attempts. If you sign in with Google or Yahoo, we store the provider's account identifier and email; we never receive your provider password. Learners and instructors using AI generation also have their uploaded study materials (or pasted text) and the resulting draft questions stored under their account, plus a running count of questions generated for billing purposes.
Study materials and AI generation
A PDF, note photo, or pasted text you upload is stored so it can be turned into practice questions, and sent to the configured AI provider (Anthropic by default) for that single purpose — extracting text and drafting questions. It is not used to train Oritavo's own systems. Deleting a material removes the stored file; the questions already drafted from it stay in your bank unless you delete those too.
Billing data
We store your plan (Free, Pro, or Institution) and monthly generation usage so quotas and upgrades work correctly. We never see or store card numbers ourselves: real payment goes through Stripe's own hosted Checkout, which shares back only a customer and subscription identifier — never the card itself.
Why we collect it
Everything above exists to deliver, grade, and report assessments — including the integrity signals instructors rely on. We don't build advertising profiles, we don't sell data, and we don't share it with third parties beyond the infrastructure that runs the service (hosting, database, and email delivery).
Visibility
Instructors see the work students submit to their assessments: answers, scores, attempt history, and integrity signals. Students see their own scores and attempt counts. Organization admins see membership of their workspace, not the contents of members' personal workspaces.
Retention and deletion
Deleting an assessment permanently removes its questions, roster, and submissions. Removing a student from a roster revokes access but preserves already-graded work, since grades often must survive roster changes. To delete an account entirely, contact support from the account's email address.