Privacy Policy
Last updated: 31 August 2026
Who we are
LIBerico is an educational service for International Baccalaureate students, operated from Sweden through domains we control, including liberico.org. We are the data controller for your personal data under the General Data Protection Regulation (GDPR).
Contact: eric@liberico.org
Our role
When you create an individual account, use LIBerico directly, buy credits, book a session, or contact us, LIBerico decides why and how your data is processed and acts as data controller.
If LIBerico is provided to you through a school, teacher, or other organization under a separate written agreement, that organization may be the controller for some classroom or school-managed processing. In that case, LIBerico may act as processor and process the relevant data only under that organization's documented instructions and the applicable data processing agreement.
What data we collect
We collect only the data necessary to provide the service:
- Account: email address, sign-in method (Google or a one-time code sent by email), and, where provided, your name.
- Profile: role (student or teacher), approximate exam date, course (e.g. Español A: Literatura, English A: Literature, Spanish B), and starting level you enter during onboarding.
- Submissions and feedback: the literary texts and analyses you submit for correction, together with the AI-generated feedback (bands, comments, annotations, rewrites). These are saved in your history so you can review them.
- Oral practice and voice input (if used): audio you submit for the Individual Oral module — or record to dictate text — is uploaded to private storage, transcribed once, and then deleted immediately, whether or not the transcription succeeds. We do not keep the recording. Only the resulting transcript and, for the Oral module, its feedback are saved in your history.
- Teacher–student links (if used): if you join a class, we store the link between your account and your teacher's account.
- 1:1 sessions (if used): scheduling availability, session notes, and the email used to create the Google Calendar event.
- Payments (if used): purchase amount, credits purchased, Stripe Checkout session ID, Stripe payment reference, payment status, and credit transactions. LIBerico does not store full card numbers or card security codes.
- Technical usage data: number of AI requests and tokens consumed, credit usage, and product events such as when a feature is started or completed, to manage quotas, billing, product reliability, and operating costs.
- Security and server logs: our hosting, database, payment, and API providers may automatically process standard request information such as IP address, request URL, browser headers, timestamps, authentication status, and error logs so the service can run securely and reliably.
We do not use clear gifs or web beacons, Google Analytics, advertising cookies, remarketing, precise geolocation, or device fingerprinting.
How we use your data
- To provide the correction and educational feedback service.
- To display your evaluation history.
- To allow your teacher (if you join a class) to view your progress, only after your explicit consent.
- To enforce usage quotas, credit balances, payment status, and prevent abuse.
- To detect and fix technical errors.
- To manage session bookings where applicable.
- To send service-related notices, receipts, security messages, or legal notices.
We do not use your data for advertising. We do not sell or share it with third parties for commercial purposes.
Legal basis
We process personal data only where we have a lawful basis under the GDPR. Depending on the feature and context, this may include:
- Contract: to create and manage your account, provide corrections, store your history, manage credits and purchases, and deliver booked sessions.
- Legitimate interests: to keep the service secure, prevent abuse, debug errors, understand feature usage, improve the product, and respond to enquiries.
- Consent: where required for optional teacher access, certain communications, or future non-essential cookies or tracking technologies.
- Legal obligation and legal claims: where we must keep records, respond to lawful requests, comply with accounting or tax rules, or establish, exercise, or defend legal claims.
You are not required to provide personal data, but some data is necessary to create an account or use specific features. Without it, parts of LIBerico may not work.
When we share your data
We do not rent or sell your personally identifiable information. We share personal data only where necessary to provide, secure, support, or bill for LIBerico, or where required by law.
This includes sharing data with the sub-processors listed below, responding to valid legal requests, enforcing our Terms & Conditions, investigating suspected abuse or fraud, protecting the rights and safety of users, and handling a merger, acquisition, or similar business transition if LIBerico is ever transferred to another operator.
Third parties that process your data
We work with the following sub-processors to deliver the service:
- Anthropic (USA): the text you submit for correction is sent to the Claude API to generate feedback. Anthropic does not use API inputs to train its models by default. See their privacy policy.
- Supabase (USA / EU): stores your account, profile, and history in a PostgreSQL database with encryption at rest and in transit. See their privacy policy.
- OpenAI (USA): if you use the Individual Oral module, your audio recording is sent to OpenAI Whisper for transcription. OpenAI does not use API inputs to train its models by default. See their privacy policy.
- ElevenLabs (USA): if you use the Oral Simulator or the live Spanish B oral, your voice and the conversation transcript are processed by ElevenLabs Conversational AI to generate the examiner's voice responses. No camera is used or recorded — only audio. In the live Spanish B oral, your raw audio is also transcribed by OpenAI Whisper and the recording is deleted right after transcription. See their privacy policy.
