Privacy Policy

In force since 28 August 2026. Last updated: 28 August 2026.

This policy explains what personal data EconDoctor collects, why, who it is shared with, how long it is kept, and what you can ask us to do with it. It applies to www.econdoctor.com and to every tool hosted on it (EconWizard, Internal Assessment and Extended Essay analysis, glossary games, quizzes, revision plans).

We apply the standard of the EU General Data Protection Regulation (GDPR) to every user, wherever you live. Users in Switzerland are additionally covered by the Swiss Federal Act on Data Protection (FADP), and users in the United Kingdom by the UK GDPR.

1. Who is responsible

The data controller is Dr Sylvain Hours, an individual operating EconDoctor on his own, domiciled in Switzerland.

Contact for anything in this policy, including to exercise your rights: admin@econdoctor.com. We answer within one month.

There is no Data Protection Officer: the size and nature of the processing do not require one under Article 37 GDPR.

2. What we collect

2.1 Data you give us

  • Account: first name, last name, email address, password (stored only as a bcrypt hash, never in clear text), account type (student or teacher), and the teacher or group you are linked to.
  • Work you submit to the tools: Internal Assessment and Extended Essay drafts, research questions, uploaded files, exam answers, scanned answer sheets, quiz and game answers, revision plans.
  • Messages you send us by email or through the contact page.

2.2 Data created by your use of the site

  • Account activity: registration date, last sign-in, coin balance and the log of coin debits and credits, scores and progress in the games.
  • Server logs: IP address, browser and operating system, pages requested, date and time. Kept for security and diagnostics.
  • Account security journal: account and administrator identifiers, sign-in attempts and their outcomes, security changes, sampled authenticated page accesses, IP address, browser information, and date and time. Only authorised administrators can consult the journal to investigate account security.
  • Anti-abuse counters: IP address and attempt counts on sign-in, registration and password reset.
  • Cookies: see the Cookie Policy.

2.3 Payment data

Coin purchases are handled by Stripe. We never see or store your card details. Our database keeps only the record of the transaction: Stripe session and payment identifiers, amount, currency, status, the email you used, and the number of coins credited.

2.4 What we do not do

We do not sell or rent personal data. We do not run advertising or profiling for advertising. We take no decision producing legal effects about you by automated means alone (Article 22 GDPR). We do not deliberately collect special category data (health, religion, political views); please do not put any into the tools.

3. Why we process it, and on what legal basis

PurposeLegal basis (Art. 6 GDPR)
Create and run your account, deliver the tools you ask for, credit and debit coins Performance of a contract
Send service emails: verification, password reset, purchase receipt, notice that an analysis is ready Performance of a contract
Keep the site secure: anti-abuse rate limits, reCAPTCHA on sign-in and registration, server logs, backups Legitimate interest in protecting the service and its users
Fix bugs and improve the tools Legitimate interest in running a working service
Audience measurement (Google Analytics) Your consent, given in the cookie banner and withdrawable at any time
Occasional email updates about EconDoctor Our legitimate interest in keeping the people who hold an account informed about the service they signed up for. You can object at any time, with the unsubscribe link in every message or in your settings
Keep accounting records of payments Legal obligation (Art. 958f Swiss Code of Obligations)

4. Who your data is shared with

We use the following processors. Each one only receives what its job requires, and none of them may use your data for their own purposes.

ProviderRoleWhere
Hetzner Online GmbH Hosting of the site, the database and the uploaded files Servers in Helsinki, Finland (EU). Company in Germany (EU)
OpenAI Runs the AI analysis of the work you submit (essays, drafts, exam answers, uploaded files) Ireland (EU) and United States
Stripe Payments Europe Ltd Payment processing for coin purchases Ireland (EU), with transfers to the United States
Google Ireland Ltd reCAPTCHA (bot protection on sign-in, registration and password reset) and, only with your consent, Google Analytics Ireland (EU), with transfers to the United States
Hostinger Outgoing email server and domain name European Union

We may also disclose data where the law requires it, or to establish or defend a legal claim.

