Back to home

Privacy Policy

Effective date: March 8, 2026

This Privacy Policy describes how QuizFuse (“the Service,” “we,” “us,” or “our”) collects, uses, and protects information when you use our web application. By using the Service, you agree to the practices described in this policy.

QuizFuse is designed with a privacy-first architecture. We do not maintain user accounts, do not operate a user database, and minimize data collection to what is strictly necessary to provide the Service.

1. Information We Collect

1.1 Information You Provide Directly

  • Class content and source material — text you paste or type into the Service for quiz generation, including notes, textbook passages, study guides, and any other educational material. This content is processed in real time and is not stored on our servers after processing is complete.
  • Uploaded files — PDFs, images, and text files you upload to the Service. These files are temporarily stored in your browser's IndexedDB storage for the duration of your editing session and are automatically deleted when you leave the editor. File contents are sent to the Anthropic API for processing but are not stored on our servers.
  • Chat messages — instructions and prompts you send to the AI assistant to generate or modify quizzes. These are held in your browser's memory during your session and stored locally on your device (see Section 3).
  • Access keys — credentials used to authenticate your access to the Service. We validate keys server-side and store the key value in an HTTP-only cookie to maintain your session and provide a personalized experience (such as customized welcome messages). We do not log access key usage to a database or track usage patterns over time.

1.2 Information Collected Through Google OAuth

When you connect your Google account to export quizzes, we receive:

  • OAuth access token — a temporary credential that allows us to create Google Forms and manage files in your Google Drive on your behalf.
  • OAuth refresh token — used to obtain new access tokens when the current one expires, so you do not need to re-authenticate each session.
  • Token expiration time — used to determine when to refresh your access token.

We do not receive or store your Google email address, name, profile picture, contact list, or any other personal information from your Google account. We only request the minimum scopes necessary:

  • forms.body — to create and edit Google Forms
  • drive.file — to create files and folders in your Google Drive

1.3 Information We Do Not Collect

We do not collect:

  • Names, email addresses, or personal identifiers
  • IP addresses or geolocation data
  • Device fingerprints or browser characteristics
  • Usage analytics or behavioral tracking data
  • Student information of any kind

2. How We Use Your Information

We use the information described above solely to operate the Service:

  • Content and chat messages are sent to the Anthropic API to generate quiz questions, answer keys, point values, and feedback. This is the core function of the Service.
  • Google OAuth tokens are used exclusively to create Google Forms in your Drive, organize them in a designated folder, and sync edits you make within the Service to the corresponding Google Form.
  • Access keys are validated to grant or deny access to the Service.

We do not use your information for:

  • Advertising, marketing, or retargeting
  • Analytics, profiling, or behavioral tracking
  • Training AI models
  • Selling, renting, or sharing with data brokers
  • Any purpose other than providing the Service as described

3. Data Storage and Retention

3.1 Server-Side (Our Infrastructure)

QuizFuse does not operate a database. No user content, quiz data, chat history, or personal information is stored on our servers. All content processing happens in memory and is discarded immediately after the response is sent.

3.2 Client-Side (Your Browser)

Quiz data — including quiz titles, questions, answer keys, point values, feedback, and chat history — is stored in your browser's local storage. Uploaded files (PDFs, images, text files) are temporarily stored in your browser's IndexedDB during your editing session and are automatically deleted when you leave the editor. This data:

  • Remains entirely on your device
  • Is not persistently stored on our servers. Content is transmitted to Anthropic for processing and to Google for export, but is not retained after the operation completes
  • Is not encrypted at rest in the browser
  • Quiz data in local storage persists until you manually delete it or clear your browser data. Uploaded files in IndexedDB are automatically cleaned up when you navigate away from the editor
  • Is not accessible to us or any third party through the Service

3.3 Cookies

QuizFuse uses two essential cookies. We do not use any tracking, analytics, or advertising cookies.

