School Draw Privacy and Data Handling Statement

Quick Summary: School Draw is a client-side web application. All drawing operations happen locally in your web browser, and you have complete control over where your drawings are saved. To access the full drawing toolset, you must sign in with a Google or Microsoft account — this allows us to verify your authorised access. We do not store your drawings on our servers, but we do process your email address to verify access, as described below.

1. Data Controller Information

Application Name: School Draw

Purpose: A web-based SVG drawing tool designed for simple, accessible drawing and illustration

Data Controller: Shuistyle

Contact: hello@schooldraw.net

Last Updated: 10 March 2026

2. What Data We Collect and Process

2.1 Data You Create

Data TypeWhat It IncludesWhere It's StoredLegal Basis (GDPR)
Your DrawingsSVG files containing your artwork, shapes, text, and coloursYour web browser's local storage, your device, or your chosen cloud storageConsent / Legitimate Interest
Drawing MetadataFilename, timestamp of creation/modification, background colourEmbedded in your SVG files and browser storageConsent / Legitimate Interest
Application PreferencesAuto-save settings, last save locationYour web browser's local storageLegitimate Interest

2.2 Authentication Data (Required to Access Auth-Gated Tools)

Signing in with Google or Microsoft is required to access the full drawing toolset. Authentication also enables cloud storage saving. When you sign in, we process:

Data TypeWhat It IncludesPurposeWhere It's StoredLegal Basis
Google Account InformationName, email address, profile picture, OAuth access tokenTo authenticate you and access your Google DriveYour browser's local storage (temporary)Consent
Microsoft Account InformationName, email address, profile picture, OAuth access tokenTo authenticate you and access your OneDriveYour browser's local storage (temporary)Consent
Cloud Storage FilesYour SVG drawings saved to Google Drive or OneDriveTo save and retrieve your drawingsYour Google Drive or OneDrive accountConsent
Important — Google tokens: Your Google OAuth access token (which grants access to Google Drive) is stored temporarily in your browser and is used only to communicate directly with Google's APIs. It is never sent to our servers. This is required by Google's API Services User Data Policy.

Important — Microsoft tokens: Your Microsoft access token is temporarily transmitted to our Firebase Cloud Function ( checkAccessWithProviderToken ) solely to verify your identity and check whether your email address is authorised to use School Draw. The token is used to retrieve your email address from Microsoft Graph and is not stored on our servers.

3. How We Use Your Data

3.1 Client-Side Drawing; Server-Side Access Verification

School Draw separates two distinct concerns:

3.2 Specific Uses

4. Where Your Data Is Stored

4.1 Browser Local Storage

When you save drawings to "Browser Storage," your data is stored in your web browser's local storage using the localStorage API. This data:

4.2 Device Downloads

When you save drawings to your device, files are downloaded directly to your chosen location on your computer, tablet, or phone. We have no access to or record of these files.

4.3 Cloud Storage (Google Drive / OneDrive)

When you choose to sign in and save to cloud storage:

5. Data Retention

Data TypeRetention PeriodHow to Delete
Browser-Stored DrawingsUntil you delete them or clear your browser dataUse the application's delete function or clear browser storage
Authentication Tokens55 minutes (Google), or until you sign outSign out of the application or clear browser storage
Auto-Save PreferencesUntil you change them or clear browser dataClear browser storage or toggle settings
Undo/Redo HistoryCurrent session only (lost when you close the tab)Automatically cleared when you close the browser tab
Cloud-Stored DrawingsUntil you delete them from your Google Drive or OneDriveDelete files directly from your Google Drive or OneDrive account

6. Data Sharing and Third Parties

6.1 No Server-Side Data Sharing

Because School Draw operates entirely in your browser, we do not share your data with any third parties through our servers.

6.2 Third-Party Services (When You Choose to Use Them)

If you choose to sign in and use cloud storage integration:

Google Services

Google API Services User Data Policy: School Draw's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy , including the Limited Use requirements. Specifically: data obtained via Google APIs is used only to provide and improve School Draw's features; it is not used for advertising; it is not shared with third parties except as necessary to operate the service; and it is not used for purposes unrelated to the application.