Signed-in users can request an export or deletion through Account data. Each request has a reference and a tracked status. We aim to review requests within 30 days. Exports are available for 7 days by default through a private download. Information about another person and unavailable files need a separate review; the export manifest records omissions. Payment and shared-record retention is recorded separately from personal-content cleanup. Keep your request reference for support after account access ends.

4.1 What OpenAI receives, and what it may do with it

When you run an AI analysis, the text or file you submitted is sent to OpenAI to produce the result. Under the OpenAI API terms, your content is not used to train their models. OpenAI keeps a short-lived copy for abuse monitoring, and files you upload stay on their side until they are deleted. When you delete a draft, or an approved account deletion is processed, we record deletion tasks for the associated files. These tasks retry if the storage service is unavailable. We confirm cleanup after the tasks succeed; processor retention outside the uploaded file service is handled separately.

If you would rather no third party ever sees a piece of work, do not put it into the AI tools. The rest of the site works without them.

5. Transfers outside the EU and Switzerland

The site and its database sit on servers in Finland, inside the EU. Some of the processors above are American groups: those transfers rely on the European Commission's Standard Contractual Clauses and, where the provider is certified, on the EU-US Data Privacy Framework, together with the technical and organisational safeguards in their data processing agreements. You may ask us for a copy of the safeguards that apply to a given transfer.

6. How long we keep it

DataRetention
Account and profile For as long as the account exists. Anonymised when an approved deletion request is processed; sign-in access then ends
Drafts, uploads, essays and answers Until removed through the relevant tool or an approved account deletion. File cleanup is queued and verified. Shared educational records may be retained for a documented reason with a review date
Inactive accounts Reviewed for accounts with no sign-in for 3 years. The inventory does not automatically delete accounts; a separate reviewed decision is required
Web server logs (IP, user agent, pages) 14 days, rotated daily
Application logs 8 weeks
Account security journal 8 weeks, with automatic daily deletion of expired entries
Anti-abuse counters A few hours
Email verification and password reset tokens Until used, or until they expire
Payment and accounting records 10 years, as required by Swiss accounting law
Cookie consent record 6 months, then we ask you again
Database backups The active rolling rotation targets 14 days. Older historical archives are reviewed separately; a deletion does not silently purge them. Erasure records must be reapplied before restoring service from an older backup

7. Your rights

You may at any time ask us to:

  • Access the personal data we hold about you, and get a copy of it;
  • Correct anything inaccurate or incomplete;
  • Delete your data (you can do this yourself: Settings then Delete my account);
  • Restrict or object to processing based on our legitimate interest;
  • Receive your data in a portable, machine-readable format;
  • Withdraw your consent at any time, for cookies through the banner and the Cookie preferences button on the Cookie Policy page, and for emails through your settings or the unsubscribe link in any message. Withdrawing does not undo what was lawfully done beforehand.

Write to admin@econdoctor.com. We may ask you to confirm your identity if the request comes from an address we do not recognise.

You also have the right to complain to a supervisory authority: the data protection authority of your country of residence in the EU (in France, the CNIL, www.cnil.fr), the ICO in the United Kingdom, or the FDPIC in Switzerland (www.edoeb.admin.ch).

8. Security

The site is served over HTTPS only, with HSTS and a content security policy. Passwords are hashed with bcrypt. Sessions use a cookie that is HttpOnly, Secure and SameSite. Files you upload are stored outside the public web root and are served only to the account they belong to. The database is backed up daily. No system is perfect, but if a breach ever put your rights at risk, we will notify you and the competent authority as Articles 33 and 34 GDPR require.

9. Children

EconDoctor is meant for users aged 16 and over. If you are under 16, you may use it only with the permission of your parent, guardian or school, and they must be the ones to accept these terms for you. We do not knowingly collect data from children under 13. If you believe a child has an account here, write to admin@econdoctor.com and we will delete it.

Teachers who invite students to the platform are responsible for making sure they may lawfully do so under their school's own rules.

10. Changes

We will update this policy when the site changes. The date at the top always tells you which version is in force. If a change materially affects your rights, we will announce it on the site, and by email where that is appropriate.

11. Contact

Any question about this policy: admin@econdoctor.com. See also the Legal Notice, the Cookie Policy and the Terms of Service.