What we handle, and what we don't.
The short version
ScholarVera's tools are built to avoid collecting student work. WriteSight stores its record inside your own document, not on our servers. InForm checks your paper on your own machine, and when it verifies a source it sends only the reference entry, never your prose. We collect the basics needed to run accounts, your email and sign-in, and we are specific below about exactly what that means. Our website sets no cookies and runs no trackers.
Who we are
ScholarVera LLC ("ScholarVera," "we," "us") is an academic-integrity software company based in Oklahoma, United States. We make two Microsoft Word add-ins: WriteSight, which records how a document was written, and InForm, which checks a paper against APA 7 and verifies whether its cited sources can be found.
This policy covers both tools, the accounts that let you sign in to them, and this website. Where a behavior differs between tools, we say so.
Our core commitment
We design our tools to minimize the student data we touch. Wherever a feature can work without us collecting or storing your writing, that is how we build it.
This is not only a privacy stance, it is how the tools are engineered. It is the reason WriteSight keeps its record inside your document rather than on a server, and the reason InForm runs its checks on your machine and never asks for the body of your work. The main data we hold is the account that signs you in, covered in its own section below; we describe the other limited information we may receive throughout this policy.
WriteSight (Word add-in)
What it records
WriteSight observes how a document is constructed while you write, patterns of typing, pasting, and revision over time, and assembles that into a "provenance record." This record is meant to give faculty context for a conversation about the writing process. It does not capture the meaning or content of what you write as something we receive; it describes how the document came together.
Where that record lives
The provenance record is stored inside the .docx file itself, in a dedicated part of the document. It travels with the file. When you submit your document, the record goes wherever the document goes, to your learning management system or to your instructor, exactly like the rest of the file's contents.
Under the standard WriteSight workflow, ScholarVera does not receive this record. Because it lives inside your document and not on our servers, we do not collect it or store it centrally. It is shared only when you share the document itself, most often with an instructor reviewing submitted work.
Tamper-evidence
The record includes integrity protection so that later alteration can be detected. This protection operates within your document and your signed-in session; it does not involve sending your writing to us.
Who can see the record
Anyone you give the document to, using compatible software, can view the provenance record, most commonly an instructor reviewing submitted work. ScholarVera is not a party to that exchange.
InForm (Word add-in)
What it does
InForm checks your document against APA 7 formatting conventions, reconciles your in-text citations with your reference list, and verifies whether the works you cite can be found in the scholarly record. It is read-only in the sense that it never changes your writing; the only thing it can add to your document is a comment, and only when you choose.
Where the checks run
The formatting and citation checks run on your own machine, inside Word. Your document is not uploaded to us and we do not keep a copy of it.
Source verification
To confirm that a cited work exists, InForm sends the reference entry (for example, an author, title, year, and DOI) to ScholarVera's verification service, which looks it up across scholarly databases and resolvers. It sends only the reference entry, never the body of your paper and never your prose. The service may query external sources such as Crossref, OpenAlex, ERIC, Google Books, Open Library, DOI resolvers, retraction and correction records, and, for web sources, the live page and public web archives. It caches public bibliographic facts about works, which are not linked to you or your document, so repeat lookups are faster.
Usage information
InForm may collect aggregate, de-identified usage counts to understand how the tool performs and where it can improve, for example the number of findings of a given type. These counts contain no document text, no titles, no author names, and nothing that identifies you or your document. As with any hosted service, our infrastructure also processes standard technical data such as request logs, noted below.
During the InForm beta, participants sign in and the tool additionally records limited beta information tied to your account: your selected role (for example, faculty or student), your answers to optional short surveys, and, if you ask to be notified when the trial ends, the email address you provide for that purpose. This helps us run and improve the beta.
Accounts and authentication
Using WriteSight and InForm requires signing in, so the tool can confirm you are an authorized user and run in the right mode. Account and access information is our primary persistent record about you, so we are specific about it. We may also receive the limited beta, support, signup, usage, and technical information described elsewhere in this policy.
What we collect for your account
- Your email address and an authentication credential, which you provide to create and access your account. Authentication is handled by Supabase on our behalf, and ScholarVera does not receive or store your password in readable form.
- Your entitlement, the record that your account has been granted access, and in which role. This tells the add-in which mode to open in.
- Basic sign-in activity needed to operate the service securely, such as when an access token was issued.
How sign-in works
Authentication is handled through Supabase, a third-party platform we use to manage accounts and access securely on our behalf. Your email and password are processed by Supabase to verify you. When you sign in, the add-in receives a short-lived access token that identifies your account and role; that token is what lets the tool run. We do not see your password in readable form.
What we do not tie to your account
Your account confirms who you are and what access you have. It is not a store of your writing. WriteSight's provenance record still lives inside your document, and InForm's checks run on your machine. Signing in does not send us the text of your work.
This website
Our website, scholarvera.com, is deliberately restrained. We set no cookies and run no advertising or cross-site trackers, and we do not build a profile of the people who visit us. If we use analytics at all, it is a privacy-preserving, cookieless measure of aggregate traffic that does not identify individual visitors.
If you submit your email through a signup form on the site (for example, to join the InForm beta list or to ask about a WriteSight pilot), we store your email address and which product you asked about, so we can contact you about that. We do not sell or share these lists. You can ask us to remove you at any time by emailing us.
Information we collect to run the service
Operating any software involves some limited data. To be straightforward about it:
- Account data, as described in the accounts section above.
- Aggregate, de-identified usage counts from InForm, as described above, which contain no writing and nothing that identifies you.
- Basic technical and service data. Like most hosted services, our infrastructure may process standard technical information, such as request logs, needed to run, secure, and troubleshoot the service.
- What you send us directly. If you email us for support or fill out a form, we receive what you send.
Third parties we rely on
We keep our list of third parties short and purposeful:
- Supabase, for account sign-in and the limited account and beta data described above.
- Scholarly databases and resolvers (such as Crossref, OpenAlex, ERIC, Google Books, Open Library, and DOI resolvers), which receive a reference entry when InForm verifies a source.
- Hosting and infrastructure providers that serve this website and our services.
We do not sell your personal information, and we do not share it with advertisers.
How we protect data
We use reasonable administrative, technical, and organizational safeguards appropriate to the limited data we handle, including encrypted connections for data in transit. No system is perfectly secure, and part of our approach is simply to hold as little as possible in the first place.
Retention and your choices
We keep account data for as long as your account is active, and signup emails until you ask us to remove them or they are no longer needed. Reference lookups are processed to produce a result and are not retained as a history against you. You may ask us to access or delete the personal data we hold about you, or to remove you from a signup list, by emailing us at the address below.
Education and institutions
Our tools are made for higher education and are not directed to children under 13. Because WriteSight keeps its record in the document and InForm runs on your machine, the amount of student data we hold is intentionally minimal. When an institution provides or manages access, it may determine the purposes for which certain account or service data is processed, and we process that data under our agreement with the institution and applicable education and privacy requirements.
Changes to this policy
We may revise this policy as our products evolve. When we do, we will update the version and effective date at the top. For material changes to how we handle personal information, we will provide notice appropriate to the change, which may include notice in the product, by email, or through an institutional administrator, and where required we will seek consent before applying materially different uses to information already collected.