Skip to main content
← Back to ibacalao

iBacalao Privacy Policy

Last updated: 21 July 2026

Who we are

ibacalao is an AI-powered study platform for Diploma Programme students. It gives criterion-by-criterion feedback on Internal Assessments, Extended Essays, and Theory of Knowledge essays across all 25 subjects. It is an independent project and is not affiliated with, endorsed by, or connected to the International Baccalaureate Organization (IBO).

What we collect

  • Your email address — only if you choose to create an account. Providing your email is optional.
  • Your sign-in provider identity — if you sign in with Google, Apple, or Microsoft, we store the display name and email that your provider shares with us.
  • Your name, country, and school — only if you choose to provide them during onboarding. These are optional profile fields.
  • Your IP address — used temporarily to enforce daily review limits and prevent abuse. It is automatically deleted after 48 hours, and is stored only as an irreversible hash, never as a raw address.
  • Your review history — for signed-in users, we store your feedback results (scores, criteria, AI output) and an extract of your document text to power the history and annotation features. Up to 100 reviews are kept per account and are deleted when you delete your account.
  • CAS and coursework data — if you use the CAS tracker, study planner, or class tools, we store the content you enter (experiences, reflections, plans, assignments) to provide those features.
  • Optional feedback — if you submit a suggestion through the feedback form, we store the message you wrote.
  • Waitlist signups — if you join our pre-launch waitlist, we store your email, a randomly generated referral code and link, your queue position, and how many people you've referred through your link. This is used only to run the referral program and to notify you when we launch.
  • Referral reward redemptions — if you redeem a referral reward tier, we generate and store a one-time activation code linked to your account, the plan and duration it unlocks, and whether it has been used. The code is deleted once activated or after it expires.

Cookies

  • Session cookie (ib_session) — a strictly necessary cookie set when you sign in. It keeps you authenticated across page loads. No consent is required for this cookie as it is essential for the service to function.
  • OAuth state cookies — two short-lived cookies (oauth_state, oauth_return) set only during a Google, Apple, or Microsoft sign-in flow. They are deleted immediately after the flow completes.
  • Google Analytics cookies (_ga, _ga_*) — set by Google Analytics when you visit the site. They help us understand how pages are used. These load on every visit.
  • Meta analytics cookies (_fbp, _fbc) — set by the Meta Pixel only if you accept optional analytics in our cookie notice. These are not loaded if you decline.
  • Browser local storage — we store your Meta analytics consent preference so we do not ask again on every visit.

Site analytics

We use Google Analytics (Google) on all visits to measure traffic and page usage. Google may receive technical information such as your IP address, browser type, pages viewed, and approximate location. Page URLs are recorded without query strings where possible, so tokens in links (for example password-reset URLs) are not sent to analytics providers. We also use PostHog for product analytics (page views, feature usage, and error diagnostics) and Vercel Analytics for aggregate performance metrics. PostHog may record anonymised session replays with form inputs masked. Signed-in users may be linked to an analytics profile using their email address solely to understand product usage — never for advertising.

Optional Meta analytics

If you accept analytics in our cookie notice, we use the Meta Pixel to record basic events such as page visits. Meta may receive technical information such as your IP address, browser information and the page visited. We do not load the Meta Pixel if you decline. We do not send document contents, email addresses or other sensitive information to Meta through the Pixel.

Your submitted document

When you request feedback, your document text is sent to Anthropic (the makers of Claude) to generate your feedback. For signed-in users, an extract of that text may also be stored in your review history to power the annotation and history features. We never use your submissions to train AI models. If you use the plagiarism or AI-content detection features, your document text is also sent to Winston AI (gowinston.ai) for analysis.

Third-party services

  • Anthropic — our AI provider. Your document text is sent to Anthropic's API to generate feedback. Anthropic may log API requests per their own privacy policy.
  • Winston AI (gowinston.ai) — plagiarism checking and AI-content detection. Document text is sent to Winston AI only when you use those features.
  • Stripe — payment processing. When you purchase a plan or day pass, your payment details are handled by Stripe. We do not store card numbers.
  • Payphone — payment processing for supported regions. Same scope as Stripe.
  • Supabase — our primary database. Stores CAS data, class data, teacher and student records, and other structured content you create on the platform.
  • Upstash (Redis) — stores user accounts, sessions, review history, and rate-limit counters.
  • Neon — a separate database used only for the Creator Rewards Program (challenges, submitted video URLs, and payout records).
  • ScrapeCreators — used to verify TikTok and Instagram video view counts for creators whose submissions need an automated check beyond our own heuristics.
  • YouTube Data API — used to verify YouTube video view counts for the Creator Rewards Program.
  • PayPal — used to send cash rewards under the Creator Rewards Program. Your PayPal email address is shared with PayPal only to process that payout.
  • Vercel — our hosting provider. All web requests pass through Vercel's infrastructure.
  • Google Analytics — site traffic and page-usage measurement on all visits (see Site analytics above).
  • PostHog — product analytics, feature usage, and masked session replays. Page URLs sent without query strings.
  • Meta — marketing analytics cookies loaded only with your consent (see Cookies section above).