- Google (USA): if you book a 1:1 session, we create a Google Calendar event with a Google Meet link. Only the student's email, the teacher's email, the session time, and a session title are shared with Google.
- Stripe (USA / EU): if you buy credits, Stripe processes the checkout, payment method, fraud checks, receipts, and related payment records. LIBerico receives payment status, session identifiers, amount, and credit-purchase metadata, but not your full card details. See Stripe's privacy policy.
- Google Fonts (USA): the app loads the Inter and Lora typefaces from Google's servers. Google may receive your IP address and browser headers when serving fonts. Google Fonts does not set cookies according to Google's documentation. See Google's privacy policy.
Transfers outside the EEA are protected by appropriate safeguards, such as European Commission adequacy decisions, Standard Contractual Clauses approved by the European Commission, and equivalent contractual and technical safeguards adopted by the relevant provider.
How we protect your data
Authentication is handled by Supabase Auth through Google or time-limited email codes. Personal data is kept in databases protected by row-level security, access controls, encryption in transit, and provider-managed infrastructure security. Administrative access is limited to people who need it to operate and support LIBerico.
No online service can guarantee perfect security. You can reduce risk by keeping your email and Google accounts secure, never sharing one-time verification codes, keeping your device and browser up to date, and contacting us immediately if you believe your account has been accessed without permission.
How long we keep your data
We keep your data for as long as your account is active. If you delete your account from Account settings, we permanently delete your account profile, evaluation history, bookings, credit purchase records, and associated educational content from the active application database. Product-event records may remain in anonymized or aggregated form where they are no longer linked to your account. Technical security logs and provider backups may be retained for a limited period, normally no more than 90 additional days, for operational security and recovery reasons.
Audio submitted for oral practice or voice input is never stored persistently. It is deleted from our storage immediately after it is transcribed, whether or not the transcription succeeds; only the resulting text is kept.
Aggregated or irreversibly anonymized information that no longer identifies you may be kept for product analysis, statistics, and service improvement.
Your rights
Under the GDPR you have the right to:
- Access the data we hold about you (your history is visible directly in the app).
- Rectify incorrect data by emailing us.
- Delete your account and all your data from Account settings.
- Restrict or object to processing by emailing us.
- Portability — receive a copy of the data you have provided to us in a structured, machine-readable format by emailing us.
- Withdraw consent at any time where processing is based on consent. This does not affect processing that happened before withdrawal.
- Not be subject to solely automated decisions that produce legal or similarly significant effects, unless permitted by law with appropriate safeguards.
- Lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, imy.se) or your local EU/EEA data protection authority.
To exercise any of these rights, email us at eric@liberico.org. We will respond within 30 days.
We may need to verify your identity before acting on a request. We may refuse or limit a request where the law allows this, for example if a request is manifestly unfounded, excessive, repetitive, or would adversely affect another person's rights.
AI-generated feedback
LIBerico uses AI models (Claude by Anthropic, and others) to generate practice feedback on your work. This feedback is educational support designed to help you improve your IB writing and oral skills — it is not official IB grading, not a prediction of your final IB score, and not a legally or significantly binding automated decision about you.
AI feedback can be incomplete or incorrect. You should always review it critically and discuss it with your teacher. LIBerico makes no guarantee of any particular exam outcome.
Marketing communications
We do not currently send advertising newsletters or third-party marketing. If we introduce optional marketing emails in the future, we will do so only where permitted by law and will provide a clear unsubscribe or opt-out mechanism.
Minimum age
LIBerico is designed for IB students. Users must be at least 13 years old to use the service independently. In EU countries where the minimum age for digital services is higher (up to 16 years, depending on national law), users below that age require parental or guardian consent before creating an account.
If you are a parent or guardian and believe your child has created an account without the required consent, please email us and we will delete it promptly.
Security incidents
If we become aware of a personal data breach that is likely to affect your rights or freedoms, we will notify the relevant supervisory authority where required by law and, where feasible, within 72 hours of becoming aware of the breach. We will notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
Cookies and local storage
LIBerico does not use tracking cookies, third-party analytics, or advertising cookies. For full details, see our Cookie Policy.
External links
LIBerico may link to third-party websites, policies, documentation, or services. When you leave LIBerico, the privacy practices of the third-party site or service apply. We are not responsible for the content, security, or privacy practices of external sites.
UK users
If you are located in the United Kingdom, we also handle your personal data in accordance with the UK GDPR and the Data Protection Act 2018 where they apply. International transfers from the UK are protected using UK adequacy regulations, International Data Transfer Agreements, or UK addenda to Standard Contractual Clauses where required.
UK users may complain to the Information Commissioner's Office (ICO) if they believe their data protection rights have been infringed, without affecting any right to seek a judicial remedy.
Changes to this policy
If we make material changes, we will notify you by email at least 30 days in advance. Continued use of the service after that date constitutes acceptance of the updated policy.