CookiePurposeDuration
qf_accessStores your access key after authentication to maintain your session and provide personalized settings7 days
qf_google_tokensStores encrypted Google OAuth tokens for quiz export30 days

Both cookies are HTTP-only (not accessible to JavaScript), encrypted where applicable (AES-256-GCM for Google tokens), and marked Secure in production (transmitted only over HTTPS).

4. Third-Party Services and Data Sharing

We do not sell, rent, or share your data with third parties for their own purposes. However, the Service relies on the following third-party services to function, and data is transmitted to them as described below:

4.1 Anthropic (AI Processing)

Your content and chat messages are sent to Anthropic's API for quiz generation. Specifically, each request includes:

  • The text content you provide for quiz generation
  • Uploaded files (PDFs, images, text files) attached to your messages
  • Your chat history with the AI assistant (up to 20 recent messages)
  • The current state of your quiz (titles, questions, answers)

Per Anthropic's current API terms, data submitted through their API is not used for model training. See Anthropic's Privacy Policy for current details on their data retention practices.

4.2 Google APIs (Quiz Export)

When you export a quiz, the following data is sent to Google's APIs:

  • Quiz title, description, and all questions with answer keys, point values, and feedback
  • Your OAuth access token (for authentication)

This data is used to create a Google Form in your Drive and, if auto-sync is active, to update it when you make changes. Google processes this data in accordance with Google's Privacy Policy.

QuizFuse's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not transfer it to third parties, and do not use it for purposes unrelated to quiz export.

4.3 Vercel (Hosting)

The Service is hosted on Vercel. All HTTP requests pass through Vercel's infrastructure. Vercel may collect standard server logs (IP addresses, request timestamps) as part of their hosting service. We do not access or use these logs. See Vercel's privacy policy for details on their data practices.

5. Data Security

We implement the following security measures:

  • Encryption in transit — all communication between your browser and our servers uses HTTPS/TLS encryption.
  • Encrypted tokens — Google OAuth tokens stored in cookies are encrypted using AES-256-GCM before being set in the browser.
  • HTTP-only cookies — authentication cookies cannot be accessed by client-side JavaScript, reducing the risk of cross-site scripting (XSS) attacks.
  • Secure cookie flag — in production, cookies are transmitted only over HTTPS connections.
  • No server-side data persistence — by not storing user content or personal data on our servers, we eliminate the primary vector for data breaches.
  • Minimal scope — Google OAuth integration requests only the minimum permissions required to create and manage forms.

Please note that quiz data stored in your browser's local storage is not encrypted. Anyone with access to your device and browser can view this data. You are responsible for securing your device.

6. Children's Privacy

QuizFuse is designed for use by educators and is not directed at minors. The Service does not require students to create accounts, interact with the application, or provide any personal information.

We do not knowingly collect personal information from minors. If you are an educator, do not input student-identifiable information (names, IDs, grades, etc.) into the Service. If you believe that a minor's personal information has been inadvertently submitted, please contact us so we can take appropriate action.

7. Student Data and Ontario Privacy Law

QuizFuse is not designed to process, store, or manage student records as defined under the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA), the Freedom of Information and Protection of Privacy Act (FIPPA), or the Personal Information Protection and Electronic Documents Act (PIPEDA).

  • The Service does not collect, receive, or store any student data.
  • Students do not interact with the Service directly.
  • No student names, grades, Ontario Education Numbers (OENs), or other personally identifiable information should be included in content you provide.
  • If you are a public sector institution subject to FIPPA or MFIPPA, or a private sector organization subject to PIPEDA, you are responsible for ensuring that your use of the Service complies with your institution's policies and applicable privacy legislation.
  • School boards and publicly funded educational institutions should consult with their privacy officer before using third-party services that process educational content.

8. Your Rights

8.1 General Rights

Because QuizFuse does not maintain user accounts or store personal data on our servers, traditional data subject rights (access, correction, deletion, portability) apply in a limited way:

  • Access and deletion of quiz data — your quiz data is stored in your browser. You can view it at any time and delete it by clearing your browser's local storage or using the delete function within the app.
  • Revoking Google access — you can disconnect QuizFuse from your Google account at any time through your Google account permissions. This immediately revokes our ability to create or modify Google Forms on your behalf.
  • Clearing cookies — you can delete your authentication cookies at any time through your browser settings, which will sign you out of the Service and remove stored Google tokens.

