The short version
- Student work is stored in Melbourne. All four apps use a database in Google’s
australia-southeast2region. Two narrow exceptions are listed below. - Students do not need an account for Litmus, Scribe or Chalk. No student email address is ever collected, in any of the four.
- Nothing is sold, shared or advertised against, and nothing is used to train AI models.
- Your school’s data is yours. Deleting your account deletes everything that came with it.
Who I am
Jotty is four small classroom tools — Litmus, Scribe, Chalk and PeerLoop — built and run by me, Ben Davies, a teacher in Victoria, Australia. There is no company behind it, no investors, and no staff. This one policy covers all four apps; where they differ, the table below says so.
You can reach me about anything on this page through the help form.
Who is responsible for what
When a teacher runs a session, the school decides what is asked, whether students put their names to it, and what happens to the results. The school is responsible for that decision, and for having the standing consents that schools already hold.
My job is to hold that data and hand it back — nothing more. I do not decide what a class is asked, I do not combine data across schools, and I do not use anyone’s classroom data for a purpose of my own.
If your school needs this stated as a formal arrangement before it can approve the tools, get in touch and I will put it in writing.
What each app collects
Every app collects a teacher account — an email address, a display name, and either a password or a Google sign-in. What is collected from students varies, and the differences matter:
| Litmus | Scribe | Chalk | PeerLoop | |
|---|---|---|---|---|
| Student account | None | None | None | Yes — see below |
| Student name | Optional — the teacher can run it anonymously | Optional — the teacher can run it anonymously | As typed on joining | From the class roster the teacher enters |
| Student email | Never | Never | Never | Never |
| What students submit | Answers to the teacher’s questions | Their writing, saved as they type | A short written response | Written work, file attachments, and peer comments |
| Activity recorded alongside it | Time submitted | Word count, last-typed time, and a flag if text was pasted in | Word count, last-typed time, and whether the tab is in focus | Time submitted, and who reviewed whom |
| Shown to other students | No | Only in peer review, if the teacher turns it on | One chosen response is shown to the class | Yes — that is the point of the app |
| Stored on the student’s own device | A random ID, so a refresh does not lose work | A random ID, so a refresh does not lose work | A random ID, and which help screens have been seen | The signed-in session |
A note on Scribe and Chalk
Scribe saves student writing continuously so a teacher can watch a draft develop, and it flags when a chunk of text is pasted in rather than typed. Chalk records whether a student’s tab is in focus while they are responding. Both of these are visible to the teacher running the session, and students should be told that before they start. Neither is a judgement — a pasted quote and a copied essay look the same to the app, and the teacher is the one who reads it.
A note on PeerLoop accounts
PeerLoop is the one app where students sign in, because peer review needs to know reliably who wrote what. A teacher types a class roster of first names, and each student sets a PIN on first use. The sign-in address behind that is generated by the app from a random slot ID — it is never a real email address, never shown to the student, and cannot be used to contact or identify anyone outside the class.
Where it is stored
Student work in all four apps lives in Google Cloud Firestore in the
australia-southeast2 region — Melbourne.
It does not leave the country in the ordinary running of the apps.
There are three exceptions, and I would rather name them than bury them:
-
Chalk’s live annotation and presence data is
held in Google’s Realtime Database in
asia-southeast1— Singapore. This covers the response being annotated on the board, student names in the live participant list, and the typing and focus signals above. Google does not offer an Australian region for this particular product, which is why it sits where it does. The permanent record of a Chalk session is still in Melbourne. -
PeerLoop’s PIN reset runs on a server in
us‑central1— Iowa, USA. It handles a student’s internal account ID at the moment a teacher resets a PIN. No classroom work passes through it. - Sign-in itself is handled by Google’s authentication service, which is global rather than region-pinned. For teachers that means an email address; for PeerLoop students, the generated address described above.
Messages sent through the help form are handled by Netlify and stored on their servers in the United States, as well as being emailed to me. That is why the form asks you not to put student names in it.
Who can see it
- The teacher who ran the session, and only their own sessions.
- Other students in the same class, where the app is built to do that — the one response chosen in Chalk, and peer review in Scribe and PeerLoop.
- Me. I can reach the data in order to run and fix the apps, and Scribe has an admin view that shows usage across every teacher account. I use it to see how the tools are being used and to find sessions that have broken — not to read anyone’s class work for interest.
- Google, as the company hosting the databases, under their own terms as a processor.
Nobody else. There is no other party with access, paid or otherwise.
How long it is kept
Sessions and student responses are kept until a teacher deletes them. Nothing expires on its own. A teacher can delete an individual session or question set at any time from their dashboard, and deleting a teacher account deletes every task, session and student response created under it.
If your school needs data cleared at the end of a term or a year, tell me and I will do it.
Analytics
There is no analytics, tracking or advertising code of any kind on the pages students use. No third party is told that a student visited, and nothing follows them off the site.
Teacher-facing pages use Google Analytics so I can see which parts of the tools are actually being used and where they are failing. It records the usual things — page, browser, approximate location from IP address — and it is never joined to any student data.
What I do not do
- Sell, rent or share data with anyone.
- Show advertising, or profile anyone for it.
- Use student work to train AI models — mine or anybody else’s.
- Ask students for an email address, a phone number, or a date of birth.
- Contact students. Ever, for any reason.
- Track anyone across other websites.
Getting data out, or deleted
Every app exports its session data as CSV from the teacher dashboard, so you can keep your own records without going through me.
For anything else — a parent asking what is held about their child, a school wanting a class or a year cleared, or a correction to something stored — use the help form and I will deal with it within 30 days, usually much sooner. Requests about a particular student should come through the school, since I have no way to verify who a student is.
Security
Everything is served over HTTPS. Database rules restrict each teacher to their own sessions, and restrict students to writing their own response and nothing else. Teacher passwords are handled by Google’s authentication service and are never stored by me or visible to me.
These are tools built by one teacher, not audited enterprise software. I have taken the care I would want taken with my own students’ work, but you should weigh that when deciding what to use them for.
Changes
If this policy changes in a way that affects what is collected or who can see it, I will say so on this page and change the date below rather than editing quietly.
Last updated 5 September 2026.