Microsoft Services

Firebase (Google Infrastructure)

6.3 No Analytics or Tracking

School Draw does not use:

7. Your Rights Under UK GDPR

Under UK GDPR, you have the following rights regarding your personal data:

RightWhat It MeansHow to Exercise
Right of AccessYou can request a copy of your personal dataAll your data is stored locally in your browser or cloud storage - you can access it directly at any time
Right to RectificationYou can correct inaccurate dataEdit your drawings directly in the application or update your account information with Google/Microsoft
Right to ErasureYou can request deletion of your dataDelete drawings from browser storage, cloud storage, or clear your browser data. For authentication data, sign out or revoke app permissions in your Google/Microsoft account
Right to Restrict ProcessingYou can limit how your data is usedDon't sign in to use cloud features; use only browser storage or device downloads
Right to Data PortabilityYou can obtain and reuse your dataDownload your drawings as SVG files at any time from any storage location
Right to ObjectYou can object to certain processingDon't use optional features like cloud storage integration
Rights Related to Automated Decision-MakingProtection against automated decisionsNot applicable - School Draw does not make automated decisions about you

8. Data Security Measures

We implement robust security measures to protect your data:

8.1 Technical Security

8.2 Data Minimisation

8.3 Storage Limitations

9. Cookies and Similar Technologies

9.1 Strictly Necessary Storage

School Draw uses browser local storage (not cookies) for essential functionality:

Note: Browser local storage is similar to cookies but is not transmitted to any server with every request. It stays on your device and is only accessible by the School Draw application.

9.2 Third-Party Cookies

Google and Microsoft may set their own cookies when you use their authentication services. These are governed by their respective privacy policies.

9.3 No Tracking Cookies

We do not use any advertising, analytics, or tracking cookies.

10. Children's Privacy

School Draw is designed to be accessible to users of all ages, including children. We take children's privacy seriously:

10.1 Protection for Young Users

10.2 Parental Guidance

We recommend that:

11. International Data Transfers

11.1 Client-Side Processing

Because School Draw operates entirely in your browser, your data is not transferred internationally by our application.

11.2 Cloud Storage Transfers

If you choose to use Google Drive or OneDrive:

12. Data Breach Notification

12.1 Our Responsibilities

In the unlikely event of a data breach affecting our application:

12.2 Limited Risk

Because School Draw does not collect or store your data on our servers, the risk of a data breach affecting your information through our systems is minimal. Your primary data security depends on:

13. Changes to This Privacy Statement

We may update this Privacy Statement from time to time to reflect:

13.1 Notification of Changes

When we make significant changes:

13.2 Reviewing Changes

We encourage you to review this Privacy Statement periodically to stay informed about how we protect your data.

14. Your Consent

14.1 Accessing School Draw

To use School Draw's drawing tools, you must sign in with Google or Microsoft. By doing so, you consent to:

14.2 Using Cloud Storage Features

When you sign in with Google or Microsoft, you explicitly consent to:

14.3 Withdrawing Consent

You can withdraw your consent at any time by:

15. Complaints and Supervisory Authority

15.1 Contact Us First

If you have concerns about how we handle your data, please contact us first using the details at the top of this document. We will do our best to resolve any issues promptly.

15.2 Right to Complain

You have the right to lodge a complaint with the UK's supervisory authority:

Information Commissioner's Office (ICO)
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF

Phone: 0303 123 1113
Website:https://ico.org.uk
Report a Concern:https://ico.org.uk/make-a-complaint/

16. Legal Basis for Processing

Under UK GDPR Article 6, we process your data based on:

Processing ActivityLegal BasisExplanation
Processing your drawingsConsent / Legitimate InterestYou choose to create drawings and save them
Storing drawings in browserConsentYou choose to save drawings to browser storage
Authentication with Google/MicrosoftConsentYou explicitly sign in to use cloud features
Saving to cloud storageConsent / ContractYou choose to save files to your cloud storage
Storing application preferencesLegitimate InterestNecessary to provide you with a consistent user experience
Security measures (input sanitisation)Legitimate InterestNecessary to protect you and other users from security threats

17. Accessibility of This Statement

We are committed to making this privacy statement accessible to all users:

18. Additional Information for Specific Users

18.1 Educational Institutions

If School Draw is used in schools or educational settings:

18.2 Business/Professional Users

If you use School Draw for business purposes:

Document Version: 1.2
Last Updated: 10 March 2026
Next Review Date: March 2027
Legal Framework: UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018

Questions or Concerns?

If you have any questions about this Privacy Statement or how we handle your data, please contact us at:

Email: hello@schooldraw.net

We aim to respond to all enquiries within 30 days.