8.2 Rights Under PIPEDA (Canada)

Under the Personal Information Protection and Electronic Documents Act (PIPEDA), you have the right to access personal information an organization holds about you, to challenge its accuracy, and to request its correction or deletion. PIPEDA's ten fair information principles — including accountability, consent, limiting collection, and safeguards — guide our data practices.

Because QuizFuse does not store personal information on our servers, these rights primarily apply to data held locally in your browser (which you control) and data processed by our third-party sub-processors (Anthropic, Google, Vercel), whose own privacy policies govern their retention.

If you believe your privacy rights have been violated, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada or the Information and Privacy Commissioner of Ontario.

8.3 Rights Under FIPPA/MFIPPA (Ontario Public Sector)

If you are an employee of an Ontario public sector institution (such as a university, college, hospital, or provincial agency) governed by the Freedom of Information and Protection of Privacy Act (FIPPA), or of a municipal institution (such as a school board) governed by the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA), you should be aware that:

  • QuizFuse does not store personal information on its servers, which limits the applicability of access and correction rights under these acts.
  • Your institution may have policies governing the use of third-party cloud services. You are responsible for ensuring your use of QuizFuse complies with those policies.
  • Content you submit may be processed by servers located outside of Canada (see Section 10). Some institutional policies restrict the storage or processing of personal information outside of Canada.

9. Google API Services Disclosure

QuizFuse's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:

  • We only use Google user data to provide the quiz export functionality you request.
  • We do not transfer Google user data to third parties except as necessary to provide the Service (i.e., sending form data to Google's own APIs).
  • We do not use Google user data for advertising or marketing purposes.
  • We do not allow humans to read Google user data except where necessary to comply with applicable law, or with the user's affirmative consent for specific messages.

10. Cross-Border Data Transfers

QuizFuse is operated from Ontario, Canada. However, the Service is hosted on Vercel, whose infrastructure is located in the United States. Additionally, content you provide is transmitted to Anthropic (United States) for AI processing and to Google (United States) for quiz export.

As a result, your content may be processed outside of Canada in jurisdictions that may have different privacy laws. Under PIPEDA, organizations may transfer personal information to a third party for processing, but the transferring organization remains responsible for the information. We take reasonable steps to ensure that our third-party service providers maintain comparable privacy protections.

By using the Service, you acknowledge and consent to the transfer and processing of your data outside of Canada as described above. If you are subject to FIPPA, MFIPPA, or institutional policies that restrict cross-border data transfers, you should consult with your institution's privacy officer before using the Service.

11. Data Breach Notification

Because QuizFuse does not store personal data on its servers, the risk of a data breach affecting your personal information is minimal. In the unlikely event that a security incident affects encrypted tokens stored in cookies or our service infrastructure, we will:

  • Investigate the incident promptly
  • Notify affected users through the Service if feasible
  • Report the breach to the Office of the Privacy Commissioner of Canada as required under PIPEDA's mandatory breach reporting provisions, and to the Information and Privacy Commissioner of Ontario if applicable under FIPPA
  • Take immediate steps to mitigate the impact, including revoking compromised tokens

12. Do Not Track

QuizFuse does not track users across websites or over time. We honor Do Not Track (DNT) browser signals by default because we do not engage in any tracking. We also recognize the Global Privacy Control (GPC) signal, though our data practices already align with the opt-out it requests.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:

  • The updated policy will be posted on this page with a revised effective date.
  • For material changes, we will make reasonable efforts to provide notice through the Service.
  • Your continued use of the Service after changes are posted constitutes acceptance of the revised policy.

We encourage you to review this policy periodically.

14. Contact

If you have questions about this Privacy Policy, your data, or your rights, you can reach us at privacy@quizfuse.com.