The short version: without an account, your data stays in your browser. With an account, we store your email address and the projects you choose to sync, on servers in the European Union. We do not sell your data or run ads. Usage analytics (including PostHog session replay, details in section 04) run only if you allow them in the consent banner on your first visit; you can change your mind at any time in Settings → Privacy.
Assignmap works signed out. Your projects — briefs, rubrics, drafts, plans — are stored in your browser's local storage on your device. We never see them, and closing your account, or never opening one, requires nothing from us.
If you configure your own AI provider (bring-your-own-key or a local model such as Ollama), the text you generate from is sent directly from your browser to that provider under your key and their privacy terms. We are not in that path.
When you sign in, we store:
This data is stored with Supabase on servers located in the European Union. Each user's data is isolated at the database level with row-level security.
When a signed-in user generates a plan or a draft check, the text of that project (brief, rubric, draft) is sent through our server to an AI model provider (currently OpenAI) to produce the result, which is streamed back to you. Under the provider's API terms, this data is not used to train their models. We do not store your prompts or the model's output on our server; the result is saved only in your project, wherever that project lives.
On your first visit we ask, in a banner, whether we may record usage statistics. Until you say yes, nothing is recorded and no analytics identifier or cookie is stored (legal basis: consent, Art. 6(1)(a) GDPR). Declining is one click, changes nothing about how the app works, and we remember it — you will not be asked again. You can withdraw or grant consent at any time in Settings → Privacy, which takes effect immediately.
If you allow it, we record a small set of usage events: that a plan was generated, how long it took, whether it succeeded, which file formats were uploaded, and which buttons were used. Each event carries counts, timings and short fixed labels — never your brief, rubric, draft, project titles or file names. These events are stored in our own database in the European Union and are deleted after 12 months. They are tagged only with a random identifier kept in your browser's local storage — they are not linked to your account or your email address, so we cannot tell which events belong to which user, and deleting your account leaves nothing tied to you behind. Clearing this site's browser data discards that identifier and starts a new one.
With the same consent, we send the same usage events to PostHog, a third-party product-analytics provider, which additionally records session replays — playbacks of how you moved through the page, so we can see where the interface confuses people. Every text field and all on-screen text is masked before recording: your brief, rubric, draft, project titles and file names are never captured, only the shapes of the layout and which controls you used. PostHog sets a cookie to recognise your browser across visits and processes this data on its EU cloud, hosted in Frankfurt, Germany — it never leaves the European Union. There is no advertising network and no cross-site advertising identifier.
We also honour your browser's “Do Not Track” setting automatically — if it is on, we treat it as a no and never show the banner.
We share data only with processors acting on our behalf:
What we do not do:
Account data is kept until you delete your account, which you can do yourself: Account → Your data → Delete account removes your account, synced projects, courses and quota ledger immediately and irreversibly. Usage events are deleted after 12 months (section 04). If you prefer, email us from your account address and we will delete it for you. Data stored only in your browser is yours to delete at any time by clearing the site's data.
Under the GDPR and the Swiss Federal Act on Data Protection you have the right of access, rectification, erasure, restriction of processing, data portability, and objection, and the right to withdraw consent at any time without affecting past processing. In-app: Account → Your data → Download my data gives you a machine-readable copy of everything we hold for your account, and Settings → Privacy withdraws analytics consent. Usage events are not included because they are not linked to your account and we have no way to identify yours (section 04). For anything else, email us and we will do it. If you believe we have mishandled your data, you can complain to your local data protection authority.
Assignmap is operated by Michael Menzi, who is the data controller for the personal data described in this policy.
If this policy changes in a way that matters, we will note it here with a new effective date. Questions and requests: support@assignmap.com.