Privacy Policy
Last updated: July 2026 · see note below
In short
- We don't sell your data, and we don't use it for advertising.
- We don't use your data to determine creditworthiness or for lending decisions.
- The Chrome extension records locally and only sends data when you explicitly export and submit it.
- You can request access to, correction of, or erasure of your data at any time.
Who we are
Colophon is built by the Functional Intelligence Research Lab (FIRL), based in the Netherlands. We haven't designated a Data Protection Officer; for any privacy question or request, contact hello@firl.nl.
Single purpose
Colophon's Chrome extension has one purpose: logging a student's own writing process (edits, pastes, and AI-assistant interactions) so it can be shown back to them and to their course instructor. Every category of data described below traces back to that one purpose; none of it is collected for anything else.
What we collect
- Waitlist & newsletter signups: email address, and, for the Colophon waitlist specifically, your name, organisation name, and role (teacher, researcher, other).
- Account data, if you sign in with Google: your Google account ID, email, name, and avatar; your role and organisation; and the OAuth access/refresh tokens needed to keep you signed in and to read Google Docs/Classroom content you explicitly connect. A timestamp is recorded when you confirm you're 16 or older; see "Age requirement" below.
- Course & assignment context a signed-in teacher sets up (course names, assignment metadata); used to organise dashboards, not to read your documents outside what you explicitly share.
- TWFF session files you choose to save while signed in, stored so
you can reopen them later. If you use the public viewer at
/viewerwithout an account, nothing is uploaded: the file is parsed entirely in your browser. - Billing for institutional subscriptions is handled by Stripe; we store a subscription reference, not your card details.
What we don't collect
The Chrome extension records locally on your device and only transmits data if you explicitly choose to upload or export. It does not capture keystrokes or full document text; see what gets recorded for exactly what each event type records, and what it deliberately never records.
Why we use it, and on what basis
Each purpose below has a legal basis under GDPR Article 13:
- Providing the product (dashboards, saved sessions, course context): necessary to perform our contract with you.
- Running the waitlist and beta program: necessary to take steps you requested before entering a contract.
- Responding to support requests: our legitimate interest in running a working product, balanced against your right to only be contacted about what you asked.
- Sending product updates: only with your consent, given separately from account creation; you can withdraw it at any time.
Who else sees it
We use two processors, each receiving only what it needs to do its job:
| Processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Sign-in, Docs/Classroom integration | United States | Standard Contractual Clauses | |
| Stripe | Institutional billing | United States | Standard Contractual Clauses |
We don't sell or share data with anyone for advertising, and we never use it to assess creditworthiness or make lending decisions.
Retention
Data is stored in the EU. Default retention is 2 years, configurable per organisation, and you can request erasure at any time by emailing hello@firl.nl.
Age requirement
Colophon is only available to users 16 or older, clearing both COPPA's age-13 threshold and GDPR's under-16 digital-consent age. Every account, whether newly created or already existing, is gated on a signup-time self-confirmation of age; we don't build or offer a parental-consent path for under-16 users, since they aren't permitted on Colophon at all. Anyone who confirms they're under 16 has their just-created account removed immediately and no data is kept.
Your rights
Under GDPR, you have the right to:
- Access the data we hold about you.
- Correct inaccurate data.
- Erase your data, including your account and TWFF files.
- Restrict or object to certain processing.
- Export your data in a portable format; your own TWFF files already are one.
- Withdraw consent at any time, where consent is the basis for processing.
- Lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens, or your own country's supervisory authority.
Contact hello@firl.nl for any of these requests.
Chrome Web Store
The use and transfer of information received from Google APIs by the Colophon extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements Consistent with that policy: we don't use or transfer this data for serving advertisements, we don't sell it, we don't use it to determine creditworthiness or for lending purposes, and the extension executes no remotely-hosted code; its behaviour matches what's in its submitted source.
Changes to this policy
If we make a material change, we'll update the date at the top of this page.