Referral reward data

  • What we collect. Your verified referral count, the highest reward tier you've claimed, and any activation code generated for a redeemed tier (which plan and duration it grants, and whether it has been used).
  • Why. This is used only to verify eligibility for referral rewards, prevent a tier from being claimed twice, and grant the correct plan duration when a code is activated.
  • Retention. A claimed-tier record is kept for as long as your account exists, so a lower tier can't be re-claimed after a higher one. An activation code is deleted immediately once used, or automatically after 90 days if never activated.

Creator Rewards Program data

  • What we collect. If you participate in the Creator Rewards Program, we store the video URLs you submit, the view counts and platform data we retrieve to verify them, your self-reported date of birth and country (used only to determine cash-reward eligibility), and — if you claim a cash reward — your PayPal email address.
  • Why. Date of birth and country are collected because U.S. law and our own program rules restrict cash payouts to adults resident in the United States; we do not use this data for any other purpose. View data is collected to verify rewards and prevent fraud.
  • Where it lives. Creator Rewards data is stored in a separate database (Neon) from the rest of your account data, access-locked to our application credentials only.
  • Retention. Challenge and submission records are kept for as long as needed to resolve a reward claim and to enforce the $500/person/year cash cap across calendar years, and are deleted on request subject to the payment-record retention period below where a payout was actually made.
  • First-time cash payouts. Before your first-ever cash payout, we ask you to verify your identity and US residency — for example with a government ID or your PayPal account's registered address. We only do this once per account, not on every payout.

Wearables pre-order data

  • What we collect. If you place a wearables hardware pre-order (Iris, Trace), we store your email, name, shipping address, order quantity, and price paid, plus a payment reference from PayPal or our crypto processor (never your full card or wallet details).
  • Why. Your shipping address is used only to fulfil and ship your order. Payment references are used to verify payment, process refunds, and prevent duplicate charges.
  • Refund and deletion requests. Submitting the refund-request or delete-account-request forms sends your email and message to our order-fulfilment inbox so we can act on it manually — see our Refund Policy and Delete My Data page.
  • Retention. Order and shipping records are kept for as long as needed to fulfil, ship, and support your order, and afterward for the payment-record retention period described above.

Security

  • All traffic is served over HTTPS with strict transport security (HSTS).
  • We apply a Content Security Policy (CSP) that restricts which scripts and connections the browser may load.
  • IP addresses used for rate limiting are stored only as irreversible hashes and deleted within 48 hours.
  • Session tokens are httpOnly cookies and expire after sign-out or 30 days of inactivity.
  • We do not sell personal data. Document text is never used to train AI models.

Desktop experience

The full product — including draft upload, PDF review, and teacher tools — is designed for desktop and laptop screens (768px width or wider). On smaller viewports you may see a message asking you to open the site on a desktop device.

Legal basis for processing

  • Contract (Art. 6(1)(b) GDPR) — feedback generation, account management, and subscription billing are necessary to perform the service you signed up for.
  • Legitimate interest (Art. 6(1)(f) GDPR) — we hash and briefly store IP addresses to enforce rate limits and prevent abuse. We use Google Analytics, PostHog, and Vercel Analytics to measure and improve the service. This is the minimum data needed to operate and protect the platform.
  • Consent (Art. 6(1)(a) GDPR) — Meta analytics cookies are only loaded if you explicitly accept them. You can withdraw consent at any time by clicking 'Necessary only' in our cookie notice or contacting us.

Data retention

  • IP address hash — deleted automatically after 48 hours.
  • Session tokens — deleted when you sign out, or after 30 days of inactivity.
  • Account data (email, name, profile) — kept until you delete your account.
  • Review history — up to 100 reviews stored per account, deleted when you delete your account.
  • CAS and coursework data — kept until you delete individual entries or your account.
  • Payment records — retained for 7 years as required by applicable tax and accounting law.
  • Creator Rewards data — challenge and submitted-video records are kept until you delete your account; paid cash-reward records are retained for 7 years as required by applicable tax and accounting law, same as other payment records.
  • Analytics data — aggregated usage data in Google Analytics, PostHog, and Vercel may be retained by those providers according to their own policies. Contact us if you want help exercising erasure rights with respect to analytics.

How we use your email

If you give us your email, we may use it to tell you about new features, product updates, and to occasionally ask for your feedback. We will never sell your email or share it with third parties for their marketing. Every email we send includes a way to unsubscribe, and you can opt out at any time.

If you are under 16

If you are under 16 (or the age of digital consent in your country), please get permission from a parent or guardian before submitting your email address or accepting optional analytics. If you are a parent or guardian and believe your child has provided personal data without consent, contact us at the address below and we will delete it.

Your rights

You can ask us to show you, correct, or delete any personal data we hold about you at any time. To do so, just email us. We will respond promptly.

Contact

For any privacy questions or requests, contact us at ibacalao [at] ibacalao [dot] com.

To delete your data, see delete my data. Service terms are in our terms of service.